Sometimes a short comment is that's warranted.
Sometimes a short comment is that's warranted.
1) your blog will have to use their URL structure, /post/:id/:slug . But who is really bugged by that? Seems a sane structure to me.
2) fact. If disqus comments are a showstopper for you, you've got to find a different service.
3) fact, but I see that as a positive, not a negative. Why in the world do you want your themes running native code?
4) Tumblr has static pages with arbitrary URLs. Here's a screenshot of the interface: http://img.skitch.com/20100507-edeg31uwc25t9hkumww2j9hk4b.jp...
Tumblr has a great bookmarklet, a good iphone app, a good community, reasonable uptime, and a good admin and customization interface. I don't recommend their group blogs, though I have several, but I highly recommend their service for one person.
Good to know about the pages.
One other issue is file uploads. Say I want to host my CV at domain.com/CV.pdf. I don't think I could do that with Tumblr. Is that too much to ask?
When I was freelancing I used to get a lot of requests like this: I want blog/comments/sharing, image gallery, video, and --insert business specific thing here--.
And Wordpress and its plugins make this easy(ier).
1) upload the pics to flickr 2) use jquery to grab the pics 3) make a static page to display them
Also, because it's clear that their service is designed for single-person blogs, their group blogs have some annoyances that range from minor to severe.
That's why nobody's "solved" this problem in the last ten years; you can't have programming language flexibility without programming language complexity.
Need, no. Want? Yes. Literally "infinite"? No. But variable beyond belief? Yes.
Elsewhere in the thread, you complain about hardcoded URL structures! That's pretty far out there on the "I demand customizability!" front, if you consider the horrible things that will do to your platform's internals. Random users running code in their templates, another feature you request, implies that we need to sandbox and resource limit the templates, if we also want to maintain the ability to have "cheap" hosting (which breaks if our users start writing infinite loops into their templates). (Sorry, did I say "if"? I meant "when".) Take your needs, and two other customers with the same level of detailed desires, but different desires, take the union of them, and you've got a freaking complicated product spec'ed out. One that, incidentally, is going to be pretty complicated to actually customize. Oh, and the odds of it suffering the classic "endless interacting-feature bugs because nobody ever said no to a feature" is basically 100%.
I mentioned more of our features below: http://news.ycombinator.com/item?id=1328512
Apache => Nginx
Sendmail => Postfix
Wordpress => _______
That is room for an enterprising open source developer.
I don't trust Sendmail but there's an emotional component to that; I would have laughed at you for using it in 1999, but I think 2 decades of analysis has to produce some result.
There's something more going on with Wordpress than simple complexity.
Apache doesn't have security issues at all like Wordpress, you are confusing FLEXIBILITY with INSECURE software.
Even if Wordpress didn't have security issues there'd be room for an nginx of blogging.
The problem is that everyone needs a different 20% customized. This is what Joel Spolsky basically argues in Bloatware and the 80/20 Myth: http://joelonsoftware.com/articles/fog0000000020.html . He's talking about desktop software, but you can see the same essential thing in blogging software; I'm using Wordpress for Grant Writing Confidential at http://blog.seliger.com chiefly because it has everything I want and is easy to use.
The extra stuff I use includes themes and a couple of plugins, like one for generating an XML sitemap and another for cacheing. I know that blogging platform X probably has the particular set of features I need -- until I find something that it can't do.
We have rich blogging features that are on par or better than most blog systems: create posts, edit your side bar, set catgories, human-readable (and adjustable) URLs, commenting, comment moderation (open/moderate/closed), close commenting after x days, post in the past, set time zones, post drafts, private drafts, etc.
Even better, a blog doesn't have to be the focus of your site -- it can be just a page. You can create other pages to put things like pictures, videos, photo galleries, slide shows, maps -- by just dragging and dropping them on. You can even create custom forms and surveys by dragging on the form elements (name, address, phone number, drop downs, etc)
While you can't upload PHP, you do have full customizability over your theme CSS and HTML.
To top it off, your site is hosted free of charge on our robust infrastructure that's machine and geographically redundant. We serve sites that hit the front page of Digg or the NYT every day and don't even see a blip in our traffic graphs :)
Is there an export option? I would have to be locked into using your guys just to see your company fail (and you don't seem to have a way to do revenue, esp. when you won't put ads on the blogs)?
Is there a way for me to host blog._somedomain_ with you, I would rather not make my blog the focus of the domain...
First, our company won't be going under any time soon -- while 95% of the features are free, there are an extra 5% available to power users as part of our "pro" package for ~$4/month. We also sell domains. We're strongly profitable, so you don't have to worry about us going under :)
But should you choose, you can export your site as a .zip file and host it somewhere else.
Also, you can choose from either a .weebly.com subdomain or point either your domain.com or blog.domain.com to us -- in either case, we'll still host your site free of charge.
based on django btw
One never seems to be touched, the other seems to have gotten a high spot on some l44t hax0r's list and is exploited just about every time there a security flaw is discovered. It's annoying to say the least.
Slowly over the years I've been moving everything that I don't absolutely have to host off shared hosting or VPS's and onto hosted services (I love Tumblr) that allow backups/exports. In my experience, it's just not worth the headaches to self-host things like blogs.
* It's written in PHP, a platform on which "remote file inclusion" vulnerabilities --- where attackers can source code to run on the server from MySpace --- continue to be found. I hesitate to bring this up, since (for instance) the last public vBulletin flaw that would have cost you your site goes back to 2008.
* It has an authentication design that uses the same database tables to track administrators who can run code on the site and anonymous Internet commenters.
* It has a template language that allows graphic designers to write templates that run code on your server.
* It hand-codes SQL statements largely out of concatenated queries.
* It is internationalized but has no coherent strategy for dealing with character sets and input filtering, on which it relies heavily, resulting in relatively recent vulnerabilities enabled by for instance UTF-7 inputs.
* It includes in the admin interface an editor for site templates that amounts to a remote login to the server, since, again, templates can run code.
* It has a vibrant community of plugins implemented by people who know exactly enough PHP to get their code working, which means every one of these flaws is repeated for every plugin developer.
Everything that you just mentioned, at best, protects the server environment from Wordpress vulnerabilities -- and that's assuming that a novice could set up a dedicated server as tightly as good hosting companies set up shared hosts.
None of your recommendations do anything to make Wordpress itself any safer, and if the Wordpress db gets compromised (which happened recently to a lot of folks), then you still don't have much of a site left.
Any piece of software that is popular (I saw a recent statistic that wordpress powers %10 of the top 1 million sites as ranked by Alexa) will be much more vulnerable to attack than less popular software. At the same time, you get a bigger community and all the goodies that come along with that popularity (more plug-ins, themes, etc...).
I don't think that getting rid of the software is the correct approach in this case. You need to approach it by assuming that your wordpress site will be attacked every day and you need to have a plan to remediate this. There is no perfect security unless you unplug your web server from the internet. For a one blogger site - one simple approach would be to:
1. Run something like open source tripwire (http://sourceforge.net/projects/tripwire/) on a nightly basis so you can get alerted if any wordpress files get changed (HN peoplez: anyone have a better tripwire-ish solution that is free?)
2. Run a nightly backup of your files and db and mail it to an external account (like a gmail account)
3. have a script that can reload your files and database quickly from your backups (obviously - this needs to be tested)
4. subscribe to the wordpress security list and to a blog like http://www.wpsecuritylock.com/blog/
I've never looked at the WP codebase, but I'm just flabbergasted that a piece of blogging software that's been around this long has so many holes. Anyone who just wants to run a simple blog with minimum hassle on a VPS is terribly ill served by Wordpress.
The people running Sendmail in the '90s went through all these arguments too.
It's hard to understand how a blog package could have created a worse track record than Sendmail (though I can tell you how). But it did.
Again: avoid Wordpress. If you can't, you have my sympathy.
Movable Type takes just a little longer to set up than WordPress, but hey, many of us here are hackers right? Plus you can tweak the code to your heart's content.
I think the main thing in the way of people using MT is that lots of people get their first introduction to blogging on some free WP hosting first and consider the switch to commercial shared hosting to be an upgrade. People like this wouldn't see switching blog platform as an upgrade so much as an inconvenience.