Earlier quoted context omitted.
A million people trusted WPE’s resources. WPE, in turn, relied on someone else’s. The real issue here is that WPE completely overlooked the fact that they haven’t done the work to maintain the availability of their apps. It’s like buying a fridge, stocking it with $200 worth of food, and forgetting to plug it in.
This is 100% correct as a position of principle, but it's not a foregone conclusion that WPE was able to take the necessary steps here. To be very specific about at least one of the issues: * The URLs pointing to the WP plugin directory on wordpress.org are hardcoded into WordPress * If WPE forks WordPress to fix that, and continues to say they host WordPress, IANAL but they probably have a trademark violation proble…
But they can be changed via filters. I do that all the time to manage when certain request are being made (and making sure it's in a cron job and not a user-request).
WP Engine does run their own plugin in the instances they host, though I assume it's not obligatory. Still, every site I ever had to look at that was on WPE had it installed and enabled.
WP does come with its own CA certs, but that file could be appended (or replaced, again via filter) as well. Since they're comfortable changing things like the revision settings, I doubt this would be something they wouldn't do.
I'm not saying Matt is reasonable, but "it's not an easy thing to do" isn't true.