Live data from Hacker News

Secure Custom Fields by WordPress.org

wordpress.org

71–80 of 210 posts

Re: Secure Custom Fields by WordPress.org

#72
post #68

Earlier quoted context omitted.

This release fixes a separate security vulnerability from the original update.

The maintainers [1] and the Wordpress project’s core security team lead [2] said that the fix was already published, despite your blocking them from publishing it directly and irresponsibly disclosing the issue out of spite [3]. Was that not true? [1] https://x.com/wp_acf/status/1843376378210857441 [2] https://x.com/johnbillion/status/1843750679141331039 [3] https://x.com/johnbillion/status/1842627564453454049

Sorry, I misread, disregard. I’d delete the comment but HN won’t let me.

Re: Secure Custom Fields by WordPress.org

#73
post #45

Earlier quoted context omitted.

> Sherlocked The verb you're looking for is stole Sherloking is when a Walmart is built next to a cornershop. Here the dude tore open the corner shop while claiming to be a victim.

When I posted, I was under the impression that ACF was open source. But the GitHub repo doesn’t list one, so if it’s not open source…WTF.

> When I posted, I was under the impression that ACF was open source. But the GitHub repo doesn’t list one, so if it’s not open source…WTF.

Isn't it here?

https://github.com/AdvancedCustomFields/acf

If you mean the licence, it's in readme.txt:

https://github.com/AdvancedCustomFields/acf/blob/master/read...

Re: Secure Custom Fields by WordPress.org

#74

Earlier quoted context omitted.

This release fixes a separate security vulnerability from the original update.

Can anyone else prove this security vulnerability actually existed?

It doesn't matter. Matt didn't have the right to hijack ACF.

Re: Secure Custom Fields by WordPress.org

#76
It is as if Wordpress [1] is asserting that the original author is a danger to public safety. Their terms read: ...

To that end, we reserve the following rights: ... to make changes to a plugin, without developer consent, in the interest of public safety.

[1]: https://x.com/WordPress/status/1845179613783142426

Re: Secure Custom Fields by WordPress.org

#77

Wordpress banned forks from the plugin directory a while ago, so they're doing what they ban everyone else from doing. https://make.wordpress.org/plugins/2021/02/16/reminder-forke...

ACF isn’t a premium plugin (linked post only concerns those). The linked post also might not reflect the current policies. This update was a security update and was done due to the unique circumstances around the original publisher.

There are a lot of other employers that won't make you lie for them.

Re: Secure Custom Fields by WordPress.org

#78
post #30

Earlier quoted context omitted.

The fucked thing is that per the article, they're not even dedicating any resources to maintain it going forward, they've just made this one fix and are throwing it to other people to maintain if they want: > Going forward, Secure Custom Fields is now a non-commercial plugin, and if any developers want to get involved in maintaining and improving it, please get in touch.

We have taken on stewardship of this code going forward, and will dedicate engineers to it. Probably more than Silver Lake does.

Why don't you mention this in the post at all?

Re: Secure Custom Fields by WordPress.org

#79

Earlier quoted context omitted.

When I posted, I was under the impression that ACF was open source. But the GitHub repo doesn’t list one, so if it’s not open source…WTF.

> When I posted, I was under the impression that ACF was open source. But the GitHub repo doesn’t list one, so if it’s not open source…WTF. Isn't it here? https://github.com/AdvancedCustomFields/acf If you mean the licence, it's in readme.txt: https://github.com/AdvancedCustomFields/acf/blob/master/read...

Thanks! The GitHub app reports it as "None" (https://imgur.com/a/5dyaTfX), but now I see it's "GPLv2 or later".

Re: Secure Custom Fields by WordPress.org

#80

Earlier quoted context omitted.

When I posted, I was under the impression that ACF was open source. But the GitHub repo doesn’t list one, so if it’s not open source…WTF.

> When I posted, I was under the impression that ACF was open source. But the GitHub repo doesn’t list one, so if it’s not open source…WTF. Isn't it here? https://github.com/AdvancedCustomFields/acf If you mean the licence, it's in readme.txt: https://github.com/AdvancedCustomFields/acf/blob/master/read...

Clearly AdvancedCustomFields should have filed a trademark to prohibit Wordpress from fully stealing it.

GPL code, trademarked branding. If you want to fork then you have to actually fork.

Oh the irony.

Post reply on HN