Aug
31
6

To the (literally) hundreds of you who wrote in about the broken photos the past few weeks, I’m happy to say that the photolog is back online. It broke because while 95% of Gallery works fine with register_globals off, apparently some bit of code somewhere doesn’t. If you haven’t been to the photolog in a while there are some fun pictures from Dallas, Seattle, and New York.

Aug
30
3

There is a new “Web 2.0 Show” (on podcast of course) that interviewed me as part of their innagural podcast. The Skype call quality was pretty bad, I must have been too close to the mic on my Powerbook or something. They said they’re fixing that for future shows.

Aug
28
29

AJAX and CSRF

Filed under: WordPress

When working on some new AJAX features for bbPress and WordPress we’ve noticed that AJAX requests don’t seem to send HTTP_REFERER values. We check referrers as one level of protection against cross-site-scripting, or XSS, so when they’re not set we aren’t able to use that value. How are most people using AJAX protecting against XSS? It seems the same things we’re doing to make things easily accesible in a dynamic fashion are also opening new vectors for attack.

Aug
18
11

Owen has a nice animated screenshot of the new WYSIWYG features in WordPress. By the way, I’ll be doing the first public demo of WP 1.6 and WordPress.com tomorrow morning at 8 AM at the Blog Business Summit.

Aug
17
21

The WordPress download counter is about to break half a million!

0

I’m blogging about the Blog Business Summit over on my WordPress.com blog. Here’s the feed.

9

At the Blog Business Summit the next few days we’ll have a graphic in the slideshow that they have on the screen during downtime. Check it out. It’s care of the extremely talented Khaled.

1

Blog Business Summit starts today, but what I’m really looking forward to is BAR Camp this weekend. I think this is the start of something very exciting.

1

Russ switched to WordPress and has written a little bit about it. His permalinks are still a little funky, but they match his old system and in terms of content the transition from his custom CMS seems to have been pretty seemless.