<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>WordPress Blue &#187; WordPress Security</title>
	<atom:link href="http://www.wordpressblue.com/tag/wordpress-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.wordpressblue.com</link>
	<description>Easy WordPress Setup and Modification</description>
	<lastBuildDate>Thu, 12 Jan 2012 13:47:46 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
		<item>
		<title>A Common-Sense WordPress Security Primer:</title>
		<link>http://www.wordpressblue.com/2010/02/a-common-sense-wordpress-security-primer/</link>
		<comments>http://www.wordpressblue.com/2010/02/a-common-sense-wordpress-security-primer/#comments</comments>
		<pubDate>Wed, 24 Feb 2010 18:48:45 +0000</pubDate>
		<dc:creator>jonathansoroko</dc:creator>
				<category><![CDATA[Blog Maintenance]]></category>
		<category><![CDATA[Security Issues]]></category>
		<category><![CDATA[WordPress tutorials and wisdom]]></category>
		<category><![CDATA[WordPress Security]]></category>

		<guid isPermaLink="false">http://www.wordpressblue.com/?p=660</guid>
		<description><![CDATA[A Common-Sense WordPress Security Primer, by David Coveney of the Liverpool-based InterConnectit IT. An excerpt: There’s been a big fuss lately over the latest WordPress hacks that have targetted older versions of WordPress. And in my view, they show the less pretty side of WordPress and some people in the community… but not all of [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.interconnectit.com/679/a-common-sense-wordpress-security-primer/">A Common-Sense WordPress Security Primer</a>, by <a href="http://www.interconnectit.com/author/david-coveney/">David Coveney</a> of the Liverpool-based <a href="http://www.interconnectit.com/">InterConnectit IT. </a>An excerpt:</p>
<p style="padding-left: 60px;">There’s been a big fuss lately over the <a title="Lorelle's breakdown on WP hack" onclick="javascript:pageTracker._trackPageview('/outbound/article/lorelle.wordpress.com');" href="http://lorelle.wordpress.com/2009/09/04/old-wordpress-versions-under-attack/">latest WordPress hacks</a> that have <a title="WordPress support forum about the hacks" onclick="javascript:pageTracker._trackPageview('/outbound/article/wordpress.org');" href="http://wordpress.org/support/topic/307518?replies=57">targetted older versions of WordPress</a>.</p>
<p style="padding-left: 60px;">And in my view, they show the less pretty side of WordPress and some people in the community… but not all of them.  The attitude has been a straight “upgrade your blog and you’ll be secure.”</p>
<p style="padding-left: 60px;">Well, I have news for you.  They’re wrong.</p>
<h3 style="padding-left: 60px;">You’re Never Secure</h3>
<p style="padding-left: 60px;">Even if you have the very latest version of everything there are, out there, what are known as <a title="Zero day exploits" onclick="javascript:pageTracker._trackPageview('/outbound/article/en.wikipedia.org');" href="http://en.wikipedia.org/wiki/Zero_day_attack">zero day exploits</a>.  These are vulnerabilities which are kept secret by the hackers who have found them.  They cease to be secret if they become widely used in a large scale attack.  Like the current one against WordPress.</p>
<p style="padding-left: 60px;">Now, if there are vulnerabilities out there that nobody knows about then your high profile WordPress site or blog could be targetted in a way that you, I, or the (great and lovely) WordPress developers out there don’t know about.</p>
<h3 style="padding-left: 60px;">Not Everyone Can Upgrade Immediately</h3>
<p style="padding-left: 60px;">Quite frankly, I find the glib assertion that staying up to date is all you need to be secure to be… terrifying.  It’s bad advice because it leaves people with the feeling that all they need to do is to stay up to date and all is well.  Not only that, but it sidesteps the whole issue that WordPress should really consider running security updates on older versions of WordPress – not all sites can quickly change from one version to another.  When WordPress 2.8 came out it broke multi-use widgets – you could recode them, but then settings could be lost.  There are sites out there that run hundreds of widgets, and re-configuring them will be a big job.  If a new vulnerability comes out in WordPress it may not even be relevant to some sites because they may be doing everything else correctly.</p>
<p style="padding-left: 60px;">In fact, in a critical environment you absolutely <em><strong>do not</strong></em> update your software without running a full suite of tests to make sure the updates won’t bring down your site.  This is a major problem for sites which, in some cases, are turning over tens of thousands of pounds a month.  Yes, they can throw money at the problem, but it still takes time – and when there’s a vulnerability the one thing you don’t have is a lot of time.  So a site needs to rely on more than just WordPress for security.</p>
<p>Mr. Coveney clearly understands something about the phenomenology of risk, and he&#8217;s got some good practical advice. Perhaps we can persuade him to write something for <em>Popular Logistics</em>, our primary blog, which is about risk assessment, mitigation and control.</p>
<p><a href="http://www.interconnectit.com/679/a-common-sense-wordpress-security-primer/">A Common-Sense WordPress Security Primer</a>. By <a href="http://www.interconnectit.com/author/david-coveney/">David Coveney</a> at <a href="http://www.interconnectit.com/">InterConnectit</a> &#8211; or perhaps it&#8217;s pronounced &#8220;<a href="http://www.interconnectit.com/">InterConnect <strong><em>IT</em></strong>.</a>&#8221;</p>
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<h4>Possibly related posts: (automatically generated)</h4>
<ul>
<li style="list-style: none;">Related posts on <b>WordPress Security</b></li>
<li><a href="http://www.saigonseo.com/2010/02/security-and-anti-spam-plugins-for-wordpress/">Security And Anti-spam Plugins For WordPress | Saigon SEO dot Com</a></li>
</ul>
<div class="evernoteSiteMemory"><a href="javascript:" onclick="Evernote.doClip({title: 'A Common-Sense WordPress Security Primer: on WordPress Blue',url: 'http://www.wordpressblue.com/2010/02/a-common-sense-wordpress-security-primer/',contentID: 'post-660',suggestTags: 'WordPress Security',providerName: 'WordPress Blue',styling: 'text' });return false" class="evernoteSiteMemoryLink"><img src="http://www.wordpressblue.com/wp-content/plugins/wp-evernote-site-memory/img/smallclip.png" class="evernoteSiteMemoryButton" /></a>
				<p class="evernoteSiteMemoryDescription">
					<strong>Evernote</strong> lets you save all the interesting things you see online into a single place. Access all those saved pages from your computer, phone or the web.  <a href="https://www.evernote.com/Registration.action" title="Sign up for Evernote" target="_blank">Sign up now</a> or <a href="https://www.evernote.com/about/learn_more/" title="Learn more about Evernote" target="_blank">learn more</a>. It's free!
				</p>
				
				<div class="evernoteSiteMemoryClear">&nbsp;</div>
			</div>]]></content:encoded>
			<wfw:commentRss>http://www.wordpressblue.com/2010/02/a-common-sense-wordpress-security-primer/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

