Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
DanielLestrange
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
DanielLestrange
2mo ago
The issue affects _all_ models (inclusive the "hidden" guardian codex-auto-review model), and _only_ happens on the PRO plans (both 5x and 20x). It does not, under any circumstances, happen with the PLUS plan. There is a probably
2.
▲
by
DanielLestrange
2y ago
Hey, sorry I was offline a while I think we might agree - and my original wording was tainted by emotions. - indeed, there was changes in code that can be sold as “attempted security fix” - indeed, as I think we both agree, the main securit
3.
▲
by
DanielLestrange
2y ago
Thanks for the reply. Actually that code (I mean the one where they started clearing POSTed data) was the "fix" WPE rushed into during the "grace period". The contract existing before, was that you throw in a user callba
4.
▲
by
DanielLestrange
2y ago
Why do you not actually provide some researched facts? I mean, I am all ears to stand corrected. Yet it appears all you (and other automatticians, and/or else employees) can do is deflect and talk down pretending you know better. Do yo
5.
▲
by
DanielLestrange
2y ago
Are you being sarcastic or a jerk? No issues? At least 50 deleted reviews spoke for themselves! Yeah, you didn’t produce any “technical” issues other than now maintaining a plugin that isn’t yours to start with, gathering thousands of posit
6.
▲
by
DanielLestrange
2y ago
If anything, the problem here is call_user_func, which when an attacker HAS ACCESS TO THE CODE, can be dangerous. How on earth does emptying POST or REQUEST solve anything at all in regards? How on earth does, no matter what crap ACF added
7.
▲
by
DanielLestrange
2y ago
For some context how you MIGHT actually “fix” the true security concern in this code: $allowed_callbacks = ['some_function', 'another_function']; // Example of allowed functions if ( in_array($original_cb, $all
8.
▲
by
DanielLestrange
2y ago
The same. Nothing. The “security” issue here would be that the user callback can access post and request data. Tell me one place in the entire wp code base where that is NOT possible? Security issues can be fixed WITHOUT renaming the plugin
9.
▲
by
DanielLestrange
2y ago
There is no proof, see my comment above.
10.
▲
by
DanielLestrange
2y ago
Unfortunately you have no proof of that, because the only relevant changes are actually neither introducing fixes, nor ever changing the plugin core code in a way that fixes security issues. The only thing done is removing a LOT of referenc
11.
▲
by
DanielLestrange
3y ago
Tal Broda made several war glorifying posts and then removed them. Reports on the subject are being deleted left and right (including HN) as if they were fake news. But they aren’t fake. Archives don’t lie. Every one is entitled to their op
12.
▲
by
DanielLestrange
3y ago
They deleted my comment with the only available somewhat proof … so here it goes again. https://twitter.com/fredberinger/status/492863743030591489?t...
13.
▲
by
DanielLestrange
3y ago
Are you sure? https://twitter.com/fredberinger/status/492863743030591489?t... The original post was deleted but the replies match the screenshots 1:1. This doesn’t appear fake news, specially given the otherwise v