Live data from Hacker News

Secure Custom Fields by WordPress.org

wordpress.org

141–150 of 210 posts

Re: Secure Custom Fields by WordPress.org

#141
post #89

Earlier quoted context omitted.

If you point to any lies told by me, I would love to correct them. No one has told me to come here and defend anyone. I work at a part of Automattic that is isolated from anything WordPress — I don’t have to be here. I am defending values I believe in. I am trying to make sure correct information is out there. You are free to not believe that of course.

What values are those, exactly?

Automattic is an open source company, albeit one controlled by a melodrama villain.

Re: Secure Custom Fields by WordPress.org

#142

Posted this in the other thread: A lot of the comments seem to call out Matt (right or wrong). But that’s the easy thing to do. No one dares address the systemic issue of for profit corporations exploitatively (ab)using open source software. There is a social contract that people should contribute back, and while it’s largely unenforceable, as it should be, when it’s happening on a systemic level something has to be…

> A lot of the comments seem to call out Matt (right or wrong). But that’s the easy thing to do.

It's also productive. If there's enough of an uproar, then the board will remove him. They're pretty much the only people who can stop him.

> There is a social contract that people should contribute back, and while it’s largely unenforceable, as it should be, when it’s happening on a systemic level something has to be done. And we are all complicit if we don’t at least say that much and spare some good will towards the guy actively in that fight at least superficially

You don't speak for me. Contributions to my OSS projects are appreciated, but all I ask is that users comply with the license terms.

If you feel that contributions are an unwritten obligation, he's made them much harder to ask for. Everyone else who asks for them in the future will be tarred with the same brush.

Matt is burning down the WordPress ecosystem because his shakedown attempt failed. He's prevented at least 2.5 million users from receiving security updates. He's earned my contempt, not my goodwill.

> I might agree with most of your points, I’m just trying to get people to realize there’s the local issue of Matt/wp and then there’s this global issue of companies building businesses off foss and not giving back.

Drew said it best. (https://drewdevault.com/2021/01/20/FOSS-is-to-surrender-your...) If you want to require contributions, pick an appropriate license.

Re: Secure Custom Fields by WordPress.org

#143
post #25

Pathetic. Matt banned one of the most popular WordPress plugins. Then, he forked the code and hosted it on WP.org, which is against the Terms of Service. He also hosted it in the plugin directory on the same path as ACF, stealing its SEO traffic. Wow! Matt's state of mind is clearly not good. If I were an investor in WordPress, I would start thinking about cutting my losses. WordPress will not recover from this self-…

Have you read the GPL?

[deleted]

Re: Secure Custom Fields by WordPress.org

#144

Earlier quoted context omitted.

What a choice, and what poor timing. Companies that make breaking changes on holiday weekends aren’t going to earn much goodwill from developers.

Nothing has broken. Perhaps WP Engine should have consider that before suing us.

Trust is what has been broken.

Childish.

Re: Secure Custom Fields by WordPress.org

#145

> This update is as minimal as possible to fix the security issue. > This is a rare and unusual situation brought on by WP Engine’s legal attacks, we do not anticipate this happening for other plugins. So.. is this fixing a security issue.. or is this because of WP Engine? > and are forking Advanced Custom Fields (ACF) into a new plugin And stealing their place in the plugin store. A fork generally implies that you a…

> So.. is this fixing a security issue.. or is this because of WP Engine? AFAIK, here's the timeline. 1. Automattic announced that there was a security issue in ACF. 2. WP Engine fixes it immediately. 3. Automattic bans the WP Engine developers from Wordpress.org, so they can't deploy the fix. This places millions of users at risk, but that's how they roll. 4. Automattic forks ACF, removes the commercial upgrade, and…

Your timeline is rearranging some things around[1]. WP Engine was banned before the security issue.

[1] https://duerrenberger.dev/blog/2024/10/08/timeline-of-the-wo...

Re: Secure Custom Fields by WordPress.org

#146

So WordPress-the-org — which is effectively Matt, as far as I can tell — just Sherlocked a developer's plug-in using the developer's own code, ostensibly as retribution for a security issue that the developer had already fixed. https://www.advancedcustomfields.com/blog/acf-6-3-8-security... What am I missing?

[deleted]

Re: Secure Custom Fields by WordPress.org

#147
post #25

Pathetic. Matt banned one of the most popular WordPress plugins. Then, he forked the code and hosted it on WP.org, which is against the Terms of Service. He also hosted it in the plugin directory on the same path as ACF, stealing its SEO traffic. Wow! Matt's state of mind is clearly not good. If I were an investor in WordPress, I would start thinking about cutting my losses. WordPress will not recover from this self-…

Have you read the GPL?

The problem isn’t GPL or code, it’s a trademark and trusting issue.

Re: Secure Custom Fields by WordPress.org

#148

Earlier quoted context omitted.

Have you read the GPL?

Parent does not mention GPL, nor is this a GPL issue. It's about the takeover of an existing plugin and it's reviews/installs.

I am not a lawyer, but I am really curious if this would amount to tortious interference.

Re: Secure Custom Fields by WordPress.org

#150

Earlier quoted context omitted.

Clearly AdvancedCustomFields should have filed a trademark to prohibit Wordpress from fully stealing it. GPL code, trademarked branding. If you want to fork then you have to actually fork. Oh the irony.

> Clearly AdvancedCustomFields should have filed a trademark to prohibit Wordpress from fully stealing it. They did: Advanced Custom Fields — https://tsdr.uspto.gov/#caseNumber=98321164&caseSearchType=U... ACF — https://tsdr.uspto.gov/#caseNumber=98321135&caseSearchType=U...

Oh nice. Then WordPress shouldn’t be able to take over without renaming, right?
Post reply on HN