WordPress 2.5 has been released.
From a security perspective, the new WP 2.5 promises secure cookie management, salted passwords and prepared SQL querying functions.
I won’t be upgrading right away… I’ll let it run a while. This may be a good move forward for the WP team. Nice work guys!
[...] Problemas de seguridad Resueltos [...]
I’m happy to see the work security slide into this release, it’s about time the development team took it seriously enough.
Things i like are:
- Salted passwords. Now we still need users to pick decent passwords in order to prevent brute-force attacks, but having this is another layer of security which is needed.
- Secure Cookies. Ok, about time we finally saw this rather fundamental protection needed for one of the main authentication/authorisation methods that WP uses.
One a side note, I’d love to know how many people here force their WP to use SSL, especially if they are readers of this site :0)
[...] Problemas de seguridad Resueltos [...]
Until you folks on this site tell me I’m not doing the update. WP always has some security issues when its released.
Dave, thanks for the faith :)
Unless there is a critical update, holding back on a stable version of software is usually the better option.
[...] got an interesting comment from Dave today that made me reflect on the question of when to update or upgrade your blog [...]