<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: WordPress Security Prevention, Reactions, and Scares</title>
	<atom:link href="http://lorelle.wordpress.com/2008/04/28/wordpress-security-prevention-reactions-and-scares/feed/" rel="self" type="application/rss+xml" />
	<link>http://lorelle.wordpress.com/2008/04/28/wordpress-security-prevention-reactions-and-scares/</link>
	<description>Helping you learn more and do more with WordPress</description>
	<lastBuildDate>Tue, 14 Jul 2009 00:36:33 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: 150 Ways To Break Into Your Blog (Hacking For Dummies) &#8212; Practice This</title>
		<link>http://lorelle.wordpress.com/2008/04/28/wordpress-security-prevention-reactions-and-scares/#comment-919947</link>
		<dc:creator>150 Ways To Break Into Your Blog (Hacking For Dummies) &#8212; Practice This</dc:creator>
		<pubDate>Fri, 17 Apr 2009 21:56:18 +0000</pubDate>
		<guid isPermaLink="false">http://lorelle.wordpress.com/?p=2507#comment-919947</guid>
		<description>[...] WordPress Security Prevention, Reactions, and Scares [...]</description>
		<content:encoded><![CDATA[<p>[...] WordPress Security Prevention, Reactions, and Scares [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Firewalling and Hack Proofing Your WordPress Blog &#171; Lorelle on WordPress</title>
		<link>http://lorelle.wordpress.com/2008/04/28/wordpress-security-prevention-reactions-and-scares/#comment-917448</link>
		<dc:creator>Firewalling and Hack Proofing Your WordPress Blog &#171; Lorelle on WordPress</dc:creator>
		<pubDate>Sun, 08 Mar 2009 04:10:39 +0000</pubDate>
		<guid isPermaLink="false">http://lorelle.wordpress.com/?p=2507#comment-917448</guid>
		<description>[...] Lorelle on WordPress - WordPress Security Prevention, Reactions, and Scares [...]</description>
		<content:encoded><![CDATA[<p>[...] Lorelle on WordPress &#8211; WordPress Security Prevention, Reactions, and Scares [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: weez</title>
		<link>http://lorelle.wordpress.com/2008/04/28/wordpress-security-prevention-reactions-and-scares/#comment-915986</link>
		<dc:creator>weez</dc:creator>
		<pubDate>Fri, 13 Feb 2009 22:46:48 +0000</pubDate>
		<guid isPermaLink="false">http://lorelle.wordpress.com/?p=2507#comment-915986</guid>
		<description>The truth is that no blanket statements are true.  That was my point in my original comment.  It is possible to write error free code (or very very close to it) if that is your goal.  In addition to rigorous testing requirements, you will have to do additional vetting on every piece that your system relies on, and for those that don&#039;t past muster, you will need to recreate them from scratch with security in mind.  These are the conditions that DJB (mentioned above) worked under.  His top goal was security, and he threw away error prone parts of the C library and wrote his own to help ensure that goal.

The last I checked, no dynamic language interpreters were created with security being the number one goal.  The security track record of all of them reflects that.  Someone should go create a dynamic language from the ground up with security in mind.  So yes, for a complex system like Wordpress, even if the Wordpress developers don&#039;t introduce vulnerabilities, they are still blamed for the weakest link, which could be Apache, PHP, or the kernel of the OS they are working on.</description>
		<content:encoded><![CDATA[<p>The truth is that no blanket statements are true.  That was my point in my original comment.  It is possible to write error free code (or very very close to it) if that is your goal.  In addition to rigorous testing requirements, you will have to do additional vetting on every piece that your system relies on, and for those that don&#8217;t past muster, you will need to recreate them from scratch with security in mind.  These are the conditions that DJB (mentioned above) worked under.  His top goal was security, and he threw away error prone parts of the C library and wrote his own to help ensure that goal.</p>
<p>The last I checked, no dynamic language interpreters were created with security being the number one goal.  The security track record of all of them reflects that.  Someone should go create a dynamic language from the ground up with security in mind.  So yes, for a complex system like WordPress, even if the WordPress developers don&#8217;t introduce vulnerabilities, they are still blamed for the weakest link, which could be Apache, PHP, or the kernel of the OS they are working on.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lorelle VanFossen</title>
		<link>http://lorelle.wordpress.com/2008/04/28/wordpress-security-prevention-reactions-and-scares/#comment-915982</link>
		<dc:creator>Lorelle VanFossen</dc:creator>
		<pubDate>Fri, 13 Feb 2009 21:50:37 +0000</pubDate>
		<guid isPermaLink="false">http://lorelle.wordpress.com/?p=2507#comment-915982</guid>
		<description>While this might be true, security vulnerabilities are found long after &quot;perfectly formed&quot; software is written, including the core code that created the Internet, which was only found last year. Programming that relies upon PHP, MySQL, Apache, operating systems, and other code from other sources occasionally have vulnerabilities uncovered - so does that make the original programming at fault? No, but people blame it anyway, as in the case of WordPress. 

Honestly, few things human made are perfect or error free. I&#039;m sure this person is good, but that doesn&#039;t change the truth.</description>
		<content:encoded><![CDATA[<p>While this might be true, security vulnerabilities are found long after &#8220;perfectly formed&#8221; software is written, including the core code that created the Internet, which was only found last year. Programming that relies upon PHP, MySQL, Apache, operating systems, and other code from other sources occasionally have vulnerabilities uncovered &#8211; so does that make the original programming at fault? No, but people blame it anyway, as in the case of WordPress. </p>
<p>Honestly, few things human made are perfect or error free. I&#8217;m sure this person is good, but that doesn&#8217;t change the truth.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: weez</title>
		<link>http://lorelle.wordpress.com/2008/04/28/wordpress-security-prevention-reactions-and-scares/#comment-915977</link>
		<dc:creator>weez</dc:creator>
		<pubDate>Fri, 13 Feb 2009 16:31:11 +0000</pubDate>
		<guid isPermaLink="false">http://lorelle.wordpress.com/?p=2507#comment-915977</guid>
		<description>In response to comment number 2 (Douglas Bell).  

Most people don&#039;t realize that it is possible to write software that is 100% bugfree, and thus no security issues.  Daniel J Bernstein has done this many times (in addition to freeing encryption software for public use in Bernstein v. United States).  Qmail is one of his contributions to the world.  His DNS software in addition to being fast was immune to the recent DNS security issues ~10 years before anyone else.  Check out his wikipedia entry</description>
		<content:encoded><![CDATA[<p>In response to comment number 2 (Douglas Bell).  </p>
<p>Most people don&#8217;t realize that it is possible to write software that is 100% bugfree, and thus no security issues.  Daniel J Bernstein has done this many times (in addition to freeing encryption software for public use in Bernstein v. United States).  Qmail is one of his contributions to the world.  His DNS software in addition to being fast was immune to the recent DNS security issues ~10 years before anyone else.  Check out his wikipedia entry</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Security and Hacking: Protect Thyself and Thy WordPress Blog &#124; The Blog Herald</title>
		<link>http://lorelle.wordpress.com/2008/04/28/wordpress-security-prevention-reactions-and-scares/#comment-915008</link>
		<dc:creator>Security and Hacking: Protect Thyself and Thy WordPress Blog &#124; The Blog Herald</dc:creator>
		<pubDate>Mon, 19 Jan 2009 10:47:58 +0000</pubDate>
		<guid isPermaLink="false">http://lorelle.wordpress.com/?p=2507#comment-915008</guid>
		<description>[...] responds immediately to any security vulnerabilities with patches and upgrades for their core program, and offer alerts for security issues on WordPress [...]</description>
		<content:encoded><![CDATA[<p>[...] responds immediately to any security vulnerabilities with patches and upgrades for their core program, and offer alerts for security issues on WordPress [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Wordpress 2.7 Coltrane! &#124; PapaJoneh&#8217;s Little Knowledge</title>
		<link>http://lorelle.wordpress.com/2008/04/28/wordpress-security-prevention-reactions-and-scares/#comment-913223</link>
		<dc:creator>Wordpress 2.7 Coltrane! &#124; PapaJoneh&#8217;s Little Knowledge</dc:creator>
		<pubDate>Sun, 14 Dec 2008 02:00:09 +0000</pubDate>
		<guid isPermaLink="false">http://lorelle.wordpress.com/?p=2507#comment-913223</guid>
		<description>[...] Some search engines and directories are considering penalizing page rank or not indexing old versions of WordPress due to security vulnerabilities and failure to upgrade (few spam sites upgrade). For more information, see Technorati: Vulnerable WordPress Blogs Not Being Indexed, Matt Cutts: Alerting Webmasters to Webserver Vulnerabilities, Fear, Uncertainty and Disinformation About The WordPress Exploits and Spam, and WordPress Security Prevention, Reactions, and Scares. [...]</description>
		<content:encoded><![CDATA[<p>[...] Some search engines and directories are considering penalizing page rank or not indexing old versions of WordPress due to security vulnerabilities and failure to upgrade (few spam sites upgrade). For more information, see Technorati: Vulnerable WordPress Blogs Not Being Indexed, Matt Cutts: Alerting Webmasters to Webserver Vulnerabilities, Fear, Uncertainty and Disinformation About The WordPress Exploits and Spam, and WordPress Security Prevention, Reactions, and Scares. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: WordPress News: WordPress 2.7 Released &#124; The Blog Herald</title>
		<link>http://lorelle.wordpress.com/2008/04/28/wordpress-security-prevention-reactions-and-scares/#comment-913060</link>
		<dc:creator>WordPress News: WordPress 2.7 Released &#124; The Blog Herald</dc:creator>
		<pubDate>Thu, 11 Dec 2008 10:11:11 +0000</pubDate>
		<guid isPermaLink="false">http://lorelle.wordpress.com/?p=2507#comment-913060</guid>
		<description>[...] Some search engines and directories are considering penalizing page rank or not indexing old versions of WordPress due to security vulnerabilities and failure to upgrade (few spam sites upgrade). For more information, see Technorati: Vulnerable WordPress Blogs Not Being Indexed, Matt Cutts: Alerting Webmasters to Webserver Vulnerabilities, Fear, Uncertainty and Disinformation About The WordPress Exploits and Spam, and WordPress Security Prevention, Reactions, and Scares. [...]</description>
		<content:encoded><![CDATA[<p>[...] Some search engines and directories are considering penalizing page rank or not indexing old versions of WordPress due to security vulnerabilities and failure to upgrade (few spam sites upgrade). For more information, see Technorati: Vulnerable WordPress Blogs Not Being Indexed, Matt Cutts: Alerting Webmasters to Webserver Vulnerabilities, Fear, Uncertainty and Disinformation About The WordPress Exploits and Spam, and WordPress Security Prevention, Reactions, and Scares. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: WordPress 2.7 Available Now &#171; Lorelle on WordPress</title>
		<link>http://lorelle.wordpress.com/2008/04/28/wordpress-security-prevention-reactions-and-scares/#comment-913018</link>
		<dc:creator>WordPress 2.7 Available Now &#171; Lorelle on WordPress</dc:creator>
		<pubDate>Thu, 11 Dec 2008 04:22:40 +0000</pubDate>
		<guid isPermaLink="false">http://lorelle.wordpress.com/?p=2507#comment-913018</guid>
		<description>[...] Some search engines and directories are considering penalizing page rank or not indexing old versions of WordPress due to security vulnerabilities and failure to upgrade (few spam sites upgrade). For more information, see Technorati: Vulnerable WordPress Blogs Not Being Indexed, Matt Cutts: Alerting Webmasters to Webserver Vulnerabilities, Fear, Uncertainty and Disinformation About The WordPress Exploits and Spam, and WordPress Security Prevention, Reactions, and Scares. [...]</description>
		<content:encoded><![CDATA[<p>[...] Some search engines and directories are considering penalizing page rank or not indexing old versions of WordPress due to security vulnerabilities and failure to upgrade (few spam sites upgrade). For more information, see Technorati: Vulnerable WordPress Blogs Not Being Indexed, Matt Cutts: Alerting Webmasters to Webserver Vulnerabilities, Fear, Uncertainty and Disinformation About The WordPress Exploits and Spam, and WordPress Security Prevention, Reactions, and Scares. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Helping in the WordPress Forums is an Education &#124; The Blog Herald</title>
		<link>http://lorelle.wordpress.com/2008/04/28/wordpress-security-prevention-reactions-and-scares/#comment-909160</link>
		<dc:creator>Helping in the WordPress Forums is an Education &#124; The Blog Herald</dc:creator>
		<pubDate>Wed, 17 Sep 2008 05:05:03 +0000</pubDate>
		<guid isPermaLink="false">http://lorelle.wordpress.com/?p=2507#comment-909160</guid>
		<description>[...] Blog Hacked? If your WordPress blog has been hacked, don&#8217;t blame WordPress. WordPress mandatory security upgrades and patches are announced as [...]</description>
		<content:encoded><![CDATA[<p>[...] Blog Hacked? If your WordPress blog has been hacked, don&#8217;t blame WordPress. WordPress mandatory security upgrades and patches are announced as [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
