Earlier quoted context omitted.
> A feature known as the Download Monitor plug-in created a webpage with the clear URL which provided a link to the live version, which bypassed the need for authentication. This rendered the protections on the ‘future’ function of WordPress redundant as it bypassed the required authentication needed to gain access to the pre-uploaded document. WordPress is a nice piece of software, but the plugin situation is gettin…
The main issue is that there isn't any governance to the plugin store. Once you have a plugin in there, you have free reign to do whatever you want with it. Getting it in there is a PITA though. For example, a library author and I created a plugin, but they wouldn't let me submit it because I wasn't the other author, and they wouldn't let him submit it because he wasn't me. True story.
WordPress plugin quirk resulted in UK Gov OBR Budget leak [pdf]
11–20 of 127 posts
Re: WordPress plugin quirk resulted in UK Gov OBR Budget leak [pdf]
#12What was the quirk?
> A feature known as the Download Monitor plug-in created a webpage with the clear URL which provided a link to the live version, which bypassed the need for authentication. This rendered the protections on the ‘future’ function of WordPress redundant as it bypassed the required authentication needed to gain access to the pre-uploaded document. WordPress is a nice piece of software, but the plugin situation is gettin…
The plugin situation is a mess largely because Wordpress isn't a nice piece of software.
It's popular, and functionally it's great, but the codebase is really showing its age. Wordpress has never properly rearchitected because it would break plugins on a scale that would endanger its dominance.
Re: WordPress plugin quirk resulted in UK Gov OBR Budget leak [pdf]
#13I find this an implausibly low number. It was all over Bluesky, X etc., not to mention journo Signal and WhatsApp groups.
Re: WordPress plugin quirk resulted in UK Gov OBR Budget leak [pdf]
#14What was the quirk?
> A feature known as the Download Monitor plug-in created a webpage with the clear URL which provided a link to the live version, which bypassed the need for authentication. This rendered the protections on the ‘future’ function of WordPress redundant as it bypassed the required authentication needed to gain access to the pre-uploaded document. WordPress is a nice piece of software, but the plugin situation is gettin…
Re: WordPress plugin quirk resulted in UK Gov OBR Budget leak [pdf]
#15There's a couple of passing mentions of Download Monitor, but also the timeline strongly implies that a specific source was simply guessing the URL of the PDF long before it was uploaded I'm not clear from the doc which of these scenarios is what they're calling the "leak"
A bunch of people were scraping commonly used urls based on previous OBR reports, in order to report as soon as it was live, as it common with all things of this kind
The mistake was that the URL should have been obfuscated, and only changed to the "clear" URL at publish time, but a plugin was bypassing that and aliasing the "clear" URL to the obfuscated one
Re: WordPress plugin quirk resulted in UK Gov OBR Budget leak [pdf]
#16There's a couple of passing mentions of Download Monitor, but also the timeline strongly implies that a specific source was simply guessing the URL of the PDF long before it was uploaded I'm not clear from the doc which of these scenarios is what they're calling the "leak"
Re: WordPress plugin quirk resulted in UK Gov OBR Budget leak [pdf]
#17>During that period, it was accessed 43 times by 32 unique IP addresses I find this an implausibly low number. It was all over Bluesky, X etc., not to mention journo Signal and WhatsApp groups.
Re: WordPress plugin quirk resulted in UK Gov OBR Budget leak [pdf]
#18>During that period, it was accessed 43 times by 32 unique IP addresses I find this an implausibly low number. It was all over Bluesky, X etc., not to mention journo Signal and WhatsApp groups.
Re: WordPress plugin quirk resulted in UK Gov OBR Budget leak [pdf]
#19There's a couple of passing mentions of Download Monitor, but also the timeline strongly implies that a specific source was simply guessing the URL of the PDF long before it was uploaded I'm not clear from the doc which of these scenarios is what they're calling the "leak"
Not hard to guess really. Wouldn't they know this was likely and simply choose a less obvious file name?
Re: WordPress plugin quirk resulted in UK Gov OBR Budget leak [pdf]
#20>During that period, it was accessed 43 times by 32 unique IP addresses I find this an implausibly low number. It was all over Bluesky, X etc., not to mention journo Signal and WhatsApp groups.
Edit: Or (and more likely) cached/copies of the original.