Live data from Hacker News

Secure Custom Fields by WordPress.org

wordpress.org

151–160 of 210 posts

Re: Secure Custom Fields by WordPress.org

#151

If anyone is interested in the extended controversy surrounding Wordpress, there is a site that has been tracking everything.[0] [0] https://bullenweg.com

Wow, I hadn't heard about the nosebleed incident. Absurd, even if he ain't snorting coke, it's deeply weird to continue an interview while profusely bleeding as if nothing is happening.

Him being in the middle of a mad coke bender would explain so much. I'm accepting this as canon until we find out WP Engine slept with his wife or something

Re: Secure Custom Fields by WordPress.org

#152

Earlier quoted context omitted.

> So.. is this fixing a security issue.. or is this because of WP Engine? AFAIK, here's the timeline. 1. Automattic announced that there was a security issue in ACF. 2. WP Engine fixes it immediately. 3. Automattic bans the WP Engine developers from Wordpress.org, so they can't deploy the fix. This places millions of users at risk, but that's how they roll. 4. Automattic forks ACF, removes the commercial upgrade, and…

Your timeline is rearranging some things around[1]. WP Engine was banned before the security issue. [1] https://duerrenberger.dev/blog/2024/10/08/timeline-of-the-wo...

Good catch! Sadly it's too late to edit my comment.

Re: Secure Custom Fields by WordPress.org

#153

Blog post on wordpress.org concerning this: https://wordpress.org/news/2024/10/secure-custom-fields/

The support notice got deleted[1]. The plugin developer got banned. Blocking access from certain ip. Shady or problematic hosting term[2]. I think hosting your code on wordpress.org is considered dangerous.

1. https://wordpress.org/support/topic/future-updates-for-acf-a...

2. https://github.com/wordpress/wporg-plugin-guidelines/blob/tr...

Re: Secure Custom Fields by WordPress.org

#154
post #140

Earlier quoted context omitted.

I feel so bad for all the Wordpress devs and shops right now. This is not the kind of community turmoil I'd want to deal with leading up to holidays/new years! It makes Drupal 8/Backdrop seem like a pleasant and wonderful experience, in comparison.

I don't think there was any bad blood between Drupal 8 and Backdrop, was there? It was forked in 2013 and look https://www.drupal.org/u/jenlampton Jen was still doing BADCamps and went to DrupalCons and all that. My memory is fuzzy a little but I do remember we were making huge progress on migrate at BADCamp 2014 and I do not remember a single tense moment with Jen or Nate. Or was that 2013? But even if it was, that…

True; I'm just thinking back to the absolute worst drama I can think of in Drupal land, it all pales in comparison. Most of it was misunderstandings that were subsequently sorted, or like Backdrop just a friendly fork with community connections still intact.

Re: Secure Custom Fields by WordPress.org

#155

So WordPress-the-org — which is effectively Matt, as far as I can tell — just Sherlocked a developer's plug-in using the developer's own code, ostensibly as retribution for a security issue that the developer had already fixed. https://www.advancedcustomfields.com/blog/acf-6-3-8-security... What am I missing?

This release fixes a separate security vulnerability from the original update.

[flagged]

Re: Secure Custom Fields by WordPress.org

#157
post #140

Earlier quoted context omitted.

I don't think there was any bad blood between Drupal 8 and Backdrop, was there? It was forked in 2013 and look https://www.drupal.org/u/jenlampton Jen was still doing BADCamps and went to DrupalCons and all that. My memory is fuzzy a little but I do remember we were making huge progress on migrate at BADCamp 2014 and I do not remember a single tense moment with Jen or Nate. Or was that 2013? But even if it was, that…

True; I'm just thinking back to the absolute worst drama I can think of in Drupal land, it all pales in comparison. Most of it was misunderstandings that were subsequently sorted, or like Backdrop just a friendly fork with community connections still intact.

I'm glad but slightly surprised neither Crell nor me counts as worst drama for you. Good? I guess.

Re: Secure Custom Fields by WordPress.org

#158
post #50

I wonder what will happen to old websites I built with ACF and did not touch for years? Are they vulnerable now, as owners cannot get updates for ACF?

The slug hasn't changed so it will receive updates (from SCF repository, now under the control of Automattic).

If you used ACF pro then the plug-in is downloaded from ACF website.

But.

The obvious next move is to put code in the core that would degrade ACF pro.

Post reply on HN