Back in December, as part of our ongoing efforts to improve Drupal.org, we kicked off a content strategy project with Forum One. Drupal Association engineering and marketing/communication staff partnered with the Drupal.org Content Working Group and met for a two-day workshop to help get the project team from Forum One (content strategists and user experience designers) up to speed on Drupal.org and the ecosystem of sites and services that our community uses to build and use Drupal.
Over the past month, we have pulled together many detailed documents to help guide our work. While we are only about halfway through this project, we wanted to share a bit of the work-in-progress that will influence Drupal.org’s content strategy in the coming months.
What is Content Strategy
Content strategy is the practice and process of planning content creation, delivery, and governance. Its purpose is to create a repeatable system that defines the entire editorial content development process for a website.
Drupal.org is a very unique website. It serves many purposes:
With so many purposes and competing objectives, a cohesive content strategy that takes in input from many contributors and users of Drupal.org is critcal.
Setting a Content Strategy Vision
To keep us aligned, we outlined three major areas to keep measuring our work against: the big ideas, key messages, and our objectives for content on the site.
Content Strategy Objectives
Identifying Content Types and Gaps in our Content
We have 17 active content types and over 1.2 million pieces of content on Drupal.org. (Really, this is just nodes, we have even more taxonomy terms and views that also represent displays of data.) That’s a lot of content. It’s more than 29,000 projects (modules, themes, distributions, etc.) and over 789,000 issues posted to those projects. We also have over 330,000 forum topics being discussed.
The Curious Case of the Book
With all of that content, 17 types does not quite give us the flexibility or degree of classification that we need to provide truly structured content. We have some content types that are used for so many different kinds of content that they’re virtually meaningless. We have over 12,000 nodes in our “book page” content type. Our book pages can be anything from documentation to landing pages to resource guides to topical pages to module comparisons… really we use them for just about everything.
During the content strategy project, we will explore ways to break our book pages into more meaningful content types that help new users find what they need.
What’s in a Forum
Another content type that gets used for more than it should is the forum topic. We use forums to post news, security announcements, discussions and even support requests. Yet at the same time, it is clear that forums are used far less now than several years ago. We had over 50,000 forum posts in 2008. We had only 11,000 in 2014.
For support and questions, our forums do not have comparable functionality to systems like Drupal Answers—powered by Stack Exchange. Many community members that provide support have already moved to that site to answer questions. Drupal.org is still a starting point for many newcomers to Drupal. One goal of the content strategy project is to make some decisions about where we can best direct newcomers for support.
Where are the Marketing Materials to Help People Choose Drupal?
A key classification of content that we are missing in our information architecture on Drupal.org is marketing materials. We create tons of documentation and handbooks, but we do not have a ton of great materials that tell business evaluators (CIOs, CTOs, managers, and decision makers) why they should choose Drupal. We have a good start with content created to promote Drupal 8, but there is a lot more we can do to help sell the qualities of Drupal.
Auditing What We Have and Mapping What We Want
We took the time to map our community’s content production over time and the totals were amazing.
The height of our community’s content creation was in 2012, when we created more than 195,000 nodes on Drupal.org and Drupal Groups. As Drupal 7 has matured, we have slowed down a bit. In 2014, we created 116,514 nodes on those two sites. That is still a huge amount of content.
Nearly 39% of all of the content on Drupal.org and Drupal Groups was created before 2010. More specifically, 55% of all book pages were created prior to the launch of Drupal 7 in 2011—that’s 5,665 book pages. Only 32% of those book pages have been updated since. That gap of 23% of all book content is a good place to begin an audit.
We are working now to finalize a process for identifying what content could be archived or removed and what content needs to be updated. The community has done admirable job of classifying our documentation by page status, but there is more work to be done. We need an automated process for regularly auditing our content.
We need a better map of related content—content we have and content we need—that can be used to build a better information architecture for new users.
One of the key deliverables for our content strategy project is a site map of what we want the site to look like in 3 months, 6 months and 1 year.
Creating a Governance Plan to Better Support our Community of Creators
We are hard at work reviewing and documenting community processes for maintaining content on Drupal.org. If users have been around for a while, they might have found their way into the content issue queue and wondered at the process and how to start helping. They may also have jumped in and helped edit a documentation page in one of our numerous books. (6,452 of community members have edited 12,326 book pages over 92,000 times.)
The problem is that these processes are not well known and not built into our tools at a level that helps users know what they should and should not do in the system. Learning the “right way” to contribute requires finding policy documentation that is often difficult to get to, and sometimes out of date. Therefore, along with our new content types, we are assessing and testing the user experience for creating, curating and maintaining all of the content on Drupal.org.
As we document the existing rules that govern how contributions are made, it’s become clear that one of the greatest barriers to contribution, especially for new users, is the sheer difficulty of learning the “right way” to make a contribution. We want to change the way these users interact with the site, so that the correct process and procedure for each type of contribution is baked right into the workflow.
Making our Communications Count
The last key deliverable that is being finalized as part of our content strategy is our communications plan. We have 50+ channels that are used by Drupal Association, working groups, social media volunteers, and maintainers to communicate with the community—everything from Twitter to newsletters to the Drupal.org homepage. We do not want to flood you with too much information, but we would like to be able to give you the information you want to see when you want to see it.
Right now, Drupal Association staff and the Drupal.org Content Working Group are mapping our messages to our audiences, our message to our channels and our channels to our audiences. It will be easier than ever to subscribe to the information you want—both email and on the site itself—in the coming year.
We will be wrapping up our content strategy work as March comes to a close.
We will publish more findings along the way. Stay tuned for new content types on Drupal.org—including news, posts, topic-based taxonomy term pages, and better ways to access and help write documentation.
It’s time for another community spotlight, and this month, we’re highlighting a community member who has made huge contributions to the success of the Drupal project and of DrupalCon — and not only through code.
Paul Johnson (pdjohnson) of Manchester is currently the Drupal Director of CTI Digital, and is the social media lead for most DrupalCons. He also maintains the @Drupal Twitter account. Paul has grown the DrupalCon social media program from a small following on twitter to a set of huge, engaged channels. (Image credit to Frank Crijns on Flickr. Thanks, Frank!)
The Drupal Association sat down with Paul in late January to talk about some of his accomplishments and passions.
DA: How did you get involved with Drupal and volunteering with DrupalCon?
Paul: I got involved in 2005 or 2006 by accident when I found it on Google, though I don’t really remember the exact moment. The company I worked for at the time wanted to move from their own homegrown CMS to something else, so I was looking for other solutions. While doing research I came across Drupal, and before I knew it I’d gone to DrupalCon Barcelona [in 2007].
Not long after that, I got really in to twitter. I was going to DrupalCon London in 2011 and I was fiercely excited about going, and I was expressing it on Twitter. Out of the blue, Isabel Schulz — a nice woman who worked for the Drupal Association at the time — reached out to me. She said, “it sounds like you want to get more involved.” It was like lighting a touch paper. Before I knew it they’d given me the username and password to the DrupalCon account and said “right, get on with it.”
DA: That’s a big responsibility!
Paul: At that time social media wasn’t so prevalent, and I don’t think anyone in the Drupal community realised how it could make a big contribution to the success of the conference— how it could reach a wider audience and get help in executing the conference.
I had no rules, and I made mistakes… I was really quite daunted by the prospect. Looking back, I might have destroyed my reputation with Drupal but thankfully I didn’t! I grew and learned, and then in Portland the social media aspect started to grow more quickly. I began writing formal processes to help myself, but it became apparent that as DrupalCon was growing, the success of the social media was perhaps leading towards other people getting involved.
I suppose I’m an unusual person — I find it difficult to find my place in the Drupal community. There are a lot of people out there who are better developers than I am, and I have this thing in my head that held me back from getting involved. I suppose it was quite a long time before I realised I had something valuable to contribute to the community. There has been this idea that contributing modules or contributing to core is cool, but there are lots of us who fall outside that immediate group of people, and who have– until recently– felt orphaned from contribution.
I’ve always thought about when the Association reached out to me. It was a small bit of recognition, but it felt very empowering. It had a big influence on me, and because of it, I’ve always tried to shout for these people who have enthusiasm, and try to ignite it.
DA: Do you have any good examples of that?
Paul: Sure. DrupalCon Portland took place at the same time as that awful Oklahoma tornado. Before it happened, I had always wanted to use social media to watch out for these kinds of things, because… with a very large audience, we can do things and help people very quickly by using the broadcast mechanism.
When the tornado hit, I saw guys in our coder lounge hacking together a solution to help people on the ground, and I used social media to draw attention to it. It snowballed, and before we knew it, FEMA was involved, and that sends shivers down my spine. I love it when social media translates from something that’s just a conversation on the internet to something with a positive, real-world impact.
DA: Switching tracks a little bit, can you tell us about some of the challenges you’ve faced when working on the DrupalCon social media?
Paul: I’ve grown up with the Drupal Association and the project, but in many respects, the biggest attraction is also one of the biggest challenges. The diversity of the Drupal community is… well, in being responsible for representing the Drupal Association and the project and the community, you have to be quite careful. You’re an ambassador, and you have to have to have the highest level of conduct. You can’t always speak your mind.
Sometimes I’ve gotten upset. It’s a big part of my life, Drupal, and people will say things to the official accounts that are upsetting, and you have to rise above that. And sometimes, people will say things from within or without the community that can be quite cutting, and I suppose that’s one of the hardest things. But, ultimately you can draw many positives from that because it becomes a question of, how do you work towards enhancing the minds of people who think like that.
Another challenge was that, in the early days, nobody knew it was me behind the accounts. It does take a reasonable amount of my time — a half an hour or more a day every day, oftentimes more. I didn’t mind [not being known] necessarily, but it’s really nice to get recognition — and, if anyone writes anything valuable I try to give them credit on social media, to encourage and celebrate people who make the effort, and put them on a pedestal so that it spurs others to do the same.
Along those lines, I so often hear, “I don’t go to local meet-ups,” or “I’m not good enough,” or “people will think I’m not clever enough or that my contribution isn’t sufficient.” I think it’s really important that people appreciate that, no matter where you are in your Drupal journey, you know more than the person who just started. You don’t have to be chx or morten or webchick– they all started at nothing, too, but they started a long time ago.
DA: What’s your favorite thing about the Drupal community?
Paul: When our community gets behind an idea, stuff really happens, and it happens really fast. Whether that’s code, or whether it would be to crowd source some funding for a blind man who lives in Italy and wants to go to DrupalCon Portland, it is just magnificent how fast things can happen if the will of the community is drawn.
And, you know, the Drupal community gives me the opportunity to meet or converse with people I would never imagine having the chance to do so with otherwise. It makes my life so much richer. It’s not about the code, Drupal is providing me with the most unimaginable opportunities. It has allowed me — in my career and my personal life — to take on challenges that would never have been available to me before.
Drupal has allowed me to be brave and to take a few risks, like interviewing Dries at the end of his keynote. I like to hide behind social media.. but then I’m projecting it onto a stage. And another thing about the community is, rarely do you meet someone who’s not nice.
DA: What’s your favorite thing about volunteering?
Paul: The thing that I enjoy the very most of volunteering is making a difference. There have been a few things where, I don’t know, I’ve seen a small smoldering fire and I’ve been able to ignite it into a bigger thing.
I was given the keys to DrupalCon, and then in the last few years I’ve taken ownership of the Drupal twitter account. Previously, it had become an abandoned channel, but under my stewardship it has gone from 30k followers to over 55k. And, you know, there are lots of people in media who are watching Drupal and who might be loosely interested. The Drupal twitter has so much opportunity to reach a wider audience with big achievements. So I love to use social media to show that Drupal is more than just America, more than just Europe — there’s a lot going on in India and in Africa and elsewhere.
I welcome anyone to approach me with news of things that they are doing in their local community that we can celebrate on official channels. I love to help grow something that’s a great idea into something that’s really big, because I think we’ve succeeded in growing the community in the USA and Australia and Europe. For me, the next big thing is to support the community in those regions that are about to flourish. How can we help them to make things happen more quickly?
DA: Who are you when you aren’t online?
Paul: I do seek solitude, and I really have a strong appreciation of wilderness. I’m a dad, and I love kids, and I suppose most of my time is spent cycling with my family. We go to The Lake District quite often in the UK, which is a beautiful and mountainous area.
I am passionately into road cycling on my bike, and mountaineering too. I like challenging myself — in everything I do, I always like to push myself. I’m always trying to climb higher or go faster. I’m no happier than when I’m in a mountaintop in the snow, even — especially — if it’s in a blizzard. I love being in a hostile environment where perhaps other people wouldn’t be able to cope. I love to explore places and trek the untrodden path. So even if I go back to the same place, I’ll take a different road.
DA: Do you have any final thoughts to share with us today?
Paul: With Drupal 8 on the way, I started a twitter account called @drupal8iscoming. It’s starting to grow and grow and grow now: it celebrates all things Drupal 8 on the internet — you know, articles, tutorials, events, and also how to help to get the word out to organisations about Drupal. Please check it out!
It’s a great time to be part of the Drupal Association. We’ve done some amazing work in the last few years, and we’re in a great position to work with the community to continue to improve and grow fully into our mission. As a Drupal Association At-Large Director, you’d be in the center of the action. The At-large Director position is specifically designed to ensure community representation on the Drupal Association board and we strongly encourage anyone with an interest to nominate themselves today.
The Board of Directors of the Drupal Association are responsible for financial oversight and setting the strategic direction of the Drupal Association. New board members will contribute to the strategic direction of the Drupal Association. Board members are advised of, but not responsible for matters related to the day to day operations of the Drupal Association, including program execution, staffing, etc. You can learn more about what’s expected of a board member in this post and presentation.
Directors are expected to contribute around five hours per month and attend three in-person meetings per year (financial assistance is available if required). All board members agree to meet the minimum requirements documented in the board member agreement.
Today we are opening the self-nomination form that allows you to throw your hat in the ring. We’re looking to elect one candidate this year to serve a two-year term.
Log in first and…
To nominate yourself, you should be prepared to answer a few questions:
We will also need to know that you are available for the next step in the process, meet the candidate sessions. We are hosting 2 sessions:
The nomination form will be open February 1, 2015 through February 20, 2015 at midnight UTC. For a thorough review of the process, please see our announcement blog post.
If you have any questions, please contact Holly Ross, Drupal Association Executive Director.
Flickr photo: Kodak Views
Front page news:
I was hired by the Drupal Association in October 2014 to develop a new revenue stream from advertising on Drupal.org. For some time we’ve been trying to diversify revenue streams away from DrupalCon, both to make the Association more sustainable and to ensure that DrupalCons can serve community needs, not just our funding needs. We’ve introduced the Drupal Jobs program already and now, after conversations with the community, we want to put more work into Drupal.org advertising initiatives.
This new revenue stream will help fund various Drupal.org initiatives and improvements including better account creation and login, organization and user profile improvements, a responsive redesign of Drupal.org, issue workflow and Git improvements, making Drupal.org search usable, improving tools to find and select projects, and the Groups migration to Drupal 7.
We spent time interviewing members of the Drupal Association board, representatives of the Drupal Community, Working Groups, Supporting Partners, and Drupal Businesses, both large and small to help develop our strategy and guidelines. Our biggest takeaways are:
There are already advertising banners on Drupal.org, however we need to expand their reach to hit our goals. We’re trying to address challenges for our current advertisers, including a relatively low amount of views on pages with ads, which makes it difficult for them to reach their goals.
We’re also facing industry-wide challenges in Digital Advertising. Advertisers are looking for larger, more intrusive ads that get the users’ attention, or at the very least use standard Interactive Advertising Bureau (IAB) ad sizes, which are larger than the ads we offer on Drupal.org.
We came up with a new line of products that we feel will help us reach our goals, but not disrupt the Drupal.org experience, or the Drupal Association Engineering Team roadmap. We want our Engineering Team to fix search on Drupal.org, not spend time developing and supporting major advertising platforms.
2015 Advertising Initiatives:
I wanted to spend most of my time explaining Audience Extension, since its unlike anything we’ve done in the past, and it may prompt questions. This product makes sense because it addresses all of the challenges we’re facing:
How does Audience Extension Work?
It’s important that we fund Drupal.org improvements, and that we do so in a responsible way that respects the community. We anticipate rolling out these new products throughout the year, starting with Audience Extension on February 5th. Thanks for taking the time to read about our initiatives, and please tell us your thoughts!
Now the new year has started, it’s time for our community to think about the future. It has become a tradition for for years now to predict what the year ahead will bring for us — so share your thoughts!
Happy birthday to Drupal! On this day in 2001, Drupal 1.0 was released.
This milestone is the perfect time to talk about some of the findings of our recent community survey. The survey findings offer a window into what community members are thinking as the project matures and evolves. It also gives us at the Drupal Association a way to better understand what we’re doing right and what we could be doing better. There aren’t many surprises (and that’s a good thing), but all of the findings are educational. Here are three results we thought were particularly interesting and insightful.
Drupal 8 Will Be Broadly Adopted
In the survey, about 80% of respondents said they either plan to start using Drupal 8 as soon as it is released, or plan to adopt it at some point after release. Another 8% said they did not have specific plans to adopt, but do plan to evaluate Drupal 8.
Drupal.org Remains an Important and Heavily-Used Tool
The overwhelming majority of respondents said they use Drupal.org more than once per week. Most also say they are satisfied or somewhat satisfied with the site. While that result is encouraging, it does not change the important mission to improve the experience of the site and make it a better tool for everyone from first time visitors to those who spend the majority of their working time on the site.
We Need to Create Broader Awareness of Drupal Association Programs
Community members who took the survey have great awareness of DrupalCons. Awareness of the work we are doing on Drupal.org seems to be steadily growing. But awareness is relatively low for Community Grants and our Supporter Programs that provide a way for organizations to give back to the Project. That awareness is clearly something we need to improve to promote transparency.
If you would like to read the full results, you can access them here (2.8M PDF). Thanks for reading, and thanks for being a part of this amazing community.
Drupal.org will be affected by maintenance Monday, December 15th 17:00 PST, 01:00 UTC (1 day after).
On October 29, the Drupal Security Team issued a Public Service Announcement (PSA) as a follow-up to Security Advisory SA-CORE-2014-005, which disclosed a serious SQL Injection vulnerability in Drupal 7. Our goals with the PSA were to:
(Speaking of which, if you have not remediated yet, please stop reading and do so.)
While we feel those goals were accomplished, the PSA also resulted in a large volume of press coverage – in fact much more coverage than the original disclosure of the vulnerability on October 15th. Not surprisingly, the general tone of the press coverage was quite negative. Unfortunately, some of the coverage was also inaccurate which we’d like to address here as well as provide additional context regarding our security processes.
While we don’t know the total number of Drupal sites affected, the number is not near 12 million as stated in several publications. Unless disabled, individual Drupal sites report their existence back to Drupal.org and this system reports around 1 million total Drupal sites. While this is not an exact measure of live Drupal sites we can infer that the affected number of specifically vulnerable Drupal 7 sites is more likely to be under 1 million.
SA-CORE-2014-005 was certainly a severe issue, if not the most severe issue in Drupal’s history; but it’s important to recognize all software has bugs and security issues that require a remediation process. Finding, fixing and announcing security patches is evidence of a healthy security process and Drupal is one of the few content management systems with a dedicated security team that covers both Drupal core and contributed code.
The above said, there are lessons from both the original disclosure and the follow-up PSA that might result in some changes to the Drupal Security Team policy and process, however we want to reinforce that we are deeply committed to keeping Drupal secure. We encourage you to read this whitepaper that explains our processes, policies and contains a good overview of Drupal security.
If you ever have questions, please use the public discussion area for general topics at https://groups.drupal.org/security or contact us (email@example.com). Or better yet, get involved. You can find more information on the Drupal Security Team page.
-Drupal Security Team
There are a growing number of licensing-related issues on Drupal.org that are unresolved. Additionally, volunteers who have been tackling licensing issues believe that the policies are often applied inconsistently. The result is that contributors are o…
Drupal 7.34 and Drupal 6.34, maintenance releases which contain fixes for security vulnerabilities, are now available for download. See the Drupal 7.34 and Drupal 6.34 release notes for further information.
Download Drupal 7.34Download Drupal 6.34
On Thursday, November 13th, 2014, Chinese censorship authorities DNS poisoned Drupal.org’s Content Distribution Network, EdgeCast. The Drupal Association and EdgeCast have been working together to fix connection issues to Drupal.org, and believe the is…
Drupal 7.33, a maintenance release with numerous bug fixes (no security fixes) is now available for download. See the Drupal 7.33 release notes for a full listing.
Download Drupal 7.33
Drupal.org is an amazing installation of Drupal. At nearly 13 years old, it is one of the largest, continuously operating examples of Drupal. It is difficult to fathom, but Drupal.org has been upgraded in place from version to version for this entire t…
This Public Service Announcement is a follow up to SA-CORE-2014-005 – Drupal core – SQL injection. This is not an announcement of a new vulnerability in Drupal.
Automated attacks began compromising Drupal 7 websites that were not patched or updated to Drupal 7.32 within hours of the announcement of SA-CORE-2014-005 – Drupal core – SQL injection. You should proceed under the assumption that every Drupal 7 website was compromised unless updated or patched before Oct 15th, 11pm UTC, that is 7 hours after the announcement.
Simply updating to Drupal 7.32 will not remove backdoors.
If you have not updated or applied this patch, do so immediately, then continue reading this announcement; updating to version 7.32 or applying the patch fixes the vulnerability but does not fix an already compromised website. If you find that your site is already patched but you didn’t do it, that can be a symptom that the site was compromised – some attacks have applied the patch as a way to guarantee they are the only attacker in control of the site.
Data and damage control
Attackers may have copied all data out of your site and could use it maliciously. There may be no trace of the attack.
Take a look at our help documentation, ”Your Drupal site got hacked, now what”
Attackers may have created access points for themselves (sometimes called “backdoors”) in the database, code, files directory and other locations. Attackers could compromise other services on the server or escalate their access.
Removing a compromised website’s backdoors is difficult because it is not possible to be certain all backdoors have been found.
The Drupal security team recommends that you consult with your hosting provider. If they did not patch Drupal for you or otherwise block the SQL injection attacks within hours of the announcement of Oct 15th, 4pm UTC, restore your website to a backup from before 15 October 2014:
While recovery without restoring from backup may be possible, this is not advised because backdoors can be extremely difficult to find. The recommendation is to restore from backup or rebuild from scratch.
For more information, please see our FAQ on SA-CORE-2014-005.
Contact and More Information
We’ve prepared a FAQ on this release. Read more at FAQ on SA-CORE-2014-005.
The Drupal security team can be reached at security at drupal.org or via the contact form at https://www.drupal.org/contact.
The biggest issues pointed out by the community had to do with the tone of the language in the documents. Many pointed out that it did not match the values of our community. We took a closer look at organizations such as the Wikimedia Foundation and Mozilla, incorporating some of the approaches they took to make our terms a bit more human. We trimmed and shortened what we could. We clarified where things were ambiguous. The end result is much more in line with our community values.
Some examples of changes include the following:
We did leave some things from the previous draft without major changes, such as bullet points under section C, for example. And we did it for a reason. One of our goals is to make Drupal.org a place where everyone feels comfortable. Additionally, we have to ensure that Drupal.org is protected if a legal issue does arise. Those bullet points are there not because we want to be able to police or censor the activity on the site. This language exists because it protects Drupal.org if one user takes issue with content from another user. We will still use the process outlined in the Drupal Code of Conduct to resolve any issues whenever we can.
With that in mind, please take a look at the latest drafts:
Thank you for all your help in building these documents.
Drupal.org will be affected by maintenance Thursday, October 23rd 14:00 PDT, 21:00 UTC.
Drupal 7.32, a maintenance release which contain fixes for security vulnerabilities, is now available for download. See the Drupal 7.32 release notes for further information.
Download Drupal 7.32
Upgrading your existing Drupal 7 is strongly recommend…
Drupal 8.0.0-beta1 has just been released for testing and feedback! This key milestone is the work of over 2,300 people who have contributed more than 11,500 committed patches to 15 alpha releases, and especially the 234 contributors who fixed 177 “bet…
Drupal.org will be affected by maintenance Tuesday, September 23rd 14:00 PDT, 21:00 UTC.
Joint Security release with WordPress
In big news, we had our first joint release with WordPress. We collaborated together with the WordPress team on a PHP security issue discovered by a security researcher. We’re thrilled that we had an opportunity to work together with others in the open source CMS community. We shared a few tips and tricks and it was great working with the WordPress team.
Keeping Drupal Secure
In keeping with our mission to showcase security best practices at Drupal’s online home, we’ve upgraded https://security.drupal.org to Drupal 7. This ensures we’re on a supported platform. We also took the opportunity to add some new features that help us enhance our team’s efficiency by automating a number of routine tasks.
As part of our dedication to keeping Drupal users safe, we’ve written and announced the Long Term support (LTS) plan for Drupal 6 (https://www.drupal.org/d6-lts-support). This is an important step as we look forward to the release of Drupal 8. Soon we will be introducing two-factor authentication to Drupal.org, thanks to hard work from security team members Ben Jeavons, Greg Knaddison , Neil Drumm, and Michael Hess. (https://groups.drupal.org/node/439868 and https://drupal.org/node/2239973)
And here’s one last, fun note: Security.Drupal.org issues now show up on the drupal.org dashboard if you add the widget. You can get it clicking on dashboard after logging in and adding the widget.
Securing Drupal E-Commerce
Some Drupal security team members were recently involved in putting together a compliance White paper for keeping track of PCI compliance. Anyone who runs a Drupal site and takes credit cards should read the whitepaper. Here’s a little more information:
Version 3.0 of the PCI compliance standard becomes mandatory on January 1st, 2015 and will be a complete game changer for many Drupal eCommerce sites. This includes triple the number of security controls if your website touches credit card information and more. The community supported Drupal PCI Compliance White Paper (http://drupalpcicompliance.org/) will give you a high level overview of what PCI compliance is, why you need to comply, and (most importantly) how to get started. This paper was written and reviewed by several members of the Drupal security team, including Rick Manelius, Greg Knaddison, Ned McClain, Michael Hess, and Peter Wolanin.
We’ve redesigned our Security Advisory system to make evaluating and analyzing security threats easier and more intuitive. This came about after several core contributors informed us that they wanted a better way to address security threats. We sent out a survey through Twitter to learn more about how people write and read the Security Advisories. Based on the responses we put together a new Security Advisory system that takes much of the guesswork out of the process of evaluating threats. We’ve added and reordered elements on the Security Advisory’s criticality scale and added explanations to help people understand where a security problem is on the spectrum of potential threats.
Our Growing Team
We’ve brought a number of new members onto the security team. Please help us give a very warm welcome to our newest security team members:
Alex Pott (alexpott) – IRC nick: alexpott, Organization: Chapter Three
We’re always looking for more qualified people who place a high priority on security. If you’d like to join the security team: https://security.drupal.org/join