<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Matt Mullenweg &#187; Search Results  &#187;  security</title>
	<atom:link href="http://ma.tt/search/security/feed/rss2/" rel="self" type="application/rss+xml" />
	<link>http://ma.tt</link>
	<description>Unlucky in Cards</description>
	<lastBuildDate>Fri, 25 May 2012 20:03:56 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4-RC1</generator>
	<atom:link rel='hub' href='http://ma.tt/?pushpress=hub'/>
<cloud domain='ma.tt' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
		<item>
		<title>On WordPress 3.2 with WebProNews</title>
		<link>http://ma.tt/2011/07/on-wordpress-3-2-with-webpronews/</link>
		<comments>http://ma.tt/2011/07/on-wordpress-3-2-with-webpronews/#comments</comments>
		<pubDate>Thu, 21 Jul 2011 22:13:03 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[Asides]]></category>
		<category><![CDATA[press]]></category>

		<guid isPermaLink="false">http://ma.tt/?p=38361</guid>
		<description><![CDATA[Abby Johnson from WebProNews posted an interview about the philosophy and thinking behind the WordPress 3.2 release, and we also recorded the video below:]]></description>
			<content:encoded><![CDATA[<p>Abby Johnson from WebProNews <a href="http://www.webpronews.com/wordpress-founder-talks-version-3-2-security-google-and-more-2011-07">posted an interview about the philosophy and thinking behind the WordPress 3.2 release</a>, and we also recorded the video below:</p>
<div id="v-jAzB26pR-1" class="video-player"><embed id="v-jAzB26pR-1-video" src="http://s0.videopress.com/player.swf?v=1.03&amp;guid=jAzB26pR&amp;isDynamicSeeking=true" type="application/x-shockwave-flash" width="640" height="360" title="Matt Mullenweg on WordPress 3.2 – WebProNews Interview" wmode="direct" seamlesstabbing="true" allowfullscreen="true" allowscriptaccess="always" overstretch="true"></embed></div>
]]></content:encoded>
			<wfw:commentRss>http://ma.tt/2011/07/on-wordpress-3-2-with-webpronews/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Airport Security</title>
		<link>http://ma.tt/2010/11/airport-security-2/</link>
		<comments>http://ma.tt/2010/11/airport-security-2/#comments</comments>
		<pubDate>Mon, 29 Nov 2010 23:45:45 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[Asides]]></category>

		<guid isPermaLink="false">http://ma.tt/?p=36560</guid>
		<description><![CDATA[It’s not that the terrorist picks an attack and we pick a defense, and we see who wins. It’s that we pick a defense, and then the terrorists look at our defense and pick an attack designed to get around it. Our security measures only work if we happen to guess the plot correctly. If [...]]]></description>
			<content:encoded><![CDATA[<div class="blockquote">
<blockquote>It’s not that the terrorist picks an attack and we pick a defense, and we see who wins. It’s that we pick a defense, and then the terrorists look at our defense and pick an attack designed to get around it. Our security measures only work if we happen to guess the plot correctly. If we get it wrong, we’ve wasted our money. This isn’t security; it’s security theater.</p></blockquote>
</div>
<p>Bruce Schnier on why airport security is <a href="http://www.nytimes.com/roomfordebate/2010/11/22/do-body-scanners-make-us-safer/a-waste-of-money-and-time">A Waste of Money and Time in the New York Times</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://ma.tt/2010/11/airport-security-2/feed/</wfw:commentRss>
		<slash:comments>15</slash:comments>
		</item>
		<item>
		<title>New VaultPress Security Scanning</title>
		<link>http://ma.tt/2010/11/new-vaultpress-security-scanning/</link>
		<comments>http://ma.tt/2010/11/new-vaultpress-security-scanning/#comments</comments>
		<pubDate>Sat, 27 Nov 2010 16:09:57 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[Asides]]></category>

		<guid isPermaLink="false">http://ma.tt/?p=36552</guid>
		<description><![CDATA[New VaultPress security scanning, scans all your core files to make sure they&#8217;re kosher.]]></description>
			<content:encoded><![CDATA[<p><a href="http://blog.vaultpress.com/2010/11/26/new-vaultpress-security-scanning/">New VaultPress security scanning</a>, scans all your core files to make sure they&#8217;re kosher.</p>
]]></content:encoded>
			<wfw:commentRss>http://ma.tt/2010/11/new-vaultpress-security-scanning/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Israeli Security Hates iPad</title>
		<link>http://ma.tt/2010/09/isreali-security-hates-ipad/</link>
		<comments>http://ma.tt/2010/09/isreali-security-hates-ipad/#comments</comments>
		<pubDate>Tue, 07 Sep 2010 08:02:38 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[Asides]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[ipad]]></category>
		<category><![CDATA[israel]]></category>

		<guid isPermaLink="false">http://ma.tt/2010/09/isreali-security-hates-ipad/</guid>
		<description><![CDATA[I had a pretty interesting experience going through security at Ben Gurion airport &#8212; I almost didn&#8217;t make it through. I had heard the airport security in Israel was different but I had no idea. They spent about an hour asking questions, turning on (and taking apart) every piece of the 20+ electronic items I [...]]]></description>
			<content:encoded><![CDATA[<p>I had a pretty interesting experience going through security at Ben Gurion airport &#8212; I almost didn&#8217;t make it through. I had heard the airport security in Israel was different but I had no idea. They spent about an hour asking questions, turning on (and taking apart) every piece of the 20+ electronic items I travel with, with particular attention and questions around my iPad. They took it out of the Apple case, turned it on, scanned it, took it away for 10 minutes to scan somewhere else, asked if anyone else in Israel had used it, when I last used it, asked when I got it, and ultimately said that their &#8220;technology team&#8221; had not cleared it for carry-on and they would need to pack it in a special box, wrap it, tape it, and check it directly with Continental (I couldn&#8217;t touch it or the box except to put some WP stickers on so I could identify it later). Wowza! My Sony PC, though, is safe to fly with. No wonder I saw so few Apple products at WordCamp. <img src='http://s.ma.tt/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://ma.tt/2010/09/isreali-security-hates-ipad/feed/</wfw:commentRss>
		<slash:comments>59</slash:comments>
		</item>
		<item>
		<title>Beyond Consumer Culture</title>
		<link>http://ma.tt/2010/05/beyond-consumer-culture/</link>
		<comments>http://ma.tt/2010/05/beyond-consumer-culture/#comments</comments>
		<pubDate>Sat, 15 May 2010 15:05:28 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[Asides]]></category>
		<category><![CDATA[Quote]]></category>

		<guid isPermaLink="false">http://ma.tt/?p=34425</guid>
		<description><![CDATA[[P]sychological evidence suggests that is is close relationships, a meaningful life, economic security, and health that contribute most to well-being. While there are marked improvements in happiness when people at low levels of income earn more (as their economic security improves and their range of opportunities grows), as incomes increase this extra earning power converts [...]]]></description>
			<content:encoded><![CDATA[<div class="blockquote">
<blockquote>[P]sychological evidence suggests that is is close relationships, a meaningful life, economic security, and health that contribute most to well-being. While there are marked improvements in happiness when people at low levels of income earn more (as their economic security improves and their range of opportunities grows), as incomes increase this extra earning power converts less effectively into increased happiness. In part, this may stem from <strong>people&#8217;s tendency to habituate to the consumption level they are exposed to.</strong> Goods that were once perceived as luxuries can over time be seen as entitlements or event necessities.</p>
<p>By the 1960s, for instance, the Japanese already viewed a fan, a washingmachine, and electric rice cookers as essential goods for a satisfactory living standard. In due course, a car, an air conditioner, and a color television were added to the list of &#8220;essentials.&#8221; And in the United States, 83 percent of people saw clothes dryers as a necessity in 2006. Even products around only a short time quickly become viewed as necessities. Half of Americans now think they must have a mobile phone, and one third of them <strong>see a high-speed Internet connection as essential.</strong></p></blockquote>
</div>
<p>Emphasis mine. From the <a href="http://www.worldwatch.org/sow10">State of the World 2010: Transforming Cultures</a>. <a href="http://blogs.worldwatch.org/transformingcultures/">They also have a nice, WordPress-powered blog</a>. (A necessity.) You can see the <a href="http://books.google.com/books?id=bTeRWMK-uM8C&#038;pg=PA9&#038;source=gbs_selected_pages&#038;cad=3#v=onepage&#038;q&#038;f=false">context of the quote in Google Books</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://ma.tt/2010/05/beyond-consumer-culture/feed/</wfw:commentRss>
		<slash:comments>14</slash:comments>
		</item>
		<item>
		<title>Facebook McAfee</title>
		<link>http://ma.tt/2010/01/facebook-mcafee/</link>
		<comments>http://ma.tt/2010/01/facebook-mcafee/#comments</comments>
		<pubDate>Wed, 13 Jan 2010 17:23:11 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[Open Source]]></category>

		<guid isPermaLink="false">http://ma.tt/?p=33561</guid>
		<description><![CDATA[Facebook is offering its users a 6-month free trial of McAfee and promoting it heavily, and even forcing people to run a scan before they can reactivate a hacked account. They&#8217;re &#8220;not aware of another free Internet service that takes this much responsibility for helping people keep their accounts secure.&#8221; (Didn&#8217;t Google promote McAfee through [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://blog.facebook.com/blog.php?post=248766257130">Facebook is offering its users a 6-month free trial of McAfee and promoting it heavily</a>, and even forcing people to run a scan before they can reactivate a hacked account. They&#8217;re &#8220;not aware of another free Internet service that takes this much responsibility for helping people keep their accounts secure.&#8221; (Didn&#8217;t Google promote McAfee through Google Pack at one point?) I think this is a laudable step, more security is intrinsically good, but I have to suspect this is more about revenue than security. They will probably make many millions of dollars from their users installing or buying McAfee as a result of this.</p>
<p>Modern versions of Windows include <a href="http://www.microsoft.com/windows/products/winfamily/defender/default.mspx">free tools like Defender</a> which are just as good and appear to have less of a performance impact on the computer. But if they really wanted to have a long-term impact on desktop as a vector for attack on web services I&#8217;m surprised they didn&#8217;t start, sponsor, or promote an Open Source equivalent of McAfee. This seems like a space very well-suited to address with an OS tool in the digital commons, much like a Windows anti-spyware equivalent of SpamAssassin, with self-updating rules and a completely transparent process.</p>
]]></content:encoded>
			<wfw:commentRss>http://ma.tt/2010/01/facebook-mcafee/feed/</wfw:commentRss>
		<slash:comments>28</slash:comments>
		</item>
		<item>
		<title>SecurityFocus SQL Injection Bogus</title>
		<link>http://ma.tt/2008/04/securityfocus-sql-injection-bogus/</link>
		<comments>http://ma.tt/2008/04/securityfocus-sql-injection-bogus/#comments</comments>
		<pubDate>Mon, 14 Apr 2008 16:30:09 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[WordPress]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://ma.tt/?p=5198</guid>
		<description><![CDATA[Since people are asking, this so-called alert on Security Focus appears to be completely false and has no information that an attacker or the WordPress developers could use. It is completely content-free, except for making claims that every version of WP since 2.0 is vulnerable. Online, apparently, it&#8217;s fine for someone to run into a [...]]]></description>
			<content:encoded><![CDATA[<p>Since people are asking, <a href="http://www.securityfocus.com/bid/28703/info">this so-called alert on Security Focus</a> appears to be completely false and has no information that an attacker or the WordPress developers could use. It is completely content-free, except for making claims that every version of WP since 2.0 is vulnerable.</p>
<p>Online, apparently, it&#8217;s fine for someone to run into a crowded theatre and yell &#8220;fire&#8221; and the less basis there is in fact the more people link to them. It&#8217;s not uncommon to see crying-wolf reports like the above several times in a week, and a big part of what the WP security team is sifting through things to see what&#8217;s valid or not.</p>
<p><a href="http://www.securityfocus.com/archive/1/490402">A valid security report looks like this</a>, it usually includes sample code and a detailed description of the problem. The WP security team was notified of the KSES problem and it was fixed in 2.5. You can impress your friends by saying whether a security report is valid or not, so it&#8217;s a good critical facility to pick up.</p>
<p>All that said, there is a wave of attacks going around targeting <em>old</em> WordPress blogs, particularly those on the 2.1 or 2.2 branch. They&#8217;re exploiting problems that have been fixed for a year or more. This typically manifests itself through hidden spam being put on your site, either in the post or in a directory, and people notice when they get dropped from Google. (Google will drop your site if it contains links they consider spammy, you&#8217;ll remember this is one of the <a href="http://weblogtoolscollection.com/archives/2007/04/12/on-sponsored-themes/">main reasons I came out against sponsored themes</a>.) Google has some guidelines as well, <a href="http://googlewebmastercentral.blogspot.com/2008/04/my-sites-been-hacked-now-what.html">what to do if your site is hacked</a>. If I were to suggest WordPress-specific ones, I would say:</p>
<p><span id="more-5198"></span></p>
<ol>
<li><strong>Upgrade your blog to the latest WP.</strong> This <em>shouldn&#8217;t</em> be hard. <a href="http://wordpress.org/extend/plugins/wordpress-automatic-upgrade/">There are plugins for it</a>, if you&#8217;re techy <a href="http://codex.wordpress.org/Installing/Updating_WordPress_with_Subversion">use Subversion</a>, <a href="http://codex.wordpress.org/Upgrading_WordPress">there is the standard FTP method</a>, and finally <a href="http://mediatemple.net/">Media Temple</a>, <a href="http://dreamhost.com/">Dreamhost</a>, and <a href="http://bluehost.com/">Bluehost</a> (through SimpleScripts) all have been pretty good about having their one-click upgrade systems ready with new versions within a day or two of a release. If your host is chronically behind, vote with your wallet and switch.
<ul>
<li>If you need someone to help you upgrade, consider <a href="http://lists.automattic.com/mailman/listinfo/wp-pro">hiring help on the wp-pro mailing list</a>. (It has close to a thousand subscribers and consultants on it.) Or you could always ply a geeky friend with caffeine, libations, food, or gadgets. Just get them to setup a system lik the above so you can do it yourself next time.</li>
</ul>
</li>
<li><strong>Change your passwords</strong>, for yourself and any other users you have on the system. If the attacker grabbed your password when you were on an old version, they can still log in after you&#8217;ve upgraded if you don&#8217;t change it. There&#8217;s a new password strength meter in 2.5 helps you pick a good password.</li>
<li><strong>Search through your posts</strong> for any that might have been modified, and comb through the directories on your web server looking for anything out of the ordinary. Your host may be able to help you with the latter.</li>
</ol>
<p>If you&#8217;re on the latest version, you&#8217;ve changed all your passwords, and something still happens to your blog, don&#8217;t panic. It&#8217;s not your (or WP&#8217;s) fault, but there is likely another account on the server which is malicious and the server you&#8217;re on is set up in a way that your neighbors can modify your files. The best thing to do here is to contact your host or sysadmin and have them check things out. They can look at the other accounts and log files in a forensic fashion to identify and find the source.</p>
<p>I follow or am involved with many, many WordPress blogs &#8211; some that receive millions of pageviews a day and have pageranks of 8 or 9 and are huge targets all the way to small personal blogs. Those that have followed the two basic tenets &#8212; keep up with upgrades and use good passwords &#8212; <strong>have <em>never</em> had a problem</strong>. Those that fall behind upgrades, <a href="http://ma.tt/2007/11/al-gore-hacked/">like Al Gore did</a>, have.</p>
<p>If you&#8217;re tech-savvy, take a look through your blogroll and see if anyone is on an old version. If they are, consider contacting them to help out. Like a <a href="http://en.wikipedia.org/wiki/Barn_raising">barn raising</a>, if we all work together it&#8217;ll happen a lot faster.</p>
<p>I often hear reasons why people don&#8217;t want to upgrade, here&#8217;s the most common and my best response:</p>
<ul>
<li><strong>I&#8217;m scared something will break, or I don&#8217;t know how.</strong> Ask a friend to help or hire a professional on the aforementioned wp-pro list. Long-term, try to use a plugin like WPAU or a host that will do upgrades.</li>
<li><strong>One of my plugins doesn&#8217;t work with the new version.</strong> This is getting rarer as we have a very public testing cycle for plugin authors to try their stuff with the latest version, but still common. I would suggest checking for an upgrade to the plugin on the author&#8217;s site, contacting the author about the incompatibility you found, maybe even donate some money, or finally search for an alternative plugin that provides similar functionality but works with the latest and greatest version of WordPress. In the big picture, though, having a secure site is much more important than the functionality of a single plugin, so you should seriously consider turning off a plugin for a few days instead of putting off core upgrades.</li>
<li><strong>I don&#8217;t like the new version, they moved my cheese.</strong> We believe every new release is better, but sometimes people just aren&#8217;t comfortable with a change, which is fine. The good news is that we constantly improve things based on feedback, including interfaces, and that more importantly for almost everything you can imagine annoying you there is a plugin that changes it. For example in 2.5 the page is fixed-width to allow for greater readability, but <a href="http://wordpress.org/extend/plugins/remove-max-width/">there&#8217;s a plugin to make it stretch to the full width of the window</a>.</li>
<li><strong>I modified core files, so upgrades are hard.</strong> You should <em>never ever</em> modify core files in WP. If you find you have to, <a href="http://trac.wordpress.org/">file a ticket</a> for a new hook or filter so your modifications can be a plugin &#8212; it makes things so much easier.</li>
<li><strong>Upgrades are too frequent.</strong> If it takes you more than 5 minutes to upgrade your blog, <a href="http://icanhascheezburger.com/category/wrong/">you&#8217;re doing it wrong</a>. Historically we do a major release about 3 times a year, and a minor release about once a month. Minor releases almost never break anything, so they are the easiest. (And often the most important.) WordPress is fast-evolving software, so this is a good problem to have.</li>
<li><strong>I don&#8217;t know when there&#8217;s an upgrade. </strong>No excuses here. Since 2.3 we include a big honking notice at the top of your dashboard when there&#8217;s a new release available. It&#8217;s also worth subscribing to our <a href="http://wordpress.org/development/">dev blog</a>, it&#8217;s not like it&#8217;s going to flood your RSS reader.</li>
</ul>
<p>Of course the millions of blogs on WordPress.com never worry about any of this, nor do the folks on good hosts that have one-click upgrades. The WP community takes security very seriously and has always done its best to respond diligently to any known problems, but all that work is for naught if you don&#8217;t upgrade. Hosting an application yourself is a responsibility. In the future we&#8217;re hoping to make this whole thing easier, for example with built-in functionality like WPAU. Until that day though, I hope the above helps. Feel free to copy, republish, or steal this post in whole or part for <a href="http://codex.wordpress.org/">whatever</a> you like.</p>
]]></content:encoded>
			<wfw:commentRss>http://ma.tt/2008/04/securityfocus-sql-injection-bogus/feed/</wfw:commentRss>
		<slash:comments>115</slash:comments>
		</item>
		<item>
		<title>Airport Security Follies</title>
		<link>http://ma.tt/2007/12/airport-security-follies/</link>
		<comments>http://ma.tt/2007/12/airport-security-follies/#comments</comments>
		<pubDate>Sun, 30 Dec 2007 02:09:08 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[Asides]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Travel]]></category>
		<category><![CDATA[nytimes]]></category>
		<category><![CDATA[tsa]]></category>

		<guid isPermaLink="false">http://photomatt.net/2007/12/29/airport-security-follies/</guid>
		<description><![CDATA[The Airport Security Follies. &#8220;And rather than rethink our policies, the best we&#8217;ve come up with is a way to skirt them â€” for a fee, naturally â€” via schemes like Registered Traveler.&#8221;]]></description>
			<content:encoded><![CDATA[<p><a href="http://jetlagged.blogs.nytimes.com/2007/12/28/the-airport-security-follies/index.html">The Airport Security Follies</a>. &#8220;And rather than rethink our policies, the best we&#8217;ve come up with is a way to skirt them â€” for a fee, naturally â€” via schemes like Registered Traveler.&#8221;</p>
]]></content:encoded>
			<wfw:commentRss>http://ma.tt/2007/12/airport-security-follies/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Al Gore Hacked</title>
		<link>http://ma.tt/2007/11/al-gore-hacked/</link>
		<comments>http://ma.tt/2007/11/al-gore-hacked/#comments</comments>
		<pubDate>Tue, 27 Nov 2007 20:18:41 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[Asides]]></category>

		<guid isPermaLink="false">http://photomatt.net/2007/11/27/al-gore-hacked/</guid>
		<description><![CDATA[The Register is reporting that Al Gore&#8217;s climate change site hacked. I looked at his WordPress blog and it&#8217;s running version 2.0.4, which was released in July of 2006, about 16 months ago. I wonder if these people want to upgrade but just need help, and if there&#8217;s something as a community we could do [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.theregister.co.uk/2007/11/27/climate_change_hack/">The Register is reporting that Al Gore&#8217;s climate change site hacked</a>. I looked at his <a href="http://www.climatecrisis.net/blog/">WordPress blog</a> and it&#8217;s running version 2.0.4, which was released in July of 2006, <a href="http://wordpress.org/development/2006/07/wordpress-204/">about 16 months ago</a>. I wonder if these people want to upgrade but just need help, and if there&#8217;s something as a community we could do to assist them? Like <a href="http://install4free.wordpress.net/">install4free</a> but for upgrades. What&#8217;s unfortunate is that people see this as an indicator of WP security, they&#8217;re judging us by bugs that have been fixed for more than a year.</p>
]]></content:encoded>
			<wfw:commentRss>http://ma.tt/2007/11/al-gore-hacked/feed/</wfw:commentRss>
		<slash:comments>82</slash:comments>
		</item>
		<item>
		<title>Head of TSA Interview</title>
		<link>http://ma.tt/2007/08/head-of-tsa-interview/</link>
		<comments>http://ma.tt/2007/08/head-of-tsa-interview/#comments</comments>
		<pubDate>Sun, 26 Aug 2007 03:37:32 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[Asides]]></category>
		<category><![CDATA[Travel]]></category>
		<category><![CDATA[homeland security]]></category>
		<category><![CDATA[tsa]]></category>

		<guid isPermaLink="false">http://photomatt.net/2007/08/25/head-of-tsa-interview/</guid>
		<description><![CDATA[After my airport security complaint the other day I found this interview of the head of the TSA by Bruce Schnier really, really interesting.]]></description>
			<content:encoded><![CDATA[<p>After my <a href="http://ma.tt/2007/08/17/airport-security/">airport security complaint</a> the other day I found this <a href="http://www.schneier.com/interview-hawley.html">interview of the head of the TSA by Bruce Schnier really, really interesting</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://ma.tt/2007/08/head-of-tsa-interview/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Airport Security?</title>
		<link>http://ma.tt/2007/08/airport-security/</link>
		<comments>http://ma.tt/2007/08/airport-security/#comments</comments>
		<pubDate>Sat, 18 Aug 2007 02:31:41 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[Asides]]></category>
		<category><![CDATA[Travel]]></category>
		<category><![CDATA[homeland security]]></category>
		<category><![CDATA[tsa]]></category>

		<guid isPermaLink="false">http://photomatt.net/2007/08/17/airport-security/</guid>
		<description><![CDATA[I just found a pocketknife in my laptop bag. This is not unusual, except I remembered that I must have taken it with me both to and from Houston earlier in the week, passing through security both times with a 2 inch blade in my bag. This happened once before, but was caught on the [...]]]></description>
			<content:encoded><![CDATA[<p>I just found a pocketknife in my laptop bag. This is not unusual, except I remembered that I must have taken it with me both to and from Houston earlier in the week, passing through security both times with a 2 inch blade in my bag. This happened once before, but was caught on the return flight. Total I have passed through airport security at least 4 times with a forgotten pocketknife, and only once did they stop me. A 25% hit rate? That&#8217;s just going to frustrate me more next time I&#8217;m standing in a security line for an hour.</p>
]]></content:encoded>
			<wfw:commentRss>http://ma.tt/2007/08/airport-security/feed/</wfw:commentRss>
		<slash:comments>45</slash:comments>
		</item>
		<item>
		<title>Price of Freedom</title>
		<link>http://ma.tt/2007/07/price-of-freedom/</link>
		<comments>http://ma.tt/2007/07/price-of-freedom/#comments</comments>
		<pubDate>Mon, 16 Jul 2007 12:17:44 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[Ask Matt]]></category>
		<category><![CDATA[Essays]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Open Source]]></category>
		<category><![CDATA[Wikipedia]]></category>
		<category><![CDATA[WordPress]]></category>
		<category><![CDATA[free software]]></category>
		<category><![CDATA[gpl]]></category>

		<guid isPermaLink="false">http://photomatt.net/2007/07/16/price-of-freedom/</guid>
		<description><![CDATA[I got asked an interesting question today: The only thing why (at least) I encode the footer is to prevent people from removing my designer link. I usually spend around 6 hours designing the graphics and coding the theme and some people simply take my link off and some of them even dare to write [...]]]></description>
			<content:encoded><![CDATA[<p>I got <a href="http://themes.wordpress.net/blog/4421/version-30/#comment-212724">asked an interesting question today</a>:</p>
<div class="blockquote">
<blockquote>The only thing why (at least) I encode the footer is to prevent people from removing my designer link. I usually spend around 6 hours designing the graphics and coding the theme and some people simply take my link off and some of them even dare to write that the theme was designed and coded by them! How would you feel if someone took your WordPress script (since it&#8217;s free) and said they made it? Wouldn&#8217;t you like to bite their head off?</p></blockquote>
</div>
<p>The response became too long for a comment, so here it is:</p>
<p>Kate, thousands of people every day remove the WordPress link, or my link, or search and replace the WP logo with their own and redistribute it, use it to spam, distribute hate speech, or any number of awful things you can imagine. So why have hundreds of people spent thousands of hours working on it?</p>
<p>Though the freedom intrinsic in the <a href="http://www.gnu.org/copyleft/gpl.html">GPL</a> that has allowed people to abuse WordPress it has allowed even more people to do amazing things and over time the good far, far outweighs the bad. Most importantly I feel like WordPress would have never gotten off the ground if it hadn&#8217;t been open from the beginning. (In fact there were several more functional blogging programs started around the same time that have since withered away.)</p>
<p>Ultimately I know our software isn&#8217;t going to change anyone&#8217;s spots. Good people will do good things with it, and bad people will do bad things with it &#8212; regardless of any protections I put in place. Windows Vista, a multi-billion dollar enterprise, was cracked within days. Does any piddling encoding I can do in PHP really matter? If protection like that isn&#8217;t broken it&#8217;s a statement of popularity, not security.  I suppose could harass the bad guys, shut down their host, send them scary letters, but it&#8217;s just going to stress me out and like cockroaches they&#8217;ll pop up someplace else. I also know that most projects, software, and ideas die from obscurity, not piracy.</p>
<p>If you accept that bad people are going to be bad then the real question becomes how do you maximize the effect of the good instead of treating them just like the bad. (No one likes to be treated like a criminal.) In my brief experience here&#8217;s three things that work:</p>
<ol>
<li>Give people the tools they need to succeed. This can be interpreted on a lot of levels,  but personally I&#8217;ve found at the most base <a href="http://www.gnu.org/philosophy/free-sw.html">the freedoms provided by the GPL</a> and other open source licenses are incredibly empowering.</li>
<li>Celebrate the successes. Talk, connect, promote, and embrace the people who are creating things on top of your creation. (The best revenge against someone doing something bad is helping create something awesome.)</li>
<li>Provide a way for people to choose to help you, and try to remove as much friction from that process as possible. Now that you&#8217;ve ignored the bad people and delighted the good, by their very nature they&#8217;ll want to give something back.</li>
</ol>
<p>The success stories around this model are numerous and growing every day. People can and do rip-off the entire Wikipedia, but it&#8217;s still become one of the top ten sites on the internet and a marvel of what can happen when you let go. (Not to mention it is run entirely on open source software.) WordPress itself was built on top of a pre-existing GPL product called b2/cafelog. Anyone can run the software behind our hosted service WordPress.com and create competitive sites, and many have, but it hasn&#8217;t hurt us one bit. Linux, GNU, and the thousands of related desktop projects haven&#8217;t taken a bit longer than folks had hoped, but the impact they&#8217;re having, especially on emerging economies, is dramatic. The list goes on and on. It&#8217;s not hard to join the movement, but first you have to figure out who you&#8217;re fighting, who you&#8217;re trying to help, and if the price of freedom is something you&#8217;re willing to embrace.</p>
]]></content:encoded>
			<wfw:commentRss>http://ma.tt/2007/07/price-of-freedom/feed/</wfw:commentRss>
		<slash:comments>65</slash:comments>
		</item>
		<item>
		<title>On PHP</title>
		<link>http://ma.tt/2007/07/on-php/</link>
		<comments>http://ma.tt/2007/07/on-php/#comments</comments>
		<pubDate>Fri, 13 Jul 2007 18:08:31 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[Essays]]></category>
		<category><![CDATA[php4]]></category>
		<category><![CDATA[php5]]></category>
		<category><![CDATA[rant]]></category>

		<guid isPermaLink="false">http://photomatt.net/2007/07/13/on-php/</guid>
		<description><![CDATA[PHP.net has announced that they will stop development of PHP4 at the end of this year, and end security updates on 2008-08. (In 2007, their site still doesn&#8217;t have obvious permalinks. They do have a RSS 1.0 feed though, remember those?) PHP 4.0 was release in May of 2000, by 2004 when the first version [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://php.net/">PHP.net</a> has announced that they will stop development of PHP4 at the end of this year, and end security updates on 2008-08. (In 2007, their site still doesn&#8217;t have obvious permalinks. They do have a RSS 1.0 feed though, remember those?)</p>
<p>PHP 4.0 was release in May of 2000, by 2004 when the first version of PHP 5.0 was released, PHP 4 had achieved complete dominance and was completely ubiquitous in both script and hosting support.</p>
<p>Fast forward 3 more years and PHP 5 has been, from an adoption point of view, a complete flop. Most estimates place it in the single-digit percentages or at best the low teens, mostly gassed by marginal frameworks. Even hosted PHP-powered services who have no shared host compatibility concerns like 30boxes, Digg, Flickr, and WordPress.com, have been slow to move and when they do it will probably be because of speed or security, not features.</p>
<p>Some app makers felt sorry for PHP 5 and decided to create the <a href="http://gophp5.org/">world&#8217;s ugliest advocacy site</a> and turn their apps in to protest pieces at the expense of their users. (Hat tip: <a href="http://trac.wordpress.org/ticket/4591#comment:1">Mark J</a>.) They say &#8220;Web hosts cannot upgrade their servers to PHP 5 without making it impossible for their users to run PHP 4-targeted web apps&#8221; ignoring the fact that there isn&#8217;t a released PHP app today that isn&#8217;t PHP 5-compatible and recent upgrade issues <a href="http://bugs.php.net/bug.php?id=39381">have been caused by PHP itself</a> in point releases. (See <a href="http://trac.wordpress.org/ticket/3354">WP#3354</a>.) It&#8217;s easy to always promote the newest thing, but why, and is it for us or our users?</p>
<p>Now the PHP core team seems to have decided that the boost their failing product needs is to kill off their successful one instead of asking the hard questions: <strong>What was it that made PHP 4 so successful?</strong> What are we doing to emphasize those strengths? Why wasn&#8217;t PHP 5 compelling to that same audience? Are the things <a href="http://jero.net/articles/php6">we&#8217;re doing in PHP 6</a> crucial to our core audience or simply &#8220;good&#8221; language problems to solve? Will they drive adoption? How can we avoid releasing (another) <a href="http://en.wikipedia.org/wiki/IBM_PCjr#Failure_in_the_marketplace">PCjr</a>?</p>
<p>I wonder if PHP 5+ should be called something other than PHP. A unique name would have allowed the effort to stand on its own, and not imply something that&#8217;s an upgrade from what came before when in many cases it&#8217;s just different, not better,  from an end-user perspective. Continue to maintain PHP 4 as like a PHP-lite. Make it harder, better, faster, <a href="http://www.kanyewest.com/?content=video_stronger">stronger</a>.</p>
<p>For all the noise though, <strong>this isn&#8217;t a big deal</strong>. It&#8217;s easy to forget that PHP 4 hasn&#8217;t had any real innovation in the past 3 years while at the same time apps and services built on top of it have created some of the richest and most compelling user experiences the web has seen. (<span class="hw">NÃ©e Web 2.0.) </span>None of the <a href="http://wordpress.org/extend/ideas/?show=popular">most requested features for WordPress</a> would be any easier (or harder) if they were written for PHP 4 or 5 or Python. <strong>They&#8217;d just be different.</strong> The hard part usually has little to do with the underlying server-side language.</p>
<p>Someday on our mailing lists I hope half the words wasted pontificating on &#8220;language version wars,&#8221; which are even duller than language wars, go toward design, copywriting, information, performance &#8212; the things that truly matter.</p>
]]></content:encoded>
			<wfw:commentRss>http://ma.tt/2007/07/on-php/feed/</wfw:commentRss>
		<slash:comments>104</slash:comments>
		</item>
		<item>
		<title>On WP Security</title>
		<link>http://ma.tt/2007/06/on-wp-security/</link>
		<comments>http://ma.tt/2007/06/on-wp-security/#comments</comments>
		<pubDate>Sat, 23 Jun 2007 03:46:42 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://photomatt.net/2007/06/22/on-wp-security/</guid>
		<description><![CDATA[Wincent Colaiuta has no problem throwing flames at WordPress, but doesn&#8217;t see fit to enable comments. (Apparently disabled to make Movable Type more secure.) His table-layout blog isn&#8217;t too notable but it got linked from Daring Fireball so a lot of people saw his article trying to draw the line between a routine point release [...]]]></description>
			<content:encoded><![CDATA[<p>Wincent Colaiuta has no problem <a href="http://wincent.com/a/about/wincent/weblog/archives/2007/06/wordpress_flaw.php">throwing flames at WordPress</a>, but doesn&#8217;t see fit to enable comments. (Apparently disabled to <a href="http://wincent.com/knowledge-base/Movable_Type_security_notes">make Movable Type more secure</a>.) His table-layout blog isn&#8217;t too notable but it got linked from <a href="http://daringfireball.net/">Daring Fireball</a> so a lot of people saw his article trying to draw the line between a <a href="http://wordpress.org/development/2007/06/wordpress-221/">routine point release</a> and encouraging people to never use WordPress on the public internet. Here are a few points for thought in response:</p>
<ul>
<li>The SQL problem in 2.2 requires both registration to be enabled (off by default) and the blog to be upgraded to 2.2. It is a serious problem but I&#8217;ve heard of fewer than 5 exploits from the flaw. Even if you assume there are 100 blogs for every one we heard about, that&#8217;s still an incredibly small percentage of the millions of WordPresses out there, especially considering, as Wincent points out, the problem has been in the public for a while now.</li>
<li>Getting people to upgrade web software is hard. We work as best we can with hosting companies, but a consideration is that it&#8217;s best to roll several security fixes into one release. It&#8217;s not responsible to do a release if we know of another problem, so sometimes there is a lag between an initial report and a final release, not to mention the testing required of a product used as much as WP.</li>
<li>Wincent digs up the server crack that modified the files of 2.1.1 for a few days. Ignoring the fact that it was a server issue and had nothing to do with WordPress the software, we actually had NO reported exploits of the problem. (Though I&#8217;m sure there are at least a handful out there with problems, it wasn&#8217;t enough to hit our radar.) Despite that we took a hit and publicized the issue as much as we could to get the word out.</li>
<li>Also about 2.1.1, the problem was found through someone proactively auditing the codebase.</li>
<li>Finally Wincent says of WP &#8220;[a]nd if you insist on installing it, then you need to watch the <a href="http://trac.wordpress.org/">trac</a> like a hawk.&#8221; You would think complete transparency of the problems (it was on our bug tracker and mailing list) would be a good thing, especially considering the software Wincent uses doesn&#8217;t have a bug tracker, and the only way to submit a bug is through a contact form.</li>
</ul>
<p>We can and do review new code for problems, and pick the vast majority up before any releases. I think the real issue though is not that WP has bugs which are sometimes security related, which all software not written by djb does, but that the mechanisms for updating complex web software are a pain. Right now the best experiences are probably with folks like Media Temple or Dreamhost that have pretty foolproof one-click upgrades and are quick with updates.</p>
<p>Making notification better and upgrading more painless for people not lucky enough to be on a host like that are problems with some very clever minds on them, and I&#8217;m confident that we&#8217;ll have good progress toward each in the next major release of WP.</p>
<p>Finally, I suppose we could act more like our proprietary competitors and try to downplay or hide security issues instead of trumpeting them loudly in our blog, but I think the benefit of having people well-informed outweighs the PR lumps we take for doing the right thing. I truly believe talking about these things in the open is the best way to address them.</p>
<p>In some ways it&#8217;s a good problem to have. When a product is popular, not only does it have more eyes from security professionals on it, but any problems garner a level of attention which is not quite warranted by the frequency of the general event, like Angelina Jolie having a baby. There are certainly things intrinsic to coding that can make software more or less secure, but all things being equal the software with the most eyes on it, which usually means Open Source, will be the most robust in the long term.</p>
]]></content:encoded>
			<wfw:commentRss>http://ma.tt/2007/06/on-wp-security/feed/</wfw:commentRss>
		<slash:comments>110</slash:comments>
		</item>
		<item>
		<title>Mac Woes</title>
		<link>http://ma.tt/2006/09/mac-woes/</link>
		<comments>http://ma.tt/2006/09/mac-woes/#comments</comments>
		<pubDate>Fri, 22 Sep 2006 20:33:24 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Asides]]></category>
		<category><![CDATA[OS X]]></category>
		<category><![CDATA[Powerbook]]></category>

		<guid isPermaLink="false">http://photomatt.net/2006/09/22/mac-woes/</guid>
		<description><![CDATA[After a security update my 12&#8243; Powerbook asked me to reboot, after which it decided that it will only boot to a command line. I have no idea how to even start to fix this, I can navigate around it like it&#8217;s Linux but there is no indication of what went wrong or how to [...]]]></description>
			<content:encoded><![CDATA[<p>After a security update my 12&#8243; Powerbook asked me to reboot, after which it decided that it will only boot to a command line. I have no idea how to even start to fix this, I can navigate around it like it&#8217;s Linux but there is no indication of what went wrong or how to fix it. I&#8217;m going to take it to the Genius bar in hopes they can do something, but all-in-all this is pretty disappointing.</p>
]]></content:encoded>
			<wfw:commentRss>http://ma.tt/2006/09/mac-woes/feed/</wfw:commentRss>
		<slash:comments>29</slash:comments>
		</item>
		<item>
		<title>Spam + Blogs = Trouble</title>
		<link>http://ma.tt/2006/09/spam-blogs-trouble/</link>
		<comments>http://ma.tt/2006/09/spam-blogs-trouble/#comments</comments>
		<pubDate>Fri, 15 Sep 2006 17:55:01 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[Akismet]]></category>
		<category><![CDATA[Asides]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[Wired]]></category>

		<guid isPermaLink="false">http://photomatt.net/2006/09/15/spam-blogs-trouble/</guid>
		<description><![CDATA[Wired had an article out last month called Spam + Blogs = Trouble where I share some of my perspectives on the whole spam thing. It&#8217;s a good article, but I strongly disagree with Anil&#8217;s comments at the end around a global identifier or &#8220;Internet Social Security number.&#8221; Akismet has shown we don&#8217;t need to [...]]]></description>
			<content:encoded><![CDATA[<p>Wired had an article out last month called <a href="http://www.wired.com/wired/archive/14.09/splogs.html">Spam + Blogs = Trouble</a> where I share some of my perspectives on the whole spam thing. It&#8217;s a good article, but I strongly disagree with Anil&#8217;s comments at the end around a global identifier or &#8220;Internet Social Security number.&#8221; Akismet has shown we don&#8217;t need to boil the ocean or make commenters jump through hoops to get effective spam protection on blogs (and blog hosting services).</p>
]]></content:encoded>
			<wfw:commentRss>http://ma.tt/2006/09/spam-blogs-trouble/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
		<item>
		<title>The Feed Validator is Dead to Me</title>
		<link>http://ma.tt/2006/04/feed-validator/</link>
		<comments>http://ma.tt/2006/04/feed-validator/#comments</comments>
		<pubDate>Sat, 15 Apr 2006 23:20:18 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[RSS]]></category>
		<category><![CDATA[Feed Validator]]></category>

		<guid isPermaLink="false">http://photomatt.net/2006/04/15/feed-validator/</guid>
		<description><![CDATA[Is anyone else sick and tired of the so-called feed validator changing its mind on fundamental issues every other week? I&#8217;m sure Sam Ruby and whoever else is still working on the Validator mean well, but the constant ivory tower decisions to change the way it interpets &#8220;valid RSS 2.0&#8243; is making it seem more [...]]]></description>
			<content:encoded><![CDATA[<p>Is anyone else sick and tired of the so-called <a href="http://www.feedvalidator.org/">feed validator</a> changing its mind on fundamental issues every other week? I&#8217;m sure <a href="http://www.intertwingly.net/blog/">Sam Ruby</a> and whoever else is still working on the Validator mean well, but the constant ivory tower decisions to change the way it interpets &#8220;valid RSS 2.0&#8243; is making it seem more like a political advocacy tool than anything else. Perhaps I should give the benefit of the doubt and &#8220;Never attribute to malice that which is adequately explained by stupidity.&#8221;</p>
<p>I&#8217;m not even talking about <a href="http://www.feedvalidator.org/news/archives/2005/09/15/atom_03_deprecated.html">deciding they can change the world by decree</a>. (Which has <a href="http://www.franklinmint.fm/blog/archives/000701.html">already been addressed</a>.) The latest in their line of enlightened changes is that the author of the Well-formed Web spec has changed the capitializition of the <code>wfw:commentRSS</code> element at some unknown point to lowercase <code>Rss</code>. This arbitrary decision has been codified by the validator, which now reports the millions and millions of feeds that use the previously correct capitialization as invalid. <a href="http://sourceforge.net/mailarchive/forum.php?thread_id=10183105&#038;forum_id=37467">Confusion</a> <a href="http://sourceforge.net/mailarchive/forum.php?thread_id=10112781&#038;forum_id=37467">ensues</a>.</p>
<p>If the previous paragraph makes your eyes glaze over, congratulations, you&#8217;re normal.</p>
<p><a href="http://sourceforge.net/mailarchive/forum.php?thread_id=10113831&#038;forum_id=37467">Here is a post on their mailing list</a> which also explains the issue and <a href="http://web.archive.org/web/20050305162845/http://wellformedweb.org/news/wfw_namespace_elements/">includes a link to the archive.org version of the page with the capitialization everyone uses</a>, which was there for <a href="http://web.archive.org/web/*/http://wellformedweb.org/news/wfw_namespace_elements/">at least two years</a>. <a href="http://svn.sourceforge.net/viewcvs.cgi/feedvalidator/trunk/feedvalidator/src/feedvalidator/extension.py?r1=598&#038;r2=597&#038;pathrev=598">One line can cause so much trouble</a>.</p>
<p>But wait, there&#8217;s more. &#8220;In addition, this feed has an issue that may cause problems for some users.&#8221; They&#8217;ve also started marking all uses of <code>content:encoded</code> as potentially causing problems, which is funny because it actually avoids a ton of problems and (again) people have been using it in RSS 2.0 feeds for 3+ years now, and I even asked Dave Winer about it in the past and he said that was fine. <a href="http://www.feedvalidator.org/docs/warning/DuplicateDescriptionSemantics.html">Their documentation on the topic</a> seems more geared toward instilling fear, uncertainty, and doubt in RSS 2.0 than addressing the reason they&#8217;ve decided to start warning about this element. Where a validator normally provides stability, the feed validator has become the Homeland Security of the RSS world, keeping us all in a constant state of dulled fear, insensitive to whatever warnings they&#8217;re giving us today because we just want it to stop.</p>
<p>I&#8217;m sure the <code>content:encoded</code> change can be rationalized with a perfectly convincing argument. I wouldn&#8217;t be surprised if someone as smart as Sam could do the same for the arbitrary <code>wft:CommentRSS</code> change. I know that the code is open source and we could fork it and create another version of the validator that doesn&#8217;t invalidate half the blogosphere on <a href="http://svn.sourceforge.net/viewcvs.cgi/feedvalidator?rev=598&#038;view=rev">a Tuesday afternoon</a>. But then we would have more than one validator, and that defeats the point.</p>
]]></content:encoded>
			<wfw:commentRss>http://ma.tt/2006/04/feed-validator/feed/</wfw:commentRss>
		<slash:comments>42</slash:comments>
		</item>
		<item>
		<title>Note to self</title>
		<link>http://ma.tt/2006/03/note-to-self-3/</link>
		<comments>http://ma.tt/2006/03/note-to-self-3/#comments</comments>
		<pubDate>Wed, 29 Mar 2006 01:56:46 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[Asides]]></category>

		<guid isPermaLink="false">http://photomatt.net/2006/03/28/note-to-self-3/</guid>
		<description><![CDATA[When flying to Canada, BRING YOUR PASSPORT. Update: I wrote the preceding from my Blackberry at the ticket counter. After I found out about the passport, I rushed to the departure area and got the world&#8217;s best cab driver. His English was atrocious, but he understood what was going on. There was thankfully no traffic [...]]]></description>
			<content:encoded><![CDATA[<p>When flying to Canada, BRING YOUR PASSPORT. <strong>Update:</strong> I wrote the preceding from my Blackberry at the ticket counter. After I found out about the passport, I rushed to the departure area and got the world&#8217;s best cab driver. His English was atrocious, but he understood what was going on. There was thankfully no traffic on 280 to SFO to my house and he did it in about 15 minutes. Ran in, grabbed the passport, ran back out. Lost a minute while he tried to ask me if I had &#8220;all three things&#8221;: passport, tickets, and ID. He says a lot of people run in to get a passport and leave the tickets on the table. He took 101 back to SFO, which had a bit of traffic. Big tip. No line at ticket counter, <strong>the flight was delayed</strong>. The lady was so kind, she switched me to the last window seat on the flight to Las Vegas and I got an upgrade to first class from Vegas to Toronto. (Maybe I&#8217;ll get some sleep.) No line at the security counter so I breezed through. Had time to grab a reuben at the deli. Sometimes I think I lead a charmed life.</p>
]]></content:encoded>
			<wfw:commentRss>http://ma.tt/2006/03/note-to-self-3/feed/</wfw:commentRss>
		<slash:comments>17</slash:comments>
		</item>
		<item>
		<title>PHP Acronym Definer</title>
		<link>http://ma.tt/scripts/acronymit/</link>
		<comments>http://ma.tt/scripts/acronymit/#comments</comments>
		<pubDate>Sat, 04 Mar 2006 07:13:02 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[Asides]]></category>

		<guid isPermaLink="false">http://photomatt.net/scripts/acronymit/</guid>
		<description><![CDATA[Released on December 21, 2002 Last Updated: December 21, 2002 2:23 AM Version: 0.1 Description When you run your text through this code it will define all the acronyms it can using the acronym tag. It also has a few other niceities, so check it out. Installation/Usage Pass whatever text you want to use through [...]]]></description>
			<content:encoded><![CDATA[<p>Released on December 21, 2002<br />
<strong>Last Updated:</strong> December 21, 2002 2:23 AM<br />
<strong>Version:</strong> 0.1</p>
<h2 class='script'>Description</h2>
<p>When you run your text through this code it will define all the acronyms it can using the <code>acronym</code> tag. It also has a few other niceities, so check it out.</p>
<h2 class='script'>Installation/Usage</h2>
<p>Pass whatever text you want to use through it, and add whatever acronyms you want to add to the array by copying what I have already. The <code>sortr_longer</code> <strong>must</strong> be above the <code>acronymit</code> function.</p>
<h2 class='script'>Code</h2>
<h3 class='script'>Reverse Sort Array on Length</h3>
<div class='scriptcode'><code>&lt;?php<br />
function sortr_longer($first, $second) {<br />
return (strlen($first) &lt; strlen($second)) ? 1 : -1;<br />
}<br />
?&gt;</code></div>
<h3 class='script'>acronymit</h3>
<div class='scriptcode'><code>&lt;?php<br />
function acronymit($text) {<br />
&nbsp;&nbsp;&nbsp;&nbsp;$acronyms = array(<br />
&#039;WYSIWYG&#039; =&gt; &#039;what you see is what you get&#039;,<br />
&#039;XHTML&#039; =&gt; &#039;eXtensible HyperText Markup Language&#039;,<br />
&#039;IIRC&#039; =&gt; &#039;if I remember correctly&#039;,<br />
&#039;HDTV&#039; =&gt; &#039;High Definition TeleVision&#039;,<br />
&#039;LGPL&#039; =&gt; &#039;GNU Lesser General Public License&#039;,<br />
&#039;MSDN&#039; =&gt; &#039;Microsoft Developer Network&#039;,<br />
&#039;WCAG&#039; =&gt; &#039;Web Content Accessibility Guidelines&#039;,<br />
&#039;SOAP&#039; =&gt; &#039;Simple Object Access Protocol&#039;,<br />
&#039;OPML&#039; =&gt; &#039;Outline Processor Markup Language&#039;,<br />
&#039;MSIE&#039; =&gt; &#039;Microsoft Internet Explorer&#039;,<br />
&#039;FOAF&#039; =&gt; &#039;Friend of a Friend vocabulary&#039;,<br />
&#039;GFDL&#039; =&gt; &#039;GNU Free Documentation License&#039;,<br />
&#039;XSLT&#039; =&gt; &#039;eXtensible Stylesheet Language Transformation&#039;,<br />
&#039;HTML&#039; =&gt; &#039;HyperText Markup Language&#039;,<br />
&#039;IHOP&#039; =&gt; &#039;International House of Pancakes&#039;,<br />
&#039;IMAP&#039; =&gt; &#039;Internet Message Access Protocol&#039;,<br />
&#039;RAID&#039; =&gt; &#039;Redundant Array of Independent Disks&#039;,<br />
&#039;HPUG&#039; =&gt; &#039;Houston Palm Users Group&#039;,<br />
&#039;VNC&#039; =&gt; &#039;Virtual Network Computing&#039;,<br />
&#039;URL&#039; =&gt; &#039;Uniform Resource Locator&#039;,<br />
&#039;W3C&#039; =&gt; &#039;World Wide Web Consortium&#039;,<br />
&#039;MSN&#039; =&gt; &#039;Microsoft Network&#039;,<br />
&#039;USB&#039; =&gt; &#039;Universal Serial Bus&#039;,<br />
&#039;P2P&#039; =&gt; &#039;Peer To Peer&#039;,<br />
&#039;PBS&#039; =&gt; &#039;Public Broadcasting System&#039;,<br />
&#039;RSS&#039; =&gt; &#039;Rich Site Summary&#039;,<br />
&#039;SIG&#039; =&gt; &#039;Special Interest Group&#039;,<br />
&#039;RDF&#039; =&gt; &#039;Resource Description Framework&#039;,<br />
&#039;AOL&#039; =&gt; &#039;American Online&#039;,<br />
&#039;PHP&#039; =&gt; &#039;PHP Hypertext Processor&#039;,<br />
&#039;SSN&#039; =&gt; &#039;Social Security Number&#039;,<br />
&#039;JSP&#039; =&gt; &#039;Java Server Pages&#039;,<br />
&#039;DOM&#039; =&gt; &#039;Document Object Model&#039;,<br />
&#039;DTD&#039; =&gt; &#039;Document Type Definition&#039;,<br />
&#039;DVD&#039; =&gt; &#039;Digital Video Disc&#039;,<br />
&#039;DNS&#039; =&gt; &#039;Domain Name System&#039;,<br />
&#039;CSS&#039; =&gt; &#039;Cascading Style Sheets&#039;,<br />
&#039;CGI&#039; =&gt; &#039;Common Gateway Interface&#039;,<br />
&#039;CMS&#039; =&gt; &#039;Content Management System&#039;,<br />
&#039;FAQ&#039; =&gt; &#039;Frequently Asked Questions&#039;,<br />
&#039;FSF&#039; =&gt; &#039;Free Software Foundation&#039;,<br />
&#039;API&#039; =&gt; &#039;Application Interface&#039;,<br />
&#039;PDF&#039; =&gt; &#039;Portable Document Format&#039;,<br />
&#039;IIS&#039; =&gt; &#039;Internet Infomation Server&#039;,<br />
&#039;XML&#039; =&gt; &#039;eXtensible Markup Language&#039;,<br />
&#039;XSL&#039; =&gt; &#039;eXtensible Stylesheet Language&#039;,<br />
&#039;GPL&#039; =&gt; &#039;GNU General Public License&#039;,<br />
&#039;KDE&#039; =&gt; &#039;K Desktop Environment&#039;,<br />
&#039;IE&#039; =&gt; &#039;Internet Explorer&#039;,<br />
&#039;CD&#039; =&gt; &#039;Compact Disk&#039;,<br />
&#039;GB&#039; =&gt; &#039;Gigabyte&#039;,<br />
&#039;MB&#039; =&gt; &#039;Megabyte&#039;,<br />
&#039;KB&#039; =&gt; &#039;Kilobyte&#039;<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;);<br />
&nbsp;&nbsp;&nbsp;&nbsp;uksort($acronyms, &#039;sortr_longer&#039;); // comment out if already sorted<br />
&nbsp;&nbsp;&nbsp;&nbsp;foreach ($acronyms as $acronym =&gt; $definition) {<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;$text = preg_replace(&quot;#$acronym(?!&lt;/(ac|sp))#&quot;, &quot;&lt;acronym title=\&quot;$definition\&quot;&gt;$acronym&lt;/acronym&gt;&quot;, $text, 1);<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;$text = preg_replace(&quot;#$acronym(?!&lt;/(ac|sp))#&quot;, &quot;&lt;span class=&#039;caps&#039;&gt;$acronym&lt;/span&gt;&quot;, $text);<br />
&nbsp;&nbsp;&nbsp;&nbsp;}<br />
&nbsp;&nbsp;&nbsp;&nbsp;return $text;<br />
}<br />
?&gt;</code></div>
<h2 class='script'>Notes</h2>
<p>You can speed it up a bit by commenting out the sort line <strong>if</strong> the array is in order of longest acronyms first. The reason for this is because the function goes down the array looking for that text to acronymfy, and it&#8217;ll grab whatever it comes to first. So if you have an acronym defined for <span class="caps">LAMB</span> and one for <acronym title="Megabyte">MB</acronym>, if <span class="caps">MB</span> is first on the list, it will eat the last two letters of <span class="caps">LAMB</span>. To make people (mainly me) not have to sort it manually by acronym length I wrote a small function to reverse sort the array by the length of the key string.</p>
]]></content:encoded>
			<wfw:commentRss>http://ma.tt/scripts/acronymit/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Livejournal Hack</title>
		<link>http://ma.tt/2006/01/livejournal-hack/</link>
		<comments>http://ma.tt/2006/01/livejournal-hack/#comments</comments>
		<pubDate>Sat, 21 Jan 2006 08:02:17 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[Asides]]></category>

		<guid isPermaLink="false">http://photomatt.net/2006/01/21/livejournal-hack/</guid>
		<description><![CDATA[I&#8217;ve been following the Livejournal hack closely because as someone who runs many services that allow user submitted content, any new developments in XSS are very important to stay on top of. So far the only official technical explanation I&#8217;ve seen is here on lj_dev. Since we don&#8217;t allow template editing or embedded JS or [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve been following the <a href="http://blogs.washingtonpost.com/securityfix/2006/01/account_hijacki.html">Livejournal hack</a> closely because as someone who runs many services that allow user submitted content, any new developments in <a href="http://ha.ckers.org/xss.html">XSS</a> are <strong>very</strong> important to stay on top of. So far the only official technical explanation I&#8217;ve seen <a href="http://community.livejournal.com/lj_dev/705052.html">is here on lj_dev</a>. Since we don&#8217;t allow template editing or embedded JS or styles on WP.com I can&#8217;t think of any vectors for attack, but you never know with these things. More on <a href="http://developer.mozilla.org/en/docs/CSS:-moz-binding">moz-binding</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://ma.tt/2006/01/livejournal-hack/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Yahoo on WordPress</title>
		<link>http://ma.tt/2005/12/yahoo-on-wordpress/</link>
		<comments>http://ma.tt/2005/12/yahoo-on-wordpress/#comments</comments>
		<pubDate>Sat, 03 Dec 2005 14:55:53 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[Asides]]></category>
		<category><![CDATA[WordPress]]></category>
		<category><![CDATA[Yahoo]]></category>

		<guid isPermaLink="false">http://photomatt.net/2005/12/03/yahoo-on-wordpress/</guid>
		<description><![CDATA[Stephen Steele (is that a real name?) just wrote in that the new Yahoo Mail updates blog is on WordPress. As far as I know this is the first official Yahoo blog on WP I&#8217;ve seen. What makes it really interesting is it&#8217;s the first time I&#8217;ve seen third-party software (like WordPress) on the yahoo.com [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.shallwesingasongforyou.co.uk/">Stephen Steele</a> (is that a real name?) just wrote in that <a href="http://updates.mail.yahoo.com/blog/">the new Yahoo Mail updates blog is on WordPress</a>. As far as I know this is the first official Yahoo blog on WP I&#8217;ve seen. What makes it really interesting is it&#8217;s the first time I&#8217;ve seen third-party software (like WordPress) on the yahoo.com domain. You&#8217;ll notice every time they&#8217;ve done blogs before it&#8217;s been on a different domain like yahoo.net or ysearchblog.com, I imagine because of the incredibly strict security requirements anything with access to Yahoo.com cookies must meet. This is very exciting news. <img src='http://s.ma.tt/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://ma.tt/2005/12/yahoo-on-wordpress/feed/</wfw:commentRss>
		<slash:comments>29</slash:comments>
		</item>
		<item>
		<title>Red Herring Alert</title>
		<link>http://ma.tt/2005/05/red-herring-alert/</link>
		<comments>http://ma.tt/2005/05/red-herring-alert/#comments</comments>
		<pubDate>Wed, 18 May 2005 08:49:20 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[Asides]]></category>
		<category><![CDATA[Six Apart]]></category>

		<guid isPermaLink="false">http://photomatt.net/?p=2190</guid>
		<description><![CDATA[I just got a Google alert for a Red Herring article on Six Apart set to publish in a few days. They mention us here: &#8220;Critics of Six Apart say that WordPress, a blog publishing platform developed by a grassroots team, is more robust than Movable Type. WordPress is also open source and free. But [...]]]></description>
			<content:encoded><![CDATA[<p>I just got a <a href="http://www.google.com/alerts">Google alert</a> for a <a href="http://www.redherring.com/Article.aspx?a=12094&#038;hed=RH-100%3A+So+Much+to+Say&#038;sector=Profiles&#038;subsector=Companies">Red Herring article on Six Apart</a> set to publish in a few days. They mention us here: &#8220;Critics of Six Apart say that WordPress, a blog publishing platform developed by a grassroots team, is more robust than Movable Type. WordPress is also open source and free. But things are different in Six Apart&#8217;s cash-crop enterprise space, where support and security are at the top of the list. Half of Movable Type servers sit behind a firewall, says Mr. Berkowitz.&#8221;</p>
]]></content:encoded>
			<wfw:commentRss>http://ma.tt/2005/05/red-herring-alert/feed/</wfw:commentRss>
		<slash:comments>18</slash:comments>
		</item>
		<item>
		<title>Update Phishing</title>
		<link>http://ma.tt/2005/05/update-phishing/</link>
		<comments>http://ma.tt/2005/05/update-phishing/#comments</comments>
		<pubDate>Wed, 18 May 2005 00:49:05 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[Asides]]></category>

		<guid isPermaLink="false">http://photomatt.net/2005/05/17/update-phishing/</guid>
		<description><![CDATA[I just got a spam/phishing email that looks exactly like a Windows Update notification, and every link in the email is to a real Microsoft site, save one. The download link, which I must &#8220;Install now to maintain the security of your computer from these vulnerabilities, the most serious of which could allow an attacker [...]]]></description>
			<content:encoded><![CDATA[<p>I just got a spam/phishing email that looks exactly like a Windows Update notification, and every link in the email is to a real Microsoft site, <strong>save one</strong>. The download link, which I must &#8220;Install now to maintain the security of your computer from these vulnerabilities, the most serious of which could allow an attacker to run code on your computer,&#8221; goes to a file named <code>Windows-KB835935-SP2-ENU.exe</code> on the domain <code>windowsupdatenow.net</code>. I&#8217;m sure the exe will do awful things to whoever falls for this. I hope Microsoft/Scoble get their lawyers on whoever is behind this, I&#8217;ll admit until I noticed the download link domain the email seemed totally legit.</p>
]]></content:encoded>
			<wfw:commentRss>http://ma.tt/2005/05/update-phishing/feed/</wfw:commentRss>
		<slash:comments>21</slash:comments>
		</item>
		<item>
		<title>Double Standards</title>
		<link>http://ma.tt/2005/05/double-standards/</link>
		<comments>http://ma.tt/2005/05/double-standards/#comments</comments>
		<pubDate>Tue, 10 May 2005 14:50:48 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[Asides]]></category>

		<guid isPermaLink="false">http://photomatt.net/2005/05/10/double-standards/</guid>
		<description><![CDATA[A lot of the same people who rant and rave every time Internet Explorer has another security snafu are being strangely silent about Firefox&#8217;s recent flaws. I wonder how many of the web technorati are willing to give Firefox a pass every now and then because of its superior standards support? The Firefox team is [...]]]></description>
			<content:encoded><![CDATA[<p>A lot of the same people who rant and rave every time Internet Explorer has another security snafu are being strangely silent about <a href="http://news.com.com/2100-1002_3-5700204.html">Firefox&#8217;s recent flaws</a>. I wonder how many of the web technorati are willing to give Firefox a pass every now and then because of its superior standards support? The Firefox team is also to be commended for their rapid response to the issue on the only site that&#8217;s vulnerable by default.</p>
]]></content:encoded>
			<wfw:commentRss>http://ma.tt/2005/05/double-standards/feed/</wfw:commentRss>
		<slash:comments>20</slash:comments>
		</item>
		<item>
		<title>MT 3.16</title>
		<link>http://ma.tt/2005/04/mt-316/</link>
		<comments>http://ma.tt/2005/04/mt-316/#comments</comments>
		<pubDate>Mon, 18 Apr 2005 22:01:20 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[Asides]]></category>
		<category><![CDATA[Six Apart]]></category>

		<guid isPermaLink="false">http://photomatt.net/2005/04/18/mt-316/</guid>
		<description><![CDATA[Congrats to Jay and his team on Movable Type 3.16. There are some &#8220;orange level&#8221; security problems fixed, so be sure to upgrade! It&#8217;s a day for releases.]]></description>
			<content:encoded><![CDATA[<p>Congrats to <a href="http://www.jayallen.org/">Jay</a> and his team on <a href="http://www.sixapart.com/about/news/2005/04/movable_type_31_3.html">Movable Type 3.16</a>. There are some &#8220;orange level&#8221; security problems fixed, so be sure to upgrade! It&#8217;s a day for releases.</p>
]]></content:encoded>
			<wfw:commentRss>http://ma.tt/2005/04/mt-316/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

