← Back to context

Comment by toyg

9 hours ago

TBF, some of it is structural: if you're the most popular anything on the internet, you'll be the most attacked and the most exploited, and hence the most exploitable.

How many times has Google been hacked? It's not zero, but just because something is popular doesn't mean it has to get exploited. Repeatedly.

  • There is only one Google and it is operated by professionals. Who do not need to disclose the vulnerabilities that they find.

    Wordpress is pretty much the exact opposite of that.

    • We can say the same about most of open source.

      It's the WordPress plugin ecosystem that's more often the security nightmare though.

That's not really true.

Edit: wow that's a lot of downvotes! I'm surprised people can't identify a trivial reasoning failure.

  • You could've included a little more nuance. An interpretation of your response is "being the most popular remotely accessible software" != "the most attacked", which would need defending.

    • 25 years ago alache hosted about 10 times as many sites as IIS, yet IIS was always the one being backed.