WordPress

Code monster

Drupalgeddon2: Should I worry about critical security updates?


No, you should not. You should let us worry about them, and go back to your business.

Seriously, we're getting questions from all kinds of people about whether this matters. I'm a bit surprised that there is any question about that. Would you be concerned if your top salesperson was selling for somebody else? If your cashiers were jotting down credit card numbers when they charged a card? If your office became a well-known spot for illicit drug or gun dealers? If your office had a bunch of scammers squatting and running a pyramid scheme? If your confidential client information could be revealed as easily as using a bic pen on an old Kryptonite lock?

Bic Pen vs Kryptonite Lock

We've seen some variation of every single one of those scenarios. And all of them are possible with a remote code execution flaw in a web application, like yesterday's Drupal security vulnerability.

And yet people still

Read More

Why auto updates are a very bad idea


A question came across the Drupal Developer's list today asking whether Drupal could auto-update itself, like WordPress. As someone who thinks about security a lot, the very thought of this horrifies me.

It's a bad idea for several reasons, but the biggest reason:

Read More

Open Source Consulting

Develop an Open Source IT Strategy

Businesses are increasingly interested in investigating and implementing Open Source technologies to help cut licensing costs, increase security, and stay ahead of their competition. Whether your organization is looking for web development using an Open Source platform, maintaining a Linux server, or simply exploring a shift towards the Open Source world, Freelock can help you navigate through the hundreds of options to ensure your systems are working for you.