[HN Gopher] Did Automattic commit open source theft?
       ___________________________________________________________________
        
       Did Automattic commit open source theft?
        
       Author : ValentineC
       Score  : 61 points
       Date   : 2024-10-19 16:33 UTC (6 hours ago)
        
 (HTM) web link (blog.pragmaticengineer.com)
 (TXT) w3m dump (blog.pragmaticengineer.com)
        
       | paulgb wrote:
       | > Amusingly, in its war against WP Engine, Automattic might have
       | created the single best advertisement for their chief rival. WP
       | Engine now has proof it's immune to unauthorized plugin takeover.
       | 
       | This is a great point. By weaponizing the fact that Automatic
       | controls the plugin registry against a rival by doing something
       | (at best) dangerously adjacent to a supply chain attack, WP
       | Engine stands out now as uniquely immune to that type of attack.
       | 
       | This whole thing makes me sad, I used to use wordpress back in
       | the 2000s and even had some plugins in the directory at the time.
       | I was rooting for Matt but the more I read about this the more it
       | seems like Automattic isn't the good actor here.
        
       | badlibrarian wrote:
       | Once the self-sabotage is over perhaps we can dig into the self-
       | dealing.
        
       | icodemuch wrote:
       | This seems like a pretty damning indictment of Automattic. The
       | WordPress foundation (that they presumably set up) may have rules
       | that give them legal cover for some of the moves they're making,
       | but it's going to hurt them in the court of public opinion. I
       | think that matters to developers, who are the people ultimately
       | responsible for choosing whether or not to contribute to / use
       | their product. It's true that migration cost might prevent churn
       | from these actions right now but stopping the train of logic
       | there seems short sighted. What about all the business that they
       | may have received in the future that they might not get now
       | because they've tarnished their brand?
        
         | benatkin wrote:
         | I don't see it catching on that this is a "supply-chain attack"
         | (from the article, but what came to mind when you said that it
         | seems pretty damning). It isn't an attack because it's done
         | deliberately by the owner (yes, owner) of the platform users
         | are downloading from and not some upstream platform. The part
         | of the _chain_ involved is only one level deep. Maybe it 's
         | time to stop hyping up the term "software supply chain" because
         | it gives me _You Wouldn 't Download a Car_ vibes.
         | 
         | Judged on its merits and not an exaggeration, I predict that
         | the court of public opinion is going to go the same way as the
         | court of law - a light pushback.
        
           | labster wrote:
           | It's only technically a supply chain attack. Pretty much all
           | they did was apply a security patch and remove the other
           | company's IP. It doesn't really attack a user or put anyone
           | at risk, which is what you normally mean with an attack, so
           | it sounds hyperbolic.
           | 
           | That said it is absolutely scummy and dumb, and a sign that
           | Automattic puts its own whims ahead of its clients'
           | stability. Even if this issue gets settled tomorrow, we now
           | know that Automattic is an irrational actor. Who is going to
           | choose a software platform for new projects where every week
           | a new drama unfolds?
        
             | benatkin wrote:
             | > Automattic is an irrational actor
             | 
             | They're more human than the WP Engines of the world,
             | though.
        
               | labster wrote:
               | Indeed. To err is human.
               | 
               | No one wants to talk about what WP Engine does, because
               | Matt is making own-goals twice a week.
        
           | WorldWideWebb wrote:
           | How is this not a supply chain attack? Mattomatic literally
           | took over a plugin that WPE owns/maintains by co-opting its
           | plugin URL/slug. They renamed the plugin but took control
           | over the URL that everyone's plugin points to for updates.
           | Literal MITM attack.
        
             | benatkin wrote:
             | wordpress.org isn't an intermediary, they're the publisher,
             | so they can't be in the middle, and they can't be MITM
             | 
             | Now, the owner of a package could do a supply chain attack
             | (with a very short chain which is why I think the concept
             | is overhyped), and it would be a supply chain attack, but
             | it wouldn't be a man in the middle attack. WordPress took
             | over ownership of it but they haven't published malicious
             | to it. Back when WP Engine owned it they could have
             | published a malicious update and it would be a supply chain
             | attack but with a very short chain unless the user
             | installed a project that depended on it and caused it to
             | automatically be installed.
        
               | WorldWideWebb wrote:
               | Wordpress.org is not the publisher of that plugin - WPE
               | is. Wordpress.org was just hosting it in their plugin
               | directory, which is where just about the entire community
               | goes to for plugins. I'd guess that because of this
               | drama, more plugin publishers will choose to not publish
               | theirs in the directory anymore.
               | 
               | https://www.advancedcustomfields.com
        
               | benatkin wrote:
               | I'll use npm as an example. When someone not at npm runs
               | npm publish, their npm client sends a request for their
               | package to be published, which to me shows that the
               | person isn't the publisher because they aren't requesting
               | for themselves to publish the package. But I see how it
               | might be confusing.
        
               | drchaos wrote:
               | If npm or Ubuntu would deliberately replace a package
               | with their own implementation, without giving you notice
               | or making this opt-in, would you call that a supply-chain
               | attack? I would, unless the original package contained
               | malicious code (which is not the case with WPE's custom
               | fields plugin)
        
       | SahAssar wrote:
       | Regardless of all else I'm hoping we can all agree on:
       | 
       | * The wordpress foundation (and wordpress.org) is not independent
       | enough from Matt & Automattic
       | 
       | * taking over a package in a package registry with automatic
       | updates is really, really bad
        
         | benatkin wrote:
         | > The wordpress foundation (and wordpress.org) is not
         | independent enough from Matt & Automattic
         | 
         | I see people call for this, and I'd like to see that energy
         | used to call for antitrust against Facebook, which grew at the
         | same time as WordPress. https://en.wikipedia.org/wiki/Federal_T
         | rade_Commission_v._Me....
         | 
         | I don't think they meant to express the intention of it being
         | independent when creating a nonprofit. I think they just
         | created a nonprofit because that's what made the most sense of
         | the available options. I think a B Corp is more along the lines
         | of what was intended.
        
           | SahAssar wrote:
           | I don't think anyone thinks of Meta or Facebook products as
           | open-source in the same way as WordPress (they have open
           | source projects but none that are as core to their business
           | as WordPress is to Automattic).
           | 
           | Even now it seems like Matt is trying to shroud himself in
           | open-source as a defense. If so the foundation should be more
           | independent.
        
       | stevenicr wrote:
       | The title made me wonder where they would go with this,
       | 
       | then it starts with "Imagine Apple decided Spotify was a big
       | enough business threat that it had to take unfair measures to
       | limit Spotify's growth on the App Store."
       | 
       | Um, okay - apple's store is not open, and spotify is not open
       | source - so the article is over in it's first line..
       | 
       | but let go further
       | 
       | Lock Spotify out of its developer ecosystem - sharecropping on
       | someone else's land has risks - good thing about then a plugin or
       | theme gets kicked out of wordpress.org's system is that WP users
       | can "sideload" from anywhere with any sort of 'jailbreaking', you
       | don't even need to click/tap 'it's okay to load from outside
       | sources' (point 1 from the story)
       | 
       | point 3 - this is completely false - see
       | https://wordpress.org/news/ - and everyone got to see news about
       | this in the wp-admin dashbaord (I think I recall from more than
       | one source)
       | 
       | the other 4 points are eye-roll worthy from me, again see point
       | one.
       | 
       | This is not the first time a similar thing has happened with the
       | wordpress plugin or theme directory.
       | 
       | The rest of this post is clearly very one sided and includes
       | other falsehoods such as "The response was universally negative:"
       | 
       | Growing tired of the article, I scroll and I see a headline "Is
       | WP Engine the only enterprise-ready WordPress hosting provider
       | left"
       | 
       | are you kidding me?
       | 
       | Disagree with the entire piece.
       | 
       | and a return how about "Imagine Apple decided Spotify was a big
       | enough business"... that they could easily afford to pay 30% of
       | the proceeds they make from an app that lives in their ecosystem
       | so that Apple can continue to develop, secure and grow
       | 
       | - so that the app could enjoy those benefits and all can grow..
       | and if they didn't pay up, they get kicked out of the Apple
       | store, I mean that would be outrageous!
       | 
       | And you could re-write the article replacing automatic with
       | apple.. oh wait.
        
         | pessimizer wrote:
         | > then it starts with "Imagine Apple decided Spotify was a big
         | enough business threat that it had to take unfair measures to
         | limit Spotify's growth on the App Store."
         | 
         | > Um, okay - apple's store is not open, and spotify is not open
         | source - so the article is over in it's first line..
         | 
         | Exactly. "Imagine that Apple wrote a GPL streaming music app,
         | and Spotify was a redistributor of that app with almost no
         | changes, but also used some of their own infrastructure to
         | serve part of the backend of their fork. Now imagine that the
         | reseller started doing nearly as much business as Apple with
         | the app, but barely contributed any code. Apple asks Spotify to
         | contribute more, Spotify replies 'lol.' Then, Apple tells
         | Spotify that they can't call their fork 'Apple Music' anymore,
         | and bans the Spotify fork from relying on Apple's infra for
         | what Spotify doesn't find profitable to do."
        
       | cycomanic wrote:
       | It's worth pointing out that even Apple (whom the auther uses as
       | an exam to illustrate the point) has engaged in similar behavior.
       | Not quite as bad, i.e. they didn't take over an app, but they
       | have suddenly blocked apps from updating when the app had similar
       | functionality to one they released.
        
         | SahAssar wrote:
         | That is not as bad, taking the url, auto-updates, reviews, etc.
         | makes it so much worse. Apple might be anticompetitive, but
         | replacing the app via auto updates is really bad.
        
       | pessimizer wrote:
       | This debate is extremely dumb, and everybody gish gallops and
       | implies something terrible when they try to explain what
       | Automattic is doing wrong, because they can't figure it out. So
       | they instead give reasons why they insist it will be bad for his
       | business (isn't that his business?) and pretend like that's him
       | "technically" not doing anything tortious. It's not technical,
       | the lawsuit from WPE is there to read. It's silly, and if it's
       | not thrown out it will be because the judge needs time to
       | understand the complexities of the license (and the promise that
       | "Wordpress" will be turned over to the community _after
       | Automattic, who has an exclusive license to the trademark, shuts
       | down_.)
       | 
       | Using the reasons that you think this is a bad business decision
       | as proxy reasons why he's _wronged_ everyone making a living from
       | his work is a veiled threat. Don 't threaten to leave, just
       | leave.
       | 
       | Maybe the problem is this haunting by the "Spirit of Open Source"
       | where people insist that they have all of these rights that
       | aren't in the license. Wordpress _is not open source._ It is Free
       | Software. You already own it. Fork it if you want. If WPEngine is
       | already doing almost as much business as Wordpress.com, they can
       | handle everything themselves. If people love WPEngine more, they
       | can leave. Don 't whine when the value proposition for WPEngine
       | changes after they have to take care of everything themselves,
       | and they start violating the _Spirit of Open Source_ until their
       | bottom line looks better again.
       | 
       | I'm swearing an oath to violate the Spirit of Open Source
       | wherever I see a hint of it, I'm just sticking to the licenses.
       | The Spirit of Open Source somehow makes already wealthy people
       | feel entitled to everything in the world. Free Software is
       | important to me, and the people who make it should be as
       | aggressive as will financially benefit them, as long as they
       | abide by _the letter_ of the GPL. The software is what 's
       | important, not that your half-billion dollar business is built on
       | top of somebody else's half-billion dollar business. That's a
       | you-problem.
       | 
       | Also, this is just straight up abuser behavior towards this guy.
       | He doesn't do what you want with what is his, so you degrade him
       | and accuse him of stealing his own property. It's hard to watch.
       | 
       | I'm going to stop commenting on these threads, but this mobbing
       | is ridiculous. I hope he's emotionally stable; but a lot of tech
       | CEOs aren't, and his awkward reactions to the pitchforks don't
       | give me confidence. If you're compulsively reading all of these
       | threads, stop now. Stay strong and know that 95% of this is
       | coming from people who are directly connected to this financially
       | and just don't want to be inconvenienced.
        
       | mediumsmart wrote:
       | maybe they made a commit to some open source that they stole in
       | broad daylight.
        
       | pushedx wrote:
       | Under which open source license was ACF originally released? That
       | would help to answer the question.
        
         | yurishimo wrote:
         | GPL. All WordPress code is GPL and plug-ins need to call WP
         | APIs to register themselves with the CMS.
        
       | yoddler wrote:
       | WPEngine blows, I hope they die somehow
        
       ___________________________________________________________________
       (page generated 2024-10-19 23:01 UTC)