Hacker News new | ask | show | jobs
by bmacho 610 days ago
> is it a hijacking, if they own that page in the first place? The community placed trust on that owner of the page to be impartial

I would say yes, it is hijacking. It is very very similar to any MITM attack ever, like anyone in the looong chain of trust deciding that they will do something with the trust they have. Like, can your ISP redirect google.com to their own google.com? They surely can, and it probably wouldn't even break their contract with you. It would be a trademark infringement, probably GDPR violation, but not much else.

Since WordPress.org acts as a traditional package repository, they can: serve you the package, or don't serve you the package for various reasons. Everything else is hijacking or worse, especially if the intent is just to turn you their user, and the result is to break your website. Even if you don't have a contract with them that they will serve WP Engine's unmodified plugin to you.