That's great, but all it means is that you just weren't in the crosshairs, not that you were actually secure. Automating updates is a wonderful way to open up an attack vector, as well - for example, a little while back, attackers got into the Wordpress SVN repo and back-doored a bunch of popular plugins[1]. Anyone performing "regular updates" without proper auditing would have installed malicious code that opened them up to full-scale breach.
It is much more practical to secure a single repo administered by competent techs than it is to secure a zillion web sites run by people with no technical experience.
Comments
Actually - I haven't had a single site hacked since implementing regular updates. And I'm managing hundreds of sites. With many plugins..
That's great, but all it means is that you just weren't in the crosshairs, not that you were actually secure. Automating updates is a wonderful way to open up an attack vector, as well - for example, a little while back, attackers got into the Wordpress SVN repo and back-doored a bunch of popular plugins[1]. Anyone performing "regular updates" without proper auditing would have installed malicious code that opened them up to full-scale breach.
[1] http://wordpress.org/news/2011/06/passwords-reset/
It is much more practical to secure a single repo administered by competent techs than it is to secure a zillion web sites run by people with no technical experience.