Live data from Hacker News

Secure Custom Fields by WordPress.org

wordpress.org

61–70 of 210 posts

Re: Secure Custom Fields by WordPress.org

#61
post #45

So WordPress-the-org — which is effectively Matt, as far as I can tell — just Sherlocked a developer's plug-in using the developer's own code, ostensibly as retribution for a security issue that the developer had already fixed. https://www.advancedcustomfields.com/blog/acf-6-3-8-security... What am I missing?

> Sherlocked The verb you're looking for is stole Sherloking is when a Walmart is built next to a cornershop. Here the dude tore open the corner shop while claiming to be a victim.

Or, more blatant and accurate, Sherlocking is when Apple literally named their search product "Sherlock" when a popular third party shareware app named "Watson" already existed.

Re: Secure Custom Fields by WordPress.org

#63
post #45

So WordPress-the-org — which is effectively Matt, as far as I can tell — just Sherlocked a developer's plug-in using the developer's own code, ostensibly as retribution for a security issue that the developer had already fixed. https://www.advancedcustomfields.com/blog/acf-6-3-8-security... What am I missing?

> Sherlocked The verb you're looking for is stole Sherloking is when a Walmart is built next to a cornershop. Here the dude tore open the corner shop while claiming to be a victim.

When I posted, I was under the impression that ACF was open source. But the GitHub repo doesn’t list one, so if it’s not open source…WTF.

Re: Secure Custom Fields by WordPress.org

#64

So WordPress-the-org — which is effectively Matt, as far as I can tell — just Sherlocked a developer's plug-in using the developer's own code, ostensibly as retribution for a security issue that the developer had already fixed. https://www.advancedcustomfields.com/blog/acf-6-3-8-security... What am I missing?

This release fixes a separate security vulnerability from the original update.

Can anyone else prove this security vulnerability actually existed?

Re: Secure Custom Fields by WordPress.org

#65

Wordpress banned forks from the plugin directory a while ago, so they're doing what they ban everyone else from doing. https://make.wordpress.org/plugins/2021/02/16/reminder-forke...

ACF isn’t a premium plugin (linked post only concerns those). The linked post also might not reflect the current policies. This update was a security update and was done due to the unique circumstances around the original publisher.

The mental gymnastics you keep doing to defend your boss are impressive, and I'm sure will reflect well on your next perf cycle!

Re: Secure Custom Fields by WordPress.org

#66

Earlier quoted context omitted.

What a choice, and what poor timing. Companies that make breaking changes on holiday weekends aren’t going to earn much goodwill from developers.

Nothing has broken. Perhaps WP Engine should have consider that before suing us.

I don't think punishing people for suing you typically plays well in court. Especially not if you, you know, publicly announce that's what you're doing.

Re: Secure Custom Fields by WordPress.org

#67

Earlier quoted context omitted.

What a choice, and what poor timing. Companies that make breaking changes on holiday weekends aren’t going to earn much goodwill from developers.

Nothing has broken. Perhaps WP Engine should have consider that before suing us.

There won't be a Wordpress community left if you continue as you have. What does the board think of your actions?

Re: Secure Custom Fields by WordPress.org

#68

So WordPress-the-org — which is effectively Matt, as far as I can tell — just Sherlocked a developer's plug-in using the developer's own code, ostensibly as retribution for a security issue that the developer had already fixed. https://www.advancedcustomfields.com/blog/acf-6-3-8-security... What am I missing?

This release fixes a separate security vulnerability from the original update.

The maintainers [1] and the Wordpress project’s core security team lead [2] said that the fix was already published, despite your blocking them from publishing it directly and irresponsibly disclosing the issue out of spite [3].

Was that not true?

[1] https://x.com/wp_acf/status/1843376378210857441

[2] https://x.com/johnbillion/status/1843750679141331039

[3] https://x.com/johnbillion/status/1842627564453454049

Re: Secure Custom Fields by WordPress.org

#70

Wordpress banned forks from the plugin directory a while ago, so they're doing what they ban everyone else from doing. https://make.wordpress.org/plugins/2021/02/16/reminder-forke...

ACF isn’t a premium plugin (linked post only concerns those). The linked post also might not reflect the current policies. This update was a security update and was done due to the unique circumstances around the original publisher.

[deleted]
Post reply on HN