Live data from Hacker News

WordPress.org's latest move involves taking control of a WP Engine plugin

theverge.com

51–60 of 222 posts

Re: WordPress.org's latest move involves taking control of a WP Engine plugin

#51
post #13

Earlier quoted context omitted.

> Where is the CVE? What risk is there continuing to use the original plugin? Here’s the diff showing what has changed: https://plugins.trac.wordpress.org/changeset?new=3167679%40a...

wow, they deleted 300 lines, many giving credit to others, just to replace it with > Security - ACF defined Post Type and Taxonomy metabox callbacks no longer have access to $_POST data. (Thanks to the Automattic Security Team for the disclosure) If I was on that security team, I would be livid they used my team's name on this behavior. If this was done by that security team, their ethics are disgusting, and likely n…

Wieldy enough, that line likely came from the original developer (ACF/WP Engine) [0].

I believe WordPress.org backported the change and named it v6.3.6.1 at that time [1], before rebranding ACF in a later version (v6.3.6.2).

[0]: https://www.advancedcustomfields.com/changelog/

[1]: https://plugins.trac.wordpress.org/changeset?new=3164480%40a...

Re: WordPress.org's latest move involves taking control of a WP Engine plugin

#52
So, ACF injected notices into everyone's dashboards to push their own legal agenda. It’s a move that reeks of self-interest more than community benefit.

While everyone’s ready to grab their pitchforks at Matt, this actually sounds somewhat reasonable. Still, given its impact, this could easily be seen as a breach of trust. Definitely a move that's going to stir the pot.

Re: WordPress.org's latest move involves taking control of a WP Engine plugin

#53

Even if they find a middle ground to this mess that Matt has created, I very much fear that the damage to the community is done and it's only a matter of time before the popularity of the once famous platform that almost everyone uses in one way or another collapses.

For better or worse, I would optimistically say that that might be a good thing. WordPress has given a lot to the internet over the years, but a very large portion of its giving has been pwned sites and security issues. If this leads to either the birth or popularization of a tool that's modern and secure, that would be a net win for everyone involved.

Re: WordPress.org's latest move involves taking control of a WP Engine plugin

#54
post #31

The appropriate twist here would be to have WPEngine find a trusted third party (one or more), start a foundation together and successfully fork wordpress.

I think Matt would be quite happy with that. His issue is WP Engine not contributing to WordPress. If they decide to maintain a fork and infrastructure, they won't be freeloading anymore. Edit: That attracted a lot of downvotes. I was giving my option in response to the parent comment. In my option Automattic would be happy if they forked it.

Where is it in the license that you need to contribute to the project if you make big bucks? We have open source licenses for a reason, contributing back is never a requirement. If you believe that is his issue, I have a bridge to sell you.

Re: WordPress.org's latest move involves taking control of a WP Engine plugin

#56
post #13

> It’s not clear what security problem Mullenweg is referring to in the post. Where is the CVE? What risk is there continuing to use the original plugin? No details at all. This results in fear: we don't know if the original is safe to use. > Going forward, Secure Custom Fields is now a non-commercial plugin Does this imply that Wordpress is potentially going after a revenue stream from WPEngine? If the plugin had Pr…

> Where is the CVE? What risk is there continuing to use the original plugin? Here’s the diff showing what has changed: https://plugins.trac.wordpress.org/changeset?new=3167679%40a...

I do see various security fixes in that patch, but most of the changes are removing references and code for a "pro" version of the plugin.

I'm guessing the WP security team has been pentesting any WPEngine code they could get their hands on to find an excuse to make all of these changes. The security issues do look bad (once again proving that WordPress' worst vulnerabilities come from the plugins they install) but I think the branding removal is pretty wild.

A quick skim through the plugin development guidelines does seem to indicate that trialware isn't allowed, and the plugin seems to be doing all kinds of other stuff that isn't really permitted by the guidelines. I don't know if WordPress is as strict in enforcing those as they are with this plugin, but the changes do seem to be based on them.

With WPEngine recommending people to install their (vulnerable) version, I once again feel like there's no right side in this conflict. What a mess.

Re: WordPress.org's latest move involves taking control of a WP Engine plugin

#57

They either have some of the best or worst legal counsel; or they just ignore the legal counsel.

They also have the worst social media team I have ever seen: https://x.com/WordPress/status/1845121130207535524

I thought I was reading a tweet from Wendy’s.

Re: WordPress.org's latest move involves taking control of a WP Engine plugin

#58
post #47
post #19

Earlier quoted context omitted.

> supply chain attack. Where's the "attack" part? I thought that was a crucial part in the definition

Injecting code that creates misleading or malicious dashboard warnings is a supply chain attack, even if it’s the intent of the supplier and not a malicious third party interfering with the supply chain.

> misleading or malicious dashboard warnings

Who did that? WP Engine was the one making these before the change

Re: WordPress.org's latest move involves taking control of a WP Engine plugin

#59
post #31

The appropriate twist here would be to have WPEngine find a trusted third party (one or more), start a foundation together and successfully fork wordpress.

If not for Microsoft I'd suggest calling it "Word" , no need for the Press.

What about "Press"?

Re: WordPress.org's latest move involves taking control of a WP Engine plugin

#60

> It’s not clear what security problem Mullenweg is referring to in the post. Where is the CVE? What risk is there continuing to use the original plugin? No details at all. This results in fear: we don't know if the original is safe to use. > Going forward, Secure Custom Fields is now a non-commercial plugin Does this imply that Wordpress is potentially going after a revenue stream from WPEngine? If the plugin had Pr…

> This results in fear: we don't know if the original is safe to use.

The exact result intended by Matt, I presume. He wants to scare WPEngine's customers away from their services.

At this point, this looks more like a war between personalities.

Post reply on HN