Home
Home
Posted Wednesday June 25, 2008, 12:47 am, Over one day old
Red Sweater: “But in my opinion, there are also good arguments to be made for rejecting the change as a damaging and misguided solution.”
This post digest is 100% of the original post size.
Incoming Links
The following posts link to WordPress To Disable Remote Access by Default:
Posted Tuesday August 5, 2008, 3:16 am, Over one day old
"Theme Vorschau ? mehr ?WordCount? im Editor ? mehr Deaktivierung der XML-RPC-Schnittstelle im Standard ? mehr und eine kritische Betrachtung Deaktivierung der Atom-Schnittstelle im Standard ? mehr und eine bessere kritische Betrachtung mit Lösung (englisch) SSL Support für den Adminbereich ? mehr wp-content kann verschoben werden ? mehr wp-config.php kann verschoben werden ? mehr Mehr Möglichkeiten für die Gravatare ? mehr Drag & Drop für die Galerie"
Posted Monday July 21, 2008, 12:02 pm, Over one day old
"Theme Vorschau ? mehr ?WordCount? im Editor ? mehr Deaktivierung der XML-RPC-Schnittstelle im Standard ? mehr und eine kritische Betrachtung Deaktivierung der Atom-Schnittstelle im Standard ? mehr und eine bessere kritische Betrachtung mit Lösung (englisch) SSL Support für den Adminbereich ? mehr wp-content kann verschoben werden ? mehr wp-config.php kann verschoben werden ? mehr Mehr Möglichkeiten für die Gravatare ? mehr Drag & Drop für die Galerie"
Posted Sunday July 20, 2008, 1:57 pm, Over one day old
"Login to WordPress 2.6 Administration Console and goto Settings -> Writing. Check the "XML-RPC" checkbox found under the Remote Publishing section. (see screen shot below). You can find more information on this issue via RedSweater and the original WordPress Trac Ticket. "
Posted Saturday July 19, 2008, 3:12 am, Over one day old
"Theme Vorschau ? mehr ?WordCount? im Editor ? mehr Deaktivierung der XML-RPC-Schnittstelle im Standard ? mehr und eine kritische Betrachtung Deaktivierung der Atom-Schnittstelle im Standard ? mehr und eine bessere kritische Betrachtung mit Lösung (englisch) SSL Support für den Adminbereich ? mehr wp-content kann verschoben werden ? mehr wp-config.php kann verschoben werden ? mehr Mehr Möglichkeiten für die Gravatare ? mehr Drag & Drop für die Galerie"
Posted Tuesday July 15, 2008, 4:30 am, Over one day old
"??? ??? ??????????? ?? ????????? ??????? ? ????????????? ? WordPress ???? ??????? ? ?????????? XML-RPC. ?????? ?????????? ???? ?????? ? ????? ????? ? ????????? ??????????? ????, ?????? ??? ? ???? ???? ?????? ??????? ? ??????????? ??????????? ??????? ??? ??????. ?? ????????"
Posted Saturday July 12, 2008, 2:36 am, Over one day old
". Users will have to enable them manually. (Movable Type requires you to use special API key instead of your password.) Daniel Jalkut, developer of MarsEdit, the excellent blog client for Mac OS X, has a good post on this in his blog: In my opinion, an entire class of problems with WordPress (and other blogging systems) stems from this interface bifurcation. Establishing a single interface to WordPress would be comparable to the ?pin code + card? interface at your bank. You"
Posted Wednesday July 9, 2008, 6:59 pm, Over one day old
" Having already seen some dialogue between Wordpress and its users, this conversation won?t go away anytime soon. WordPress To Disable Remote Access by Default: Red Sweater: ?The WordPress developers have decided that, starting with WordPress 2.6, access to the XMLRPC and AtomPub-based remote publishing interfaces will be disabled by default. Users who wish to use a remote client such as "
Posted Wednesday July 2, 2008, 6:52 pm, Over one day old
" about some changes coming to WordPress in 2.6 ? namely disabling ATOM and XML-RPC APIs by default. The argument is that this will make WordPress more secure out of the box ? but the question is at what cost? And, is there a better solution to this problem rather than disabling features and functionality (even if only a small subset of users currently make use of these APIs) if the changes end up being short-sighted"
Posted Wednesday July 2, 2008, 7:10 am, Over one day old
"s about damn time WordPress tackles something like this. The other 10 things are certainly worth reading, including a new compromise to the ridiculous disabling of external blog editor access (by default) that MarsEdit developer Daniel Jalkut rightfully called BS on. ShareThis "
Posted Monday June 30, 2008, 2:03 pm, Over one day old
"discussion. In the development cycle, XML-RPC and Atom Pub API for remote editing was turned off by default as a ?security precaution? since many recent WordPress security issues seem to stem from the XML-RPC protocol. Daniel took the issue up on his blog"
Posted Friday June 27, 2008, 12:51 am, Over one day old
"Theme Vorschau ? mehr ?WordCount? im Editor ? mehr Deaktivierung der XML-RPC-Schnittstelle im Standard ? mehr und eine kritische Betrachtung Deaktivierung der Atom-Schnittstelle im Standard ? mehr und eine bessere kritische Betrachtung mit Lösung (englisch) SSL Support für den Adminbereich ? mehr wp-content kann verschoben werden ? mehr wp-config.php kann verschoben werden ? mehr Mehr Möglichkeiten für die Gravatare ? mehr Drag & Drop für die Galerie"
Posted Thursday June 26, 2008, 8:53 am, Over one day old
"send to people who choose to, or who are encouraged to turn the service back on? It sets up a perception of insecurity which may not even be warranted. If the remote publishing interfaces are insecure, they should be fixed, not merely disabled! (via Red Sweater Blog) Ich schreibe nie Blogeinträge im Browser, sondern benutze immer MarsEdit als externen Editor. Für mich klingt das jetzt so, dass ich ? also der Benutzer ? schuld bin, wenn ich das XMLRPC Interface einschalte und dann passiert etwas."
Posted Thursday June 26, 2008, 8:31 am, Over one day old
"Write page and enable them individually if you want to use them. Mac software developer and MarsEdit creator Daniel Jalkut believes this to be a fundamentally wrong choice. He?s said so on the wp-hackers list and on his website: WordPress?s decision to shut off remote access by default is analogous to a bank offering unrestricted drive-through access to its cash machines, while requiring pedestrians to ring a bell and wait for a security guard to open the door to the"
Posted Wednesday June 25, 2008, 11:32 pm, Over one day old
"the WordPress developers are ignoring the root cause: If your web service only provides one, first-class API through which all access flows, then you?ve only got one point to secure, you?re likely to have feature parity across interfaces, and the risk of marginalizing one interface is dramatically"
Posted Wednesday June 25, 2008, 9:42 pm, Over one day old
"I can certainly understand the remote editor community getting upset. For them it is an extra hoop for end users to jump through, their products are meant to make things easier and this will be a hinderance. As Daniel Jalkut (Marsedit) says For users who would find value in a remote client, this decision will put one more roadblock in their way My main question is, what exactly is the security concern they have with XMLRPC? Why now? If there is a clear danger, fair"
Posted Wednesday June 25, 2008, 5:17 pm, Over one day old
"closing a remote API"
Posted Wednesday June 25, 2008, 12:24 pm, Over one day old
"Daniel Jalkut Bashes WordPress 2.6 XMLRPC Decision June 25, 2008 | By Thord Daniel Hedengren | 1 Comment Daniel Jalkut is the creator of Mac blog application MarsEdit (a great one, by the way), so it should come as no surprise that he?s a bit pissed about the fact that XMLRPC will be disabled by default in WordPress 2.6. For those who doesn?t know, XMLRPC is the way outside applications can communicate with WordPress. Naturally, disabling XMLRPC in WordPress 2.6 isn"
Posted Wednesday June 25, 2008, 9:47 am, Over one day old
". Users will have to enable them manually. (Movable Type requires you to use special API key instead of your password.) Daniel Jalkut, developer of MarsEdit, the excellent blog client for Mac OS X, has a good post on this in his blog: In my opinion, an entire class of problems with WordPress (and other blogging systems) stems from this interface bifurcation. Establishing a single interface to WordPress would be comparable to the ?pin code + card? interface at your bank. You"
Posted Wednesday June 25, 2008, 8:23 am, Over one day old
" Red Sweater Blog - WordPress To Disable Remote Access "
* Incoming Links data provided by Technorati
.
Sponsored