From: Matt Mullenweg <m...@mullenweg.com>
Date: Sun, 23 Sep 2007 12:35:26 -0700
Local: Sun, Sep 23 2007 3:35 pm
Subject: Re: [wp-hackers] Plugin update & security / privacy
Moritz 'Morty' Strübe wrote: Your blog URL and version has been sent by default for 4+ years to every > I know this will not change until Monday, but is it really necessary to > transmit the URL? ping service in the world, including Ping-O-Matic, every time you make a post. Of course you can turn that off, just like you can turn update notification off, but statistically no one does. The only new information being sent by the update checker is PHP version http://wordpress.org/extend/plugins/disable-wordpress-core-update/ Of course don't forget the WP dev blog and planet RSS feeds, and most I would also recommend disabling the updates in Mac OS X, Firefox, > If that database Such an attack would not be more effective, it would just be more > gets public and you find a security bug in one of the plugins - there > are enough - you can start a _very_ effective attack! efficient. Historically, however, scripts that attack against WordPress don't bother checking the version or if a plugin is there or not, they just seek out every WP blog and check the specific capability or vulnerability. Nevertheless, we're beefing up the infrastructure and security of I think this feature is actually going to dramatically improve the I would like to remind the participants of this thread that WP.org != -- You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||