Live data from Hacker News

Secure Custom Fields by WordPress.org

wordpress.org

161–170 of 210 posts

Re: Secure Custom Fields by WordPress.org

#161

Earlier quoted context omitted.

What is he gaining at this point?

Harm of WP Engine.

Harming WPEngine is not even beneficial to Wordpress anymore.

With the level of revenge matt is applying you'd think WPEngine murdered his dog or something.

It just makes no sense.

Re: Secure Custom Fields by WordPress.org

#162
post #27

Earlier quoted context omitted.

> This update is as minimal as possible to fix the security issue. What is the actual issue? CVE number?

Details haven't been made public yet: https://www.cve.org/CVERecord?id=CVE-2024-9529 Though, Automattic posted publicly that there was a vulnerability shortly after filing the CVE, while simultaneously blocking WPEngine from being able to push a fix to it because they'd cut off access to wp.org

I wonder how many Automattic resources Matt threw at ACF to find a vulnerability to catalyze this situation?

Re: Secure Custom Fields by WordPress.org

#163
post #157

Earlier quoted context omitted.

True; I'm just thinking back to the absolute worst drama I can think of in Drupal land, it all pales in comparison. Most of it was misunderstandings that were subsequently sorted, or like Backdrop just a friendly fork with community connections still intact.

I'm glad but slightly surprised neither Crell nor me counts as worst drama for you. Good? I guess.

Well instances were both painful but in my mind mostly affected a few core groups of devs, and a lot of the community was oblivious to anything going on. The Drupal 8 migration and subsequent forking of D7 into Backdrop caused a lot more consternation with smaller agencies especially.

I mostly did Drupal stuff with local and regional camps at the time, I was hired at Acquia slightly after, so I remember a lot of pain back then, especially as Wordpress and Drupal were often considered in the same meetings when building small local sites for nonprofits, small businesses, etc.

Nowadays it seems Drupal isn't part of the conversation unless there's a C-suite at the place building the website, it's moved upmarket quite a bit.

Re: Secure Custom Fields by WordPress.org

#165
post #27

Earlier quoted context omitted.

Details haven't been made public yet: https://www.cve.org/CVERecord?id=CVE-2024-9529 Though, Automattic posted publicly that there was a vulnerability shortly after filing the CVE, while simultaneously blocking WPEngine from being able to push a fix to it because they'd cut off access to wp.org

I wonder how many Automattic resources Matt threw at ACF to find a vulnerability to catalyze this situation?

Same, I was imagining Gavin Belsom and his warehouse full of Hooli employees scouring over the Pied Piper demo.

Similarly, this is all to resolve the personal grudge of an exceedingly rich dude who wants even more money.

Re: Secure Custom Fields by WordPress.org

#166

Earlier quoted context omitted.

There are a lot of other employers that won't make you lie for them.

If you point to any lies told by me, I would love to correct them. No one has told me to come here and defend anyone. I work at a part of Automattic that is isolated from anything WordPress — I don’t have to be here. I am defending values I believe in. I am trying to make sure correct information is out there. You are free to not believe that of course.

[flagged]

Re: Secure Custom Fields by WordPress.org

#167

Posted this in the other thread: A lot of the comments seem to call out Matt (right or wrong). But that’s the easy thing to do. No one dares address the systemic issue of for profit corporations exploitatively (ab)using open source software. There is a social contract that people should contribute back, and while it’s largely unenforceable, as it should be, when it’s happening on a systemic level something has to be…

A number of people have dealt with the maker/taker issue, for example Dries, the founder and BDFL of the Drupal project: https://dri.es/solving-the-maker-taker-problem I think we're pretty far removed from the original issue of WP Engine and WordPress and people are just trying to deal with the fallout from Matt's nuke-the-entire-ecosystem approach he's elected to take.

Hey Jeff! :)))))

That was a great article from drupal. It’s a great idea and really goes along way to help, but we still need more.

This only addresses foss projects that are hosted as an offering. It wouldn’t address how for example the pgp guy basically went broke or just the general amount of pressure maintainers of “critical” foss packages are under and are spread so thin, that it’s always a triage fire and there’s never any room to “level up” with rewrites or full code base audits. And a lot of it comes at a huge personal cost but it just so happens the people often times in those shoes end up being super noble.

Maybe this is a cynical take but year after year it really does seem the software we rely on for modern life is just a house of cards where most cards are solo devs or a handful each doing the task of atlas cus the worlds corporations just don’t give back!

My words will ring true in 10-20 years when most of these people kick the bucket or retire and all we have left will be google’s next android| fuchsia and windows server.

Re: Secure Custom Fields by WordPress.org

#168

Earlier quoted context omitted.

> Clearly AdvancedCustomFields should have filed a trademark to prohibit Wordpress from fully stealing it. They did: Advanced Custom Fields — https://tsdr.uspto.gov/#caseNumber=98321164&caseSearchType=U... ACF — https://tsdr.uspto.gov/#caseNumber=98321135&caseSearchType=U...

Oh nice. Then WordPress shouldn’t be able to take over without renaming, right?

they renamed to "secure custom fields"

Re: Secure Custom Fields by WordPress.org

#169
post #113

If you were an insider deliberately trying to tank WordPress, it is hard for me to imagine anything you could do that would be more effective than this.

Perhaps he shorted the Automattic stock... no, wait, Automattic is privately held... make it make sense!

Re: Secure Custom Fields by WordPress.org

#170

Earlier quoted context omitted.

This release fixes a separate security vulnerability from the original update.

You are abusing the community for your own gain. Stop!

So far as I can tell, when Matt talks about "the WordPress Community", he means:

  - Matt
  - the people who didn't quit Automattic last week
  - _maybe_ the WP core developers who don't work at Automattic, so long as they keep their criticisms to themselves
And the community of people who _use_ WordPress to run their websites, and the people who help them to do that, and the 3rd party plugin and theme developers who make WP work for so many different kinds of websites - can all go and get fucked.
Post reply on HN