<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: WordPress 2.3 &#8211; Privacy Issue &#8211; My Thoughts</title>
	<atom:link href="http://wpthemes.info/posts/2007/09/25/wordpress-23-privacy-issue-my-thoughts/feed/" rel="self" type="application/rss+xml" />
	<link>http://wpthemes.info/posts/2007/09/25/wordpress-23-privacy-issue-my-thoughts/</link>
	<description>Home of MistyLook and other great WordPress Themes !</description>
	<lastBuildDate>Thu, 17 May 2012 10:12:26 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Vern</title>
		<link>http://wpthemes.info/posts/2007/09/25/wordpress-23-privacy-issue-my-thoughts/comment-page-1/#comment-108341</link>
		<dc:creator>Vern</dc:creator>
		<pubDate>Wed, 07 Nov 2007 20:56:23 +0000</pubDate>
		<guid isPermaLink="false">http://wpthemes.info/posts/2007/09/25/wordpress-23-privacy-issue-my-thoughts/#comment-108341</guid>
		<description>Thanks, Sadish, for this information.  When I looked around today to see what the new features were in WP 2.3, I couldn&#039;t quickly find any info.  I hopped over to your site to see if an update to one of your cool themes (The Office) was available and came across this post -- which gave me exactly the kind of info I would have expected to find in a WordPress update.  I have long been a little aggravated with the &quot;automatic&quot; updates and posting in my WP Admin Panel as there was no easy way to get rid of them without them reappearing on every WordPress update.  I, too, love WordPress but I hate to see any &quot;bad behavior&quot; creeping into it.  Any &quot;call home&quot; function that is not absolutely necessary (and not well explained) begins the creeping phase.  Hopefully the developers will continue to guard the code and our privacy as they have done so well in the past.</description>
		<content:encoded><![CDATA[<p>Thanks, Sadish, for this information.  When I looked around today to see what the new features were in WP 2.3, I couldn&#8217;t quickly find any info.  I hopped over to your site to see if an update to one of your cool themes (The Office) was available and came across this post &#8212; which gave me exactly the kind of info I would have expected to find in a WordPress update.  I have long been a little aggravated with the &#8220;automatic&#8221; updates and posting in my WP Admin Panel as there was no easy way to get rid of them without them reappearing on every WordPress update.  I, too, love WordPress but I hate to see any &#8220;bad behavior&#8221; creeping into it.  Any &#8220;call home&#8221; function that is not absolutely necessary (and not well explained) begins the creeping phase.  Hopefully the developers will continue to guard the code and our privacy as they have done so well in the past.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: WordPress Themes by Sadish &#187; How to upgrade your WordPress Theme for WP 2.3?</title>
		<link>http://wpthemes.info/posts/2007/09/25/wordpress-23-privacy-issue-my-thoughts/comment-page-1/#comment-108215</link>
		<dc:creator>WordPress Themes by Sadish &#187; How to upgrade your WordPress Theme for WP 2.3?</dc:creator>
		<pubDate>Tue, 06 Nov 2007 15:01:29 +0000</pubDate>
		<guid isPermaLink="false">http://wpthemes.info/posts/2007/09/25/wordpress-23-privacy-issue-my-thoughts/#comment-108215</guid>
		<description>[...] anyone who is starting their blog right now, they can just install the WordPress 2.3 [and some plugins if they are privacy conscious] and start using one of my upgraded [...]</description>
		<content:encoded><![CDATA[<p>[...] anyone who is starting their blog right now, they can just install the WordPress 2.3 [and some plugins if they are privacy conscious] and start using one of my upgraded [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: forum</title>
		<link>http://wpthemes.info/posts/2007/09/25/wordpress-23-privacy-issue-my-thoughts/comment-page-1/#comment-107417</link>
		<dc:creator>forum</dc:creator>
		<pubDate>Sun, 28 Oct 2007 22:15:45 +0000</pubDate>
		<guid isPermaLink="false">http://wpthemes.info/posts/2007/09/25/wordpress-23-privacy-issue-my-thoughts/#comment-107417</guid>
		<description>I agree with you. 

now i am aware about it. 

thanks</description>
		<content:encoded><![CDATA[<p>I agree with you. </p>
<p>now i am aware about it. </p>
<p>thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dave J. (Scoop0901)</title>
		<link>http://wpthemes.info/posts/2007/09/25/wordpress-23-privacy-issue-my-thoughts/comment-page-1/#comment-107054</link>
		<dc:creator>Dave J. (Scoop0901)</dc:creator>
		<pubDate>Wed, 24 Oct 2007 13:07:57 +0000</pubDate>
		<guid isPermaLink="false">http://wpthemes.info/posts/2007/09/25/wordpress-23-privacy-issue-my-thoughts/#comment-107054</guid>
		<description>As Sadish has said, the vulnerability is there.

Put WP, as an organization, aside.  Let&#039;s look at the vulnerability as just that: a vulnerability.

Next week Bill Snoaks is going to write a plugin that does everything three current, very popular plugins do, but, instead of having to use all three, you use just one, plus -- it has a few other goodies built in.  On top of that, though, Bill also adds a snip of coding to call home -- to his site (he isn&#039;t uploading the plugin to the WP Plugin site, but rather self-hosting the plugin.  He uses this vulnerability to have the &quot;call home&quot; feature relay all that information to him, which is now stored in a database.  Big deal, right?

Bill takes that database, sells it or gives it to friends.  They now know the URL of the site, the version software you&#039;re running (easily discernable by visiting the site and/or doing VIEW SOURCE unless, of course, the site has snipped some footer content, as well as header content, to get rid of WP&#039;s versioning info).  Instead of having to hunt down each site, Bill&#039;s plugin is now calling home with info on a few thousand sites, at least.

What could happen as a result?  I dunno, why don&#039;t you tell me?</description>
		<content:encoded><![CDATA[<p>As Sadish has said, the vulnerability is there.</p>
<p>Put WP, as an organization, aside.  Let&#8217;s look at the vulnerability as just that: a vulnerability.</p>
<p>Next week Bill Snoaks is going to write a plugin that does everything three current, very popular plugins do, but, instead of having to use all three, you use just one, plus &#8212; it has a few other goodies built in.  On top of that, though, Bill also adds a snip of coding to call home &#8212; to his site (he isn&#8217;t uploading the plugin to the WP Plugin site, but rather self-hosting the plugin.  He uses this vulnerability to have the &#8220;call home&#8221; feature relay all that information to him, which is now stored in a database.  Big deal, right?</p>
<p>Bill takes that database, sells it or gives it to friends.  They now know the URL of the site, the version software you&#8217;re running (easily discernable by visiting the site and/or doing VIEW SOURCE unless, of course, the site has snipped some footer content, as well as header content, to get rid of WP&#8217;s versioning info).  Instead of having to hunt down each site, Bill&#8217;s plugin is now calling home with info on a few thousand sites, at least.</p>
<p>What could happen as a result?  I dunno, why don&#8217;t you tell me?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sadish</title>
		<link>http://wpthemes.info/posts/2007/09/25/wordpress-23-privacy-issue-my-thoughts/comment-page-1/#comment-106957</link>
		<dc:creator>Sadish</dc:creator>
		<pubDate>Tue, 23 Oct 2007 15:07:06 +0000</pubDate>
		<guid isPermaLink="false">http://wpthemes.info/posts/2007/09/25/wordpress-23-privacy-issue-my-thoughts/#comment-106957</guid>
		<description>1. For me, my website&#039;s URL is a personally identifiable information. The moment someone knows my URL, they know who is running it.
2. They do send your blog&#039;s url along with the plugins and their version numbers.

I am not trying to suggest wordpress.org will misuse the information sent to them. 
I am just trying to make people aware of what is being sent back to the mothership, and what plugins they need to install if they do not want this information to be sent.
Thats all.

Thanks.</description>
		<content:encoded><![CDATA[<p>1. For me, my website&#8217;s URL is a personally identifiable information. The moment someone knows my URL, they know who is running it.<br />
2. They do send your blog&#8217;s url along with the plugins and their version numbers.</p>
<p>I am not trying to suggest wordpress.org will misuse the information sent to them.<br />
I am just trying to make people aware of what is being sent back to the mothership, and what plugins they need to install if they do not want this information to be sent.<br />
Thats all.</p>
<p>Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Shane</title>
		<link>http://wpthemes.info/posts/2007/09/25/wordpress-23-privacy-issue-my-thoughts/comment-page-1/#comment-106867</link>
		<dc:creator>Shane</dc:creator>
		<pubDate>Mon, 22 Oct 2007 21:21:46 +0000</pubDate>
		<guid isPermaLink="false">http://wpthemes.info/posts/2007/09/25/wordpress-23-privacy-issue-my-thoughts/#comment-106867</guid>
		<description>This doesn&#039;t concern me too much, for a couple of reasons.

First, you&#039;re misusing the term &quot;personally identifiable information.&quot;  While some of the info they send back isn&#039;t public knowledge, it&#039;s doesn&#039;t identify an individual.  That&#039;s what &quot;personally identifiable&quot; means.

Second, it doesn&#039;t look like they&#039;re sending all the data you list.  The only new information being sent by the update checker is PHP version and a list of plugins.

It does appear that this opens up a &lt;i&gt;slight&lt;/i&gt; new possibility of a security vulnerability, but it looks like the odds are very slight.  It certainly isn&#039;t like they&#039;re suddenly sending personal information about you back to the mothership.  This is some pretty benign stuff.</description>
		<content:encoded><![CDATA[<p>This doesn&#8217;t concern me too much, for a couple of reasons.</p>
<p>First, you&#8217;re misusing the term &#8220;personally identifiable information.&#8221;  While some of the info they send back isn&#8217;t public knowledge, it&#8217;s doesn&#8217;t identify an individual.  That&#8217;s what &#8220;personally identifiable&#8221; means.</p>
<p>Second, it doesn&#8217;t look like they&#8217;re sending all the data you list.  The only new information being sent by the update checker is PHP version and a list of plugins.</p>
<p>It does appear that this opens up a <i>slight</i> new possibility of a security vulnerability, but it looks like the odds are very slight.  It certainly isn&#8217;t like they&#8217;re suddenly sending personal information about you back to the mothership.  This is some pretty benign stuff.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stephan Miller</title>
		<link>http://wpthemes.info/posts/2007/09/25/wordpress-23-privacy-issue-my-thoughts/comment-page-1/#comment-106526</link>
		<dc:creator>Stephan Miller</dc:creator>
		<pubDate>Thu, 11 Oct 2007 23:17:21 +0000</pubDate>
		<guid isPermaLink="false">http://wpthemes.info/posts/2007/09/25/wordpress-23-privacy-issue-my-thoughts/#comment-106526</guid>
		<description>I never thought of it that way or even thought about how the plugins would be able to check for a version. I thought a simple check of plugin name and version would be all that is required. But the extra data?
You could say a company could be trusted with your data so far. But looking at the history of Wordpress.com spamming the search engines, I assume that a cheat could be capable of the same or more again.</description>
		<content:encoded><![CDATA[<p>I never thought of it that way or even thought about how the plugins would be able to check for a version. I thought a simple check of plugin name and version would be all that is required. But the extra data?<br />
You could say a company could be trusted with your data so far. But looking at the history of WordPress.com spamming the search engines, I assume that a cheat could be capable of the same or more again.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: OPENGIGA</title>
		<link>http://wpthemes.info/posts/2007/09/25/wordpress-23-privacy-issue-my-thoughts/comment-page-1/#comment-106516</link>
		<dc:creator>OPENGIGA</dc:creator>
		<pubDate>Tue, 02 Oct 2007 19:02:16 +0000</pubDate>
		<guid isPermaLink="false">http://wpthemes.info/posts/2007/09/25/wordpress-23-privacy-issue-my-thoughts/#comment-106516</guid>
		<description>I agree with you. 

now i am aware about it. 

thanks</description>
		<content:encoded><![CDATA[<p>I agree with you. </p>
<p>now i am aware about it. </p>
<p>thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dave J. (Scoop0901)</title>
		<link>http://wpthemes.info/posts/2007/09/25/wordpress-23-privacy-issue-my-thoughts/comment-page-1/#comment-106496</link>
		<dc:creator>Dave J. (Scoop0901)</dc:creator>
		<pubDate>Fri, 28 Sep 2007 23:26:44 +0000</pubDate>
		<guid isPermaLink="false">http://wpthemes.info/posts/2007/09/25/wordpress-23-privacy-issue-my-thoughts/#comment-106496</guid>
		<description>I agree, Sadish.  Matt was irresponsible in the way he handled that response.  He seemed a little ... too over-protective.

The comment about not being sure about what they will do with the info, but &quot;will find some use for it in the future&quot; is inherently wrong -- especially for an open-source, supposedly open, supposedly &quot;friendly&quot; community that wants to grow.

More and more, it looks like &lt;a href=&quot;http://en.wikipedia.org/wiki/Founder&#039;s_syndrome&quot; rel=&quot;nofollow&quot;&gt;Founder&#039;s Syndrome&lt;/a&gt; has set in among the clique that&#039;s formed in &quot;the community&quot;, and if you&#039;re not in that clique, well, you&#039;re a nobody and ought be discarded -- oh, but use WordPress!</description>
		<content:encoded><![CDATA[<p>I agree, Sadish.  Matt was irresponsible in the way he handled that response.  He seemed a little &#8230; too over-protective.</p>
<p>The comment about not being sure about what they will do with the info, but &#8220;will find some use for it in the future&#8221; is inherently wrong &#8212; especially for an open-source, supposedly open, supposedly &#8220;friendly&#8221; community that wants to grow.</p>
<p>More and more, it looks like <a href="http://wpthemes.info/out/?u=http://en.wikipedia.org/wiki/Founder"s_syndrome" class="ext-link" rel="external nofollow" target="_blank">Founder&#8217;s Syndrome</a> has set in among the clique that&#8217;s formed in &#8220;the community&#8221;, and if you&#8217;re not in that clique, well, you&#8217;re a nobody and ought be discarded &#8212; oh, but use WordPress!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sadish</title>
		<link>http://wpthemes.info/posts/2007/09/25/wordpress-23-privacy-issue-my-thoughts/comment-page-1/#comment-106479</link>
		<dc:creator>Sadish</dc:creator>
		<pubDate>Wed, 26 Sep 2007 12:41:47 +0000</pubDate>
		<guid isPermaLink="false">http://wpthemes.info/posts/2007/09/25/wordpress-23-privacy-issue-my-thoughts/#comment-106479</guid>
		<description>Those who follow me for the past couple of years would know how much I love WordPress.
I am not trying to mislead anyone to believe WordPress is doing something wrong.

but when people are asking questions, please see what kind of response they get.
&lt;blockquote&gt;
If you don&#039;t trust wordpress.org, I suggest you do one of the following:
1. Use different software.
2. Fork WordPress.
3. Install one of the aforementioned plugins.
- Matt
&lt;/blockquote&gt;
as you can see in this link. http://comox.textdrive.com/pipermail/wp-hackers/2007-September/014868.html

This is the answer that made me write this post.

It could very well be addressed something like this.
&quot;We are already on a &quot;code freeze&quot; for the 2.3 release and so we would try to include an admin option in the next version of WordPress.&quot;

This is the kind of step I want them to take.

I know there are so many optional functionality in WordPress, but when you are adding a new feature that could potentially collect personally identifiable information, they should &lt;strong&gt;make the user aware&lt;/strong&gt; of what is going on.
That is the missing thing here.</description>
		<content:encoded><![CDATA[<p>Those who follow me for the past couple of years would know how much I love WordPress.<br />
I am not trying to mislead anyone to believe WordPress is doing something wrong.</p>
<p>but when people are asking questions, please see what kind of response they get.</p>
<blockquote><p>
If you don&#8217;t trust wordpress.org, I suggest you do one of the following:<br />
1. Use different software.<br />
2. Fork WordPress.<br />
3. Install one of the aforementioned plugins.<br />
- Matt
</p></blockquote>
<p>as you can see in this link. <a href="http://wpthemes.info/out/?u=http://comox.textdrive.com/pipermail/wp-hackers/2007-September/014868.html" class="ext-link" rel="external nofollow" target="_blank">http://comox.textdrive.com/pipermail/wp-hackers/2007-September/014868.html</a></p>
<p>This is the answer that made me write this post.</p>
<p>It could very well be addressed something like this.<br />
&#8220;We are already on a &#8220;code freeze&#8221; for the 2.3 release and so we would try to include an admin option in the next version of WordPress.&#8221;</p>
<p>This is the kind of step I want them to take.</p>
<p>I know there are so many optional functionality in WordPress, but when you are adding a new feature that could potentially collect personally identifiable information, they should <strong>make the user aware</strong> of what is going on.<br />
That is the missing thing here.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

