This post is sure to ruffle some feathers…

Because I’ve been in the “not putting up with any BS” mood all weekend, I present to you some critiques of things you commonly see online:

As more information came in about the blogger hack, it is amazing how many people who immediately kicked in with their own “expert” opinions about what happened were so absolutely wrong. First it was “the blogger programming is obviously insecure”, then it was, “well that’s what they get for using IIS and SQL Server”, when in fact the hack was through an unpatched server running Red Hat Linux. Yes, it appears that even Linux has to be patched to remain secure, imagine that.

The second thing that seemed to be popular was “well I use Movable Type, so I don’t have to worry about security problems like this.”, no not really. If you’re running MT on a Red Hat server, you still have to have the same vulnerability patched, since it was a server vulnerability, not a blogging software vulnerability. Secondly, take a look at Phil’s post about spammers using a script to comment to every one of your MT posts. Sounds like an issue to me, although it obviously isn’t limited to MT.

My point is not to trash MT and Red Hat, but it is to point out to those of you who have an “expert” opinion about every security hole out there, that security is a problem for every OS, every software package, and every PC on the internet, not just the one’s you happen to not like. Those are both examples of fine software, but software that still requires you to pay attention to security issues! I am so tired of hearing from supposed experts that because of the software they use, they don’t have to worry about security holes. Anyone who would say such a thing is obviously not an expert, and it’s an opinion you should pay absolutely no heed to at all! Blogger got hacked because they missed a security issue and failed to patch one of their servers. They messed up and got caught, just like hundreds of other websites have. If you think it’s so easy and that you would never get caught like that, maybe you should open up your own hosting company and prove it instead of bitching from the sidelines.

We don’t host websites at my job, but there have certainly been issues that I missed, or made the wrong call on. It happens. You fix it, admit you screwed up and move on with your life.

Similar Posts

  • Short day

    Short day today, we’re just working a half-day and then I’m off for the rest of the week! Of course, Angelahas been the one battling a cold/flu type thing all week and she has to work a full day today and Friday, so I wish there was some way I could switch with her and…

  • Net privacy and the myth of self-regulation

    Net privacy and the myth of self-regulation – Tech News – CNET.com “How invasive is this? ComScore Chairman Fulgoni said that his company has examined the online banking records of some of its customers in order to verify household income information provided during the sign-up process. ” If that doesn’t get you to take privacy…

  • Odds and Ends

    I was amused by the back and forth between Robert Scoble and Kevin Devin this weekend. If you follow through the comments there, and the original post at Scoble’s you’ll see that he didn’t really mean to call all IT workers f***ers, just the one’s who implemented policy, and the IT folks at Microsoft were…

  • Windows 2000 SP4

    Thanks to Andy for pointing to the list of Windows 2000 Service Pack 4 issues. I haven’t installed it on anything yet, so this’ll be a nice resource to have. BTW, I’m not neglecting my job, we don’t actually have anything running 2000 in the whole office. It’s either XP or NT here. I do,…

  • Even the Pope Wants You on Twitter

    If you think about it, the Pope’s recent encouragement to believers to spread the Church’s message on Twitter and other social networking tools makes perfect sense. If you go back and ask the ever popular question about “What Would Jesus Do?”, I think it’s pretty clear that the same guy who reached out to the…

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

To respond on your own website, enter the URL of your response which should contain a link to this post's permalink URL. Your response will then appear (possibly after moderation) on this page. Want to update or remove your response? Update or delete your post and re-enter your post's URL again. (Find out more about Webmentions.)