<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: WordPress 1.5.2 Security FUD</title>
	<atom:link href="http://dougal.gunters.org/blog/2005/08/17/wordpress-152-security-fud/feed" rel="self" type="application/rss+xml" />
	<link>http://dougal.gunters.org/blog/2005/08/17/wordpress-152-security-fud</link>
	<description>Random musings of a Southern geek</description>
	<pubDate>Thu, 04 Dec 2008 03:06:27 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7-RC1-10026</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: WordPress Security Annoyances &#124; no wow</title>
		<link>http://dougal.gunters.org/blog/2005/08/17/wordpress-152-security-fud/comment-page-1#comment-157062</link>
		<dc:creator>WordPress Security Annoyances &#124; no wow</dc:creator>
		<pubDate>Sat, 03 Mar 2007 03:11:39 +0000</pubDate>
		<guid isPermaLink="false">http://dougal.gunters.org/?p=643#comment-157062</guid>
		<description>[...] comments from the WordPress crowd are a bit weak in my opinion. If there&#8217;s FUD about WordPress&#8217; [...]</description>
		<content:encoded><![CDATA[<p>[...] comments from the WordPress crowd are a bit weak in my opinion. If there&#8217;s <acronym title='Fear, Uncertainty, and Doubt'><span class='caps'>FUD</span></acronym> about WordPress&#8217; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: logtar</title>
		<link>http://dougal.gunters.org/blog/2005/08/17/wordpress-152-security-fud/comment-page-1#comment-26830</link>
		<dc:creator>logtar</dc:creator>
		<pubDate>Mon, 22 Aug 2005 20:42:16 +0000</pubDate>
		<guid isPermaLink="false">http://dougal.gunters.org/?p=643#comment-26830</guid>
		<description>Upgrading is SIMPLE, got it done, been so lazy lately.</description>
		<content:encoded><![CDATA[<p>Upgrading is SIMPLE, got it done, been so lazy lately.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: WordPress Station &#187; Blog Archive &#187; WordPress 1.5.2 Security FUD</title>
		<link>http://dougal.gunters.org/blog/2005/08/17/wordpress-152-security-fud/comment-page-1#comment-26789</link>
		<dc:creator>WordPress Station &#187; Blog Archive &#187; WordPress 1.5.2 Security FUD</dc:creator>
		<pubDate>Sun, 21 Aug 2005 17:50:41 +0000</pubDate>
		<guid isPermaLink="false">http://dougal.gunters.org/?p=643#comment-26789</guid>
		<description>[...] Dougal Campbell writes at hisgeek ramblings about the confusion and clarifications regarding the most recent security update, 1.5.2. [...]</description>
		<content:encoded><![CDATA[<p>[...] Dougal Campbell writes at hisgeek ramblings about the confusion and clarifications regarding the most recent security update, 1.5.2. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Basic Thinking Blog &#187; Wordpress: Ganz schlechtes Releasemanagement</title>
		<link>http://dougal.gunters.org/blog/2005/08/17/wordpress-152-security-fud/comment-page-1#comment-26787</link>
		<dc:creator>Basic Thinking Blog &#187; Wordpress: Ganz schlechtes Releasemanagement</dc:creator>
		<pubDate>Sun, 21 Aug 2005 15:56:30 +0000</pubDate>
		<guid isPermaLink="false">http://dougal.gunters.org/?p=643#comment-26787</guid>
		<description>[...] dear guys from Wordpress, dont mess with good versioning and information policy. Regarding the security story with WP 1.5.2, your reaction, still missing an official statement, i am somehow disappointed, that your information policy is that bad. Is it that hard to report all relevant news onto wordpress.org? [...]</description>
		<content:encoded><![CDATA[<p>[...] dear guys from Wordpress, dont mess with good versioning and information policy. Regarding the security story with WP 1.5.2, your reaction, still missing an official statement, i am somehow disappointed, that your information policy is that bad. Is it that hard to report all relevant news onto wordpress.org? [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Robert</title>
		<link>http://dougal.gunters.org/blog/2005/08/17/wordpress-152-security-fud/comment-page-1#comment-26786</link>
		<dc:creator>Robert</dc:creator>
		<pubDate>Sun, 21 Aug 2005 15:25:30 +0000</pubDate>
		<guid isPermaLink="false">http://dougal.gunters.org/?p=643#comment-26786</guid>
		<description>How do i know if my WP 1.5.2. is ok or not?</description>
		<content:encoded><![CDATA[<p>How do i know if my WP 1.5.2. is ok or not?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: The Ten Thousand Year Blog &#187; Blog Archive &#187; Newer version of WordPress (1.5.2) available for download</title>
		<link>http://dougal.gunters.org/blog/2005/08/17/wordpress-152-security-fud/comment-page-1#comment-26703</link>
		<dc:creator>The Ten Thousand Year Blog &#187; Blog Archive &#187; Newer version of WordPress (1.5.2) available for download</dc:creator>
		<pubDate>Fri, 19 Aug 2005 04:40:54 +0000</pubDate>
		<guid isPermaLink="false">http://dougal.gunters.org/?p=643#comment-26703</guid>
		<description>[...] Due to a security issue uncovered after the initial announcement of version 1.5.2 of WordPress, anyone who downloaded it late Sunday night (August 14, 02005) should check that they have the latest version of wp-settings.php, according to the WordPress Development Blog, and this interesting post and comments in Doug Campbell&#8217;s Geek Ramblings blog. [...]</description>
		<content:encoded><![CDATA[<p>[...] Due to a security issue uncovered after the initial announcement of version 1.5.2 of WordPress, anyone who downloaded it late Sunday night (August 14, 02005) should check that they have the latest version of wp-settings.php, according to the WordPress Development Blog, and this interesting post and comments in Doug Campbell&#8217;s Geek Ramblings blog. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: POS Software</title>
		<link>http://dougal.gunters.org/blog/2005/08/17/wordpress-152-security-fud/comment-page-1#comment-26682</link>
		<dc:creator>POS Software</dc:creator>
		<pubDate>Fri, 19 Aug 2005 01:27:29 +0000</pubDate>
		<guid isPermaLink="false">http://dougal.gunters.org/?p=643#comment-26682</guid>
		<description>Well, I fully agree with your comment. :-) 

BTW: I visited your blog earlier today and I just wanted to congratulate you on a well presented, and informative resource. 

It's not often that I come across a web site that offers a wealth of quality. ;-)

Martin (aka POS Software Man)</description>
		<content:encoded><![CDATA[<p>Well, I fully agree with your comment. <img src='http://dougal.gunters.org/wordpress/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>BTW: I visited your blog earlier today and I just wanted to congratulate you on a well presented, and informative resource. </p>
<p>It&#8217;s not often that I come across a web site that offers a wealth of quality. <img src='http://dougal.gunters.org/wordpress/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<p>Martin (aka POS Software Man)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stefan</title>
		<link>http://dougal.gunters.org/blog/2005/08/17/wordpress-152-security-fud/comment-page-1#comment-26641</link>
		<dc:creator>Stefan</dc:creator>
		<pubDate>Thu, 18 Aug 2005 18:12:39 +0000</pubDate>
		<guid isPermaLink="false">http://dougal.gunters.org/?p=643#comment-26641</guid>
		<description>LOL @ Stefan (not Esser)

I wish people like you would not make things up to get arguments. Show me an instance, where I have disclosed stuff before the developer was contacted.</description>
		<content:encoded><![CDATA[<p><acronym title='Laughing out loud'><span class='caps'>LOL</span></acronym> @ Stefan (not Esser)</p>
<p>I wish people like you would not make things up to get arguments. Show me an instance, where I have disclosed stuff before the developer was contacted.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stefan (not Esser)</title>
		<link>http://dougal.gunters.org/blog/2005/08/17/wordpress-152-security-fud/comment-page-1#comment-26635</link>
		<dc:creator>Stefan (not Esser)</dc:creator>
		<pubDate>Thu, 18 Aug 2005 17:48:06 +0000</pubDate>
		<guid isPermaLink="false">http://dougal.gunters.org/?p=643#comment-26635</guid>
		<description>I don't like the idea that the ends justify the means. I see a lot of people saying that they don't agree with the way Stefan behaves but appreciate his work. While I can agree that he often makes a positive impact, I don't think it's unreasonable to expect more mature behavior. The point is, Stefan could make a really positive impact, but the harm he does often matches the good he does. With a bit more professionalism, he could do really great things for us all. I do appreciate his work, but I can't help but be very disappointed with his behavior. And I'm not just talking about the way he talks, but also his actions.

I won't point to specific instances, but he has a habit of public disclosure before a vulnerability has been fixed. There have even been cases where he has done this before notifying the developers. In cases where he does contact the developers first (like this one), he likes to publicize an exploit in the wild (if there is one) or "warn" users of the vulnerability, claiming that nothing short of irresponsibility could be the reason that no fix is available yet. This does not help.

So, while I find fault in the way Wordpress handled this particular event, I can't excuse Stefan's irresponsible and immature behavior. I say foul.</description>
		<content:encoded><![CDATA[<p>I don&#8217;t like the idea that the ends justify the means. I see a lot of people saying that they don&#8217;t agree with the way Stefan behaves but appreciate his work. While I can agree that he often makes a positive impact, I don&#8217;t think it&#8217;s unreasonable to expect more mature behavior. The point is, Stefan could make a really positive impact, but the harm he does often matches the good he does. With a bit more professionalism, he could do really great things for us all. I do appreciate his work, but I can&#8217;t help but be very disappointed with his behavior. And I&#8217;m not just talking about the way he talks, but also his actions.</p>
<p>I won&#8217;t point to specific instances, but he has a habit of public disclosure before a vulnerability has been fixed. There have even been cases where he has done this before notifying the developers. In cases where he does contact the developers first (like this one), he likes to publicize an exploit in the wild (if there is one) or &#8220;warn&#8221; users of the vulnerability, claiming that nothing short of irresponsibility could be the reason that no fix is available yet. This does not help.</p>
<p>So, while I find fault in the way Wordpress handled this particular event, I can&#8217;t excuse Stefan&#8217;s irresponsible and immature behavior. I say foul.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: markku</title>
		<link>http://dougal.gunters.org/blog/2005/08/17/wordpress-152-security-fud/comment-page-1#comment-26631</link>
		<dc:creator>markku</dc:creator>
		<pubDate>Thu, 18 Aug 2005 16:44:16 +0000</pubDate>
		<guid isPermaLink="false">http://dougal.gunters.org/?p=643#comment-26631</guid>
		<description>Dougal, releasing the updated package as version 1.5.2.1 or whatever unique version number would've been more advisable. It removes any confusion concerning the quality (with respect to the reported vulnerability) of the code that is within the hands of the users. I had 1.5.2, but I didn't know I was still vulnerable.</description>
		<content:encoded><![CDATA[<p>Dougal, releasing the updated package as version 1.5.2.1 or whatever unique version number would&#8217;ve been more advisable. It removes any confusion concerning the quality (with respect to the reported vulnerability) of the code that is within the hands of the users. I had 1.5.2, but I didn&#8217;t know I was still vulnerable.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
