WordPress.org's latest move involves taking control of a WP Engine plugin
31–40 of 222 posts
Re: WordPress.org's latest move involves taking control of a WP Engine plugin
#32Re: WordPress.org's latest move involves taking control of a WP Engine plugin
#33Earlier quoted context omitted.
> Where is the CVE? What risk is there continuing to use the original plugin? Here’s the diff showing what has changed: https://plugins.trac.wordpress.org/changeset?new=3167679%40a...
wow, they deleted 300 lines, many giving credit to others, just to replace it with > Security - ACF defined Post Type and Taxonomy metabox callbacks no longer have access to $_POST data. (Thanks to the Automattic Security Team for the disclosure) If I was on that security team, I would be livid they used my team's name on this behavior. If this was done by that security team, their ethics are disgusting, and likely n…
I don't know how much overlap there is between the Automattic and WP security teams but I assume there's some like with most things in WP.
Re: WordPress.org's latest move involves taking control of a WP Engine plugin
#34Re: WordPress.org's latest move involves taking control of a WP Engine plugin
#35Earlier quoted context omitted.
> supply chain attack. Where's the "attack" part? I thought that was a crucial part in the definition
The author of a library has lost all control over the codebase, and a third party is now making changes to it. That's pretty much the textbook definition of stage one of a supply chain attack. Considering what Matt has already done, it wouldn't even remotely come as a surprise if a future ACF update would, say, brick all WP installations using ACF on a WP Engine host.
That tactic would work, if WP Engine had access to the update server hosted at wordpress.org.
Re: WordPress.org's latest move involves taking control of a WP Engine plugin
#36Hats of to Matt for at least showing some personality and showing a bit of faith.
Now, go build another CMS. Use Rust or Go perhaps and make sure it can scale wildly
Re: WordPress.org's latest move involves taking control of a WP Engine plugin
#37> It’s not clear what security problem Mullenweg is referring to in the post. Where is the CVE? What risk is there continuing to use the original plugin? No details at all. This results in fear: we don't know if the original is safe to use. > Going forward, Secure Custom Fields is now a non-commercial plugin Does this imply that Wordpress is potentially going after a revenue stream from WPEngine? If the plugin had Pr…
> Where is the CVE? What risk is there continuing to use the original plugin? Here’s the diff showing what has changed: https://plugins.trac.wordpress.org/changeset?new=3167679%40a...
Re: WordPress.org's latest move involves taking control of a WP Engine plugin
#38The appropriate twist here would be to have WPEngine find a trusted third party (one or more), start a foundation together and successfully fork wordpress.
Re: WordPress.org's latest move involves taking control of a WP Engine plugin
#39You make an opensource project, provide hosting services, then others take your project, modify it for their needs, cut into your hosting market share and then you try to get rid of them. ...What was the end game plan?
At this point I wouldn't be surprised if he'd had secured funding for a new CMS platform startup and is secretly working on it. He seems absolutely hellbent on assuring nobody should use Wordpress.
Re: WordPress.org's latest move involves taking control of a WP Engine plugin
#40Earlier quoted context omitted.
> supply chain attack. Where's the "attack" part? I thought that was a crucial part in the definition
The author of a library has lost all control over the codebase, and a third party is now making changes to it. That's pretty much the textbook definition of stage one of a supply chain attack. Considering what Matt has already done, it wouldn't even remotely come as a surprise if a future ACF update would, say, brick all WP installations using ACF on a WP Engine host.
WordPress have the rights, just like the responsibility and possible liability of everything distrubted on their platform.