[HN Gopher] Did Automattic commit open source theft?
___________________________________________________________________
Did Automattic commit open source theft?
Author : ValentineC
Score : 61 points
Date : 2024-10-19 16:33 UTC (6 hours ago)
(HTM) web link (blog.pragmaticengineer.com)
(TXT) w3m dump (blog.pragmaticengineer.com)
| paulgb wrote:
| > Amusingly, in its war against WP Engine, Automattic might have
| created the single best advertisement for their chief rival. WP
| Engine now has proof it's immune to unauthorized plugin takeover.
|
| This is a great point. By weaponizing the fact that Automatic
| controls the plugin registry against a rival by doing something
| (at best) dangerously adjacent to a supply chain attack, WP
| Engine stands out now as uniquely immune to that type of attack.
|
| This whole thing makes me sad, I used to use wordpress back in
| the 2000s and even had some plugins in the directory at the time.
| I was rooting for Matt but the more I read about this the more it
| seems like Automattic isn't the good actor here.
| badlibrarian wrote:
| Once the self-sabotage is over perhaps we can dig into the self-
| dealing.
| icodemuch wrote:
| This seems like a pretty damning indictment of Automattic. The
| WordPress foundation (that they presumably set up) may have rules
| that give them legal cover for some of the moves they're making,
| but it's going to hurt them in the court of public opinion. I
| think that matters to developers, who are the people ultimately
| responsible for choosing whether or not to contribute to / use
| their product. It's true that migration cost might prevent churn
| from these actions right now but stopping the train of logic
| there seems short sighted. What about all the business that they
| may have received in the future that they might not get now
| because they've tarnished their brand?
| benatkin wrote:
| I don't see it catching on that this is a "supply-chain attack"
| (from the article, but what came to mind when you said that it
| seems pretty damning). It isn't an attack because it's done
| deliberately by the owner (yes, owner) of the platform users
| are downloading from and not some upstream platform. The part
| of the _chain_ involved is only one level deep. Maybe it 's
| time to stop hyping up the term "software supply chain" because
| it gives me _You Wouldn 't Download a Car_ vibes.
|
| Judged on its merits and not an exaggeration, I predict that
| the court of public opinion is going to go the same way as the
| court of law - a light pushback.
| labster wrote:
| It's only technically a supply chain attack. Pretty much all
| they did was apply a security patch and remove the other
| company's IP. It doesn't really attack a user or put anyone
| at risk, which is what you normally mean with an attack, so
| it sounds hyperbolic.
|
| That said it is absolutely scummy and dumb, and a sign that
| Automattic puts its own whims ahead of its clients'
| stability. Even if this issue gets settled tomorrow, we now
| know that Automattic is an irrational actor. Who is going to
| choose a software platform for new projects where every week
| a new drama unfolds?
| benatkin wrote:
| > Automattic is an irrational actor
|
| They're more human than the WP Engines of the world,
| though.
| labster wrote:
| Indeed. To err is human.
|
| No one wants to talk about what WP Engine does, because
| Matt is making own-goals twice a week.
| WorldWideWebb wrote:
| How is this not a supply chain attack? Mattomatic literally
| took over a plugin that WPE owns/maintains by co-opting its
| plugin URL/slug. They renamed the plugin but took control
| over the URL that everyone's plugin points to for updates.
| Literal MITM attack.
| benatkin wrote:
| wordpress.org isn't an intermediary, they're the publisher,
| so they can't be in the middle, and they can't be MITM
|
| Now, the owner of a package could do a supply chain attack
| (with a very short chain which is why I think the concept
| is overhyped), and it would be a supply chain attack, but
| it wouldn't be a man in the middle attack. WordPress took
| over ownership of it but they haven't published malicious
| to it. Back when WP Engine owned it they could have
| published a malicious update and it would be a supply chain
| attack but with a very short chain unless the user
| installed a project that depended on it and caused it to
| automatically be installed.
| WorldWideWebb wrote:
| Wordpress.org is not the publisher of that plugin - WPE
| is. Wordpress.org was just hosting it in their plugin
| directory, which is where just about the entire community
| goes to for plugins. I'd guess that because of this
| drama, more plugin publishers will choose to not publish
| theirs in the directory anymore.
|
| https://www.advancedcustomfields.com
| benatkin wrote:
| I'll use npm as an example. When someone not at npm runs
| npm publish, their npm client sends a request for their
| package to be published, which to me shows that the
| person isn't the publisher because they aren't requesting
| for themselves to publish the package. But I see how it
| might be confusing.
| drchaos wrote:
| If npm or Ubuntu would deliberately replace a package
| with their own implementation, without giving you notice
| or making this opt-in, would you call that a supply-chain
| attack? I would, unless the original package contained
| malicious code (which is not the case with WPE's custom
| fields plugin)
| SahAssar wrote:
| Regardless of all else I'm hoping we can all agree on:
|
| * The wordpress foundation (and wordpress.org) is not independent
| enough from Matt & Automattic
|
| * taking over a package in a package registry with automatic
| updates is really, really bad
| benatkin wrote:
| > The wordpress foundation (and wordpress.org) is not
| independent enough from Matt & Automattic
|
| I see people call for this, and I'd like to see that energy
| used to call for antitrust against Facebook, which grew at the
| same time as WordPress. https://en.wikipedia.org/wiki/Federal_T
| rade_Commission_v._Me....
|
| I don't think they meant to express the intention of it being
| independent when creating a nonprofit. I think they just
| created a nonprofit because that's what made the most sense of
| the available options. I think a B Corp is more along the lines
| of what was intended.
| SahAssar wrote:
| I don't think anyone thinks of Meta or Facebook products as
| open-source in the same way as WordPress (they have open
| source projects but none that are as core to their business
| as WordPress is to Automattic).
|
| Even now it seems like Matt is trying to shroud himself in
| open-source as a defense. If so the foundation should be more
| independent.
| stevenicr wrote:
| The title made me wonder where they would go with this,
|
| then it starts with "Imagine Apple decided Spotify was a big
| enough business threat that it had to take unfair measures to
| limit Spotify's growth on the App Store."
|
| Um, okay - apple's store is not open, and spotify is not open
| source - so the article is over in it's first line..
|
| but let go further
|
| Lock Spotify out of its developer ecosystem - sharecropping on
| someone else's land has risks - good thing about then a plugin or
| theme gets kicked out of wordpress.org's system is that WP users
| can "sideload" from anywhere with any sort of 'jailbreaking', you
| don't even need to click/tap 'it's okay to load from outside
| sources' (point 1 from the story)
|
| point 3 - this is completely false - see
| https://wordpress.org/news/ - and everyone got to see news about
| this in the wp-admin dashbaord (I think I recall from more than
| one source)
|
| the other 4 points are eye-roll worthy from me, again see point
| one.
|
| This is not the first time a similar thing has happened with the
| wordpress plugin or theme directory.
|
| The rest of this post is clearly very one sided and includes
| other falsehoods such as "The response was universally negative:"
|
| Growing tired of the article, I scroll and I see a headline "Is
| WP Engine the only enterprise-ready WordPress hosting provider
| left"
|
| are you kidding me?
|
| Disagree with the entire piece.
|
| and a return how about "Imagine Apple decided Spotify was a big
| enough business"... that they could easily afford to pay 30% of
| the proceeds they make from an app that lives in their ecosystem
| so that Apple can continue to develop, secure and grow
|
| - so that the app could enjoy those benefits and all can grow..
| and if they didn't pay up, they get kicked out of the Apple
| store, I mean that would be outrageous!
|
| And you could re-write the article replacing automatic with
| apple.. oh wait.
| pessimizer wrote:
| > then it starts with "Imagine Apple decided Spotify was a big
| enough business threat that it had to take unfair measures to
| limit Spotify's growth on the App Store."
|
| > Um, okay - apple's store is not open, and spotify is not open
| source - so the article is over in it's first line..
|
| Exactly. "Imagine that Apple wrote a GPL streaming music app,
| and Spotify was a redistributor of that app with almost no
| changes, but also used some of their own infrastructure to
| serve part of the backend of their fork. Now imagine that the
| reseller started doing nearly as much business as Apple with
| the app, but barely contributed any code. Apple asks Spotify to
| contribute more, Spotify replies 'lol.' Then, Apple tells
| Spotify that they can't call their fork 'Apple Music' anymore,
| and bans the Spotify fork from relying on Apple's infra for
| what Spotify doesn't find profitable to do."
| cycomanic wrote:
| It's worth pointing out that even Apple (whom the auther uses as
| an exam to illustrate the point) has engaged in similar behavior.
| Not quite as bad, i.e. they didn't take over an app, but they
| have suddenly blocked apps from updating when the app had similar
| functionality to one they released.
| SahAssar wrote:
| That is not as bad, taking the url, auto-updates, reviews, etc.
| makes it so much worse. Apple might be anticompetitive, but
| replacing the app via auto updates is really bad.
| pessimizer wrote:
| This debate is extremely dumb, and everybody gish gallops and
| implies something terrible when they try to explain what
| Automattic is doing wrong, because they can't figure it out. So
| they instead give reasons why they insist it will be bad for his
| business (isn't that his business?) and pretend like that's him
| "technically" not doing anything tortious. It's not technical,
| the lawsuit from WPE is there to read. It's silly, and if it's
| not thrown out it will be because the judge needs time to
| understand the complexities of the license (and the promise that
| "Wordpress" will be turned over to the community _after
| Automattic, who has an exclusive license to the trademark, shuts
| down_.)
|
| Using the reasons that you think this is a bad business decision
| as proxy reasons why he's _wronged_ everyone making a living from
| his work is a veiled threat. Don 't threaten to leave, just
| leave.
|
| Maybe the problem is this haunting by the "Spirit of Open Source"
| where people insist that they have all of these rights that
| aren't in the license. Wordpress _is not open source._ It is Free
| Software. You already own it. Fork it if you want. If WPEngine is
| already doing almost as much business as Wordpress.com, they can
| handle everything themselves. If people love WPEngine more, they
| can leave. Don 't whine when the value proposition for WPEngine
| changes after they have to take care of everything themselves,
| and they start violating the _Spirit of Open Source_ until their
| bottom line looks better again.
|
| I'm swearing an oath to violate the Spirit of Open Source
| wherever I see a hint of it, I'm just sticking to the licenses.
| The Spirit of Open Source somehow makes already wealthy people
| feel entitled to everything in the world. Free Software is
| important to me, and the people who make it should be as
| aggressive as will financially benefit them, as long as they
| abide by _the letter_ of the GPL. The software is what 's
| important, not that your half-billion dollar business is built on
| top of somebody else's half-billion dollar business. That's a
| you-problem.
|
| Also, this is just straight up abuser behavior towards this guy.
| He doesn't do what you want with what is his, so you degrade him
| and accuse him of stealing his own property. It's hard to watch.
|
| I'm going to stop commenting on these threads, but this mobbing
| is ridiculous. I hope he's emotionally stable; but a lot of tech
| CEOs aren't, and his awkward reactions to the pitchforks don't
| give me confidence. If you're compulsively reading all of these
| threads, stop now. Stay strong and know that 95% of this is
| coming from people who are directly connected to this financially
| and just don't want to be inconvenienced.
| mediumsmart wrote:
| maybe they made a commit to some open source that they stole in
| broad daylight.
| pushedx wrote:
| Under which open source license was ACF originally released? That
| would help to answer the question.
| yurishimo wrote:
| GPL. All WordPress code is GPL and plug-ins need to call WP
| APIs to register themselves with the CMS.
| yoddler wrote:
| WPEngine blows, I hope they die somehow
___________________________________________________________________
(page generated 2024-10-19 23:01 UTC)