Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I wanted to snark "yes", but truthfully, the problem is that Wordpress' security has been average, not especially bad. The problem is that average is terrible. Most average products don't get hit with this level of scrutiny, but certainly the sort of errors that Wordpress makes with frightening regularity are made by numerous other commercial and open source projects as well.


There are unforced errors in Wordpress. Every web application will have a cross-site scripting mistake. It takes a special one to have "anonymous commenter" -> "admin" privilege escalation, or executable style templates.


Alas, I could (but won't) name fairly equivalent errors made at a place that I may or may not work. (If not worse than the ones you mention.) I think the only place we differ here is our exact level of cynicism. "More cynical than tptacek" probably means I need to tone it down.


That is my favorite Hacker News comment sentence of the year. Thanks.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: