Live data from Hacker News

WordPress.org's latest move involves taking control of a WP Engine plugin

theverge.com

211–220 of 222 posts

Re: WordPress.org's latest move involves taking control of a WP Engine plugin

#211

Earlier quoted context omitted.

Where is it in the license that you need to contribute to the project if you make big bucks? We have open source licenses for a reason, contributing back is never a requirement. If you believe that is his issue, I have a bridge to sell you.

Mullenweg literally said that this was his issue. That’s what kicked off the whole debacle.

At this point there is absolutely no reason to believe Mullenweg.

Re: WordPress.org's latest move involves taking control of a WP Engine plugin

#212
post #177

Earlier quoted context omitted.

This is how users will unknowingly update from ACF to Secure Custom Fields: https://x.com/Brugman/status/1845195750550143424 https://archive.is/u6ZbY

As user how were you affected? Are there any features you can no longer access?

Users will no longer have security updates from the actual makers, and the team that specializes and has built it is not able to touch the code (unless you use theirs)

Re: WordPress.org's latest move involves taking control of a WP Engine plugin

#213
post #58
post #47

Earlier quoted context omitted.

Injecting code that creates misleading or malicious dashboard warnings is a supply chain attack, even if it’s the intent of the supplier and not a malicious third party interfering with the supply chain.

> misleading or malicious dashboard warnings Who did that? WP Engine was the one making these before the change

One of Matt's complaints was that WPE disabled revisions...which JetPack (owned by Automattic) suggests to do in order to improve performance. https://jetpack.com/blog/wordpress-revisions/

I ran servers for an agency with ~1200 WordPress installs on Azure VMs, and I disabled revisions on every one of the sites. How is that different? Did I fiddle too much, despite it being in official documentation on how to do so? Even despite it being actually recommended by Automattic itself for performance improvements? Many of his complaints don't add up. The copyright and WP confusion, I get...but the rest is largely non-sense. Even his Stripe/Woocommerce complaint is largely bunk.

The best outcome is for Matt to step down, Wordpress.org/WP Foundation gets sold to multiple hosting providers (WordPress.com, WPE, 1&1, GoDaddy, etc) and they all commit x amount of money to the project (given it is a very important platform for all of them) and in exchange WPE drops its suit. Unfortunately, I doubt that will happen, because some of this seems very ego driven.

Re: WordPress.org's latest move involves taking control of a WP Engine plugin

#214
post #162

Got a call today from a client I hadn't heard from in 5 years. They use ACF, they use another plugin that WPEngine acquired to move their uploaded files to S3. They're freaking out at all this and worried about how the next thing might impact their business... so they want off WordPress. Thanks for the work, Matt!

a very common story. not just damaging for WP but OS as a whole when it comes to large companies attempting to decide on a stable outcome.

Re: WordPress.org's latest move involves taking control of a WP Engine plugin

#215
post #64

Earlier quoted context omitted.

Yes, no one stopped the co-funder and it's unlikely he did the fork and the change of ownership only by himself. Other people at Automattic are responsible too.

Considering how many people stayed, it's clear that they've been brainwashed to think what he's doing is ok.

In this job market?

Damn, where's common sense and logic?

Re: WordPress.org's latest move involves taking control of a WP Engine plugin

#216
post #13

Earlier quoted context omitted.

> Where is the CVE? What risk is there continuing to use the original plugin? Here’s the diff showing what has changed: https://plugins.trac.wordpress.org/changeset?new=3167679%40a...

wow, they deleted 300 lines, many giving credit to others, just to replace it with > Security - ACF defined Post Type and Taxonomy metabox callbacks no longer have access to $_POST data. (Thanks to the Automattic Security Team for the disclosure) If I was on that security team, I would be livid they used my team's name on this behavior. If this was done by that security team, their ethics are disgusting, and likely n…

Yes, the whole changelog: gone. That's weird. And:

`Author: WP Engine`

is now

`Author: WordPress.org`

Is that even legal? If they had changed to "Maintained by" it would make more sense.

Re: WordPress.org's latest move involves taking control of a WP Engine plugin

#217
post #176

Earlier quoted context omitted.

Who is our in this context? If you are a party to this dispute, why on Earth would you comment publicly?

It really is strange Automattic's lawyers haven't clamped down on any public comment. Have any of WP Engine's people been as free with commentary as Automattic employees have been? If I were an employee at a company being sued I wouldn't say anything related to it even without an order from legal because I wouldn't want to have to risk answering for it in the trial. Why dangle yourself out there as a target for the o…

[deleted]

Re: WordPress.org's latest move involves taking control of a WP Engine plugin

#219
post #13

Earlier quoted context omitted.

> Where is the CVE? What risk is there continuing to use the original plugin? Here’s the diff showing what has changed: https://plugins.trac.wordpress.org/changeset?new=3167679%40a...

wow, they deleted 300 lines, many giving credit to others, just to replace it with > Security - ACF defined Post Type and Taxonomy metabox callbacks no longer have access to $_POST data. (Thanks to the Automattic Security Team for the disclosure) If I was on that security team, I would be livid they used my team's name on this behavior. If this was done by that security team, their ethics are disgusting, and likely n…

Confirmed: that patch was actually authored by ACF.

https://x.com/WordPress/status/1845698272888811775

Re: WordPress.org's latest move involves taking control of a WP Engine plugin

#220

Earlier quoted context omitted.

Not contributing back to the project you're basing your business (eg. the smallest example being infrastructure they are cut off from). Honestly zero sympathy for WP engine, and I don't really see a better way to force them to pay.

They contribute in both plugins, core developers, and conference sponsorships. “Don’t contribute anything” is pure lies from Matt conveniently excluding anything he doesn’t want to count.

I don't know enough about the ecosystem - but mentioning conference sponsorships is enough for me to realize they/you are being dishonest. Conference sponsorships are 100% company promotion, it even gets budgeted towards that.
Post reply on HN