Preventing Attacks
WordPress Has Thousands of Maintainers. Does Your Replacement?
Last month, a critical WordPress vulnerability triggered emergency patching across the web — and reignited a familiar argument: if WordPress keeps having security problems, why not let AI build something new instead?
It’s a reasonable question.
AI has made software dramatically cheaper and faster to create. But somebody still has to understand it, patch it, test it, and keep it running eighteen months from now.
That’s the part of the “AI instead of WordPress” pitch we think is getting overlooked.
Every Night, Argo Watches
While your site is running, things change. A content editor tweaks a configuration setting. A security vulnerability surfaces in a dependency. A production fix gets applied directly instead of going through the normal release process.
The Night the Internet Tried to Kill Your Website
The Rules Have Changed: Security in the Age of AI-Assisted Attacks
Error Prevention
Imagine clicking "Submit" on a legal contract, only to realize you meant to click "Save Draft." Or transferring $1,000 to the wrong account with no confirmation step. Or deleting your entire photo library with a single misclick. These aren't hypothetical scenarios - they happen every day when websites don't implement proper error prevention.
Is your host a single point of failure?
Just ran across a sad story where Digital Ocean is accused of killing a startup:
Assessment of May 8 Drupal Security update SA-CORE-2019-007
New versions of Drupal core dropped today, to fix a file handling issue.
After assessing the patches, statements, and risks associated with this update, we have decided this is an important update to apply, but not urgent for most of the sites we manage.
Drupalgeddon2: Should I worry about critical security updates?
No, you should not. You should let us worry about them, and go back to your business.
Seriously, we're getting questions from all kinds of people about whether this matters. I'm a bit surprised that there is any question about that. Would you be concerned if your top salesperson was selling for somebody else? If your cashiers were jotting down credit card numbers when they charged a card? If your office became a well-known spot for illicit drug or gun dealers? If your office had a bunch of scammers squatting and running a pyramid scheme? If your confidential client information could be revealed as easily as using a bic pen on an old Kryptonite lock?
We've seen some variation of every single one of those scenarios. And all of them are possible with a remote code execution flaw in a web application, like yesterday's Drupal security vulnerability.
And yet people still
Meltdown notes
The Meltdown vulnerability leaked out into public news a full week before patches were available for many distributions. When patches did become available, sometimes the patch caused further trouble.