<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: WordPress Upgrade: I could cry</title>
	<atom:link href="http://robinmonks.com/2009/02/13/wordpress-upgrade-i-could-cry/feed/" rel="self" type="application/rss+xml" />
	<link>http://robinmonks.com/2009/02/13/wordpress-upgrade-i-could-cry/</link>
	<description>Only the interesting stuff.</description>
	<lastBuildDate>Thu, 08 Jul 2010 02:17:31 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
	<item>
		<title>By: Mike</title>
		<link>http://robinmonks.com/2009/02/13/wordpress-upgrade-i-could-cry/comment-page-1/#comment-1939</link>
		<dc:creator>Mike</dc:creator>
		<pubDate>Sat, 23 May 2009 20:07:18 +0000</pubDate>
		<guid isPermaLink="false">http://robinmonks.com/?p=247#comment-1939</guid>
		<description>Hi, nice posts there :-) thank&#039;s for the interesting information</description>
		<content:encoded><![CDATA[<p>Hi, nice posts there <img src='http://robinmonks.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' />  thank&#8217;s for the interesting information</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bèr Kessels</title>
		<link>http://robinmonks.com/2009/02/13/wordpress-upgrade-i-could-cry/comment-page-1/#comment-1905</link>
		<dc:creator>Bèr Kessels</dc:creator>
		<pubDate>Sun, 15 Feb 2009 14:25:23 +0000</pubDate>
		<guid isPermaLink="false">http://robinmonks.com/?p=247#comment-1905</guid>
		<description>drush pm update. Just onder 3 secs (clocked it) and 6 modules were updated. 

drush pm update --svnsync --svncommit. Just over 12 seconds, my SVN conncetion is not extremely fast. same six modules, only now i have them updates in my svn repos too. 

The very fact that you can update wordpress from within wordpress is a severe security hole. The fact that the wordpress comm. does not see it as such says a lot more about the proefessional attitude of the WPteam then about drupal.</description>
		<content:encoded><![CDATA[<p>drush pm update. Just onder 3 secs (clocked it) and 6 modules were updated. </p>
<p>drush pm update &#8211;svnsync &#8211;svncommit. Just over 12 seconds, my SVN conncetion is not extremely fast. same six modules, only now i have them updates in my svn repos too. </p>
<p>The very fact that you can update wordpress from within wordpress is a severe security hole. The fact that the wordpress comm. does not see it as such says a lot more about the proefessional attitude of the WPteam then about drupal.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Boris Mann</title>
		<link>http://robinmonks.com/2009/02/13/wordpress-upgrade-i-could-cry/comment-page-1/#comment-1902</link>
		<dc:creator>Boris Mann</dc:creator>
		<pubDate>Fri, 13 Feb 2009 22:51:49 +0000</pubDate>
		<guid isPermaLink="false">http://robinmonks.com/?p=247#comment-1902</guid>
		<description>Sorry, but I actually *don&#039;t have FTP on any of the servers that I run* (it uses either FTP or FTP/S). So, I get to manually upgrade WordPress, all the time. I was actually going to do a blog post about this, because this feature doesn&#039;t work for me at all on any of the WP sites I run.

This feature is a perfect fit for the shared hosting that most WordPress sites run on. It&#039;s not a good fit for custom, production hosting that most less-than-trivial Drupal sites run on.</description>
		<content:encoded><![CDATA[<p>Sorry, but I actually *don&#8217;t have FTP on any of the servers that I run* (it uses either FTP or FTP/S). So, I get to manually upgrade WordPress, all the time. I was actually going to do a blog post about this, because this feature doesn&#8217;t work for me at all on any of the WP sites I run.</p>
<p>This feature is a perfect fit for the shared hosting that most WordPress sites run on. It&#8217;s not a good fit for custom, production hosting that most less-than-trivial Drupal sites run on.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: greggles</title>
		<link>http://robinmonks.com/2009/02/13/wordpress-upgrade-i-could-cry/comment-page-1/#comment-1901</link>
		<dc:creator>greggles</dc:creator>
		<pubDate>Fri, 13 Feb 2009 21:27:06 +0000</pubDate>
		<guid isPermaLink="false">http://robinmonks.com/?p=247#comment-1901</guid>
		<description>@naresh - Congratulations on being the first uninformed commenter _after_ my comment (Nicholas Thompson gets the award for before it).

I spent many hours last summer (as did Joshua Rogers, chx, Khalid Baheyeldin, and other community members) working hard to implement this feature.  There is no screaming at auto install - there is screaming at the idea of doing it in an unsafe manner.</description>
		<content:encoded><![CDATA[<p>@naresh &#8211; Congratulations on being the first uninformed commenter _after_ my comment (Nicholas Thompson gets the award for before it).</p>
<p>I spent many hours last summer (as did Joshua Rogers, chx, Khalid Baheyeldin, and other community members) working hard to implement this feature.  There is no screaming at auto install &#8211; there is screaming at the idea of doing it in an unsafe manner.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Naresh</title>
		<link>http://robinmonks.com/2009/02/13/wordpress-upgrade-i-could-cry/comment-page-1/#comment-1899</link>
		<dc:creator>Naresh</dc:creator>
		<pubDate>Fri, 13 Feb 2009 19:18:18 +0000</pubDate>
		<guid isPermaLink="false">http://robinmonks.com/?p=247#comment-1899</guid>
		<description>Unless we loosen up and do things that are in larger interest of 99.9999% people, we are not going to survive long or become plone (enterprise only).

We need to start making Drupal more user friendly in administering it, rather than screaming ****** at the thought of having auto install in Drupal.

Can anyone point to me an instance where this feature has been used by script kiddies or others to mess up Wordpress?

It sounds to me like people who screen bloody merry on not having SSL on every single website when their own physical house is secured by $2 lock.

I think paranoid people are holding back the true potential of Drupal by preventing it from becoming mass market product like Wordpress, and turning it into another plone.</description>
		<content:encoded><![CDATA[<p>Unless we loosen up and do things that are in larger interest of 99.9999% people, we are not going to survive long or become plone (enterprise only).</p>
<p>We need to start making Drupal more user friendly in administering it, rather than screaming ****** at the thought of having auto install in Drupal.</p>
<p>Can anyone point to me an instance where this feature has been used by script kiddies or others to mess up WordPress?</p>
<p>It sounds to me like people who screen bloody merry on not having SSL on every single website when their own physical house is secured by $2 lock.</p>
<p>I think paranoid people are holding back the true potential of Drupal by preventing it from becoming mass market product like WordPress, and turning it into another plone.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: greggles</title>
		<link>http://robinmonks.com/2009/02/13/wordpress-upgrade-i-could-cry/comment-page-1/#comment-1898</link>
		<dc:creator>greggles</dc:creator>
		<pubDate>Fri, 13 Feb 2009 17:03:04 +0000</pubDate>
		<guid isPermaLink="false">http://robinmonks.com/?p=247#comment-1898</guid>
		<description>Indeed it uses FTP.  If it stores the credentials...that&#039;s a little weird.

There is a module for Drupal that does this for modules and themes - http://drupal.org/project/plugin_manager

We just need someone to take it home to core and make it work for core itself.</description>
		<content:encoded><![CDATA[<p>Indeed it uses FTP.  If it stores the credentials&#8230;that&#8217;s a little weird.</p>
<p>There is a module for Drupal that does this for modules and themes &#8211; <a href="http://drupal.org/project/plugin_manager" rel="nofollow">http://drupal.org/project/plugin_manager</a></p>
<p>We just need someone to take it home to core and make it work for core itself.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: matttthieu</title>
		<link>http://robinmonks.com/2009/02/13/wordpress-upgrade-i-could-cry/comment-page-1/#comment-1897</link>
		<dc:creator>matttthieu</dc:creator>
		<pubDate>Fri, 13 Feb 2009 16:56:27 +0000</pubDate>
		<guid isPermaLink="false">http://robinmonks.com/?p=247#comment-1897</guid>
		<description>Matt Mullenweg spoke @ Wordcamp Paris last week-end about the next version and WP is not going to have CCK-alike feature (but I did not listen to the whole presentation, I may have missed something)

Wtechdog may certainly be a missing feature for developers.

But I don&#039;t think WP is designed to a be Content Manager Framework as drupal is.</description>
		<content:encoded><![CDATA[<p>Matt Mullenweg spoke @ Wordcamp Paris last week-end about the next version and WP is not going to have CCK-alike feature (but I did not listen to the whole presentation, I may have missed something)</p>
<p>Wtechdog may certainly be a missing feature for developers.</p>
<p>But I don&#8217;t think WP is designed to a be Content Manager Framework as drupal is.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Robin</title>
		<link>http://robinmonks.com/2009/02/13/wordpress-upgrade-i-could-cry/comment-page-1/#comment-1896</link>
		<dc:creator>Robin</dc:creator>
		<pubDate>Fri, 13 Feb 2009 16:53:08 +0000</pubDate>
		<guid isPermaLink="false">http://robinmonks.com/?p=247#comment-1896</guid>
		<description>I believe the feature is done using FTP with stored creds, but, I can&#039;t verify that; and don&#039;t know enough about the system to say for sure how it works,

Robin</description>
		<content:encoded><![CDATA[<p>I believe the feature is done using FTP with stored creds, but, I can&#8217;t verify that; and don&#8217;t know enough about the system to say for sure how it works,</p>
<p>Robin</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Robin</title>
		<link>http://robinmonks.com/2009/02/13/wordpress-upgrade-i-could-cry/comment-page-1/#comment-1895</link>
		<dc:creator>Robin</dc:creator>
		<pubDate>Fri, 13 Feb 2009 16:52:02 +0000</pubDate>
		<guid isPermaLink="false">http://robinmonks.com/?p=247#comment-1895</guid>
		<description>I believe the next Wordpress version will allow custom content types like CCK.  Views are a different thing altogether.  But, maybe will be available as a plugin to go with the next WP version.</description>
		<content:encoded><![CDATA[<p>I believe the next WordPress version will allow custom content types like CCK.  Views are a different thing altogether.  But, maybe will be available as a plugin to go with the next WP version.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nicholas Thompson</title>
		<link>http://robinmonks.com/2009/02/13/wordpress-upgrade-i-could-cry/comment-page-1/#comment-1894</link>
		<dc:creator>Nicholas Thompson</dc:creator>
		<pubDate>Fri, 13 Feb 2009 16:51:07 +0000</pubDate>
		<guid isPermaLink="false">http://robinmonks.com/?p=247#comment-1894</guid>
		<description>This post implies to me that the entire installation folder is writable by the &quot;apache&quot; user (apache, www, wwwrun, lighttpd... whatever the user is that runs the web server).

This to me screams &quot;security issue!!&quot;. I personally dont want my website to be able to rewrite its own code - be it for a legit update or a bastard script kiddie finding a loop hole... :-)</description>
		<content:encoded><![CDATA[<p>This post implies to me that the entire installation folder is writable by the &#8220;apache&#8221; user (apache, www, wwwrun, lighttpd&#8230; whatever the user is that runs the web server).</p>
<p>This to me screams &#8220;security issue!!&#8221;. I personally dont want my website to be able to rewrite its own code &#8211; be it for a legit update or a bastard script kiddie finding a loop hole&#8230; <img src='http://robinmonks.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
</channel>
</rss>
