[wp-trac] [WordPress Trac] #16778: wordpress is leaking user/blog information during wp_version_check()

WordPress Trac noreply at wordpress.org
Wed Dec 7 10:45:55 UTC 2016


#16778: wordpress is leaking user/blog information during wp_version_check()
----------------------------+-----------------------
 Reporter:  investici       |       Owner:
     Type:  enhancement     |      Status:  reopened
 Priority:  normal          |   Milestone:
Component:  Administration  |     Version:
 Severity:  minor           |  Resolution:
 Keywords:  has-patch       |     Focuses:
----------------------------+-----------------------

Comment (by MattyRob):

 Replying to [comment:55 TJNowell]:
 > I would note that this information is being sent to WordPress.org, not
 Automattic. WP is an open-source community project, not an Automattic
 product
 >
 > I'd also note that an opt in is going to be much more complicated to
 implement as the immediate result is no stats or a prompt on update, both
 of which are bad. '''WP just needs to state what it sends and where''',
 and we should be doing this anyway if only for documentation purposes


 Your bold text misses one valuable point - I agree that WordPress need to
 tell users what information is being sent and where to, but users also
 deserve to be told exactly '''why''', and for each individual piece of
 data collected.

--
Ticket URL: <https://core.trac.wordpress.org/ticket/16778#comment:56>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list