Brad Williams: Lock it Up

3 responses on “Brad Williams: Lock it Up

  1. pcgs51

    At 7:50 (timestamp) in this video, we are instructed to create a new administrator ID, log out and log back in as the new administrator user, remove the original ‘admin” ID, and set the new user ID to display a friendly name (firstname lastname).

    I did that and noticed that even when logged out and viewing pages as any visitor would, that if I click on the friendly name displayed, I see

    Author Archive for:
    ‘mynewusername’

    If the new user name can still be viewed on my site by any visitor doesn’t that defeat the whole exercise of removing the ‘admin’ ID in the first place?

    I’m new to all this and just wondering. Thanks.

    Like

  2. Travis Phillips

    I realize that this article is now over 5 years old. With WordPress 4.x, it may not even be as relevant today as it was then. But I do think it is still somewhat relevant at the least and I’ve got a nagging question that I’ve been wrestling with for a long time. I hope you don’t mind me asking it now – despite it being 5 years later.

    I’ve heard it said many times by many people that you should delete the default admin account with the username “admin”. But what about leaving the “admin” username there, changing it to a random password, and finally changing the user role to subscriber? That way a hacker can waste time and resources trying to login to the admin account and then ultimately get nothing.

    My only concern with this logic is this, if a hacker does get access to a subscriber level account, is there anything he (or she) can do with that? Is there any other reason that the account should just be deleted verses changing the role to subscriber?

    Like

Continue the discussion

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s

Published

January 23, 2010

Learn how to keep your WordPress-powered website secure from hackers and exploits. Brad Williams from WebDevStudios.com shows examples of hacked sites, shares tips and plugins for keeping WordPress secure, and talks about his experiences with WordPress and security.

Special thanks to the Microsoft NERD Center for hosting WordCamp Boston.

Rate this:

Event

WordCamp Boston 2010 15

Speakers

Brad Williams 13

Tags

development 204
Plugins 134
security 75

Language

English 2451

Download
MP4: Low, Med, High
OGG: Low
Subtitles
Subtitle this video →
Follow

Get every new post delivered to your Inbox.

Join 12,877 other followers

%d bloggers like this: