#known 2015-09-18

2015-09-18 UTC
tantek, endi and travis-ci joined the channel
#
travis-ci
idno/Known#2464 (master - 3d209b3 : Ben Werdmuller): The build passed.
travis-ci joined the channel
#
travis-ci
idno/Known#2465 (master - cef3c40 : Ben Werdmuller): The build passed.
travis-ci joined the channel
#
travis-ci
idno/Known#2466 (master - f0c78d7 : Ben Werdmuller): The build passed.
tantek, loic_m, norguir1 and travis-ci joined the channel
#
travis-ci
idno/Known#2467 (master - 7898785 : Ben Werdmuller): The build passed.
loic_m, mapkyca and norguir joined the channel
loic_m, endi and endi_ joined the channel
#
dosch
any change known will support updates from the site configuration page?
#
dosch
as opposed to having to use ftp
#
mapkyca
the main problem with that is that the web server typically only has read access to your web directory, so to update code from within a PHP script is deceptively complex.
#
mapkyca
(there's also security issues to consider)
#
mapkyca
I don't think that's a "no" (and I can't speak for the project team), but I'd suggest filing it as a feature request :)
#
dosch
yeah, I might do that. I like how WP handles this and it allows me to easily update many sites I manage.
#
dosch
and being able to update fast to the latest version is also good for security, in general :)
#
mapkyca
I typically manage the latter by using a git checkout as my install, but that's not an option for some folk...
travis-ci joined the channel
#
travis-ci
mapkyca/idno#61 (master - 409ba87 : Ben Werdmuller): The build passed.
#
mapkyca
wp manages updates nicely, although any mechanism that lets you upload live php to a web visible folder sets my nerves on edge!
#
mapkyca
would need to be managed very carefully
norguir joined the channel
cleverdevil joined the channel
#
aaronpk
the fact that wordpress can update its own code is the same reason why it's so often hacked
#
mapkyca
indeed... it opens up a whole can of worms. Code signing might help, but I'd rather avoid the complexity....
#
aaronpk
to be fair, it's almost always a rogue plugin that enables an attacker to write arbitrary files
#
mapkyca
aye...
#
mapkyca
it's a whole can of worms
#
mapkyca
modsecurity helps, plus disabling things like access to .php in wp-content/**
#
mapkyca
wordpress has a very large attack surface compared to Known of course
tantek and j12t joined the channel
#
cleverdevil
the amount of effort we put into WP security is enormous... but, it is likely related to the fact that we've got *so* many installed instances of WordPress.
#
Loqi
cleverdevil: mapkyca left you a message on 9/3 at 4:18pm: Which one? There are two - the known team one and the one I wrote before them (i think Ben wasn't watching my feed ;) )... moot point I guess, neither are bundled. Mine is at https://github.com/mapkyca/IdnoMarkdown
#
cleverdevil
at last count, it was approaching a million!
#
cleverdevil
we do our own automated upgrades for major releases of WordPress.
#
cleverdevil
but, WP does have its own self-updating mechanism...
#
@voxpelli
@mymlan @emanuelkarlsten @kwasbeb MÃ¥nga verktyg/tjänster byggs nu för att överbrygga gapet mellan blogg och sociala medier – tex. @withknown
(twitter.com/_/status/644919867552960512)
#
@mymlan
@voxpelli men hur bra tjänster som än byggs har de ju NOLL betydelse om ingen använder dem. Som Jaiku. @emanuelkarlsten @kwasbeb @withknown
(twitter.com/_/status/644920188329140224)
cleverdevil and j12t joined the channel
#
@codebear
@_crossdiver the biggest mover right now is the WithKnown folks
(twitter.com/_/status/644929245450534912)
j12t, endi, tantek and endi_ joined the channel
cleverdevil, norguir, tantek, rhiaro_ and endi joined the channel
j12t and cleverdevil joined the channel