<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: WordPress 1.5.2 released</title>
	<atom:link href="http://www.blogherald.com/2005/08/14/wordpress-152-released/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.blogherald.com/2005/08/14/wordpress-152-released/</link>
	<description>The leading source of news covering social media and the blogosphere.</description>
	<lastBuildDate>Sun, 12 Feb 2012 21:12:36 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
	<item>
		<title>By: Eitan Caspi</title>
		<link>http://www.blogherald.com/2005/08/14/wordpress-152-released/comment-page-1/#comment-44623</link>
		<dc:creator>Eitan Caspi</dc:creator>
		<pubDate>Tue, 16 Aug 2005 16:33:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.blogherald.com/2005/08/14/wordpress-152-released/#comment-44623</guid>
		<description>Hello Juergen,

Of course anyone can dive into the code and search for it, be it a hacker, be it administrator, but it will not be simple.
The developers should not hand it &quot;on a silver platter&quot; â€“ it will more be a benefit for script kiddies (learn and harm) than to administrators (learn andâ€¦???).
I believe you will agree that it is better for you to be in dark than any malicious surfer being more knowledgeable.

Regarding your note (linked from your former note) â€“ I couldn&#039;t agree more, that any software should have a simple automatic and scheduled update applet.
But don&#039;t expect too much of the free code projects, they usually struggle to build functionality with their limited resources.
Even many commercial vendors still not at it. Go figure.

Eitan</description>
		<content:encoded><![CDATA[<p>Hello Juergen,</p>
<p>Of course anyone can dive into the code and search for it, be it a hacker, be it administrator, but it will not be simple.<br />
The developers should not hand it &#8220;on a silver platter&#8221; â€“ it will more be a benefit for script kiddies (learn and harm) than to administrators (learn andâ€¦???).<br />
I believe you will agree that it is better for you to be in dark than any malicious surfer being more knowledgeable.</p>
<p>Regarding your note (linked from your former note) â€“ I couldn&#8217;t agree more, that any software should have a simple automatic and scheduled update applet.<br />
But don&#8217;t expect too much of the free code projects, they usually struggle to build functionality with their limited resources.<br />
Even many commercial vendors still not at it. Go figure.</p>
<p>Eitan</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: &#187; WordPress 1.5.2 Released TurboBlogger.com</title>
		<link>http://www.blogherald.com/2005/08/14/wordpress-152-released/comment-page-1/#comment-44552</link>
		<dc:creator>&#187; WordPress 1.5.2 Released TurboBlogger.com</dc:creator>
		<pubDate>Mon, 15 Aug 2005 20:35:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.blogherald.com/2005/08/14/wordpress-152-released/#comment-44552</guid>
		<description>[...] ly make it easier for more exploits to be designed.  I&#8217;m going to have to agree with Duncan Riley and some others that this type of security by obscurity is not appropri [...]</description>
		<content:encoded><![CDATA[<p>[...] ly make it easier for more exploits to be designed.  I&#8217;m going to have to agree with Duncan Riley and some others that this type of security by obscurity is not appropri [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Juergen Kreileder</title>
		<link>http://www.blogherald.com/2005/08/14/wordpress-152-released/comment-page-1/#comment-44549</link>
		<dc:creator>Juergen Kreileder</dc:creator>
		<pubDate>Mon, 15 Aug 2005 19:31:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.blogherald.com/2005/08/14/wordpress-152-released/#comment-44549</guid>
		<description>That&#039;s a naive argument, Eitan. Hackers are not stupid, they can figure out the issue from looking at the source code. As you&#039;ve just demonstrated, just saying &quot;we&#039;ve fixed a security issue&quot; but not giving more specific information easily leads to a false sense of security.

(Slightly longer reply to some comments I&#039;ve received available &lt;a href=&quot;http://blog.blackdown.de/2005/08/15/more-on-security-announcements/&quot; rel=&quot;nofollow&quot;&gt;here&lt;/a&gt;)</description>
		<content:encoded><![CDATA[<p>That&#8217;s a naive argument, Eitan. Hackers are not stupid, they can figure out the issue from looking at the source code. As you&#8217;ve just demonstrated, just saying &#8220;we&#8217;ve fixed a security issue&#8221; but not giving more specific information easily leads to a false sense of security.</p>
<p>(Slightly longer reply to some comments I&#8217;ve received available <a href="http://blog.blackdown.de/2005/08/15/more-on-security-announcements/" rel="nofollow">here</a>)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: James</title>
		<link>http://www.blogherald.com/2005/08/14/wordpress-152-released/comment-page-1/#comment-44547</link>
		<dc:creator>James</dc:creator>
		<pubDate>Mon, 15 Aug 2005 18:57:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.blogherald.com/2005/08/14/wordpress-152-released/#comment-44547</guid>
		<description>You&#039;re not the only one who feels this way: http://www.blogherald.com/2005/08/14/wordpress-152-released/

At least MT has always talked about security fixes right on their hompage, even before WP came out. WP could &lt;a href=&quot;http://www.sixapart.com/about/corner/2005/04/movable_type_31_2.html&quot; rel=&quot;nofollow&quot;&gt;learn from Mena&lt;/a&gt;.</description>
		<content:encoded><![CDATA[<p>You&#8217;re not the only one who feels this way: <a href="http://www.blogherald.com/2005/08/14/wordpress-152-released/" rel="nofollow">http://www.blogherald.com/2005/08/14/wordpress-152-released/</a></p>
<p>At least MT has always talked about security fixes right on their hompage, even before WP came out. WP could <a href="http://www.sixapart.com/about/corner/2005/04/movable_type_31_2.html" rel="nofollow">learn from Mena</a>.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Eitan Caspi</title>
		<link>http://www.blogherald.com/2005/08/14/wordpress-152-released/comment-page-1/#comment-44542</link>
		<dc:creator>Eitan Caspi</dc:creator>
		<pubDate>Mon, 15 Aug 2005 16:22:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.blogherald.com/2005/08/14/wordpress-152-released/#comment-44542</guid>
		<description>Think about those who did not upgrade, because of any reason.
Why should the developers give anyone the knowledge of how to attack this people?!

It is better that you simply upgrade and be left in the dark about how and why, and others won&#039;t be attacked.

Eitan
Israel</description>
		<content:encoded><![CDATA[<p>Think about those who did not upgrade, because of any reason.<br />
Why should the developers give anyone the knowledge of how to attack this people?!</p>
<p>It is better that you simply upgrade and be left in the dark about how and why, and others won&#8217;t be attacked.</p>
<p>Eitan<br />
Israel</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt</title>
		<link>http://www.blogherald.com/2005/08/14/wordpress-152-released/comment-page-1/#comment-44520</link>
		<dc:creator>Matt</dc:creator>
		<pubDate>Mon, 15 Aug 2005 04:59:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.blogherald.com/2005/08/14/wordpress-152-released/#comment-44520</guid>
		<description>We wouldn&#039;t have been in such a hurry to get a release out if the security problems were obscure! The exact issues are easily findable for anyone in the security community, and there is at least one script kiddie script out there so I don&#039;t want to point more people to it while people are still upgrading.</description>
		<content:encoded><![CDATA[<p>We wouldn&#8217;t have been in such a hurry to get a release out if the security problems were obscure! The exact issues are easily findable for anyone in the security community, and there is at least one script kiddie script out there so I don&#8217;t want to point more people to it while people are still upgrading.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

