Live data from Hacker News

Secure Custom Fields by WordPress.org

wordpress.org

171–180 of 210 posts

Re: Secure Custom Fields by WordPress.org

#171

Earlier quoted context omitted.

You are abusing the community for your own gain. Stop!

What is he gaining at this point?

Avoiding the embarrassment of backing down and admitting he is wrong.

Apparently that's worth burning down his life's work and legacy for.

Re: Secure Custom Fields by WordPress.org

#172
post #89

Earlier quoted context omitted.

What values are those, exactly?

US dollar values deposited into the accounts every paycheck, I assume.

"It is difficult to get a man to understand something, when his salary depends upon his not understanding it." -- Upton Sinclair (probably, may be apocryphal)

Re: Secure Custom Fields by WordPress.org

#173

So WordPress-the-org — which is effectively Matt, as far as I can tell — just Sherlocked a developer's plug-in using the developer's own code, ostensibly as retribution for a security issue that the developer had already fixed. https://www.advancedcustomfields.com/blog/acf-6-3-8-security... What am I missing?

This release fixes a separate security vulnerability from the original update.

Unfortunately you have no proof of that, because the only relevant changes are actually neither introducing fixes, nor ever changing the plugin core code in a way that fixes security issues. The only thing done is removing a LOT of references, links, and instructions that would remind of WP Engine, as well as all compatibility with the POR features.

Then, you added a few irrelevant changes that to the inexperienced eye look like security fixes https://plugins.trac.wordpress.org/changeset?old_path=%2Fadv...

However, these are no fixes. You just introduce a new variable, that you never use, and re-assign the same contents of that new variable back to the $_REQUEST

Unless you show proof of a security fix - which you could have pushed to users WITHOUT renaming the plugin, WITHOUT removing original, non-security related code, and WITHOUT breaking compatibility with the PRO features - you have LIED and STOLEN code in the name of WP.ORG

This will hopefully be recognized by WP Engine and if god wills, remove you from the equation once and for all legally speaking.

Re: Secure Custom Fields by WordPress.org

#174

Earlier quoted context omitted.

This release fixes a separate security vulnerability from the original update.

Can anyone else prove this security vulnerability actually existed?

There is no proof, see my comment above.

Re: Secure Custom Fields by WordPress.org

#175
post #8

We no longer do custom WordPress work --- it turned out to never be worth the hassle --- but when we did, our company used ACF extensively. High quality plugin with responsive support and very fair licensing terms. This --- to me --- smacks of complete bullshit.

It is complete bullshit, but calling ACF high quality is also pretty out there. It's one of those giants in WP that is stuck in the past, arguably much like a lot of core.

It's certainly "high quality" in the sense of "it solves a huge number of requirements that WP core doesn't, in a way that's better that alternative plugins". It's a high quality WP Admin user experience. Just don't try looking too deeply into the database mess it creates.

For WordPress _users_, as in the people who log into the WordPress dashboard to run their website, 'stuck in the past' is often an advantage and not a bad thing. You'll be able to find blog posts and tutorials and youtube showing you how to use in, unlike the "new shiny" where there's no easily found example or support for.

Re: Secure Custom Fields by WordPress.org

#176

Earlier quoted context omitted.

If you point to any lies told by me, I would love to correct them. No one has told me to come here and defend anyone. I work at a part of Automattic that is isolated from anything WordPress — I don’t have to be here. I am defending values I believe in. I am trying to make sure correct information is out there. You are free to not believe that of course.

[flagged]

Some people have better things to do with their life than win internet arguments, man.

Re: Secure Custom Fields by WordPress.org

#177
post #101

Earlier quoted context omitted.

ACF isn’t a premium plugin (linked post only concerns those). The linked post also might not reflect the current policies. This update was a security update and was done due to the unique circumstances around the original publisher.

Exactly. ACF is free and open source. ACF Pro is not. Secure Custom Fields is based on the free version (ACF, without "Pro").

Because WordPress is licensed under the GPL, all plugins must be licensed under GPL-compatible licenses. This applies to ACF Pro as well.

Re: Secure Custom Fields by WordPress.org

#178

Earlier quoted context omitted.

It is complete bullshit, but calling ACF high quality is also pretty out there. It's one of those giants in WP that is stuck in the past, arguably much like a lot of core.

It's certainly "high quality" in the sense of "it solves a huge number of requirements that WP core doesn't, in a way that's better that alternative plugins". It's a high quality WP Admin user experience. Just don't try looking too deeply into the database mess it creates. For WordPress _users_, as in the people who log into the WordPress dashboard to run their website, 'stuck in the past' is often an advantage and n…

I'm not arguing against its usefulness, not at all. The sites I work on use it as well (and abuse, you really shouldn't do complex things with it), though we're looking into replacing it with something custom because the dev experience is bad and the performance isn't great. But for the average small to medium site, it's great, especially because of what you mention: the standard use cases are super well documented by a million people having gone through them before you.

I wouldn't call it high quality though. 200k LOC even for the free version (I use pro), no OOP, global variables, bugs get no attention unless they're major. It was amazing when it first came out, but it has fallen behind even compared to core + other plugins (and the WP average is a very low bar).

It clearly belongs in core, just like 90% of Yoast's (or AIOSEO's, Rank Math') functionality, Redirection and permalinks, and they should have focused on getting that done instead of gutenberg. But also clearly this isn't the way to bring it into core.

Re: Secure Custom Fields by WordPress.org

#179

Earlier quoted context omitted.

What a choice, and what poor timing. Companies that make breaking changes on holiday weekends aren’t going to earn much goodwill from developers.

Nothing has broken. Perhaps WP Engine should have consider that before suing us.

There must be a timeline in which this is de-escalated, compromises are being made and everyone's happy.

In your perspective - what does it look like? What could be done to go the opposite way and keep going?

Also, I'm surprised to see people only siding with WP Engine here. Usually the discussions here are much more balanced.. What do you think could be the reason for it?

Re: Secure Custom Fields by WordPress.org

#180
This is a human being, making a mistake, only to be bullied by literally the whole internet?

Never have I ever witnessed a lynch with any positive consequence whats so ever in my entire life.

Empathy all the way. We all make mistakes. Stay kind and positive.

Post reply on HN