Bonum Certa Men Certa

Back Door (Automatic Update) in WordPress and What It Means to Techrights

Matt Mullenweg
Author: Ronny Siegel



Summary: Techrights is moving to Drupal now that WordPress introduces back doors as part of the core package

Techrights was always a WordPress-based Web site. I have been with the WordPress for nearly a decade and I met its co-founder (Mike Little) for coffee about 8 years ago, back when I was more actively involved in the development side. That was around the time this Web site started. It used WordPress 2.0 for quite a few years (and since the very start) because this version was a long-term support release (as required for inclusion in Debian GNU/Linux software respositories). Contrary to some smears and lies, Techrights never got cracked in any way whatsoever. It's build very securely and only DDOS attacks took it down. Around 2009 there was an upgrade which resulted in very little change to the site's appearance as consistency was a priority. In response to DDOS attacks it also added a cache proxy and more CPU cores. To the outsider (visitor), this site today looks very similar to how it looked 7 years ago. But this aging look makes it less suitable for its breadth. In fact, a blogging platform was outgrown when we added a Wiki (later in the same year) and now we deal with issues of organisational nature. WordPress has just had a release with automatic updates [1,2] (security risk in itself, but it's toggled off by default, for now) and there is already a bugfix release [3], which in many cases will get installed automatically even though it has no security-related fixes. This can be risky if the update mechanism gets hijacked (as has happened before to other companies). Governments can compel companies to misuse this mechanism or secretly take over it* in order to install Trojan horses in the background (targeting particular sites). In any event, automatic updates come with risks that are backdoor-like; Drupal, a European project, does not have this issue, at least not yet. The front page of this site is now Drupal-powered and it is a sign of things to come. The plan is -- one way or another -- to make Drupal the primary component of the site without disrupting or even changing the old pages. The transition can be slow, but we're determined to make it happen.

____ * The NSA is good at covert action and Automattic would be easy pickings for it, not just because it's US-based (packets can be sniffed and decrypted for passwords). While I have enormous trust and respect for Matt Mullenweg, who is a charming man of integrity, I very much doubt he can challenge his government technically and legally. An intervention-free remote update mechanism is a trade-off between security and so-called 'national security' (the oppressors' power). Remember that WordPress got backdoored once before (core -- not plugins -- in version 2.1.1). Linux too was a victim, a few years earlier (it was developed and hosted in the United States at the time). The very existence of backdoor-like mechanism is begging to be abused. Experience teaches that it does get abused, and far more often than most of us choose to believe. The more subversive sites become, the bigger a target they become for authorities' 'legalised' cracking teams.

Related/contextual items from the news:



  1. WordPress 3.7 introduces automatic updates
    The WordPress team has announced the release of version 3.7 which makes WordPress more secure. The release is named “Basie” in honor of Count Basie.


  2. WordPress 3.7 Debuts, Improving Security for Millions


  3. WordPress 3.7.1 Maintenance Release


Recent Techrights' Posts

Microsoft Windows Down to 23% in Spain
the rate of change is noteworthy
Truth is Always Truth
Desperate efforts to suppress the truth resulted in even worse chaos and some people are going to pay for it
GNOME Foundation Welcomes Dolly
It didn't work out with Molly and Holly
 
Windows Falls Below 20% in Tunisia
A month ago we wrote about GNU/Linux in Tunisia
Links 15/07/2024: Google Wants Wiz and Why "Sports Ruin Everything"
Links for the day
Gemini Links 15/07/2024: Old Computer Challenge and Sending Files via NNCP
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, July 14, 2024
IRC logs for Sunday, July 14, 2024
Debian History Harassment & Abuse culture evolution
Reprinted with permission from Daniel Pocock
[Meme] It Is Not About Empowerment, It's About Optics for Bigots and Businessmen
Truth hurts
Android Surges to New Highs in Georgia, Windows Plunges to 30% (It Was 99% in 2012)
Until 2012 almost all Web requests there came from Windows
Another Casualty of the 'GAI' Ponzi Scheme: Most of the News Cycle and News Sites
accelerated death of journalism
Empowering Predators Who Fancy Exercising Control Over Women (Using Corporate Money)
Remember this when Google talks about diversity, women etc.
GNU/Linux Continues Its Rapid Growth in July, Today We Look at Belgium
Again, a word of caution: statCounter isn't a perfect yardstick
Links 14/07/2024: Goldman Sachs Says 'Advanced' or 'Generative' Hey Hi (AI) is Just Hype, Thoughts on Negatives
Links for the day
Links 14/07/2024: Perils for AI PC Hype Train, Further Attacks on Freedom of the Press
Links for the day
A Response to Bill Maher's Senseless Attacks on Julian Assange and Wikileaks
published a few hours ago
The List of Sites or Sources for Linux News is Getting Shorter Over Time (Despite GNU and Linux Steadily Growing in Usage)
A lack of publishing begets lack of educated, informed population (a return to Dark Ages where rulers leverage mass ignorance)
The Number of Web Servers Has Gone Down
Cloud fatigue deux?
[Meme] GNOME Foundation's Relationship With Women
Lots more coming soon, so stay tuned
The Smugness of "I'm a Journalist"
Attacking women for expressing their opinions (for example, about the abuse they received) isn't unprecedented
It Takes No Courage to Become Another Corporate Stooge
transition to spam
Why Techrights Has Just Programmatically Blacklisted ZDNet
Even their "Linux" writers are AWOL
Gemini Links 14/07/2024: The Stress of 24/7 Notifications and FOSS tools for Sipeed Tang Nano 1K
Links for the day
Windows Already Down to 10% in Lao (It was 96% a Decade and a Half Ago), Vista 11 Adoption Has Stalled
And GNU/Linux is topping a 1-year high in Loa
IRC Proceedings: Saturday, July 13, 2024
IRC logs for Saturday, July 13, 2024
Over at Tux Machines...
GNU/Linux news for the past day
Links 13/07/2024: Patent Trolls in UK Court of Appeal, Eric Schmidt Continues so Show Womanising at Google
Links for the day
Links 13/07/2024: Not Quite Dead Yet After All and Unfederated E-mail
Links for the day
Holly Million, GNOME Foundation departure after Albanian whistleblower revelations
Reprinted with permission from Daniel Pocock
Julian Assange’s Brother Gabriel Shipton Explains the Logistics of 'Smuggling' Julian Out of the United Kingdom
a lot of new information and prison stories
[Meme] Like They Got Rid of Molly (and Now Holly)
Pay over 100,000 dollars a year for someone without any background in tech (to "lead" a tech project)
Microsoft Windows Falls to Almost 10% in Palestine (It Was Measured at 100% Just 15 Years Ago)
quite a big drop
Guardianship of the Licence is Not Enough (the Case of Systemd and Microsoft)
Whether the GPL gets enforced or not, if people adopt lousy software, that will have negative consequences
Speaking Out and Spreading the Message of GNU
Free Software Foundation (FSF) got 112 new members since 2.5 weeks ago
[Video] Why Wikileaks Publishing War-Related Documents Was Both Important and Justified
It's important to remember the principle which says privacy is for the powerless, whereas the powerful (like those with the power to kill) deserve not privacy but transparency
3.5 Years in Gemini
It's important to speak about and spread the word (about software freedom, BSD, GNU/Linux, patents etc.) in a medium that's strategic and growing
[Meme] Whoever in GNOME Decided to Attack the G (GNU), It Was a Foolish Miscalculation
How could they expect any outcome other than GNOME's own collapse?
Windows Down to Unprecedented Low in Czech Republic, Android Rises to New Record
From 98% in July 2009 (15 years ago) Windows is down to all-time low of 38% and well below Android
GNOME Foundation Lost Nearly a Million Dollars in 2 Years, IBM and GAFAM Won't Bail It Out Anymore
Seems like a suicide mission
Google News Has Become a Big Pile of Garbage
The issue predates chatbots, but these SEO tricks were accelerated somewhat by slop
OpenAI and ChatGPT Could Very Well Collapse and Shut Down Later This Year (Huge Losses, Sagging Usage Levels, and Massive Debt)
we illuminate the suppressed observations that Microsoft-sponsored publishers and cheaply-made slop (LLM spew disguised as "news") try to distract from
[Meme] Attacking the "G" in GNOME (Since 2009) Was a Mistake
Spending 50,000 pounds to sue women of racial minority
Difficult Times in GNOME Foundation
GNOME Foundation is in "crisis management" or "face-saving" or "damage control" mode
Links 13/07/2024: TikTok Interferences, YouTube Throttled in Russia
Links for the day
Kathy Lette on Julian Assange Staying at Her Attic, Why His Release Matters So Much, and Jen Robinson Staying Over Yesterday
They talk a lot about politics, but the segment mentions publishers, including Rushdie
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, July 12, 2024
IRC logs for Friday, July 12, 2024
Microsoft Windows Down to a New Low in Canada (Only a Third)
Very steep decline a decade ago