-
,
- You can do this in wp-config.php, you generate secret keys from there; reach out to Dre or Brad for details
-
,
- You can add ssl in your wp-config.php using something like this: define('force_ssl_login', true); I might have got that wrong, so once again, reach out to Brad and / or Dre ,
- Use .htaccess in your wp-admin directory
-
,
- Didn't know this myself, cool
-
,
- In case you're wondering about this, this is where it tells folks what version of a software you're using. Someone can run a query that says "Show Users that use WP 2.6". Now they can attack you with known vulnerabilities with that version. Disable it folks.
-
,
- wpmu.org had a great article on this, I'll have to look it back up and post it here as part of this. In short, just because you go to Google and search 'Free Themes' it doesn't mean they are trusted sources - Do you really want to sell Viagra on your site?
-
,
- In 3.0 you can now change this on install, if you don't, change it at some point. People look for folks with user name admin.
-
,
- Set File to 644 an Folder to 775, if your host requires something else, find a new host
-
,
- Can't stress enough
WordPress End-User Security
Alright folks, this is all I got. Hope it helps. Once again, thanks to the WP app for the iPad for making this post possible.,
View more presentations from Dre Armeda.
