Automattic turns to weaponizing responsible disclosure against WP Engine
twitter.com
twitter.com
Basically:
1. Ban them from updating the plugin.
2. "btw, here's a CVE for that plugin, you have 30 days until it gets removed or ownership changed."
You can guess what's going to happen next... "Oh, they didn't fix their plugin, the repo is now owned by Automattic."
Given Matt isn't doing it, I'm of the opinion that he is using it maliciously.
Not sure, I'm not a lawyer.
Couple that with Matt's clearly hinting post earlier today[0] and it really feels... calculated. Just another thing for them to throw on the lawsuit I guess.
[0]: https://x.com/photomatt/status/1842500184825090060
> What are the best alternatives to Advanced Custom Fields @wp_acf for people who want to switch away? Is there an easy way to migrate?
> I suspect there are going to be millions of sites moving away from it in the coming weeks.
There is no way this wasn't done in bad faith. I'd have to wonder if it's also crossed the line legally as well, due to being done in bad faith.
I actually struggled with a good one and felt this is the most fair take when seen in context of
A) Matt's post <8 hours before this disclosure saying
> "I suspect there are going to be millions of sites moving away from it in the coming weeks."[0].
B) WordPress has banned WP Engine from updating the plugin on the repo.
I would have liked to make it "WP-Engine-developed plugin" or something like that because it's not specifically a WP Engine plugin, but the title length limit is 80 chars, right?
(Copied from here: https://news.ycombinator.com/item?id=41753687)
Why is it unseemly for Automattic to find this bug?
Matt (CEO of Automattic) tries to get WP Engine to contribute more to WordPress development, including stuff close to blackmail
WP Engine sends a cease and desist
Automattic sends cease and desist to WP Engine claiming Trademark infringement
Automattic bans Access of WP Engine customers to WordPress servers, breaking plugin updates (which was temporarily reinstated and then banned after a deadline of a few days)
WP Engine sues Automattic
Automattic has a program where employees can leave until a deadline and get a severance payout if they are unhappy with the management.
Here's an article about it: https://techcrunch.com/2024/10/04/wordpress-vs-wp-engine-dra...
Essentially they are announcing a CVE on software while holding the fix for it hostage to normal users.
Leverage.
Make of that what you will.
A cursory google search reveals the CEO of Automattic did not go to business school, and in fact dropped out of undergraduate studies.
What exactly does this situation have to do with business schools, and the extremely-generic term "leverage"?
This same thread has already seen the next step in the playbook, too: reassign ownership of plugins that have high-severity CVEs open for more than 30 days, in the name of protecting the product, its integrity, and the community. The blunt word for that would be "theft".
Just like a sibling comment to yours rightly called this tactic "extortion".
Extortion
So should everyone have to pay then? Everyone who uses the software uses the servers. If not what's the threshold? And remember that Matt has insisted WordPress.org ("those servers") belong to him personally, not to WordPress or to Automattic.
If you're going to monetize access to plugins and themes produced from volunteer work on your open source code... can they monetize too? Does everyone get a cut?
Making this configurable is something he has explicitly rejected:
> > When do you plan to add support in the admin UI for alternate source urls for plugins and themes, so that others can more effectively mirror your apparently overtaxed infrastructure?
> Why would I build that? The built-in source works great, for tens of millions of servers.
Summarized from the following article: https://github.com/microsoft/vscode/wiki/Differences-between...
If your whole business depends on leeching off of someone else’s servers, you should probably be contributing to those servers in some way.