This post is sure to ruffle some feathers…

Because I’ve been in the “not putting up with any BS” mood all weekend, I present to you some critiques of things you commonly see online:

As more information came in about the blogger hack, it is amazing how many people who immediately kicked in with their own “expert” opinions about what happened were so absolutely wrong. First it was “the blogger programming is obviously insecure”, then it was, “well that’s what they get for using IIS and SQL Server”, when in fact the hack was through an unpatched server running Red Hat Linux. Yes, it appears that even Linux has to be patched to remain secure, imagine that.

The second thing that seemed to be popular was “well I use Movable Type, so I don’t have to worry about security problems like this.”, no not really. If you’re running MT on a Red Hat server, you still have to have the same vulnerability patched, since it was a server vulnerability, not a blogging software vulnerability. Secondly, take a look at Phil’s post about spammers using a script to comment to every one of your MT posts. Sounds like an issue to me, although it obviously isn’t limited to MT.

My point is not to trash MT and Red Hat, but it is to point out to those of you who have an “expert” opinion about every security hole out there, that security is a problem for every OS, every software package, and every PC on the internet, not just the one’s you happen to not like. Those are both examples of fine software, but software that still requires you to pay attention to security issues! I am so tired of hearing from supposed experts that because of the software they use, they don’t have to worry about security holes. Anyone who would say such a thing is obviously not an expert, and it’s an opinion you should pay absolutely no heed to at all! Blogger got hacked because they missed a security issue and failed to patch one of their servers. They messed up and got caught, just like hundreds of other websites have. If you think it’s so easy and that you would never get caught like that, maybe you should open up your own hosting company and prove it instead of bitching from the sidelines.

We don’t host websites at my job, but there have certainly been issues that I missed, or made the wrong call on. It happens. You fix it, admit you screwed up and move on with your life.

Similar Posts

  • Blog opinions..

    Warning, actual real-life criticism ahead. If you can’t handle it, back away from the computer slowly… OK, first off there’s Chris Pirillo and the flak he’s getting for charging for Gnometomes. I’m of two minds on this one. First, I understand what Chris is doing, he’s trying to bring in some money for Lockergnome while…

  • |

    Is Blogging Dead?

    Well no, it’s not. Despite the ominous sounding headline, blogging is more popular than ever, people just aren’t calling it that any more. Yes, the “blog” that we first talked about at the turn of the century, and in 2001 when I started; a list of entries sorted in reverse chronological order and with full…

  • A breakthrough?

    Maybe. I found another machine that sends emails like mine does. They always go through and they push or drag the other emails with them. Once I found that, it was simply a matter of figuring out what my machine and that one have in common that others don’t. Well, it’s one of the new…

  • It’s a matter of trust

    Saw this post today and it set off some random thoughts in my head, so being the self-absorbed blogging type, you get to read them. Blocking Access to Web sites at Work Could Backfire It seems that a recent study is showing that people who work for companies that block a lot of access to…

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

To respond on your own website, enter the URL of your response which should contain a link to this post's permalink URL. Your response will then appear (possibly after moderation) on this page. Want to update or remove your response? Update or delete your post and re-enter your post's URL again. (Find out more about Webmentions.)