You can sign up for a free hosted version of WordPress at http://wordpress.com, though it has paid upgrades, or you can download the self-hosted version for free at http://wordpress.org.
You could even go with a webhost (like http://dreamhost.com) and use their one-click-install for WordPress (feel free to use the coupon code JACOBWG for $97 off one year of DreamHost... disclosure: I do NOT receive any referral money or benefits from that code - all benefits have been rolled into that code's discount).
If you're the "hacker" type, then check out http://jekyllrb.com/...
It doesn't seem to have had a secure design from the outset. Worse still, ordinarily one might advise "keep up to date", but wordpress had a release backdoored (http://www.cgisecurity.com/2007/03/wordpress-websi.html) once, so keeping up-to-date isn't without its risks too.
I've been giving tumblr a try, and so far - so good, but the functionality is pretty minimal.
I personally view having security updates as a plus - it shows that the WordPress team (open source community) supports their software. The fact that WordPress is running on 70 million plus websites [1], about 15% of the web [2], means that if a security hole is found, it will be fixed, and it can be fixed by anyone without having to wait for a limited amount of employees of a particular company to write the patch (one of the benefits of open source).
What you do get from Tumblr, though, is the fact that a 3rd party is responsible for keeping your website up and keeping it fast - you basically trade ownership of your website's software for a 3rd-party guarantee. This also means that if Tumblr is down or is hacked or you want to customize something beyond the theme, you are dependent on Tumblr...
So, while each may have its own use-case (Tumblr is great for the following/reblogging stuff), the fact that WordPress is regularly updated is not a reason to avoid using it as a platform.
[1] http://en.wordpress.com/stats/ [2] http://wordpress.org/news/2011/08/state-of-the-word/
I looked at using Tumblr when we were getting her set up, but it did not have enough functionality for what they needed.
Honestly, I think you're better off just writing your own blog software. Obscure it, close source it, lock down DB permissions and put it on your own VPS, you could knock out a simple platform in a weekend. And you're much less likely to get hit by hackers.
Obviously you have to be a programmer to roll your own blogging platform so that option is not for everyone, but you'd be reinventing a wheel being run on 70 million websites for the stated reason of writing something that is more secure? You'd have to be REALLY good at what you do compared to the 1000s of WP developers contributing to WP, the dedicated security team, and the hivemind of bug-reporting WP installations. Plus, when you do encounter a security vulnerability (not if you do), it will be your sole responsibility to patch the hole.
Closed-source is not a security solution - security by obscurity is no security at all.
I do not think that rolling your own blog platform is a bad idea as it's a great learning experience, but it is not a good solution if you are concerned about blog security.
Wordpress still has no unit testing. It still forces you to upgrade a version to get bugfixes and security patches. It relies entirely on beta testers to find data-destroying bugs. And it's increasingly being transformed into a catspaw for Automattic.
I've been administering Wordpress for 6 or 7 years. And I hate its guts. I hate its developers. And I hate that it's an absolute triumph of Worse is Better.
Such systems just render your conveniently created post content into a static HTML website than can be published on various free systems (github pages etc) or $2/month VPS. Or an Amazon S3 bucket.
Why?
1. It is not anyore significantly harder or more inconvenient than using a 'platform' like wordpress.com
2. A static site is 10000000% more resistant to idiotic exploits (which unless you are some kind of PROFESSIONAL blogger, keeping up with is more trouble than its worth on any dynamic 'blogging platform' type of system)
3. A static blog system can serve your blogs with any web server in 2012, and will be able to in 2112, whereas none of the free or even for-money 'blogging platforms' is likely to exist in 2112. Which in terms of your life (unless we are lucky and get the gerontological life-extending technology soon) is essentially 'forever.
4. Why on earth would you cede control of your personal output to walmart.com or google+ or similar?
[2]: http://jekyllrb.com/
EDIT: meant to mention somewhere in there that comments, one of the raisons d'être for these dynamic blogging systems, can now be superbly handled by off-site add ons like disqus.
(I personally don't find comments important at all, and even take advantage of the various browser extensions[1] to hide them on various sites that do have them.)
[1]: e.g. http://stevenf.com/pages/shutup.css.html
If you look at the best blogs, I mean top blogs in their niche such as
http://www.thesartorialist.com/
http://girishshambu.blogspot.com/
http://www.freakonomics.com/blog/
http://krugman.blogs.nytimes.com/
http://terrytao.wordpress.com/
you will see that they are comment heavy. In fact there are very interesting discussions in the comments.
You may think comments are "unimportant" for most blogs, but that is not up to you, it is up to the blogger, and I guarantee that blogger would rather have some comments. And it might help to have a half-decent comment system.
I personally am not much of a blogger, so my own proclivities as a blog writer ('fuck no I don't allow comments on any blog for which I am responsible for picking up the dogshit and spam') aren't too relevant. But many of the blogs I find most valuable do not feature comments, or if they do, they are 99.9% what you'd expect: utterly worthless, time-wasting digital turds.
I think the whole comment thing is misguided. If you really had something worthwhile to say, why on earth would you entrust that to whatever crap-ass 'blogging platform' that blogger in question happened to be using at the moment?
Say it somewhere that you control, and link it. That's how the web works.
Of course, I have seen worthwhile comments (especially on blogs where the author takes the time/effort to aggressively police them). But that's far and away the exception, and not the rule.
Comments can be important if you're trying to build a community or what have you and want people to stay on site longer. But most people use aggregators of one stripe or another, whether RSS or a link site or Facebook.
When you say "Say it somewhere that you control, and link it. That's how the web works." I understand where you're coming from, but this is simply not true. Wanting something to be true doesn't make it so. The web is not made of a collection of interlinked static HTML files. But the root of your complaint, that by commenting on someone's blog you give away your worthwhile thoughts, is also a failure of the bad comment system.
Comments should work a lot more like email does. Imagine if each blog entry had an email address (or sub-address of the blog's email address) and sending a "comment" was really sending an email to that address. The comment box below the blog entry is really a small email composing window which sends the comment to the blog. And it can also send it to your own email address (as a cc for the purposes of the thought experiment). Then it would be in your email archive and not lost, but you would still be contributing to the discussion happening at the blog. A further benefit of this is that the spam filter for the email address would function for comments on a blog. Why reinvent the wheel? /end example.
I have come to this issue from the experience of working with bloggers with quite long-running substantial blogs on Wordpress or Blogger. They have a huge laundry list of complaints and annoyances with the software but I cannot in good faith recommend a jekyll-octopress solution or a wikified solution, or a "static--html" solution etc. These "solutions" are poorly thought out and would represent a severe reduction in functionality for the sake of "that's how it should be done". It is the result of developers who look at a hard problem (how to best implement all these required features) and decide to get rid of the problem by disparaging the features or the requesters themselves.
Overall, if you're a hacker, definitely look at Jekyll (https://github.com/mojombo/jekyll/). The easiest way to get started is to fork an existing jekyll blog and start customizing.
If you're not a hacker, I'd probably recommend Tumblr. It offers the best balance of features and ease of use, and they seem to have solved their downtime problems. If for, some reason, you don't like Tumblr, check out Posterous. If that still doesn't suit your needs, Wordpress.com would be my third recommendation.
I would not bother with self-hosted blogs unless you really have a need for that level of control, since the cloud-based or static options are so powerful these days.
I also recently discovered OhLife (http://ohlife.com/), which is a great way to keep a private journal. It'll send you an email at your chosen frequency (daily or weekly) asking "How did your day go?" and you just reply with your journal entry.
Wordpress would be the way to go if you want to have more control over your blog, but I always ended up tweaking the function of the blog more and writing less. Tumblr basically breaks that tinkering distraction and allows you to focus on your content.
Seems like about half of the most productive people/ most interesting blog posts I read are hosted at *.wordpress.com or someplace similarly humble.
But I mostly post this because I'm just finally finishing up a migration from self-hosted wordpress (which was working fine, but I wasn't happy with for various reasons) to octopress. This has taken me several months to get around to almost finishing (during which time I've gotten out of the blogging habit), and many hours of fooling with ruby environments, converting my old posts, etc., etc.
Hopefully the payoff for me will be simplicity, a better work-flow, new blog format that fits what I'd like to do better, etc. but it might have been a lot of wasted time and energy.
If you are still going strong after a few weeks and feel the need for something more powerful, then look into switching to something else. I personally switched to wordpress after a couple of weeks on Tumblr, but I have a lot of friends who still use Tumblr for everything.
A geekier alternative is Calepin (http://calepin.co), amazing concept: you write your posts in multimarkdown, in a Dropox folder, and you publish by clicking a button that automatically checks that folder for new stuff (no template customization yet but Disqus integration). I am seriously thinking about switching to Calepin, Tumblr feels heavy on the browser.
It's simple, provides me with a versioned and easily portable archive and doesn't require constant security updates. Here are some tips from migrating from WP: http://decafbad.com/blog/2011/06/08/moved-to-jekyll
I'd say it depends on your purpose (e.g. personal blogging for your day-to-day realizations, philosophical epiphanies, etc.).
(Disclosure: TechPolish is my website.) EDIT: fixed typo. moved link up.
Personally, I'm very happy to be http://andrewducker.dreamwidth.org/ because I have control over whether things are public or just for a personal audience, lots of control over comments - and most importantly, threaded comments. I loathe non-threaded comment systems with a fiery passion.
* Are you a developer?
* How comfortable are you with the command line?
* Do you intend to display a lot of media on your blog?
* Do you intend to display code examples on your blog?
There is no "best" tool in any parlance. The tool you choose will have a lot to do with your preferences.
WordPress: Lots of plug-ins available; common, thus easy to get assistance for; supports a wide variety of blog types; requires diligent attention to security patches and performance tweaking (caching).
Hosted platform (like Tumblr): Zero maintenance; great community; easy to apply themes.
Static site generator (like Jekyll/Octopress): Very hackable; provides some level of street cred for devs; extremely minimal hosting requirements; easy to use your favorite flavor of markup (HTML, ERb, HAML, Markdown, Textile, you name it).
If you want to farm out to someone else, tumblr is good because it's inherently social (people will follow you, share your posts, etc), but it's largely visual and a bit spammy at times.
Posterous is another good platform because it's simple, has some social features, and tends toward the more content driven format.
Wordpress is still my vote though, because it can grow with your blog/site and vary from the fairly simple to as advanced as you want.
It would be good to actually define "blogging" and "blogging platform", which I think would be somewhat difficult to do.
Just make sure you backup not only your database but themes because if you get malware, its really difficult to find out the source. Easiest thing to do is to revert to a clean copy, change passwords, and protect yourself!
minimal static site generator. Worth it if you just want to put your content up and don't need or want pre-packaged bells and whistles.
Then you get to implement things like a sitemap, categories, comments/Disqus, page caching, and anything else you're so inspired to add. Makes for good blogging material.
No slower than any static content generator like Jekyll if you just cache everything to a static directory, too.
It's pretty primitive, not actively developed, and has no native commenting system. On the other hand, its exactly as secure as your HTTPd of choice, unlike Wordpress.
Pick any of the free platform WP, posterous, tumblr, etc. Most of these tools are inter-portable. It really does not matter, the one thing that really matter is the blogging platform that you actually use.
If you (or anyone else) end up giving it a spin, let me know how it goes.
[1]: http://calepin.co/