Live data from Hacker News

WordPress.org's latest move involves taking control of a WP Engine plugin

theverge.com

41–50 of 222 posts

Re: WordPress.org's latest move involves taking control of a WP Engine plugin

#41
post #37
post #13

Earlier quoted context omitted.

> Where is the CVE? What risk is there continuing to use the original plugin? Here’s the diff showing what has changed: https://plugins.trac.wordpress.org/changeset?new=3167679%40a...

For those reviewing the changeset: There are two places where they read a value directly from $POST into an $args array. There is no validation applied, which means an attacker can inject whatever value they wish.

In 2024, wtf. How can anyone especially on software with this kind of reach still do such absolute amateur things?

Re: WordPress.org's latest move involves taking control of a WP Engine plugin

#42
post #31

The appropriate twist here would be to have WPEngine find a trusted third party (one or more), start a foundation together and successfully fork wordpress.

I think Matt would be quite happy with that. His issue is WP Engine not contributing to WordPress. If they decide to maintain a fork and infrastructure, they won't be freeloading anymore.

Edit: That attracted a lot of downvotes. I was giving my option in response to the parent comment. In my option Automattic would be happy if they forked it.

Re: WordPress.org's latest move involves taking control of a WP Engine plugin

#43

I just cancelled my ACF subscription as it's up for renewal in 30 days. I'll wait and see how the dust settles.

My advice would be to make plans to move away from WordPress entirely. While I think that the “supply chain attack” is hyperbolic, if technically true, it’s indicative of an organization that cares about winning more than ensuring any form of stability whatsoever to their users and clients. Beware.

Re: WordPress.org's latest move involves taking control of a WP Engine plugin

#45
post #39

Earlier quoted context omitted.

At this point I wouldn't be surprised if he'd had secured funding for a new CMS platform startup and is secretly working on it. He seems absolutely hellbent on assuring nobody should use Wordpress.

After this, who would trust his second try?

I certainly wouldn't, true.

Re: WordPress.org's latest move involves taking control of a WP Engine plugin

#46
post #31

The appropriate twist here would be to have WPEngine find a trusted third party (one or more), start a foundation together and successfully fork wordpress.

I think Matt would be quite happy with that. His issue is WP Engine not contributing to WordPress. If they decide to maintain a fork and infrastructure, they won't be freeloading anymore. Edit: That attracted a lot of downvotes. I was giving my option in response to the parent comment. In my option Automattic would be happy if they forked it.

If the new project offers a more stable platform, one that cannot be controlled by a single person, the community might like that more and might move; then there will be little left to freeload.

Is that an option btw? I.e. is it possible to offer hosting with seamless migration from wordpress.org?

Re: WordPress.org's latest move involves taking control of a WP Engine plugin

#47
post #19
post #10

Mullenweg is hijacking existing users with supply chain attack.

> supply chain attack. Where's the "attack" part? I thought that was a crucial part in the definition

Injecting code that creates misleading or malicious dashboard warnings is a supply chain attack, even if it’s the intent of the supplier and not a malicious third party interfering with the supply chain.

Re: WordPress.org's latest move involves taking control of a WP Engine plugin

#48
post #40
post #25

Earlier quoted context omitted.

The author of a library has lost all control over the codebase, and a third party is now making changes to it. That's pretty much the textbook definition of stage one of a supply chain attack. Considering what Matt has already done, it wouldn't even remotely come as a surprise if a future ACF update would, say, brick all WP installations using ACF on a WP Engine host.

It's like claiming going to the bank is stage one in a robbery. So if you go to the bank you're a thief. WordPress have the rights, just like the responsibility and possible liability of everything distrubted on their platform.

It's more like gaining backdoor access to the bank's server.

At this stage no attack has happened(but can happen)

Re: WordPress.org's latest move involves taking control of a WP Engine plugin

#49

They either have some of the best or worst legal counsel; or they just ignore the legal counsel.

One of Automattic’s statements was issued by Neal Katyal, who was Acting Solicitor General of the United States. I would tend towards thinking the client himself may be the problem.

Re: WordPress.org's latest move involves taking control of a WP Engine plugin

#50
post #40

Earlier quoted context omitted.

It's like claiming going to the bank is stage one in a robbery. So if you go to the bank you're a thief. WordPress have the rights, just like the responsibility and possible liability of everything distrubted on their platform.

It's more like gaining backdoor access to the bank's server. At this stage no attack has happened(but can happen)

They didn't gain access anywhere, it's their platform.
Post reply on HN