Live data from Hacker News

Why Wordpress?

johnmaeda.com

1–10 of 90 posts

Re: Why Wordpress?

#2
Because it's ability to generate a limitless supply of zero-days makes it easier for us in San Francisco to go after blogs we don't politically agree with.

Isn't that right, Mr. Altman. :D

Re: Why Wordpress?

#3
I'm looking at the "dead" comment by PravlageTiem. I understand that PravlageTiem was being sarcastic, and some people feel that sarcasm undermines the tone that is supposed to prevail on Hacker News. But still, PravlageTiem raises an important point:

WordPress has historically been a security nightmare.

Possibly there was a tone of anger in the way PravlageTiem expressed themselves, but the security flaws in WordPress are worth discussing any time that WordPress is discussed.

Certainly, when I have a freelance client, and they ask me "Should we use WordPress?" I typically answer with some long version of "It has a good admin section for non-technical users, and also designers love it, but it also has a lot of security flaws."

Re: Why Wordpress?

#4
post #3

I'm looking at the "dead" comment by PravlageTiem. I understand that PravlageTiem was being sarcastic, and some people feel that sarcasm undermines the tone that is supposed to prevail on Hacker News. But still, PravlageTiem raises an important point: WordPress has historically been a security nightmare. Possibly there was a tone of anger in the way PravlageTiem expressed themselves, but the security flaws in WordPre…

That's why wpengine is such an excellent choice for a lot of users.

On the topic of PravlageTiem, the issue of WordPress' security flaws seems to be incidental to his attempt to accuse Sam Altman of censorship. If I had to guess, that would be why the comment is dead. I wouldn't call that sarcasm.

Re: Why Wordpress?

#5
post #3

I'm looking at the "dead" comment by PravlageTiem. I understand that PravlageTiem was being sarcastic, and some people feel that sarcasm undermines the tone that is supposed to prevail on Hacker News. But still, PravlageTiem raises an important point: WordPress has historically been a security nightmare. Possibly there was a tone of anger in the way PravlageTiem expressed themselves, but the security flaws in WordPre…

> WordPress has historically been a security nightmare.

This. And all this started around the same time - in 2006 -- when Stefan Esse, the PHP security expert "resigned".

In a blog post in 2006 (that can no longer be found) Esse was quoted as saying he quit > "because among other things they were resistant to his finding bugs in PHP, and had refused to patch some of the bugs he found."

Source(s)

http://www.darkreading.com/risk/php-security-expert-quits/d/...?

https://preilly.me/2006/11/09/php-security-expert-resigns/

PHP is the backbone of WordPress and none of the core team members have taken any of it's security holes seriously, many of which can be traced back to PHP's security hole. They simply come out with "It's the Plugin-Developer's fault" every few months when a security hole is found.

I don't think it's in their best (business) interest to fix WordPress' security holes any time soon. Because Matt Mullenweg, and other "Wordpress Security" companies like Sucuri Security, even WP Engine, all charge an arm and a length (WP Engine is 100$ a month for a simple blog serving < 25K pageviews a month) by selling "Peace of Mind" security with Wordpress if you use them / host with them.

Re: Why Wordpress?

#6
post #4
post #3

I'm looking at the "dead" comment by PravlageTiem. I understand that PravlageTiem was being sarcastic, and some people feel that sarcasm undermines the tone that is supposed to prevail on Hacker News. But still, PravlageTiem raises an important point: WordPress has historically been a security nightmare. Possibly there was a tone of anger in the way PravlageTiem expressed themselves, but the security flaws in WordPre…

That's why wpengine is such an excellent choice for a lot of users. On the topic of PravlageTiem, the issue of WordPress' security flaws seems to be incidental to his attempt to accuse Sam Altman of censorship. If I had to guess, that would be why the comment is dead. I wouldn't call that sarcasm.

> wpengine is such an excellent choice for a lot of users.

Here we go! Like I stated in my comment, companies like WP Engine, Sucuri and other can easily charge 100$ + for what costs Fear is a great motivator.

Re: Why Wordpress?

#7
post #4
post #3

I'm looking at the "dead" comment by PravlageTiem. I understand that PravlageTiem was being sarcastic, and some people feel that sarcasm undermines the tone that is supposed to prevail on Hacker News. But still, PravlageTiem raises an important point: WordPress has historically been a security nightmare. Possibly there was a tone of anger in the way PravlageTiem expressed themselves, but the security flaws in WordPre…

That's why wpengine is such an excellent choice for a lot of users. On the topic of PravlageTiem, the issue of WordPress' security flaws seems to be incidental to his attempt to accuse Sam Altman of censorship. If I had to guess, that would be why the comment is dead. I wouldn't call that sarcasm.

Even with WPengine, security issues are a very common thing. WPengine can keep some things up to date, but plugins and themes are exploited often. Worse, an enterprise deployment at scale is a huge nightmare. Exploiting WP sites on HackerOne can be a very profitable business for many.

Re: Why Wordpress?

#8
post #3

I'm looking at the "dead" comment by PravlageTiem. I understand that PravlageTiem was being sarcastic, and some people feel that sarcasm undermines the tone that is supposed to prevail on Hacker News. But still, PravlageTiem raises an important point: WordPress has historically been a security nightmare. Possibly there was a tone of anger in the way PravlageTiem expressed themselves, but the security flaws in WordPre…

For context, here's what the dead comment says:

""" Because it's ability to generate a limitless supply of zero-days makes it easier for us in San Francisco to go after blogs we don't politically agree with.

Isn't that right, Mr. Altman. :D """

Re: Why Wordpress?

#9
Because people who don't actually know how to build websites are fooled into thinking they have a tool that will fill that knowledge gap, despite the security implications that they are oblivious to.

Re: Why Wordpress?

#10
I used to have a WordPress-based blog. It was indeed a nightmare to keep up to date, unless a bit after version 2, where they included the option of automatic updates, and the whole thing was a bit more manageable. Not because it was too much of a problem before (download the compressed file, uncompress, move to the correct folder), but because sometimes an update came out and I didn't notice. Had malware installed once, was a nightmare to get rid of.

For a variety of reasons, the blog crashed and when I started a new one, I chose Pelican[1]. Haven't looked back.

[1] https://github.com/getpelican/pelican (linking to the github repository because the main site happens to be down https://github.com/getpelican/pelican/issues/2079).

Post reply on HN