<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:series="http://unfoldingneurons.com/"
		>
<channel>
	<title>Comments on: WordPress 3.0 Security Design That NEED to Be Addressed</title>
	<atom:link href="http://www.howtospoter.com/web-20/wordpress/wordpress-3-0-security-design-that-need-to-be-addressed/feed" rel="self" type="application/rss+xml" />
	<link>http://www.howtospoter.com/web-20/wordpress/wordpress-3-0-security-design-that-need-to-be-addressed</link>
	<description>WordPress Guides, Tips And Strategies For Successful Blogs</description>
	<lastBuildDate>Fri, 10 Feb 2012 23:22:56 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
	<item>
		<title>By: Jaki Levy</title>
		<link>http://www.howtospoter.com/web-20/wordpress/wordpress-3-0-security-design-that-need-to-be-addressed/comment-page-2#comment-29980</link>
		<dc:creator>Jaki Levy</dc:creator>
		<pubDate>Mon, 09 May 2011 09:26:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.howtospoter.com/?p=1388#comment-29980</guid>
		<description>These are great WordPress resources - I actually just started digging into a really really solid book on WordPress 3.0. It&#039;s got some really nice code samples, and is written by a few pro WordPress developers (including some from Envato). I&#039;m actually giving away 2 copies of the e-book on my site - check out the details about the e-book and the giveaway here - I think you&#039;ll dig it : &lt;a href=&quot;http://bit.ly/lq20Ff&quot; rel=&quot;nofollow&quot;&gt;http://bit.ly/lq20Ff&lt;/a&gt; </description>
		<content:encoded><![CDATA[<p>These are great WordPress resources &#8211; I actually just started digging into a really really solid book on WordPress 3.0. It&#039;s got some really nice code samples, and is written by a few pro WordPress developers (including some from Envato). I&#039;m actually giving away 2 copies of the e-book on my site &#8211; check out the details about the e-book and the giveaway here &#8211; I think you&#039;ll dig it : <a href="http://bit.ly/lq20Ff" rel="nofollow">http://bit.ly/lq20Ff</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: WordPress 3.0 &#8211; The Ultimate Roundup For Developers &#38; Users &#124; KreativeThemes.com</title>
		<link>http://www.howtospoter.com/web-20/wordpress/wordpress-3-0-security-design-that-need-to-be-addressed/comment-page-2#comment-26548</link>
		<dc:creator>WordPress 3.0 &#8211; The Ultimate Roundup For Developers &#38; Users &#124; KreativeThemes.com</dc:creator>
		<pubDate>Thu, 29 Jul 2010 22:51:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.howtospoter.com/?p=1388#comment-26548</guid>
		<description>[...] Snippets To Prepare Your Theme For WordPress 3.0WordPress 3.0: Changing The Way We Manage ContentWordPress 3.0 Security Design That NEED to Be AddressedP.S : If you find this roundup post useful, do share it with others. And if you have any good [...]</description>
		<content:encoded><![CDATA[<p>[...] Snippets To Prepare Your Theme For WordPress 3.0WordPress 3.0: Changing The Way We Manage ContentWordPress 3.0 Security Design That NEED to Be AddressedP.S : If you find this roundup post useful, do share it with others. And if you have any good [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Philip M. Hofer (Frumph)</title>
		<link>http://www.howtospoter.com/web-20/wordpress/wordpress-3-0-security-design-that-need-to-be-addressed/comment-page-2#comment-24767</link>
		<dc:creator>Philip M. Hofer (Frumph)</dc:creator>
		<pubDate>Sun, 23 May 2010 14:17:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.howtospoter.com/?p=1388#comment-24767</guid>
		<description>Actually my claim is there no more security risks in the standalone vrs. the multisite.    The login attempts not-withstanding which can be protected with a plugin that handles that even more so with things like the SI Captcha plugin which can captcha logins.

I challenge *anyone* to try to inject into my site.  I&#039;ll even give them a bonus and give them access to their own site on my server to help them along.
.-= Philip M. Hofer (Frumph)´s last blog ..&lt;a href=&quot;http://frumph.net/blog/frumph-crew-on-tgt-webcomics-tonight-6pm-pst/&quot; rel=&quot;nofollow&quot;&gt;Frumph &amp; Crew on TGT Webcomics tonight, 6pm PST&lt;/a&gt; =-.</description>
		<content:encoded><![CDATA[<p>Actually my claim is there no more security risks in the standalone vrs. the multisite.    The login attempts not-withstanding which can be protected with a plugin that handles that even more so with things like the SI Captcha plugin which can captcha logins.</p>
<p>I challenge *anyone* to try to inject into my site.  I&#8217;ll even give them a bonus and give them access to their own site on my server to help them along.<br />
.-= Philip M. Hofer (Frumph)´s last blog ..<a href="http://frumph.net/blog/frumph-crew-on-tgt-webcomics-tonight-6pm-pst/" rel="nofollow">Frumph &amp; Crew on TGT Webcomics tonight, 6pm PST</a> =-.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lorrette</title>
		<link>http://www.howtospoter.com/web-20/wordpress/wordpress-3-0-security-design-that-need-to-be-addressed/comment-page-2#comment-24761</link>
		<dc:creator>Lorrette</dc:creator>
		<pubDate>Sat, 22 May 2010 21:23:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.howtospoter.com/?p=1388#comment-24761</guid>
		<description>Alex I have been following you for sometime now and I have to say I could not be more grateful for the security DVD and other valuable advice that you so freely provide.  Please keep us posted if you do upgrade the Security DVD ... Oh ... and keep up all the good work Alex, there are many of us that do appreciate it.

Celebrate Life
Lorrette
.-= Lorrette´s last blog ..&lt;a href=&quot;http://dailyscrewups.com/3653/good-blonde-jokes/&quot; rel=&quot;nofollow&quot;&gt;Good Blonde Jokes&lt;/a&gt; =-.</description>
		<content:encoded><![CDATA[<p>Alex I have been following you for sometime now and I have to say I could not be more grateful for the security DVD and other valuable advice that you so freely provide.  Please keep us posted if you do upgrade the Security DVD &#8230; Oh &#8230; and keep up all the good work Alex, there are many of us that do appreciate it.</p>
<p>Celebrate Life<br />
Lorrette<br />
.-= Lorrette´s last blog ..<a href="http://dailyscrewups.com/3653/good-blonde-jokes/" rel="nofollow">Good Blonde Jokes</a> =-.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Albert Hallado</title>
		<link>http://www.howtospoter.com/web-20/wordpress/wordpress-3-0-security-design-that-need-to-be-addressed/comment-page-2#comment-24717</link>
		<dc:creator>Albert Hallado</dc:creator>
		<pubDate>Thu, 20 May 2010 23:44:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.howtospoter.com/?p=1388#comment-24717</guid>
		<description>Hi Alex,

Hey Bro. great job man and thank you for letting everyone aware on security it is very important matter especially when your running a Business Blog. My blog been hacked before and it was a nightmare so I really appreciate you making your effort on this again thank you and way to go...

God bless you and yours,

Albert Hallado
.-= Albert Hallado´s last blog ..&lt;a href=&quot;http://feedproxy.google.com/~r/AlbertHallado/~3/EGokMQcVwyE/&quot; rel=&quot;nofollow&quot;&gt;Need More Customers?&lt;/a&gt; =-.</description>
		<content:encoded><![CDATA[<p>Hi Alex,</p>
<p>Hey Bro. great job man and thank you for letting everyone aware on security it is very important matter especially when your running a Business Blog. My blog been hacked before and it was a nightmare so I really appreciate you making your effort on this again thank you and way to go&#8230;</p>
<p>God bless you and yours,</p>
<p>Albert Hallado<br />
.-= Albert Hallado´s last blog ..<a href="http://feedproxy.google.com/~r/AlbertHallado/~3/EGokMQcVwyE/" rel="nofollow">Need More Customers?</a> =-.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michey</title>
		<link>http://www.howtospoter.com/web-20/wordpress/wordpress-3-0-security-design-that-need-to-be-addressed/comment-page-2#comment-24714</link>
		<dc:creator>Michey</dc:creator>
		<pubDate>Thu, 20 May 2010 20:19:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.howtospoter.com/?p=1388#comment-24714</guid>
		<description>Thank you Alex!
.-= Michey´s last blog ..&lt;a href=&quot;http://michaelacernescu.com/clickbank-predators-review/&quot; rel=&quot;nofollow&quot;&gt;CB Predators Review&lt;/a&gt; =-.</description>
		<content:encoded><![CDATA[<p>Thank you Alex!<br />
.-= Michey´s last blog ..<a href="http://michaelacernescu.com/clickbank-predators-review/" rel="nofollow">CB Predators Review</a> =-.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michey</title>
		<link>http://www.howtospoter.com/web-20/wordpress/wordpress-3-0-security-design-that-need-to-be-addressed/comment-page-2#comment-24712</link>
		<dc:creator>Michey</dc:creator>
		<pubDate>Thu, 20 May 2010 19:56:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.howtospoter.com/?p=1388#comment-24712</guid>
		<description>Alex, I am looking forward to the release of WP 3.0, this is good and deep info you provide here, I have your security DVD so I try to stay informed and apply your tactics...
May I have a question, do you intend to have an update of the Security DVD which will work for WP 3.0?
Thanks
Michey
.-= Michey´s last blog ..&lt;a href=&quot;http://michaelacernescu.com/clickbank-predators-review/&quot; rel=&quot;nofollow&quot;&gt;CB Predators Review&lt;/a&gt; =-.</description>
		<content:encoded><![CDATA[<p>Alex, I am looking forward to the release of WP 3.0, this is good and deep info you provide here, I have your security DVD so I try to stay informed and apply your tactics&#8230;<br />
May I have a question, do you intend to have an update of the Security DVD which will work for WP 3.0?<br />
Thanks<br />
Michey<br />
.-= Michey´s last blog ..<a href="http://michaelacernescu.com/clickbank-predators-review/" rel="nofollow">CB Predators Review</a> =-.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: TheSpotter</title>
		<link>http://www.howtospoter.com/web-20/wordpress/wordpress-3-0-security-design-that-need-to-be-addressed/comment-page-2#comment-24711</link>
		<dc:creator>TheSpotter</dc:creator>
		<pubDate>Thu, 20 May 2010 19:35:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.howtospoter.com/?p=1388#comment-24711</guid>
		<description>Thanks Barney,

I don&#039;t expect everyone to agree with my &lt;em&gt;personal option&lt;/em&gt; or like my choice of style used in the post but I feel sometimes that bold or italics simply don&#039;t do justice to emphasize the point. 

I do appreciate the time you took to provide such a detailed comment and obviously glad that my concern rings true for you as well. I know for a fact of hosts planning to provide mass support for WPMU to separate themselves and I see it becoming (higher priced) norm at some point.</description>
		<content:encoded><![CDATA[<p>Thanks Barney,</p>
<p>I don&#8217;t expect everyone to agree with my <em>personal option</em> or like my choice of style used in the post but I feel sometimes that bold or italics simply don&#8217;t do justice to emphasize the point. </p>
<p>I do appreciate the time you took to provide such a detailed comment and obviously glad that my concern rings true for you as well. I know for a fact of hosts planning to provide mass support for WPMU to separate themselves and I see it becoming (higher priced) norm at some point.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: barney</title>
		<link>http://www.howtospoter.com/web-20/wordpress/wordpress-3-0-security-design-that-need-to-be-addressed/comment-page-2#comment-24710</link>
		<dc:creator>barney</dc:creator>
		<pubDate>Thu, 20 May 2010 19:20:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.howtospoter.com/?p=1388#comment-24710</guid>
		<description>It is easy thing - and commonly done! - to focus on one aspect of a conversation to the exclusion of all else.  It happens every day, at work, at home, at leisure/play.  (More than one [bar] fight has been started for just that reason.)  

It&#039;s not quite so easy to ignore the possible incendiary nature of a single concept until the conversation has completed and the whole can be taken in context.

Several folk commenting here have chosen that 1st path &amp; ignored the 2nd.

Any discussion involving security will include &#039;scare tactics&#039; ... it&#039;s the nature of the beast.  Security can only be evaluated _when it fails_.  So, any rational discussion of security is likely to include a worst-case scenario.  That&#039;s not fear-mongering, it&#039;s rational thought.  Before we implement a security _solution_, we need to have a reasonable expectation of what to expect if it fails - what happens when the failsafe fails?

Andrea_R had several points, some of which violated the precepts of her own post on contributing.
 
Some time back, when I first became interested in password strengths, a casual search turned up four (4) of them, which produced four (4) widely variant strength judgements on the same eight (8) character password.  So the question is how good is the validator?  (TheSpotter, pay attention.)

Her 2nd &amp; 3rd points have to do with privilege and elevation, an issue which WP has _addressed_, but not _resolved_.

The 4th point (as well as the 2nd and 3rd)?  Don&#039;t tell a developer/hacker that they cannot do something:  they will take it as a challenge, do it, and publish it.

The 5th point is irrelevant to the post upon which you comment - the mention was of a possibility of hacking the server from within WP, not an aim, per se, of taking over the server.

The following paragraph containded several statements not germane to the discussion at hand - obfuscation &amp; misdirection, whether intended or not.  (Oh, yeah, she used caps to complain about caps .).

Andrea_S seems to have violated several precepts of her own recommended post:
precepts 1-3, although that is open to interpretation;
precept 7, to my mind, was definitely violated by the sftp/ftp comment and the closing paragraph.

(Follow your own advice, young lady .)

Then Philip M Hofer came up with an extraneous and totally invalid [grandfather] argument that a fault in the discussion has always been there.  Does that mean it should remain?  As for the analogy, although analogy is always suspect, _yes_ - if the umpire made an obviously bad call, chastise the umpire.

Although I have [cosmetic] complaints in regard to the post (TheSpotter, you have italics &amp; bold capability - use them!), the meat of the post proposes a real concern.  I disagree with a couple of the statements, but the overall concept registers as valid and true.

While WPMU has been around for a while, it has been in a very tightly controlled environment.  This version of WP will release it into the wild, where control will be questionable, at best.  The built-in safeguards are simply not adequate to the projected usage.  A fairly simple SQL injection attack, while it might not work on http://wordpress.com, could be sufficient to take control of MU elements in the wild.  From there, total control is a possibility.</description>
		<content:encoded><![CDATA[<p>It is easy thing &#8211; and commonly done! &#8211; to focus on one aspect of a conversation to the exclusion of all else.  It happens every day, at work, at home, at leisure/play.  (More than one [bar] fight has been started for just that reason.)  </p>
<p>It&#8217;s not quite so easy to ignore the possible incendiary nature of a single concept until the conversation has completed and the whole can be taken in context.</p>
<p>Several folk commenting here have chosen that 1st path &amp; ignored the 2nd.</p>
<p>Any discussion involving security will include &#8216;scare tactics&#8217; &#8230; it&#8217;s the nature of the beast.  Security can only be evaluated _when it fails_.  So, any rational discussion of security is likely to include a worst-case scenario.  That&#8217;s not fear-mongering, it&#8217;s rational thought.  Before we implement a security _solution_, we need to have a reasonable expectation of what to expect if it fails &#8211; what happens when the failsafe fails?</p>
<p>Andrea_R had several points, some of which violated the precepts of her own post on contributing.</p>
<p>Some time back, when I first became interested in password strengths, a casual search turned up four (4) of them, which produced four (4) widely variant strength judgements on the same eight (8) character password.  So the question is how good is the validator?  (TheSpotter, pay attention.)</p>
<p>Her 2nd &amp; 3rd points have to do with privilege and elevation, an issue which WP has _addressed_, but not _resolved_.</p>
<p>The 4th point (as well as the 2nd and 3rd)?  Don&#8217;t tell a developer/hacker that they cannot do something:  they will take it as a challenge, do it, and publish it.</p>
<p>The 5th point is irrelevant to the post upon which you comment &#8211; the mention was of a possibility of hacking the server from within WP, not an aim, per se, of taking over the server.</p>
<p>The following paragraph containded several statements not germane to the discussion at hand &#8211; obfuscation &amp; misdirection, whether intended or not.  (Oh, yeah, she used caps to complain about caps .).</p>
<p>Andrea_S seems to have violated several precepts of her own recommended post:<br />
precepts 1-3, although that is open to interpretation;<br />
precept 7, to my mind, was definitely violated by the sftp/ftp comment and the closing paragraph.</p>
<p>(Follow your own advice, young lady .)</p>
<p>Then Philip M Hofer came up with an extraneous and totally invalid [grandfather] argument that a fault in the discussion has always been there.  Does that mean it should remain?  As for the analogy, although analogy is always suspect, _yes_ &#8211; if the umpire made an obviously bad call, chastise the umpire.</p>
<p>Although I have [cosmetic] complaints in regard to the post (TheSpotter, you have italics &amp; bold capability &#8211; use them!), the meat of the post proposes a real concern.  I disagree with a couple of the statements, but the overall concept registers as valid and true.</p>
<p>While WPMU has been around for a while, it has been in a very tightly controlled environment.  This version of WP will release it into the wild, where control will be questionable, at best.  The built-in safeguards are simply not adequate to the projected usage.  A fairly simple SQL injection attack, while it might not work on <a href="http://wordpress.com" rel="nofollow">http://wordpress.com</a>, could be sufficient to take control of MU elements in the wild.  From there, total control is a possibility.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: TheSpotter</title>
		<link>http://www.howtospoter.com/web-20/wordpress/wordpress-3-0-security-design-that-need-to-be-addressed/comment-page-1#comment-24708</link>
		<dc:creator>TheSpotter</dc:creator>
		<pubDate>Thu, 20 May 2010 19:06:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.howtospoter.com/?p=1388#comment-24708</guid>
		<description>Thanks Robert, I agree and your plugin recommendation is appreciated. I haven&#039;t used it but I know it is extremely similar in what it does to &lt;em&gt;&quot;Limit Login Attempts&quot;&lt;/em&gt; plugin I shared here.</description>
		<content:encoded><![CDATA[<p>Thanks Robert, I agree and your plugin recommendation is appreciated. I haven&#8217;t used it but I know it is extremely similar in what it does to <em>&#8220;Limit Login Attempts&#8221;</em> plugin I shared here.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

