saw a report about this and just updated my blogs
- Rachel Clarke
also, love that Friendfeed now has the 'comment' button at the bottom even when viewing as part of stream,A change that happened in the last few days
- Rachel Clarke
I upgraded mine to 2.8.4 this morning, and then later saw a report about the 2.8.3 vulnerability.
- Joey Gibson
It's a pain in the butt, but I upgraded all of my sites this morning.
- Derek Coward
Alan: it was worse than that. We were still on 2.7x.
- Robert Scoble
Someone might want to warn the Techcrunch blog(s), they appear to be on 2.7.1 still.
- Mo Kargas
No, don't tell Techcrunch, they are too busy reporting on stuff.
- Alex Scoble
Any who has a following should let any of their Wordpress friends know about this. As I understand this flaw doesn't give the hacker access to the blog, just changes the password to mess with the owner.
- Keith Rowland
"Yesterday a vulnerability was discovered: a specially crafted URL could be requested that would allow an attacker to bypass a security check to verify a user requested a password reset. As a result, the first account without a key in the database (usually the admin account) would have its password reset and a new password would be emailed to the account owner." - Wordpress.org
- Keith Rowland
I tried calling Arrington, he didn't pick up the phone. Oh well. I did leave him a message.
- Robert Scoble
Does anybody use Thesis and if you do how do you like it? I'm considering purchasing a Thesis to update my old blog.
- Jeunelle Foster
I use Thesis on four blogs. It is well worth it. I ran K2 before that, which was good, but the things you can do with openhook on Thesis takes it to another class.
- david
I don't personally use Wordpress currently but for the "we wouldn't touch wordpress etc.." crew, what makes you think your choice of CMS/blog is any more secure? Even if you use static HTML, http servers can still sometimes be exploited. Being complacent about security because you chose some other software, is almost recklessly naive.
- dannystaple
Bummer. This happened to me in April. Someone hacked into one of my Wordpress accounts and dismantled my blog completely. I'm pretty tired of updating and maintaining my Wordpress sites. It's a constant task. Typepad has actually been the most headache free platform in my experience. Squarespace is sounding pretty good these days though. Maybe I'll go totally minimalist and just do the Posterous thing.
- Richard Merritt
It's a little easier with the the in admin update tool. Would be nice if it could do it automatically though
- James Tenniswood
The "vulnerability" found the other day was more of an annoyance, really. It didn't offer a way into the site, just a way to reset the password and mail the new password to the admin.
- Otto
Richard: or you could switch to a managed wordpress.com blog and import all your posts easily. then you dont have to worry about upgrading. A upgraded Wordpress.com site is better than a squarespace site IMO.
- Logan Lindquist
From what I understand the admin password vuln isn't that big a deal because they would need access to your email as well and if they have that your already screwed.
- Logan Lindquist
This once more raises the question: is wordpress really worth all the hassles? It's far from the clean, intuitive system it once was, as anyone who has tried to show someone how to use it to build and maintain a reasonably full featured solution will find out.
- Joelle Nebbe (iphigenie)
I'm sorry to hear you were hacked. Yes, I upgraded to 2.8.4 when I read about the vulnerabilities.
- Shevonne
"my FTP client kept timing out." - Have you tried the automatic updater in the control panel?
- John Craft
Joelle: its not a hassle. yes its worth it. if you dont like managing the upgrades pay for a wordpress.com.
- Logan Lindquist
what do you mean hacked? 2.8.3 only meant someone could do something that reset your password and emailed it to you (happened to me) but they wouldnt know your password. (this all assuming you were on 2.8.3?)
- Paul Stamatiou
Paul: well, I was on 2.7x and someone reset my password AND posted some porn links into a blog post of mine.
- Robert Scoble
Congrats, Tamar! And good to see you back. If you're interested, you can run your own baby pool contest on my site here: http://bebepool.com ~ all the best!
- Micah Wittman
Yay! I can talk about it publicly now! Congratulations, Tamar. Great to see you at SXSW. (Also, sounds like I have to send a louisgray.com onesie)
- Louis Gray