Re: Plone security
Dylan Jay <djay-n0pU0XVUApFWk0Htik3J/[email protected]> Fri, 3 Aug 2012 11:54:13 +1000
| Newsgroups | gmane.comp.web.zope.plone.website |
|---|---|
| Message-ID | <[email protected]> |
I'd also add that the current security page needs some more explanation.
Most people counter plones low vulnerability claim by saying "Plone
isn't as popular, so it's targeted less or hasn't had the same number
of eyes on the code".
This can be countered by looking at the market share graph on http://w3techs.com/technologies/details/cm-plone/all/all
This shows that indeed Plone is less popular overall but is infact
more popular in the top 10,000 websites than drupal, wp or joomla.
Being the frontend for both fbi.gov and cia.gov and neither being
hacked despite presumably many attempts is the best statement to
Plone's security and I think we could make a much bigger deal out of
this than we do.
---
Dylan Jay
Technical Solutions Manager
PretaWeb: Multisite Performance Support
P: +612 80819071 | M: +61421477460 | twitter.com/djay75 | linkedin.com/
in/djay75
On 02/08/2012, at 9:11 PM, Christian Ledermann wrote:
> Hello,
>
> One field where Plone (/zope/python) really excels in is security. I
> think this deserves
> a bit more of exposure on the plone.org website. (and i use plones
> security
> quite regularly in plone pitches, so this is a marketing issue too)
>
> there is https://plone.org/products/plone/security which is a bit
> hidden and though
> I knew that it was somewhere had to search for it.
>
> https://plone.org/products/plone/security/overview is probably what
> people
> unfamiliar with plone are looking for.
>
> Can we give this more exposure, maybe in the doormat?
>
> Another thing i like to see is a regular security comparison between
> plone
> and it's competitors like:
>
> http://plonemetrics.blogspot.com/2009/04/plone-security.html
>
> Once a year seems to me appropriate (maybe just before the ploneconf)
> The report should contain all vulnerabilities that plone had in the
> last year, how they were discovered and addressed, and if there were
> known incidences exploiting these vulnerabilities.
>
> Just a though, tell me what you think.
>
>
> --
> Best Regards,
>
> Christian Ledermann
>
> Nairobi - Kenya
> Mobile : +254 702978914
>
> <*)))>{
>
> If you save the living environment, the biodiversity that we have
> left,
> you will also automatically save the physical environment, too. But If
> you only save the physical environment, you will ultimately lose both.
>
> 1) Don’t drive species to extinction
>
> 2) Don’t destroy a habitat that species rely on.
>
> 3) Don’t change the climate in ways that will result in the above.
>
> }<(((*>
>
> ------------------------------------------------------------------------------
> Live Security Virtual Conference
> Exclusive live event will cover all the ways today's security and
> threat landscape has changed and how IT managers can respond.
> Discussions
> will include endpoint security, mobile security and the latest in
> malware
> threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
> _______________________________________________
> Plone-website mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/plone-website
> The Wiki: http://plone.org/development/current/projects/WebsiteTeam
------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and
threat landscape has changed and how IT managers can respond. Discussions
will include endpoint security, mobile security and the latest in malware
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
_______________________________________________
Plone-website mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/plone-website
The Wiki: http://plone.org/development/current/projects/WebsiteTeam