5 ms·
> supply chain attack. Where's the "attack" part? I thought that was a crucial part in the definition
by shprd 2y ago
> supply chain attack.
Where's the "attack" part? I thought that was a crucial part in the definition
- crote 2y agoThe author of a library has lost all control over the codebase, and a third party is now making changes to it. That's pretty much the textbook definition of stage one of a supply chain attack. Considering what Matt has already done, it wouldn't even remotely come as a surprise if a future ACF update would, say, brick all WP installations using ACF on a WP Engine host.
- mimsee 2y ago> brick all WP installations using ACF on a WP Engine host That tactic would work, if WP Engine had access to the update server hosted at wordpress.org.
- shprd 2y agoIt's like claiming going to the bank is stage one in a robbery. So if you go to the bank you're a thief. WordPress have the rights, just like the responsibility and possible liability of everything distrubted on their platform.
- chucky123 2y agoIt's more like gaining backdoor access to the bank's server. At this stage no attack has happened(but can happen)
- shprd 2y agoThey didn't gain access anywhere, it's their platform.
- immibis 2y agoIf the bank starts fiddling with the numbers in your account: "I'm not being attacked, it's their database"
- shprd 2y ago> bank starts fiddling with the numbers in your account If a bank messes with your money, you ask for your money when that happens. Not defame the bank based that they updated their database, business as usual, but you liked the old one. how exactly did they mess with your stuff? where's the attack you're speaking about? where's physical harm?
- rbanffy 2y agoInjecting code that creates misleading or malicious dashboard warnings is a supply chain attack, even if it’s the intent of the supplier and not a malicious third party interfering with the supply chain.
- shprd 2y ago> misleading or malicious dashboard warnings Who did that? WP Engine was the one making these before the change
- throw16180339 2y agoMatt did when he posted his vitriolic rant to every WordPress install.
- partiallypro 2y agoOne of Matt's complaints was that WPE disabled revisions...which JetPack (owned by Automattic) suggests to do in order to improve performance. https://jetpack.com/blog/wordpress-revisions/ https://jetpack.com/blog/wordpress-revisions/ I ran servers for an agency with ~1200 WordPress installs on Azure VMs, and I disabled revisions on every one of the sites. How is that different? Did I fiddle too much, despite it being in official documentation on how to do so? Even despite it being actually recommended by Automattic itself for performance improvements? Many of his complaints don't add up. The copyright and WP confusion, I get...but the rest is largely non-sense. Even his Stripe/Woocommerce complaint is largely bunk. The best outcome is for Matt to step down, Wordpress.org/WP Foundation gets sold to multiple hosting providers (WordPress.com, WPE, 1&1, GoDaddy, etc) and they all commit x amount of money to the project (given it is a very important platform for all of them) and in exchange WPE drops its suit. Unfortunately, I doubt that will happen, because some of this seems very ego driven.
- DonnieBurger 2y agoThis is how users will unknowingly update from ACF to Secure Custom Fields: https://x.com/Brugman/status/1845195750550143424 https://x.com/Brugman/status/1845195750550143424 https://archive.is/u6ZbY https://archive.is/u6ZbY
- shprd 2y agoAs user how were you affected? Are there any features you can no longer access?
- partiallypro 2y agoUsers will no longer have security updates from the actual makers, and the team that specializes and has built it is not able to touch the code (unless you use theirs)