Ignorance Is Frightening -- The Hospital Stay That Made Me Take Security Seriously
On this site, I have written about Joomla vulnerabilities and about how to check whether your site is safe. This time, let me change tack: not a story about technology, but a story about my own failure. Why do I care so much about security? This is the event that lies at the very bottom of that reason.
Back when I used WordPress
Before I used Joomla, I ran my site on WordPress.
WordPress had an abundance of Japanese-language extensions, and there was plenty of information explaining how to modify them. Whenever I found a feature that looked useful, I would customize it to my liking and use it. I liked working with my hands, and it was fun to make things behave exactly as I wanted.
But there was something decisively missing in me back then. What danger those modifications might invite -- I had no awareness of it at all. Security, the very idea of safety, was something I had never once considered in those days.
Continuing to modify extensions without taking any protective measures. Looking back now, it was like drilling more holes into the walls of a house that was already full of them. Yet at the time, I did not even realize it was dangerous.
Hospitalization, and neglect
Then one day, I had no choice but to be hospitalized. I needed surgery for a rare disease called OPLL (ossification of the posterior longitudinal ligament). Little did I imagine back then that I would end up undergoing the same kind of surgery three times, counting this most recent one.
While I was in the hospital, I naturally could not manage my WordPress site. The site was left untended.
What I saw after being discharged
When I was discharged and opened my own site for the first time in a while --
there were many unfamiliar things there.
That was the first moment I knew. The vulnerability in the extensions I had modified had been exploited, and my site had been defaced by spammers. Those very features I had enjoyed customizing had become the entry points for intrusion.
It is a sorry story, but there was nothing I could do. I only flailed about helplessly, and my health was poor on top of it. In the end, unable to deal with it, I left it as it was, and eventually the hosting company seems to have taken care of it. But the site never returned to what it had been; it became something incomplete.
From there, to now
This one incident changed me.
I resolved three things. First, do not attempt anything beyond my own ability. Second, prioritize security above all else. And third, rather than relying on countless extensions that an amateur cannot fully manage, as with WordPress, choose a CMS better suited to me.
The result of that is what has led to my current operation on Joomla.
So, as readers of this site may have noticed, I basically use things "as they come, by default." Even when I change a setting, I try not to stray far from the default. This is not because I lack the skill. It is the opposite. It is because I learned, through that pain, that being able to modify something and being right to modify it are two different things.
What I want to convey
Ignorance is truly frightening.
But the most frightening thing, I now believe, is not ignorance itself, but proceeding without noticing that you are ignorant. Back then, I did not even have the awareness that I was doing something dangerous.
If there is someone now who, just as I once did, is enjoying tinkering with extensions without thinking about security, please stop just once. Is that modification not drilling a hole into the wall of your house? And if, for some reason, you were to be away from your site for a while, could that site defend itself while you were gone?
You do not need flashy features or elaborate modifications. What you need is to stay within the range you can handle, and to have the courage not to reach for what you do not understand. That alone makes a site far safer.
I do not want anyone to go through what I went through.