Live data from Hacker News

WordPress plugin quirk resulted in UK Gov OBR Budget leak [pdf]

obr.uk

81–90 of 127 posts

Re: WordPress plugin quirk resulted in UK Gov OBR Budget leak [pdf]

#81
post #28

Earlier quoted context omitted.

> The effects of this particular instance of the failure were minimal the effects are not minimal if you're crooked: getting this sort of information early is potentially extremely lucrative (why crooked? because trading on UPSI is illegal)

Surely it was no longer UPSI (Unpublished Price Sensitive Information) after the OBR published it?

I wouldn't be betting my freedom on the regulator agreeing with that logic

the regulations specifically go into great detail about official publications and formal circulation

would a reasonable person consider this a leak? then it's UPSI

Re: WordPress plugin quirk resulted in UK Gov OBR Budget leak [pdf]

#82
post #4

Why are government organisations which handle sensitive information using Wordpress?

It's not sensitive information. It's public information.

Before it’s been released I would consider it sensitive for many reasons.

Re: WordPress plugin quirk resulted in UK Gov OBR Budget leak [pdf]

#83
post #25

Earlier quoted context omitted.

Yes, it’s getting quite ridiculous now. Labour, for sure, have not done themselves any favours in their first 18 months in charge, but the level of attack and vitriol is exceptional and beyond any reasonable level. It makes me wonder what exactly is driving this.

The fact that they were elected as a 'change' government and have barely done anything that really faces up to the scale of the challenge the country faces? If you're below the age of about 55, then the budget did absolutely nothing for you except put taxes up, and not even to improve services. I appreciate things time but so far the government have enormously walked back their planning reform proposals, which was on…

They have done a lot of sensible, boring things that are objectively positive but are going largely going unnoticed (plus of course a few massive footguns that make the headlines).

I keep recommending r/GoodNewsUK on Reddit. It’s often just a lot of press releases and government announcements, but there seem to be a continual stream of them, and it’s hard to hear about them by any other source.

Re: WordPress plugin quirk resulted in UK Gov OBR Budget leak [pdf]

#84
post #81

Earlier quoted context omitted.

Surely it was no longer UPSI (Unpublished Price Sensitive Information) after the OBR published it?

I wouldn't be betting my freedom on the regulator agreeing with that logic the regulations specifically go into great detail about official publications and formal circulation would a reasonable person consider this a leak? then it's UPSI

The OBR admits that they published it too early.

I am not an expert but I think that even trading on a leak is not unlawful as long as that leaked information was indeed made public (e.g. someone leaks to the media and the media then publish it), although it may have been unlawful to leak the information. The point is that insider trading is not allowed. It is no insider trading if the information is available to everyone.

Re: WordPress plugin quirk resulted in UK Gov OBR Budget leak [pdf]

#85
post #78

Earlier quoted context omitted.

> In other words, someone was guessing the correct staging URL before the OBR had even uploaded the file to the staging area. This suggests that the downloader knew that the OBR was going to make this mistake, and they were polling the server waiting for the file to appear. The URLS are predictable. Hedge-funds would want to get the file as soon as it would be available - I imagine someone set up a cron-job to try th…

This is so incompetent. Given the market significance of the report it's damn obvious that this would happen. They should have assumed that security via obscurity was simply not enough, and the OBR should have been taking active steps to ensure the data was only available at the correct time. > Hedge-funds would want to get the file as soon as it would be available - I imagine someone set up a cron-job to try the URL…

This setup was not initially approved, see 1.7 in the document:

> 1.7 Unlike all other IT systems and services, the OBR’s website is locally managed and outside the gov.uk network. This is the result of an exemption granted by the Cabinet Office in 2013. After initially rejecting an exemption request, the Cabinet Office judged that the OBR should be granted an exemption from gov.uk in order to meet the requirements of the Budget Responsibility and National Audit Act. The case for exemption that the OBR made at the time centred on the need for both real and perceived independence from the Treasury in the production and delivery of forecasts and other analysis, in particular in relation to the need to publish information at the right time.

Re: WordPress plugin quirk resulted in UK Gov OBR Budget leak [pdf]

#86
post #78

Earlier quoted context omitted.

> In other words, someone was guessing the correct staging URL before the OBR had even uploaded the file to the staging area. This suggests that the downloader knew that the OBR was going to make this mistake, and they were polling the server waiting for the file to appear. The URLS are predictable. Hedge-funds would want to get the file as soon as it would be available - I imagine someone set up a cron-job to try th…

This is so incompetent. Given the market significance of the report it's damn obvious that this would happen. They should have assumed that security via obscurity was simply not enough, and the OBR should have been taking active steps to ensure the data was only available at the correct time. > Hedge-funds would want to get the file as soon as it would be available - I imagine someone set up a cron-job to try the URL…

They weren't in any way attempting to rely on security by obscurity.

They didn't assume nobody would guess the URL.

They did take active steps to ensure the data was only available at the correct time.

But they didn't check that their access control was working, and it wasn't.

Re: WordPress plugin quirk resulted in UK Gov OBR Budget leak [pdf]

#87
post #81

Earlier quoted context omitted.

I wouldn't be betting my freedom on the regulator agreeing with that logic the regulations specifically go into great detail about official publications and formal circulation would a reasonable person consider this a leak? then it's UPSI

The OBR admits that they published it too early. I am not an expert but I think that even trading on a leak is not unlawful as long as that leaked information was indeed made public (e.g. someone leaks to the media and the media then publish it), although it may have been unlawful to leak the information. The point is that insider trading is not allowed. It is no insider trading if the information is available to eve…

> I am not an expert

I have had regulatory training on this exact matter, and it covers unintended leaks explicitly

and there is no way I would trade

> The point is that insider trading is not allowed. It is no insider trading if the information is available to everyone.

no, it isn't the point

the regulator cares that participants are seen to be clean, practicing "fit and proper" behaviour

if a reasonable person would think it was dodgy, they'll have your head (and your certification to practice)

regardless of whether or not it was illegal

Re: WordPress plugin quirk resulted in UK Gov OBR Budget leak [pdf]

#88

Earlier quoted context omitted.

> which it blamed on a "technical error" It's not a technical error at all! Technical errors are faults caused by technology, like a software or hardware bug. That's not what happened here. WordPress behaved exactly as it was supposed to. The true cause is revealed later in the article, > staff thought they had applied safeguards to prevent early publication, there were two errors in the way in which they were set up…

I don't think that's a worthwhile distinction. All software bugs are human errors, since the machine is correctly following the human programmer's incorrect instructions; whether that's at the level of assembly instructing the CPU; or a higher level like Wordpress instructing the PHP interpreter; or an even higher level of a document hosting solution instructing Wordpress.

Eh, I think the distinction is broken tool vs improper use of the tool or in this case, the wrong tool all together

Re: WordPress plugin quirk resulted in UK Gov OBR Budget leak [pdf]

#89

Ok, it was the Download Monitor plugin. But I still have a few questions. What is WordPress’s default behavior? Does it prevent files uploaded to the media library from having public URLs? Are they only public once they are inserted into a published post? Images make sense because they are embedded, but what about a PDF linked inside a post? My understanding is that media files become publicly accessible as soon as t…

Correct. Files uploaded get stored in the wp-content/uploads folder and are public.

Re: WordPress plugin quirk resulted in UK Gov OBR Budget leak [pdf]

#90

The real kicker is in point 1.13: > website activity logs show the earliest request on the server for the URL https://obr.uk/docs/dlm_uploads/OBR_Economic_and_fiscal_outl... . This request was unsuccessful, as the document had not been uploaded yet. Between this time and 11:30, a total of 44 unsuccessful requests to this URL were made from seven unique IP addresses. In other words, someone was guessing the correct st…

Part of this is a product of the UK's political culture where expenses for stuff like this are ruthlessly scrutinised from within and without.

The idea of the site hosting such an important document running independently on WordPress, being maintained by a single external developer and a tiny in-house team would seem really strange to many other countries.

Everyone is so terrified of headlines like "OBR spends £2m upgrading website" that you get stuff like this.

Post reply on HN