Dec 20 2004

Movable Type 3.14 released

We have just released Movable Type v3.14 which fixes the issue of extreme loads witnessed on servers under the strain of a massive spam attack. Because these attacks are increasing in both frequency and severity, we strongly recommend that all Movable Type users install this update. This is particularly important for any installation that is visible to the public on the web.

This release is a free update for Movable Type v3.x users and has been thoroughly tested both in-house, by our ProNet members and also by many of the web hosting companies initially affected by the problem. If you already purchased Movable Type or downloaded the free version, you’ll be able to download the new release from your Movable Type account.

The main changes in this new version are explained in detail below, but in summary, you can expect these updates:

  • Unnecessary rebuilds upon comment moderation are eliminated.
  • Generation of internal bookkeeping data for dynamic pages is not performed when using static pages.
  • New weblogs default to having comment moderation enabled.

We have also attempted to use our response to this issue, both in communicating with our end users and with our partners who host web sites powered by Movable Type, to set a baseline of expectation for our future communications about vulnerabilities in our software.

About the changes in Movable Type 3.14

The most important change in this release concerns unnecessary rebuilding in the case of comments which are forced into a moderated state for whatever reason (e.g. via a preference setting or a plugin callback). Moderated comments should not trigger a rebuild because the content of the site remains unchanged. However, due to an errant conditional statement, rebuilds occurred regardless of comment status. We have fixed this problem which will make a significant difference in performance for servers under the burden of a comment spam attack.

The second change eliminates unnecessary database connections related to internal bookkeeping for dynamic publishing. Dynamic publishing relies on these records to know what content to serve the user in place of a static file. In previous versions, this overhead was incurred even if the user had not elected to use dynamic pages. This issue has been rectified and improves the balance of benefits between static and dynamic pages.

Finally, we have altered the defaults for new weblogs in Movable Type to enable comment moderation by default for commenters who are not authenticated via TypeKey. Not only is this an improvement in the quest for sane defaults for new users, but as a side benefit, it also eliminates the following error on new Movable Type blogs:

"Comment registration is required but no TypeKey token has been given in weblog configuration!"

We're expecting no shortage of smiles when that error fades into obscurity.

A note to MT-Blacklist users

A portion of the changes implemented in this version are masked by MT-Blacklist v2.x. However, if you are using MT-Blacklist, there is no need to disable it as it works perfectly fine with this version of Movable Type.

Look for a new beta release of the plugin within the next twenty-four hours (in the usual place) which will provide yet another improvement in system performance.

More to come

In case you missed it, Mena wrote a few words about this release and the events that led up to it.

I would like to echo her sentiment in apologizing to any users or web hosting companies who have been affected by this problem. We hope that you understand both through our responsiveness and the visibility we've given to this issue that we are dedicated to taking care of our customers needs and solving problems that confront them on a daily basis. We've worked very hard to provide full information as soon as it's been available, on our company website, on the Movable Type product homepage, and within the Movable Type application itself.

While we are always working hard to improve the quality of the software we release, the reality is that all software has bugs. What we promise, however, is that we will always strive to be as responsive and forthcoming as as possible to make sure that you can trust Movable Type as a platform and Six Apart as a company.

Categories

75 TrackBacks

Listed below are links to blogs that reference this entry: Movable Type 3.14 released.

TrackBack URL for this entry: http://www.movabletype.com/cgi-bin/mt4/mt-tb-nospam.cgi/5

» Movable Type 3.14 released from Six Log

We've just released Movable Type 3.14, which addresses the server load issues we've been discussing for the past few days.... Read More

» Movable Type 3.14 released from Six Apart Professional Network

Thanks in large part to the help and feedback from Professional Network members, we've just released Movable Type 3.14. This release addresses the performance issues detailed last week, and we'll be providing additional guidance and information to ProN... Read More

» Movable Type 3.14 released from Looking Out

According to MT News a new version of MT has been released to address some of the immidiate issues concerning comment and trackback spam. We have just released Movable Type v3.14 which fixes the issue of extreme loads witnessed on... Read More

» MT 3.14 is out! from Geeks, Guitars and Guinness

Movable Type Publishing Platform: Movable Type 3.14 released It's out and has the fixes in place to stop comment spam from taking out machines (hopefully). I've re-enabled comments, so let's see what happens.... Read More

» MT 3.14? Easy as π from ALLABOUTGEORGE.com

Per Six Apart, I've downloaded Movable Type 3.14 and upgraded my installation. Let's see if my server load notices the difference!... Read More

» Movable Type 3.14 released from Movalog Sideblog

Movable Type 3.14 released... Read More

» MovableType Upgrade from Tong Family Blog

Movable Type Publishing Platform: Movable Type 3.14 released. You'll want to get this one, it fixes slow downs because of massive spam attacks. Sigh. Sign of the modern world.... Read More

» 从MT2.6�?�级到MT3.x from 车东Blog^2

mtupgrade - Upgrading Movable Type 终于找到了将Movabletype 2.x�?�级到movabletype 3.x版本的�?�级文档: 方法就是下载时,选择... Read More

» 从MT2.6�?�级到MT3.x from 车东Blog^2

mtupgrade - Upgrading Movable Type 终于找到了将Movabletype 2.x�?�级到movabletype 3.x版本的�?�级文档: 方法就是下载时,选择... Read More

» Movable Type 3.14 Released from Ravensky.org

Just a quick note. A new version of movable type has been released. It fixes problems that made your server do extra work. All becuase of the blog spammers. Link to the original story is here.... Read More

» Movable Type 3.14 released from greenplastic.net

  Movable Type 3.14�?�リリース�?�れ�?��?��?��?��?�。�?��?�やらコメント... Read More

» Movable Type 3.14 from blog.bulknews.net

Movable Type Publishing Platform: Movable Type 3.14 released We have just released Movable Type v3.14 which fixes the issue of Read More

» Movable Type 3.14 released from Exist a Reason

Movable Type 3.14 released MT��3.14�����꡼��(... Read More

Movable Type 3.14 released (Finally, it will fix the high server load problem because of the blog spammers - Die spammers! Die! - I'll do my upgrade later)... Read More

» Movable Type v3.14 is out! from 数�?�库管�?�员的Blog

Movable Type 3.14 �?�布了 Read More

» The Greatest Canadian... Blog from Bow. James Bow.

Robert McClelland over at MyBlahg has been active of late. Not only does he run the Cavalcade of the Canucks, but he is accepting nominations for his brand of the Canadian Blogging Awards. Left or right, why not go... Read More

» Movable Type 3.14 Released from LMT Announcements

Six Apart has announced a new release of Movable Type which addresses a critical bug that was causing extreme server loads on MT installations. Six Apart recommends that all MT3 uers install the updated software.... Read More

» yo. from sledgeblog

for you MT bloggers: movable type 3.14 has been released.... Read More

» MovableType 3.14 Released from UtterlyBoring.com

I've been using the beta version of this (will be installing the release version tonight), and I would recommend everybody download and install the newest version. There are some bugs... Read More

» Movable Type 3.14 released from poocs.net

SixApart reacts to the recent comment spam issues that drained bloghosters’ servers by putting unnecessary on the systems. They officially released Version 3.14 to the public. This release mainly comes with the following changes: Unnecessary reb... Read More

» Empty Pie (MT v 3.14) from e53 update

Welcome to the 'war on comment spam'. 6a released an upgrade for MT today which is supposed to help beat back the high level of idiocy that his being presented by comment spammers recently. Apparently, in the old version, there... Read More

» A Couple of Late-Night Updates from Josh's Weblog

I have upgraded the blog to MoveableType 3.14, mostly to continue the war against comment spam. So far I have been only lightly attacked, but a denial-of-service (DOS) issue is certainly important for good relations with my host provider. In... Read More

» Movable Type 3.14 from Ogawa::Memoranda

Movable Type 3.14英語版�?�リリース�?�れ�?��?��?�。3.121�?�ら�?�マイナー��?ージョンアップ�?���?以下�?�点�?�新�?��??�?��?��?��?��?��?�。 Movable Type Publishing Platform: Movable Type 3.14 released 事��?承��?�?�必��?�?�コメ... Read More

» Movable Type 3.14 released from Lutz-R. Frank MT 3.1

Movable Type Publishing Platform: Movable Type 3.14 released MT just released Movable Type v3.14 which fixes the issue of extreme loads witnessed on servers under the strain of a massive spam attack. Because these attacks are increasing in both frequen... Read More

» MT Pi from Neurotic Fishbowl

Six Apart has just released the newest upgrade to Movable Type, v.314. It addresses the issue of extreme server load Read More

» MT 3.14 from Phil's Diary

Movable Type has had a small bug in it for a while which adds to system load when comments are added to the site, even if those comments get sent... Read More

» MovableType 3.14 di-rilis! from vikingkarwur.com | blog

MovableType merilis versi terbarunya yaitu versi 3.14 dengan beberapa kemampuan baru. Info detail bisa di baca di sini. Note Situs ini sudah mengunakan rilis terbaru MovableType 3.14... Read More

12.19�ոոհ�װ��������MT�������ͷ���MT�Ѿ�������3.1.4�汾�� ����һ��֮��. 3.1.2���������2004.10.19�������µ�ʱ�䡣 ����������ǿ�ҽ����ý¼¶£¬¾ï¿½ï¿½ï¿½ï¿½Ë¹ï¿½ï¿½ï¿½ï¿½ï¿½ï¿½ï¿½È»ï¿½ï¿½Ã»ï¿½ï¿½ï¿½ï¿½È«ï¿½ï¿½ï¿½ï¿½ï¿½ï¿½MT�ĸ��ֹ���...... Read More

» Movable Type 3.14 from Neil's World

No idea where 3.13 went, but Movable Type 3.14 has been released. Read More

» Geek News Central Podcast #21 2004-12-21 from Geek News Podcast

Went thru Geek Hell yesterday, details are in the Podcast. Little less than 30 minutes today due to software issues yesterday. May do 3 shows this week we will see. GeekNewsCentral-2004-12-21.mp3 GeekNewsCentral-2004-12-21.wma GeekNewsCentral-2004-12-2... Read More

» Geek News Central Podcast #21 2004-12-21 from Geek News Central Podcast

Went thru Geek Hell yesterday, details are in the Podcast. Little less than 30 minutes today due to software issues yesterday. May do 3 shows this week we will see. GeekNewsCentral-2004-12-21.mp3 GeekNewsCentral-2004-12-21.wma GeekNewsCentral-2004-12-2... Read More

» Geek News Central Podcast #21 2004-12-21 from Geek News Central

Went thru Geek Hell yesterday, details are in the Podcast. Little less than 30 minutes today due to software issues... Read More

Six Apart acaba de lanzar la versi�n 3.14 de Movable Type que corrige un error de c�digo que facilitaba el colapso y enlentecimiento de los servidores sometidos a un ataque de spam. Read More

» Movable Type 3.14 released from Gemal's Psyched Blog

We have just released Movable Type v3.14 which fixes the issue of extreme loads witnessed on servers under the strain of a massive spam attack. Because these attacks are increasing in both frequency and severity, we strongly recommend that all... Read More

» mod_security from Movalog

During the comment spam crisis, before 3.14 was released, my host installed something called modsecurity. I have noticed that ever since it was installed, the comment spam flooding that normally happened turned into a trickle. modsecurity helps with a ... Read More

» Movable Type 3.14 from Bibi's box

Movable Type 3.14 is out! I want it! I'm a little compulsive, but the blog of Movable Type Publishing Platform showed to me some good reasons to update: The most important change in this release concerns unnecessary rebuilding in the case of comments w... Read More

SixApart have just released MT 3.14 which addresses some of the se

Read More

» MovableType 3.14 released from Vu d'ici : we are the new heros!

* MT 3.14 (via heiko)... Read More

» MT 3.14 from Denken Über

6A lanzó una nueva version de MT, la 3.14 con cambios principalmente en el manejo de moderacion de comentarios y borrado de comment-spam. En realidad, el gran problema que soluciona es el rebuild que tiene que hacer cada página al borrar comentari... Read More

» Attention, clients using Moveable Type from Hop Studios Blog

We want to write to let you know about an upgrade to Moveable Type that's become available. It's a small upgrade, but it fixes several issues related to comment spam and its related server load. If you've had problems with server load or spam comments,... Read More

» New Version of Movable Type from Conservative Dialysis

I have upgraded the blog installation to Movable Type, Version 3.14. Apparently, many blogs were having problems with comment spam and this release has helped with that. As usual, if you notice anything isn't right, please contact me via email... Read More

» Upgrade from B12 Partners

Upgrading your databases:Running ......Done upgrading your schema! All went well. Read More

» Comments Reopened from Electrolicious

Six Apart released Movable Type version 3.14 which should address the server-side issues being caused by comment spam. I reopened all old comments last night...and blacklist moderated my first comment spam a mere 30 minutes later! sigh... But the issue... Read More

» eWeek on Comment Spam from birdhouse.org

Heard from a reporter at eWeek yesterday who wanted to interview me about Movable Type comment spam overloads and how they affect web hosts. Unfortunately I got the email too late and wasn't interviewed for the story, which was published today. Six Apa... Read More

» New version of Movable Type Released from Geof's Waste of Bandwidth Blog

The latest version of Movable Type has been released. Version 3.14 fixes the issue of extreme loads witnessed on servers under the strain of a massive spam attack. Because these attacks are increasing in both frequency and severity, it... Read More

» Painless upgrades from Child Abuse Survivor

Just finished doing upgrades of both the Movable Type installation that this blog runs on, and of the software the forums run on. The new version of Movable Type is aimed at helping with comment spam and server issues surrounding... Read More

» icmp oops from daily babble

Right, so, apparently the dynamic address updater on fungus doesn't actually work correctly quite yet…. I think I need to fix that. Today. Even before I upgrade the BITTER. Thanks to Crystal for getting us back on track in an... Read More

» SixApart releases MT 3.14 with flood fix from The Blog Herald: more blog news more often

SixApart has released MovableType 3.14 with a fix to the bug which led spam comments to still cause a load on Web servers and databases even when the comments were blocked from appearing on blogs, resulting in server shutdowns. Interestingly the compan... Read More

» Life During Wartime from Munuviana

I mentioned in a comment to Helen's post about MT Blacklist that I couldn't see just what Blacklist was up to because I could no longer view the Activity Log. And the reason for that is that there were over... Read More

���� �������� �������, �� Six Apart ������ ����������� ��������� � ������ ������� ������������ � MT. ��������� � �������� ����� �������� ����� �� ������� � ����� �� ����������. ������� ����� ���c�� ����� �� ����������� ����� ������.... Read More

Six Apart have just announced the release of Movable Type 3.14 which they have developed to fix 'the issue of extreme loads witnessed on servers under the strain of a massive spam attack. Its a free upgrade for all... Read More

» Update from Der Schockwellenreiter

MovableType 3.14 released. Das Update soll das Problem der massiven Serverbelastung beim Auftreten von Kommentarspam beheben. [Thomas K. in meinen Kommentaren.] Read More

» Next beta coming soon from MT-Blacklist/Comment Spam Clearinghouse

Movable Type 3.14 has been released to address the comment spam server load issue. You should all upgrade immediately because of the potential for massive spam attacks. As I mentioned earlier, I will be spinning a new MT-Blacklist release very... Read More

» Just stuff from CrabAppleLane Blog

Lunch yesterday came from the Central Grocery in the French Quarter. I�ve been kind of craving it since I was down there back in October. Muffulettas are large and the Central Grocery cuts them into quarters. This is the sole survivor from lunch. It d... Read More

» MovableType 3.14 ver�ffentlicht from klubbing's personal blog

Haupt�nderung soll die geringere Serverlast bei Kommentarspam sein.MovableType�via schockwellenreiter Read More

» MovableType 3.14 Upgrade from kilic.net

The upgrade seems to have gone well except that the rebuilding of the individual archives seems to stall, but that's an issue to be resolved for another day. Hopefully this upgrade will effectively counter any comment spamming (to which I... Read More

» Handling comment spam from Ann Elisabeth's blog

Update: Update your MT to 3.14, to fix some of the issues described here Many webhosts have had whole servers go down recently, because of comment spam. This has been especially evident for those hosts with popular Movable Type blogs... Read More

» When Movable Type met Comment Spam.. from Bamsaemi Blog

via eweek.com Movable Type Fixing Bug as Spam Clogs Blogs blogger���� �ѹ����� comment spam�� �ָ� ���� ���� �����̴ϴ�. Ư���� movable type�� �����ϴ� blogger�� ���쿡�� ������. ^^ �ֱ� movable type������ comment spam ������ �̽��� �Ǿ����µ�.. �̸� �... Read More

» Movable Type 3.14 released from brain dumplings, the weblog

I'm posting this as a PSA, for those who have MT blogs... Movable Type 3.14 has been released. The main reason to upgrade is due to some recent floods of comment spam, that have exposed some flaws in MT's performance under heavy comment load. This upda... Read More

» Movable Type 3.14 released from The Fishbowl

How does one keep up? But this looks pretty important inasmuch as comment spam has been an increasing irritation on this site. SixApart announced on their site earlier this week:The most important change in this release concerns unnecessary rebuilding ... Read More

» Upgraded to MovableType 3.14 from The ArcterJournal

Just threw the new version of MovableType up. Please let me know if anything is busted.... Read More

» Upgraded to MovableType 3.14 from The ArcterJournal

Just threw the new version of MovableType up. This is a proactive measure to eliminate the high CPU loads due to comment spam that I'm seeing on UFies. I'm wondering if I should also throw in this hack which adds... Read More

» MovableType 3.14 released from A View From Home

This is an example of how to respond to an issue. Months ago I made the decision to stick with Six Apart's MovableType despite the bruhaha over the pricing. I figured the dust would settle, Six Apart would figure things... Read More

» Movable Type 3.14 released from larfs Weblog - oder ists ein Blog?

�brigens gibt es seit einigen Tagen eine neue Movable Type Version, n�mlich 3.14 und s. hier. ...Und funktioniert auch. ;-)... Read More

» Movable Type 3.14 released from larfs Weblog - oder ists ein Blog?

�brigens gibt es seit einigen Tagen eine neue Movable Type Version, n�mlich 3.14 und s. hier. ...Und funktioniert auch. ;-)... Read More

» Worthy of comment from Waveflux

While driving about town yesterday, finishing up my holiday shopping (a Ryobi reciprocating saw for my beloved wife, who is the handy one in the family; I also got her an Ian McKellen "Gandalf" t-shirt, which she has gratly desired... Read More

» Movable Type v3.14 from Roel's Weblog

Movable Type: The main changes in this new version are explained in detail below, but in summary, you can expect... Read More

» MT-Blacklist v2.03-beta released from MT-Blacklist/Comment Spam Clearinghouse

I've just released MT-Blacklist version 2.03-beta for immediate public testing. This release contains the following changes from v2.02: Now using CommentFilter API callback to force moderate (fixes issue discussed here) Added re-initialization function... Read More

Comment spam is back in the spotlight after Six Apart fixed a big Movable Type bug that was causing the load of comment spam to DoS servers. This eWeek story on the subject led me to a post where Sean... Read More

» Upgrade to MT 3.14 from random ruminations

I just finished upgrading my site to Movable Type version 3.14. It addresses a number of issues associated with comment spam. This post is to test that everything is working correctly.... Read More

» Upgrade time from esoterically.net

If you are publishing your weblog with Movable Type, it is time to upgrade to version 3.14. You will most... Read More

» Upgrade time from esoterically.net

If you are publishing your weblog with Movable Type, it is time to upgrade to version 3.14. You will most... Read More

» Agressive Mailer - Spam on Movable Type from Birkh�user+GBC - Master Blog

http://www.movabletype.org/news/2004/12/movable_type_314_release.shtml... Read More

» Due To DoS Attacks from democracyforcalifornia.com

comments are temporarily disabled until this issue is resolved. Bloggers using Movabletype take note: There have been a number of reports about the escalating effect of comment spam on Movable Type installations, especially evident in shared hosting en... Read More

» Movable Type 3.14 Released! from quack the planet!

Another release from SixApart... there has been major discussion in the blogosphere about comment spam, and MT had a major bug that would cause a rebuild of your pages when a moderated comment was posted. If your server was being... Read More