Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I did. It's factually inaccurate.

> There was function in an older version of the plugin which could be used to reset a site back to the default settings. This function had no risk of of malicious or unintentional use.

> The portrayal of this feature is not based on reality. There is a function in the plugin which can be used to clear database tables, much like a backup or standard reset plugin. To confirm, we do not have the ability to “kill” a site, nor would we ever, ever want to do that! The function is in place to reset a site back to defaults, however it is only activated after being in touch with the site owner.

It dropped all wordpress tables. This is not a reset. There's also no reason to only have PipDig able to do this via their server, vs. an option in the configuration.

They also don't address the password reset functionality.

At best, these people are incompetent and don't realize the power their code wields. At worst, they're just backpedaling and trying to mitigate damage. (I especially like their attempt to humanize themselves by saying they're just four people who like cat memes.)



Not just inaccurate, but heavily misleading as well.

"Older version", for example, is only true because they pushed a new version after getting caught that stripped out the nasty code.


Definitely. That they're trying to position this as an oversight is frankly disgusting. That code was intentional.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: