<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: WordPress Plugins &#8211; check before you upgrade automatically</title>
	<atom:link href="http://scott.yang.id.au/2008/07/wordpress-plugins-check-before-you-upgrade-automatically/feed/" rel="self" type="application/rss+xml" />
	<link>http://scott.yang.id.au/2008/07/wordpress-plugins-check-before-you-upgrade-automatically/</link>
	<description>Faith, Technology and Randomness in Life, According to Scott</description>
	<lastBuildDate>Wed, 08 Feb 2012 13:17:24 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: massimux</title>
		<link>http://scott.yang.id.au/2008/07/wordpress-plugins-check-before-you-upgrade-automatically/#comment-95789</link>
		<dc:creator>massimux</dc:creator>
		<pubDate>Mon, 20 Oct 2008 11:39:02 +0000</pubDate>
		<guid isPermaLink="false">http://scott.yang.id.au/2008/07/wordpress-plugins-check-before-you-upgrade-automatically/#comment-95789</guid>
		<description>Hello,

I have installed your plug-in but reflected problems with rss feeds unfortunately no longer reachable at http://miosito.com/blog/feed

How can I fix this?</description>
		<content:encoded><![CDATA[<p>Hello,</p>
<p>I have installed your plug-in but reflected problems with rss feeds unfortunately no longer reachable at <a href="http://miosito.com/blog/feed" rel="nofollow">http://miosito.com/blog/feed</a></p>
<p>How can I fix this?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: moserw</title>
		<link>http://scott.yang.id.au/2008/07/wordpress-plugins-check-before-you-upgrade-automatically/#comment-94773</link>
		<dc:creator>moserw</dc:creator>
		<pubDate>Sun, 17 Aug 2008 15:16:12 +0000</pubDate>
		<guid isPermaLink="false">http://scott.yang.id.au/2008/07/wordpress-plugins-check-before-you-upgrade-automatically/#comment-94773</guid>
		<description>Sounds freaky.  Will need to be careful and double check henceforth after upgrading to see if it is indeed the plugin that I had before.  Thanks for the update.</description>
		<content:encoded><![CDATA[<p>Sounds freaky.  Will need to be careful and double check henceforth after upgrading to see if it is indeed the plugin that I had before.  Thanks for the update.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Microkid</title>
		<link>http://scott.yang.id.au/2008/07/wordpress-plugins-check-before-you-upgrade-automatically/#comment-94623</link>
		<dc:creator>Microkid</dc:creator>
		<pubDate>Sat, 02 Aug 2008 08:40:53 +0000</pubDate>
		<guid isPermaLink="false">http://scott.yang.id.au/2008/07/wordpress-plugins-check-before-you-upgrade-automatically/#comment-94623</guid>
		<description>@Matt
Nope, it&#039;s stilling updating to Joost de Valk&#039;s Permalink Redirect plugin.</description>
		<content:encoded><![CDATA[<p>@Matt<br />
Nope, it&#8217;s stilling updating to Joost de Valk&#8217;s Permalink Redirect plugin.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt</title>
		<link>http://scott.yang.id.au/2008/07/wordpress-plugins-check-before-you-upgrade-automatically/#comment-94454</link>
		<dc:creator>Matt</dc:creator>
		<pubDate>Fri, 18 Jul 2008 22:28:49 +0000</pubDate>
		<guid isPermaLink="false">http://scott.yang.id.au/2008/07/wordpress-plugins-check-before-you-upgrade-automatically/#comment-94454</guid>
		<description>Now that you&#039;ve added your plugin to the repository, has the problem gone away?</description>
		<content:encoded><![CDATA[<p>Now that you&#8217;ve added your plugin to the repository, has the problem gone away?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: scotty</title>
		<link>http://scott.yang.id.au/2008/07/wordpress-plugins-check-before-you-upgrade-automatically/#comment-94442</link>
		<dc:creator>scotty</dc:creator>
		<pubDate>Fri, 18 Jul 2008 01:13:40 +0000</pubDate>
		<guid isPermaLink="false">http://scott.yang.id.au/2008/07/wordpress-plugins-check-before-you-upgrade-automatically/#comment-94442</guid>
		<description>@Glenn -- indeed, and I think you can compare that with Firefox add-on auto-updates. First of all, you shouldn&#039;t need to host your plugin with WordPress but something like updateURL directive can be added to direct WordPress installs to find where the new update is.

Then updates must be signed with a unique key so that if the 3rd party repository has been compromised, they would not be able to temper with the binary zip files.</description>
		<content:encoded><![CDATA[<p>@Glenn &#8212; indeed, and I think you can compare that with Firefox add-on auto-updates. First of all, you shouldn&#8217;t need to host your plugin with WordPress but something like updateURL directive can be added to direct WordPress installs to find where the new update is.</p>
<p>Then updates must be signed with a unique key so that if the 3rd party repository has been compromised, they would not be able to temper with the binary zip files.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Glenn</title>
		<link>http://scott.yang.id.au/2008/07/wordpress-plugins-check-before-you-upgrade-automatically/#comment-94441</link>
		<dc:creator>Glenn</dc:creator>
		<pubDate>Fri, 18 Jul 2008 00:50:57 +0000</pubDate>
		<guid isPermaLink="false">http://scott.yang.id.au/2008/07/wordpress-plugins-check-before-you-upgrade-automatically/#comment-94441</guid>
		<description>Why doesn&#039;t the Wordpress repository generate a guid for it&#039;s plugins, then require that to be added as a key in the plugin file.  That would then be what your blog looked for in the repository when it goes to upload</description>
		<content:encoded><![CDATA[<p>Why doesn&#8217;t the WordPress repository generate a guid for it&#8217;s plugins, then require that to be added as a key in the plugin file.  That would then be what your blog looked for in the repository when it goes to upload</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: scotty</title>
		<link>http://scott.yang.id.au/2008/07/wordpress-plugins-check-before-you-upgrade-automatically/#comment-94440</link>
		<dc:creator>scotty</dc:creator>
		<pubDate>Fri, 18 Jul 2008 00:09:15 +0000</pubDate>
		<guid isPermaLink="false">http://scott.yang.id.au/2008/07/wordpress-plugins-check-before-you-upgrade-automatically/#comment-94440</guid>
		<description>@Pablo -- when I said &quot;Do Not Click Upgrade Automatically&quot;, I am talking about my specific example of Permalink Redirect because you would be upgrading to Joost&#039;s plugin instead of mine.

Now, Joost is a nice guy who is willing to work around now, and his plugin is so different from mine that my users picked up the difference straight away so we are sure there is no sneaky activities around.

Imagine it is Joost&#039;s evil twin (sorry Joost!), who grabbed my plugin, add his code to turn all infested WordPress installation into part of his evil botnet that DDoS websites who he has blackmailed for a ransom. Everything still points at me as &quot;Permalink Redirect 2008&quot; on WordPress.org still has &quot;Scott Yang&quot; all over the place, and most people who automatically upgraded have no idea as it appears functional... Meanwhile Australian Federal Police knocks on my door for committing cyber crime.

Now. You have automatically upgraded all 47 plugins. Did you check whether they are genuine and they all came from the original author.</description>
		<content:encoded><![CDATA[<p>@Pablo &#8212; when I said &#8220;Do Not Click Upgrade Automatically&#8221;, I am talking about my specific example of Permalink Redirect because you would be upgrading to Joost&#8217;s plugin instead of mine.</p>
<p>Now, Joost is a nice guy who is willing to work around now, and his plugin is so different from mine that my users picked up the difference straight away so we are sure there is no sneaky activities around.</p>
<p>Imagine it is Joost&#8217;s evil twin (sorry Joost!), who grabbed my plugin, add his code to turn all infested WordPress installation into part of his evil botnet that DDoS websites who he has blackmailed for a ransom. Everything still points at me as &#8220;Permalink Redirect 2008&#8243; on WordPress.org still has &#8220;Scott Yang&#8221; all over the place, and most people who automatically upgraded have no idea as it appears functional&#8230; Meanwhile Australian Federal Police knocks on my door for committing cyber crime.</p>
<p>Now. You have automatically upgraded all 47 plugins. Did you check whether they are genuine and they all came from the original author.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pablo DiCiacco</title>
		<link>http://scott.yang.id.au/2008/07/wordpress-plugins-check-before-you-upgrade-automatically/#comment-94438</link>
		<dc:creator>Pablo DiCiacco</dc:creator>
		<pubDate>Thu, 17 Jul 2008 23:06:20 +0000</pubDate>
		<guid isPermaLink="false">http://scott.yang.id.au/2008/07/wordpress-plugins-check-before-you-upgrade-automatically/#comment-94438</guid>
		<description>OK, I counted.... I upgraded 47 plugins on eight sites today with no problems anywhere.
Out of the Wordpress 2,571 available plugins, I think it may be prudent for you to cite more examples of your &quot;alert&quot; before claiming this as a potential epidemic.
I&#039;m not discounting that the problems you mention are needing attention, but to state &quot;Let me repeat, Do Not Click on Upgrade Automatically&quot; might be a bit of an overreaction at this point.</description>
		<content:encoded><![CDATA[<p>OK, I counted&#8230;. I upgraded 47 plugins on eight sites today with no problems anywhere.<br />
Out of the WordPress 2,571 available plugins, I think it may be prudent for you to cite more examples of your &#8220;alert&#8221; before claiming this as a potential epidemic.<br />
I&#8217;m not discounting that the problems you mention are needing attention, but to state &#8220;Let me repeat, Do Not Click on Upgrade Automatically&#8221; might be a bit of an overreaction at this point.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Joost de Valk</title>
		<link>http://scott.yang.id.au/2008/07/wordpress-plugins-check-before-you-upgrade-automatically/#comment-94432</link>
		<dc:creator>Joost de Valk</dc:creator>
		<pubDate>Thu, 17 Jul 2008 19:08:36 +0000</pubDate>
		<guid isPermaLink="false">http://scott.yang.id.au/2008/07/wordpress-plugins-check-before-you-upgrade-automatically/#comment-94432</guid>
		<description>Let me make clear that it was absolutely NOT my intention to do this! We&#039;ll have to find a way to make this system a bit more robust :)</description>
		<content:encoded><![CDATA[<p>Let me make clear that it was absolutely NOT my intention to do this! We&#8217;ll have to find a way to make this system a bit more robust :)</p>
]]></content:encoded>
	</item>
</channel>
</rss>

