How to Keep WordPress Secure
wordpress.org
wordpress.org
Instead of having a single big kick ass dedicated server running everything, you can have maybe 10 VPS's each doing a different thing. You can group things together in terms of risk - put wordpress on its own vps, put your customer db on another, etc etc. At least then, if someone hacks into wordpress, it doesn't really matter that much - they only get wordpress, nothing else, and you just clean off that machine from backups.
(Obviously have completely different login credentials for each VPS, and only grant access from one VPS to another when really necessary, and restrict it).
But yes, you are right for the most part. However, just throwing apps in VPS doesn't automatically solve your security issues.
Yes, there could theoretically be a way to punch through from an insecure VPS into a secure VPS on the same host, but I think the chances are pretty slim there.
The security is just an added bonus.
This is misleading. Windows NT was built with security in mind. Windows Xp, Vista and 7 are descended from NT.
...wait, that's cheating, isn't it?
Given that, software with an exceedingly low historical defect rate could reasonably be considered 'secure'.
If you only allow people to edit standard HTML, then this issue would go away.
Everybody gets owned, kept or rm'ed; just a matter of time.
They prefer new features over security. Have you noticed how with each major upgrade there are new holes in it?
WordPress is like Swiss cheese, full of holes. I'd prefer Swiss banks or watches instead.
WP 2.8, WP 2.7, WP 2.5 etc. each were compromised almost immediately and each time several security updates have been issued in the matter of days and weeks.
Nobody can keep up with it so no wonder WordPress blogs get hacked.
Why don't they just release stable and secure versions?
You appear to be suggesting -- I can't tell how seriously -- that WordPress is deliberately made insecure so that when Automattic (ugh, I hate that name) want people to upgrade they always have a security issue they can use to scare people into doing so. Sorry, but that's absolutely nuts.
(In case it isn't clear: I am not, in the least, defending WP's security record. I am pointing out that the things you're saying here are crazy.)
No, YOU said that. I just said they don't care enough for security. Otherwise they wouldn't spit out new versions with holes so often.
So there is no reason to insult me.
Also the WordPress people pointing out all the time how wordpress.com hasn't been hacked is just obvious advertising for their hosted services.
Specifically: you said "This is the way they advertise for their wordpress.com version obviously. Stick with us or you get compromised." So, my mistake: I interpreted "their wordpress.com version" as "the latest version" rather than "hosting your blog on wordpress.com". That was dumb of me; sorry.
On the other hand, even after fixing my brain in that respect, I still can't see any way to read that as just saying that "they don't care enough for security".
If in fact it's true that wordpress.com consistently gets updated immediately when a new version comes out that fixes a security problem, and that people hosting their own WordPress blogs tend to be sluggish about upgrading, then I don't see why one of the things they say when a compromise happens is "you'd be in much less danger on wordpress.com". Because, y'know, it's true. What would be improper would be if (1) they are deliberately putting out insecure code to make their hosted version more appealing, or (2) the only thing they say when a security problem comes up is "come and use our hosted version". #1 is what it still looks to me like you were saying, but seems immensely improbable, not least because I find it very hard to believe that their net gain in paying customers from an incident like this one is positive. #2 would be bad. indeed; is it true?
http://www.google.com/search?q=wordpres.com+hcked&pws=0&...
You'll find threads like these:
http://en.forums.wordpress.com/topic/my-site-got-hacked
http://en.forums.wordpress.com/topic/my-friends-site-was-hac...
http://en.forums.wordpress.com/topic/i-got-hacked-1
where wordpress.com users seek help after they got hacked.
There are communities (like Club Penguin) where they are quite promiscuous with their passwords and share login details with each other regularly, and then "hack" each others blogs.
I did the same search. In each of those cases it seems like being "hacked" means adding another admin and having them screw you over or having your password guessed. Though I'm no Wordpress fan, blaming them for things like that is rather absurd.
My guess is that people don't update because they fear potentially breaking their styles or something.
That said, I don't use any plugins, so I didn't have to worry about compatibility issues.
The upgrade process may be simplified but who wants to spend hours trying to fix compatibility every time they discover a bug they introduced with the last patch because they've broken backwards compatibility yet again.
What they should be doing is a general upgrade release for non-technical users and a technical bulletin about what exactly was wrong so technical users can manage older versions as desired. Instead you have to dig for an hour in trac notes to find what the heck they changed and why.
I have version 2.3 & 2.5 installs running safe because I've manually patched them and locked down the server. Delete any XMLRPC interface which is where half the bugs are introduced. The other half is the open ended admin interface which even regular users are allowed into to escalate privileges, which is asinine - you can even run PHPINFO through the admin panel as a regular member on many WP installs.
I immediately got the "white screen of death" afterwards and had to do a binary search to figure out which plugin(s) were the culprit (and then try to track down newer versions or alternatives).
Some API changes are not backwards-compatible, so your themes have to be upgraded also (for example, the "show comments" api will by default say "comments off" on every page that doesn't allow them, which it didn't before). I'm sure there's other such changes I haven't yet noticed.
I'm glad I upgraded, but it was a major hassle and nearly a full day's work in my case.
Much less hassle than setting up a database, installing Wordpress (as easy as it is) and most of all remembering to update Wordpress every few weeks, as long as you don't need in-browser editing and such.
With Github pages (http://github.com/blog/272-github-pages) it's as simple as pushing your source templates and documents (in HTML, Markdown, or Textile)
Jekyll is a little limited though, so I also have some scripts that do a little preprocessing before handing it off to Jekyll.
Source: http://www.codinghorror.com/blog/archives/001291.html
http://www.noupe.com/how-tos/wordpress-security-tips-and-hac...
They rather blame other people for suggesting the wrong solutions.
There is no other software out there that demands upgrades so often to no avail getting infected again and again nonetheless.
Oh, sorry, there is one: Internet Explorer!
This makes your blog a dead end. Pingbacks are crucial to spread the message througout the blogosphere.
Another issue is the backend interface plus the frontend templates/themes. MT has a decent backend but you barely get any templates you can use. The same problem arises with S9Y. Is just installed it and both the default templates like the remaining choices are awful. So basically you have to design and code everything yourself.
svn sw http://svn.automattic.com/wordpress/tags/2.8.4
Which is about the acceptable level of hassle IMO. Much more and I'd be outta there.