Live data from Hacker News

WordPress.org's latest move involves taking control of a WP Engine plugin

theverge.com

31–40 of 222 posts

Re: WordPress.org's latest move involves taking control of a WP Engine plugin

#32
Even if they find a middle ground to this mess that Matt has created, I very much fear that the damage to the community is done and it's only a matter of time before the popularity of the once famous platform that almost everyone uses in one way or another collapses.

Re: WordPress.org's latest move involves taking control of a WP Engine plugin

#33
post #13

Earlier quoted context omitted.

> Where is the CVE? What risk is there continuing to use the original plugin? Here’s the diff showing what has changed: https://plugins.trac.wordpress.org/changeset?new=3167679%40a...

wow, they deleted 300 lines, many giving credit to others, just to replace it with > Security - ACF defined Post Type and Taxonomy metabox callbacks no longer have access to $_POST data. (Thanks to the Automattic Security Team for the disclosure) If I was on that security team, I would be livid they used my team's name on this behavior. If this was done by that security team, their ethics are disgusting, and likely n…

It's extra funny when you consider all the recent acts where some plugin developer sells his plugin to some shady company, they go and add "functionality" to it that fundamentally changes the plugin, adds forced widgets to users' websites to promote their services etc, and the WP security team is like "they're allowed to do that, that's perfectly fine".

I don't know how much overlap there is between the Automattic and WP security teams but I assume there's some like with most things in WP.

Re: WordPress.org's latest move involves taking control of a WP Engine plugin

#34

They either have some of the best or worst legal counsel; or they just ignore the legal counsel.

They also have the worst social media team I have ever seen: https://x.com/WordPress/status/1845121130207535524

Mullengweg taking a leaf out of Musk PR playbook, clearly.

Re: WordPress.org's latest move involves taking control of a WP Engine plugin

#35
post #25
post #19

Earlier quoted context omitted.

> supply chain attack. Where's the "attack" part? I thought that was a crucial part in the definition

The author of a library has lost all control over the codebase, and a third party is now making changes to it. That's pretty much the textbook definition of stage one of a supply chain attack. Considering what Matt has already done, it wouldn't even remotely come as a surprise if a future ACF update would, say, brick all WP installations using ACF on a WP Engine host.

> brick all WP installations using ACF on a WP Engine host

That tactic would work, if WP Engine had access to the update server hosted at wordpress.org.

Re: WordPress.org's latest move involves taking control of a WP Engine plugin

#36
I like this whole so-called debate because it mostly shows that if 40% of Websites can be run on top WP then there is clear telling that we either haven't gone very far as an industry or that people that make websites couldn't give less fucks about who owns what plugin and what the fuck else people are yapping about.

Hats of to Matt for at least showing some personality and showing a bit of faith.

Now, go build another CMS. Use Rust or Go perhaps and make sure it can scale wildly

Re: WordPress.org's latest move involves taking control of a WP Engine plugin

#37
post #13

> It’s not clear what security problem Mullenweg is referring to in the post. Where is the CVE? What risk is there continuing to use the original plugin? No details at all. This results in fear: we don't know if the original is safe to use. > Going forward, Secure Custom Fields is now a non-commercial plugin Does this imply that Wordpress is potentially going after a revenue stream from WPEngine? If the plugin had Pr…

> Where is the CVE? What risk is there continuing to use the original plugin? Here’s the diff showing what has changed: https://plugins.trac.wordpress.org/changeset?new=3167679%40a...

For those reviewing the changeset: There are two places where they read a value directly from $POST into an $args array. There is no validation applied, which means an attacker can inject whatever value they wish.

Re: WordPress.org's latest move involves taking control of a WP Engine plugin

#38
post #31

The appropriate twist here would be to have WPEngine find a trusted third party (one or more), start a foundation together and successfully fork wordpress.

If not for Microsoft I'd suggest calling it "Word", no need for the Press.

Re: WordPress.org's latest move involves taking control of a WP Engine plugin

#39

You make an opensource project, provide hosting services, then others take your project, modify it for their needs, cut into your hosting market share and then you try to get rid of them. ...What was the end game plan?

At this point I wouldn't be surprised if he'd had secured funding for a new CMS platform startup and is secretly working on it. He seems absolutely hellbent on assuring nobody should use Wordpress.

After this, who would trust his second try?

Re: WordPress.org's latest move involves taking control of a WP Engine plugin

#40
post #25
post #19

Earlier quoted context omitted.

> supply chain attack. Where's the "attack" part? I thought that was a crucial part in the definition

The author of a library has lost all control over the codebase, and a third party is now making changes to it. That's pretty much the textbook definition of stage one of a supply chain attack. Considering what Matt has already done, it wouldn't even remotely come as a surprise if a future ACF update would, say, brick all WP installations using ACF on a WP Engine host.

It's like claiming going to the bank is stage one in a robbery. So if you go to the bank you're a thief.

WordPress have the rights, just like the responsibility and possible liability of everything distrubted on their platform.

Post reply on HN