Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. This discussion atop Hackernews right now about how someone bought 30 WordPress plugins and planted a backdoor in all of them has me wondering, is there a plugin that blocks plugins from being automagically updated if the plugin's ownership changes?

This discussion atop Hackernews right now about how someone bought 30 WordPress plugins and planted a backdoor in all of them has me wondering, is there a plugin that blocks plugins from being automagically updated if the plugin's ownership changes?

Scheduled Pinned Locked Moved Uncategorized
11 Posts 10 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • briankrebs@infosec.exchangeB This user is from outside of this forum
    briankrebs@infosec.exchangeB This user is from outside of this forum
    briankrebs@infosec.exchange
    wrote last edited by
    #1

    This discussion atop Hackernews right now about how someone bought 30 WordPress plugins and planted a backdoor in all of them has me wondering, is there a plugin that blocks plugins from being automagically updated if the plugin's ownership changes?

    Link Preview Image
    Someone bought 30 WordPress plugins and planted a backdoor in all of them | Hacker News

    favicon

    (news.ycombinator.com)

    J R davep@infosec.exchangeD noplasticshower@infosec.exchangeN i@toot.pouyan.netI 8 Replies Last reply
    0
    • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

      This discussion atop Hackernews right now about how someone bought 30 WordPress plugins and planted a backdoor in all of them has me wondering, is there a plugin that blocks plugins from being automagically updated if the plugin's ownership changes?

      Link Preview Image
      Someone bought 30 WordPress plugins and planted a backdoor in all of them | Hacker News

      favicon

      (news.ycombinator.com)

      J This user is from outside of this forum
      J This user is from outside of this forum
      jackryder@infosec.exchange
      wrote last edited by
      #2

      @briankrebs There is a lot of conversation going on about this new issue.

      sempf@infosec.exchangeS 1 Reply Last reply
      0
      • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

        This discussion atop Hackernews right now about how someone bought 30 WordPress plugins and planted a backdoor in all of them has me wondering, is there a plugin that blocks plugins from being automagically updated if the plugin's ownership changes?

        Link Preview Image
        Someone bought 30 WordPress plugins and planted a backdoor in all of them | Hacker News

        favicon

        (news.ycombinator.com)

        R This user is from outside of this forum
        R This user is from outside of this forum
        roses4cardinals@hachyderm.io
        wrote last edited by
        #3

        @briankrebs How much to buy hypothetical plugin that blocks plugins from updating?

        briankrebs@infosec.exchangeB 1 Reply Last reply
        0
        • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

          This discussion atop Hackernews right now about how someone bought 30 WordPress plugins and planted a backdoor in all of them has me wondering, is there a plugin that blocks plugins from being automagically updated if the plugin's ownership changes?

          Link Preview Image
          Someone bought 30 WordPress plugins and planted a backdoor in all of them | Hacker News

          favicon

          (news.ycombinator.com)

          davep@infosec.exchangeD This user is from outside of this forum
          davep@infosec.exchangeD This user is from outside of this forum
          davep@infosec.exchange
          wrote last edited by
          #4

          @briankrebs But what if the plugin that blocks plugins from being automagically updated if the plugin's ownership changes' ownership changes?

          1 Reply Last reply
          0
          • R roses4cardinals@hachyderm.io

            @briankrebs How much to buy hypothetical plugin that blocks plugins from updating?

            briankrebs@infosec.exchangeB This user is from outside of this forum
            briankrebs@infosec.exchangeB This user is from outside of this forum
            briankrebs@infosec.exchange
            wrote last edited by
            #5

            @Roses4Cardinals I was being only partially facetious here. IMHO, this should be WordPress's job, whether or not you host a blog with them, seeing as they automatically update your plugins now whether you want them to or not.

            1 Reply Last reply
            0
            • J jackryder@infosec.exchange

              @briankrebs There is a lot of conversation going on about this new issue.

              sempf@infosec.exchangeS This user is from outside of this forum
              sempf@infosec.exchangeS This user is from outside of this forum
              sempf@infosec.exchange
              wrote last edited by
              #6

              @jackryder @briankrebs This is NOT a new issue, which is probably why there is conversation. People have a preset viewpoint.

              I don't know how they are gonna solve that problem, but with the constant political shakeups at Wordpress, woof. I'm just glad I got my last client off of WordPress.

              1 Reply Last reply
              0
              • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                This discussion atop Hackernews right now about how someone bought 30 WordPress plugins and planted a backdoor in all of them has me wondering, is there a plugin that blocks plugins from being automagically updated if the plugin's ownership changes?

                Link Preview Image
                Someone bought 30 WordPress plugins and planted a backdoor in all of them | Hacker News

                favicon

                (news.ycombinator.com)

                noplasticshower@infosec.exchangeN This user is from outside of this forum
                noplasticshower@infosec.exchangeN This user is from outside of this forum
                noplasticshower@infosec.exchange
                wrote last edited by
                #7

                @briankrebs and who updates that one?

                1 Reply Last reply
                0
                • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                  This discussion atop Hackernews right now about how someone bought 30 WordPress plugins and planted a backdoor in all of them has me wondering, is there a plugin that blocks plugins from being automagically updated if the plugin's ownership changes?

                  Link Preview Image
                  Someone bought 30 WordPress plugins and planted a backdoor in all of them | Hacker News

                  favicon

                  (news.ycombinator.com)

                  i@toot.pouyan.netI This user is from outside of this forum
                  i@toot.pouyan.netI This user is from outside of this forum
                  i@toot.pouyan.net
                  wrote last edited by
                  #8

                  @briankrebs@infosec.exchange @andrewnez@mastodon.social would definitely know. He's the supply chain expert.

                  1 Reply Last reply
                  0
                  • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                    This discussion atop Hackernews right now about how someone bought 30 WordPress plugins and planted a backdoor in all of them has me wondering, is there a plugin that blocks plugins from being automagically updated if the plugin's ownership changes?

                    Link Preview Image
                    Someone bought 30 WordPress plugins and planted a backdoor in all of them | Hacker News

                    favicon

                    (news.ycombinator.com)

                    mbpaz@mas.toM This user is from outside of this forum
                    mbpaz@mas.toM This user is from outside of this forum
                    mbpaz@mas.to
                    wrote last edited by
                    #9

                    @briankrebs Plugin ownership is a slippery concept.
                    Many wordpress plugins are published by small companies that can be bought outright.

                    1 Reply Last reply
                    0
                    • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                      This discussion atop Hackernews right now about how someone bought 30 WordPress plugins and planted a backdoor in all of them has me wondering, is there a plugin that blocks plugins from being automagically updated if the plugin's ownership changes?

                      Link Preview Image
                      Someone bought 30 WordPress plugins and planted a backdoor in all of them | Hacker News

                      favicon

                      (news.ycombinator.com)

                      neilshadrach@fosstodon.orgN This user is from outside of this forum
                      neilshadrach@fosstodon.orgN This user is from outside of this forum
                      neilshadrach@fosstodon.org
                      wrote last edited by
                      #10

                      @briankrebs And is it for sale?

                      1 Reply Last reply
                      0
                      • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                        This discussion atop Hackernews right now about how someone bought 30 WordPress plugins and planted a backdoor in all of them has me wondering, is there a plugin that blocks plugins from being automagically updated if the plugin's ownership changes?

                        Link Preview Image
                        Someone bought 30 WordPress plugins and planted a backdoor in all of them | Hacker News

                        favicon

                        (news.ycombinator.com)

                        kidko92@mastodon.socialK This user is from outside of this forum
                        kidko92@mastodon.socialK This user is from outside of this forum
                        kidko92@mastodon.social
                        wrote last edited by
                        #11

                        @briankrebs So How many plugins could a hacker backdoor, if a plugin could block backdoored plugins?

                        1 Reply Last reply
                        0
                        Reply
                        • Reply as topic
                        Log in to reply
                        • Oldest to Newest
                        • Newest to Oldest
                        • Most Votes


                        • Login

                        • Login or register to search.
                        • First post
                          Last post
                        0
                        • Categories
                        • Recent
                        • Tags
                        • Popular
                        • World
                        • Users
                        • Groups