Re: Suggestion: security fix area

Dylan Jay <djay-n0pU0XVUApFWk0Htik3J/[email protected]> Wed, 29 Jun 2011 13:09:25 +1000
Newsgroups gmane.comp.web.zope.plone.website
Message-ID <[email protected]>
If anything I think it's possible to make a positive press release  
around this issue. Both cia and fbi sites have been targeted by some  
very talented hackers. Presumably if they could have been hacked they  
would have been. Instead lolsec choose to instead hack a FBI affiliate  
site and do DDOS attacks on cia to achieve their aim when hacking them  
directly (in all likelihood) was tried and failed.

but I'm no expert on PR :)

---
Dylan Jay
Technical Solutions Manager
PretaWeb: reducing duplication in the government web.
P: +612 80819071 | M: +61421477460 | twitter.com/djay75 | linkedin.com/ 
in/djay75

On 29/06/2011, at 12:57 PM, Alberto Lopes wrote:

> Even so, I suggest a statement from the community on Plone.org.
>
> You see, if someone who is considering using Plone gets the piece of  
> news that several Plone sites were attacked by hackers recently  
> (several government sites in Brazil which were Plone powered were  
> attacked last week), and that we had two or three security hotfixes  
> released this year, they might get to the wrong conclusion that the  
> two facts are related.
>
> My suggestion is for the sake of marketing, just that.
>
> On Tue, Jun 28, 2011 at 7:48 PM, Laurence Rowe <[email protected]> wrote:
>
> Alberto Lopes wrote:
> >
> > 3 - I dunno if this list is the best one to talk about that, but  
> some of
> > the
> > sites attacked the last few weeks are powered by Plone. There  
> should be an
> > "official" statement about whether the attacks have something to  
> do with
> > Plone or not.
> >
>
> Todays security hotfix was not prompted by any of the recent  
> attacks. The
> vulnerability was discovered, investigated and fixed by the Plone  
> Security
> Team.
>
> Laurence
>
> --
> View this message in context: http://plone.293351.n2.nabble.com/Suggestion-security-fix-area-tp6512214p6526969.html
> Sent from the plone.org Web Site mailing list archive at Nabble.com.
>
> ------------------------------------------------------------------------------
> All of the data generated in your IT infrastructure is seriously  
> valuable.
> Why? It contains a definitive record of application performance,  
> security
> threats, fraudulent activity, and more. Splunk takes this data and  
> makes
> sense of it. IT sense. And common sense.
> http://p.sf.net/sfu/splunk-d2d-c2
> _______________________________________________
> Plone-website mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/plone-website
> The Wiki: http://plone.org/development/current/projects/WebsiteTeam
>
> ------------------------------------------------------------------------------
> All of the data generated in your IT infrastructure is seriously  
> valuable.
> Why? It contains a definitive record of application performance,  
> security
> threats, fraudulent activity, and more. Splunk takes this data and  
> makes
> sense of it. IT sense. And common sense.
> http://p.sf.net/sfu/splunk-d2d-c2_______________________________________________
> Plone-website mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/plone-website
> The Wiki: http://plone.org/development/current/projects/WebsiteTeam


------------------------------------------------------------------------------
All of the data generated in your IT infrastructure is seriously valuable.
Why? It contains a definitive record of application performance, security 
threats, fraudulent activity, and more. Splunk takes this data and makes 
sense of it. IT sense. And common sense.
http://p.sf.net/sfu/splunk-d2d-c2
_______________________________________________
Plone-website mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/plone-website
The Wiki: http://plone.org/development/current/projects/WebsiteTeam