Live data from Hacker News

WordPress plugin quirk resulted in UK Gov OBR Budget leak [pdf]

obr.uk

31–40 of 127 posts

Re: WordPress plugin quirk resulted in UK Gov OBR Budget leak [pdf]

#31

The real kicker is in point 1.13: > website activity logs show the earliest request on the server for the URL https://obr.uk/docs/dlm_uploads/OBR_Economic_and_fiscal_outl... . This request was unsuccessful, as the document had not been uploaded yet. Between this time and 11:30, a total of 44 unsuccessful requests to this URL were made from seven unique IP addresses. In other words, someone was guessing the correct st…

The report also says a previous report was also accessed 30 mins early.

Re: WordPress plugin quirk resulted in UK Gov OBR Budget leak [pdf]

#33
post #25

Earlier quoted context omitted.

In the popular press it’s been sidelined because it would distract from the continuous attacks on the chancellor

Yes, it’s getting quite ridiculous now. Labour, for sure, have not done themselves any favours in their first 18 months in charge, but the level of attack and vitriol is exceptional and beyond any reasonable level. It makes me wonder what exactly is driving this.

Money.

Re: WordPress plugin quirk resulted in UK Gov OBR Budget leak [pdf]

#34
So is the significance of this news based on what could have leaked if the document was not intended for the public? [1]

Or is the significance of this news based on the advantages that players on the market who caught hold of it early will have? Is it only important to civilians relative to their ability to question who may be benefitting from the 40 minute head start that these players might have gained or (for the conspiracy-minded) been handed through nefarious means?

[1]: Which would lead me to ask why would it belong on a platform typically intended for publishing things in public.

Re: WordPress plugin quirk resulted in UK Gov OBR Budget leak [pdf]

#35
post #11

Earlier quoted context omitted.

The main issue is that there isn't any governance to the plugin store. Once you have a plugin in there, you have free reign to do whatever you want with it. Getting it in there is a PITA though. For example, a library author and I created a plugin, but they wouldn't let me submit it because I wasn't the other author, and they wouldn't let him submit it because he wasn't me. True story.

TBF there is some scrutiny on existing plugins, the team is just extremely understaffed (it’s ran by volunteers after all). I got involved in a plugin that ended up getting de-listed for some minor ToS violations after several years of being “fine”, they re-reviewed the plugin with the same rigor as a new submission.

Kudos to these volunteers, but as long as one single company continues to insist on owning all the resources of the plugin and theme directories, I don't think they deserve to continue profiting from volunteer labor.

Re: WordPress plugin quirk resulted in UK Gov OBR Budget leak [pdf]

#36
post #4

Why are government organisations which handle sensitive information using Wordpress?

In huge org's, doing computer-related stuff the "right" way often involves so many meetings, sign-offs, and miles of red tape that your grandchildren would die of old age before anything actually got done.

Vs. if you just let Will and Pete do it in WordPress (or on Facebook, or such) then needed tasks might actually be accomplished.

Re: WordPress plugin quirk resulted in UK Gov OBR Budget leak [pdf]

#37
post #25

Earlier quoted context omitted.

In the popular press it’s been sidelined because it would distract from the continuous attacks on the chancellor

Yes, it’s getting quite ridiculous now. Labour, for sure, have not done themselves any favours in their first 18 months in charge, but the level of attack and vitriol is exceptional and beyond any reasonable level. It makes me wonder what exactly is driving this.

This is politics so attacks will always follow blunders on either side.

In this case this is an extremely unpopular government to start with that increases taxes across the board while handing out more benefits and claiming that they had no choice because of the state of the public finances, and we learn that they possibly misled the public on that latter point. So, yes, in politics and especially British politics this means a riot against the Chancellor (who was also caught recently having let her house without the required legal licence, btw, after the [now former] Deputy PM was caught dodging taxes on the purchase of a second home...) because everyone "smells blood" but that's the game and it's not completely undeserved, either.

Re: WordPress plugin quirk resulted in UK Gov OBR Budget leak [pdf]

#38
post #25

Earlier quoted context omitted.

In the popular press it’s been sidelined because it would distract from the continuous attacks on the chancellor

Yes, it’s getting quite ridiculous now. Labour, for sure, have not done themselves any favours in their first 18 months in charge, but the level of attack and vitriol is exceptional and beyond any reasonable level. It makes me wonder what exactly is driving this.

The fact that they were elected as a 'change' government and have barely done anything that really faces up to the scale of the challenge the country faces? If you're below the age of about 55, then the budget did absolutely nothing for you except put taxes up, and not even to improve services.

I appreciate things time but so far the government have enormously walked back their planning reform proposals, which was one of their few pro-growth policies, and haven't really made any dent in anything else substantive. It's been pretty clear since even before the election that they didn't really have a plan, and they got a fairly light scrutiny through the campaign because the Tories were so appalling. Then since they got in they're just scrambling around looking fairly incompetent and the dearth of talent on the cabinet has been pretty plain to see as well. Largely I want Labour to succeed but they're not making it easy to like them.

Re: WordPress plugin quirk resulted in UK Gov OBR Budget leak [pdf]

#39

There's a couple of passing mentions of Download Monitor, but also the timeline strongly implies that a specific source was simply guessing the URL of the PDF long before it was uploaded I'm not clear from the doc which of these scenarios is what they're calling the "leak"

> but also the timeline strongly implies that a specific source was simply guessing the URL of the PDF long before it was uploaded A bunch of people were scraping commonly used urls based on previous OBR reports, in order to report as soon as it was live, as it common with all things of this kind The mistake was that the URL should have been obfuscated, and only changed to the "clear" URL at publish time, but a plugi…

> in order to report as soon as it was live

We don't actually know that, it's just that the report did hit Reuters pretty swiftly.

Re: WordPress plugin quirk resulted in UK Gov OBR Budget leak [pdf]

#40

The real kicker is in point 1.13: > website activity logs show the earliest request on the server for the URL https://obr.uk/docs/dlm_uploads/OBR_Economic_and_fiscal_outl... . This request was unsuccessful, as the document had not been uploaded yet. Between this time and 11:30, a total of 44 unsuccessful requests to this URL were made from seven unique IP addresses. In other words, someone was guessing the correct st…

> In other words, someone was guessing the correct staging URL before the OBR had even uploaded the file to the staging area. This suggests that the downloader knew that the OBR was going to make this mistake, and they were polling the server waiting for the file to appear.

The URLS are predictable. Hedge-funds would want to get the file as soon as it would be available - I imagine someone set up a cron-job to try the URL every few minutes.

Post reply on HN