- ¿umop apisdn upside down? #
Archive for August, 2009
And we’re up to 2.8.4
08.12
Yesterday a vulnerability was discovered: a specially crafted URL could be requested that would allow an attacker to bypass a security check to verify a user requested a password reset. As a result, the first account without a key in the database (usually the admin account) would have its password reset and a new password would be emailed to the account owner. This doesn’t allow remote access, but it is very annoying.
We fixed this problem last night and have been testing the fixes and looking for other problems since then. Version 2.8.4 which fixes all known problems is now available for download and is highly recommended for all users of WordPress.
In the word of the WordPress site itself…
How many open source licenses do you need?
08.05
After an impassioned plea from a developer ont he opensource mailing lists, looking for help through the myriad of 73 versions of open source licenses that are out there, a participant pointed out this link, an article by written back in February 2009 by Bruce Perens (“Bruce Perens is the creator of the Open Source Definition, the manifesto of Open Source and the criterion for Open Source software licensing. Perens represented Open Source at the United Nations World Summit on the Information Society, at the request of the United Nations Development Program.”)
In the article, Perens draws the conclusion that, when looked at it realistically, a business can do with a decision between no more than 4 licences, and then they’d only have to choose between 2, really…
Larry Rosen, of Rosenlaw and Einschlag (“a technology law firm”) commented on this just last night: “It’s bullshit and should be called out as such every time it is repeated”. He goes on to say that those who believe their software is of value and importance should spend the time on research rather than preferring simple answers. In that case, “help yourself to Bruce’s choices”.
The open source world, and patent and copyright legislation is not yet at a point that allows neat simplification of license selection into “three or four [...] buckets”.
There are no shortcuts in the license, copyright and patent decision-making process.
But you knew that already…
Update for Microsoft Outlook / Outlook Express (KB910721)
08.05
You’ve seen the mail, you’ve looked at the headers, you realise that mail from Microsoft typically does not route through a Brazilian ADSL line (times may be bad, but hey!)
You may be wondering why, even though you chose not to register with Microsoft when you booted up for the first time, even though you’re using an Ubuntu machine, you’re getting mail from Redmond asking you to upgrade.
Sophos calls it Troj/Spy-CU.
I call it a scammy, spammy, malware waste of bandwidth…
But you knew that already…
New version of WordPress released yesterday
08.04
First ping of the month — PING!
So version 2.8.3 is out — upgrade now (if you haven’t already!)
Quick note – wordpress.com claims “207,826 bloggers, 156,343 new posts, 275,786 comments, and 40,936,549 words today” — I’m a man of far fewer words! <grin>