Your Theme, Plugin, Site Has a

Security Vulnerability
Now What?

WordCamp Toronto 2015

WordCamp Toronto, 2015
Slides: https://adcwp.me/wcto2015

Aaron D. Campbell

Aaron D. Campbell – https://aarondcampbell.com/
aaron@ithemes.com – @AaronCampbell
http://profiles.wordpress.org/aaroncampbell/

You’re
Vulnerable

What Now?

Don't Panic

Your Users Are Your Priority

Security
Researchers

What you need from a reporter

  • Steps to repeat
  • Understanding on disclosure

Things a reporter might do

  • Help fix the issue
  • Test patches

What a reporter should NOT do

  • Ask for money to give steps to repeat
  • Ask for money to delay disclosure

What you need to do for a reporter

  • Communicate
  • Thank them:
    • Props / Link to them
    • Swag if you have it
    • Payment if it makes sense

Time to Disclose Publicly?

No

plugins@wordpress.org

Fix It

Time to Disclose Publicly?

No

Get Trusted Users to Test

Prepare Release

Commit and update messages should mention that this is a security fix but not give details

Release Fix

Need a forced update?
security@wordpress.org

Time to Disclose Publicly?

No

A post about the new release and how important it is to upgrade could be helpful

How long do you wait?

My Rule of thumb: At least a day

Now you disclose publicly

What goes in a public disclosure?

  • What could have happened
  • What a user can look for to tell if they’ve been compromised
  • Steps that can be taken clean things up
  • No sugar coating
  • No working examples

Remember

It doesn’t have to be scary

Your users are your priority

Q & A

Aaron D. Campbell – https://aarondcampbell.com/
aaron@ithemes.com – @AaronCampbell
http://profiles.wordpress.org/aaroncampbell/

Slides: https://adcwp.me/wcto2015

This presentation is running on WordPress using the Presenter plugin