| ▲ | 0xbadcafebee 11 hours ago | |
Most attacked, sure. Most exploited? You get out of it what you put into it. If you work to make it more secure, it will stay more secure, popular or not. WordPress is a software design from the early 2000's - and not a particularly good example. Even back then there were more secure designs. Take QMail for example. A simple design, it had security baked in from the start, and remains one of the most secure software packages in history. This exploit would have been prevented if WordPress had followed QMail's security designs. Enforced data flow, avoidance of parsing, eliminating untrusted code, and eliminating bugs by choosing code paths with fewer variables, would've all prevented this bug. DJB wrote a paper on QMail[1] to try to explain what worked and what was unnecessary. Anyone implementing new software (and wants it to be secure) should consider these [and other] design points. Popular software doesn't have to be bad software. [1] https://cr.yp.to/qmail/qmailsec-20071101.pdf | ||