Where's the "attack" part? I thought that was a crucial part in the definition
Considering what Matt has already done, it wouldn't even remotely come as a surprise if a future ACF update would, say, brick all WP installations using ACF on a WP Engine host.
That tactic would work, if WP Engine had access to the update server hosted at wordpress.org.
WordPress have the rights, just like the responsibility and possible liability of everything distrubted on their platform.
At this stage no attack has happened(but can happen)
If a bank messes with your money, you ask for your money when that happens. Not defame the bank based that they updated their database, business as usual, but you liked the old one.
how exactly did they mess with your stuff? where's the attack you're speaking about? where's physical harm?
What money? who did you pay? for what?
Who did that? WP Engine was the one making these before the change
I ran servers for an agency with ~1200 WordPress installs on Azure VMs, and I disabled revisions on every one of the sites. How is that different? Did I fiddle too much, despite it being in official documentation on how to do so? Even despite it being actually recommended by Automattic itself for performance improvements? Many of his complaints don't add up. The copyright and WP confusion, I get...but the rest is largely non-sense. Even his Stripe/Woocommerce complaint is largely bunk.
The best outcome is for Matt to step down, Wordpress.org/WP Foundation gets sold to multiple hosting providers (WordPress.com, WPE, 1&1, GoDaddy, etc) and they all commit x amount of money to the project (given it is a very important platform for all of them) and in exchange WPE drops its suit. Unfortunately, I doubt that will happen, because some of this seems very ego driven.