Bonum Certa Men Certa

Back Door (Automatic Update) in WordPress and What It Means to Techrights

Matt Mullenweg
Author: Ronny Siegel



Summary: Techrights is moving to Drupal now that WordPress introduces back doors as part of the core package

Techrights was always a WordPress-based Web site. I have been with the WordPress for nearly a decade and I met its co-founder (Mike Little) for coffee about 8 years ago, back when I was more actively involved in the development side. That was around the time this Web site started. It used WordPress 2.0 for quite a few years (and since the very start) because this version was a long-term support release (as required for inclusion in Debian GNU/Linux software respositories). Contrary to some smears and lies, Techrights never got cracked in any way whatsoever. It's build very securely and only DDOS attacks took it down. Around 2009 there was an upgrade which resulted in very little change to the site's appearance as consistency was a priority. In response to DDOS attacks it also added a cache proxy and more CPU cores. To the outsider (visitor), this site today looks very similar to how it looked 7 years ago. But this aging look makes it less suitable for its breadth. In fact, a blogging platform was outgrown when we added a Wiki (later in the same year) and now we deal with issues of organisational nature. WordPress has just had a release with automatic updates [1,2] (security risk in itself, but it's toggled off by default, for now) and there is already a bugfix release [3], which in many cases will get installed automatically even though it has no security-related fixes. This can be risky if the update mechanism gets hijacked (as has happened before to other companies). Governments can compel companies to misuse this mechanism or secretly take over it* in order to install Trojan horses in the background (targeting particular sites). In any event, automatic updates come with risks that are backdoor-like; Drupal, a European project, does not have this issue, at least not yet. The front page of this site is now Drupal-powered and it is a sign of things to come. The plan is -- one way or another -- to make Drupal the primary component of the site without disrupting or even changing the old pages. The transition can be slow, but we're determined to make it happen.

____ * The NSA is good at covert action and Automattic would be easy pickings for it, not just because it's US-based (packets can be sniffed and decrypted for passwords). While I have enormous trust and respect for Matt Mullenweg, who is a charming man of integrity, I very much doubt he can challenge his government technically and legally. An intervention-free remote update mechanism is a trade-off between security and so-called 'national security' (the oppressors' power). Remember that WordPress got backdoored once before (core -- not plugins -- in version 2.1.1). Linux too was a victim, a few years earlier (it was developed and hosted in the United States at the time). The very existence of backdoor-like mechanism is begging to be abused. Experience teaches that it does get abused, and far more often than most of us choose to believe. The more subversive sites become, the bigger a target they become for authorities' 'legalised' cracking teams.

Related/contextual items from the news:



  1. WordPress 3.7 introduces automatic updates
    The WordPress team has announced the release of version 3.7 which makes WordPress more secure. The release is named “Basie” in honor of Count Basie.


  2. WordPress 3.7 Debuts, Improving Security for Millions


  3. WordPress 3.7.1 Maintenance Release


Recent Techrights' Posts

Computer Users Aren't Zoo Animals
Animals don't belong inside cages in zoos, either
[Meme] Not About How Many Locks One Adds
Some people try to point their fingers in all the wrong directions now that a new patch is available for rsync
Total Lock-down Ambitions - Part I - DRM and TPM Need Not be the Future of Computing, There's Another Way
Who is being restricted? Us, the users.
New Upcoming Series About DRM and TPM
We'll do our best to name and explain some of the alternatives that are still available
 
Links 16/01/2025: "Meduza, IRL" and the Clock is Ticking on TikTok in the US
Links for the day
Gemini Links 16/01/2025: Yesterday's Gone, The Hour of the Dragon by Robert E Howard
Links for the day
Links 16/01/2025: Scale and Scope of Microsoft Layoffs Revealed (Two Waves of Layoffs in 2025 Already)
Links for the day
Gemini Links 16/01/2025: Meta Has a Pixelfed Problem and Space Time Scoping
Links for the day
Anti-Linux 'Articles' in linuxsecurity.com (Guardian Digital, Inc) Are Composed by Bots, Probably Microsoft's
linuxsecurity.com has become a mindless stream of LLM slop
"New Year, New Career"
published a few hours ago
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, January 15, 2025
IRC logs for Wednesday, January 15, 2025
If You See Many Microsoft Puff Pieces That All Say More or Less the Same, Consider the Possibility That Microsoft LLMs 'Wrote' Those
There are also many phantom fake 'reports' about Microsoft in relation to some "hey hi" (AI) things
[Meme] The Crybully
Crybullies shrug
IRC Logs Complete in Geminispace (Even in GemText Format!)
We still envision ourselves - a community of justice-seeking enthusiasts - as a multi-protocol platform, not just some ordinary Web site
It Was Only a Matter of Time
We're going to pursue justice
[Meme] "Well, He’s Dead So," Bill Gates Tells the Media (Which He Pays) About His Close Friend Jeffrey Epstein
Does the police in San Francisco cover up crimes instead of solving them?
The Rumour Was Right, Today is the Second Large Wave of Microsoft Layoffs in 2025
It has only been two weeks since the year began
The Free Software Foundation (FSF) Has Had a Good 2025 Already (Its "Year 40")
FSF will reach $400,000
[Meme] His Existence is Proof It's Not Infeasible
We salute the FSF's original mission
Links 15/01/2025: Efforts to End Wars and 'Newsflation'
Links for the day
Gemini Links 15/01/2025: Abandoning Windows for GNU/Linux, SIS Progress Update
Links for the day
Links 15/01/2025: Social Control Media Spreading Lies, TikTok Banned in 4 Days
Links for the day
More Microsoft Cuts and Layoffs (Microsoft Media Mole Jordan Novet Tries to Float "Hiring Freezes" Spin After the "Headcount" Spin Failed)
As one might expect...
Microsoft Breaks Linux Again
Does it even care? It's selling Windows.
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, January 14, 2025
IRC logs for Tuesday, January 14, 2025
Links 14/01/2025: Vaccination Hesitancy Problems and Kangaroo Courts (UPC)
Links for the day
Gemini Links 14/01/2025: Introduction to GrapheneOS and Small Internet
Links for the day
Dr. Miriam Bastian From the Free Software Foundation (FSF) Gives a Talk in a Couple of Weeks at FOSDEM (Brussels, Belgium)
It's good to see people from all around the world and with very different backgrounds united around digital philosophy
Andy Farnell on Eating Your Own Dog Food
focuses on security but goes beyond that
EPO Uses the Misnomer "AI" to Attack Software Developers in Europe
The EPO is nowadays a huge pile of crimes
The European Patent Office’s (EPO) Communication on "Reform" is "Incomplete and Misleading," Says the Central Staff Committee at the EPO
This puts Europe at risk and makes it more vulnerable
[Meme] How to Lose Social Life (While Pretending to Still Have It)
Talk to people, not to microphones
Android (or AOSP) is More Free Than iOS, Both in Practice (as OEM Bundles) Both Are User-Hostile
In a perfect world, people would choose and deploy software that is entirely made up of reciprocally-licensed bits
Neuroscience of Consciousness Paper: Why Social Control Media and Proprietary Spyware Harm Your Health
"Software Freedom turns out to be good for your health"
Access to the Source Code of the Programs You're Using Matters (Even If You're Not a Coder and Cannot Fix Bugs)
Companies like Microsoft tell us that full access to all the code isn't important
Guardian Digital (linuxsecurity.com) Publishes Fake Articles About Linux and About (for) 'Linux' Foundation Openwashing
Brittany Day is at it again
Links 14/01/2025: LA Crisis and EU, UK Respond to "X.com" Threat From South African Oligarch
Links for the day
The Word About the Upcoming Talk by Richard Stallman - Scheduled for Friday This Week - Has Spread ("The Cost of Freedom," Lausanne, Switzerland)
So the word is spreading
"AI Music" is Not Music and It's Hardly "AI" Either
Synthetic garbage is a solution in search of a problem
Webspam in BetaNews
Not only is it marketing SPAM
[Meme] 13 Years a Slave of Microsoft
Might makes right?
Gemini Links 14/01/2025: The Gemtext Print Hurdle and New Game: Fill!
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, January 13, 2025
IRC logs for Monday, January 13, 2025