Live data from Hacker News

WordPress plugin quirk resulted in UK Gov OBR Budget leak [pdf]

obr.uk

91–100 of 127 posts

Re: WordPress plugin quirk resulted in UK Gov OBR Budget leak [pdf]

#91
post #87

Earlier quoted context omitted.

The OBR admits that they published it too early. I am not an expert but I think that even trading on a leak is not unlawful as long as that leaked information was indeed made public (e.g. someone leaks to the media and the media then publish it), although it may have been unlawful to leak the information. The point is that insider trading is not allowed. It is no insider trading if the information is available to eve…

> I am not an expert I have had regulatory training on this exact matter, and it covers unintended leaks explicitly and there is no way I would trade > The point is that insider trading is not allowed. It is no insider trading if the information is available to everyone. no, it isn't the point the regulator cares that participants are seen to be clean, practicing "fit and proper" behaviour if a reasonable person woul…

Yes, I have had the corporate training on leaks and insider trading, too...

Trading on public information is fit and proper (Edit: Indeed, a technical term, but that does not make my statement incorrect, or does it?)

I think you may have skipped the part of leak to whom. If it is a leak to you then it is still not public and indeed insider trading. But if leaked to the public then it is different (and also how do you prevent people from trading on what they see in the media?)

But that's in general as in this case, the OBR admits they released it and, again, anyway once it's on BBC News it's free for all.

Re: WordPress plugin quirk resulted in UK Gov OBR Budget leak [pdf]

#92
post #87

Earlier quoted context omitted.

> I am not an expert I have had regulatory training on this exact matter, and it covers unintended leaks explicitly and there is no way I would trade > The point is that insider trading is not allowed. It is no insider trading if the information is available to everyone. no, it isn't the point the regulator cares that participants are seen to be clean, practicing "fit and proper" behaviour if a reasonable person woul…

Yes, I have had the corporate training on leaks and insider trading, too... Trading on public information is fit and proper (Edit: Indeed, a technical term, but that does not make my statement incorrect, or does it?) I think you may have skipped the part of leak to whom . If it is a leak to you then it is still not public and indeed insider trading. But if leaked to the public then it is different (and also how do yo…

> Yes, I have had the corporate training on leaks and insider trading, too...

by a regulated investment firm? specifically on UPSI?

"fit and proper" is a technical term in the FCA manual

I would not risk my regulator not considering me as such by trading on this information

if you would: provide your reference number, and we can ask them if they agree!

Re: WordPress plugin quirk resulted in UK Gov OBR Budget leak [pdf]

#93
post #56

Earlier quoted context omitted.

The fact that they were elected as a 'change' government and have barely done anything that really faces up to the scale of the challenge the country faces? If you're below the age of about 55, then the budget did absolutely nothing for you except put taxes up, and not even to improve services. I appreciate things time but so far the government have enormously walked back their planning reform proposals, which was on…

I largely agree, expect I think my expectations were lower than yours to start with. The ruling class all think alike regardless of party. They have pushed ahead with the Tories Online Safety Act. Legislation I have looked at or that affect things I know about such as the Children's Wellbeing and Schools Act is terrible. There is a lot of smoke and mirrors. For example, if you assume the justification for the "mansio…

Although I agree it should be proportional to value, a £5M property puts you in the top 1% of property prices in the country. Even within London, it’s also within the top 1% of all but the most expensive boroughs. The average home property sale in the UK is less than £275,000.

A tax on a £5M home is not a tax on the moderately wealthy, it’s a tax on the wealthy.

Re: WordPress plugin quirk resulted in UK Gov OBR Budget leak [pdf]

#94
The log of events in that document is absolutely hilarious/pitiful. It’s like something lifted directly from an episode of In The Thick Of It.

A honest-to-goodness proper fucking omnishambles.

11:52 - senior OBR and Treasury officials telephoned each other to discuss the breach. These Treasury officials made OBR staff aware of the URL leading to the PDF of the EFO that was accessible.

11:53 - OBR staff and the web developer attempted to pull the PDF from the website, and also to pull the entire website (e.g. via password protection), but struggled to do so initially due to the website being overloaded with traffic.

11:58 - an email was received to the OBR press inbox from a Reuters journalist confirming that Reuters had published details of the EFO and asking for comment.

12:07 - the EFO PDF was renamed by the web developer.

12:07 - the EFO PDF appeared on the Internet Archive. This means it was, at that precise time, visible entirely generally on the open internet via search engines. It is assumed that this happened very briefly in the rush to remove it.

Re: WordPress plugin quirk resulted in UK Gov OBR Budget leak [pdf]

#95

Earlier quoted context omitted.

The fact that they were elected as a 'change' government and have barely done anything that really faces up to the scale of the challenge the country faces? If you're below the age of about 55, then the budget did absolutely nothing for you except put taxes up, and not even to improve services. I appreciate things time but so far the government have enormously walked back their planning reform proposals, which was on…

> The fact that they were elected as a 'change' government and have barely done anything that really faces up to the scale of the challenge the country faces? They have done a lot. But they haven't even stopped the runaway train yet. And the fundamental mistake they have made is not explaining to people clearly enough, during the election campaign, that it would take the first three years just to stop it. Then you ha…

> They have done a lot.

I really don’t agree. Look at the first year of 1997 Labour:

* Good Friday agreement signed and referendum * Introduction of Minimum Wage * Human Rights act introduced and passed * Scottish and Welsh devolution set out, Parliament voted on it, referendums passed * Bank of England independence

A government coming into a mess of a country on a platform of change cannot just fiddle around with minor things, which is what many of the changes they have done, though positive, are. And at the same time, they’ve also wasted so much political capital on some really stupid things that it’s hard to see where they can go from here.

Re: WordPress plugin quirk resulted in UK Gov OBR Budget leak [pdf]

#96
post #13

>During that period, it was accessed 43 times by 32 unique IP addresses I find this an implausibly low number. It was all over Bluesky, X etc., not to mention journo Signal and WhatsApp groups.

I agree, and I also am familiar with how WP Engine's 'GES' (global edge security) works. obr.uk points to two IP addresses held in the name of WP Engine, but they're actually BYOIP with Cloudflare. Cloudflare act as a caching layer, DDOS mitigation and WAF.

Note that GES works a bit different to traditional Cloudflare implementations, HTML requests are basically passed through to the WP Engine NGINX reverse proxy server that's in front of the WordPress site (as opposed to being heavily cached with Cloudflare). Static assets, like a PDF - would indeed be cached with GES.

Re: WordPress plugin quirk resulted in UK Gov OBR Budget leak [pdf]

#97
If you've ever looked at the admin panel of even a minor league, single page Wordpress site you'd probably recognize it as a major risk for any organization instantly. So many of the plugins look like spaghetti, with most you're trusting some random name to not be malicious. Unsurprisingly there are 60,000 CVE related to WP. I get that we all use a dozen node packages that we can't reasonably verify, but WP seems so much more wild west than that. I guess i's fine if you are a low value target, but a commercial CMS is not terribly expensive, and should be mandatory for any government org.

Re: WordPress plugin quirk resulted in UK Gov OBR Budget leak [pdf]

#98

There's a couple of passing mentions of Download Monitor, but also the timeline strongly implies that a specific source was simply guessing the URL of the PDF long before it was uploaded I'm not clear from the doc which of these scenarios is what they're calling the "leak"

https://www.pluginscore.com/plugins/download-monitor

Re: WordPress plugin quirk resulted in UK Gov OBR Budget leak [pdf]

#99

The real kicker is in point 1.13: > website activity logs show the earliest request on the server for the URL https://obr.uk/docs/dlm_uploads/OBR_Economic_and_fiscal_outl... . This request was unsuccessful, as the document had not been uploaded yet. Between this time and 11:30, a total of 44 unsuccessful requests to this URL were made from seven unique IP addresses. In other words, someone was guessing the correct st…

> In other words, someone was guessing the correct staging URL before the OBR had even uploaded the file to the staging area. This suggests that the downloader knew that the OBR was going to make this mistake, and they were polling the server waiting for the file to appear. The URLS are predictable. Hedge-funds would want to get the file as soon as it would be available - I imagine someone set up a cron-job to try th…

I used to do this for BOE / Fed minutes, company earnings etc on the off chance they published it before the official release time.

2025-Q1-earnings.pdf - smash it every 5 seconds - rarely worked out, generally a few seconds head start at best. By the time you pull up the pdf and parse the number from it the number was on the wires anyway. Very occasionally you get a better result however.

Re: WordPress plugin quirk resulted in UK Gov OBR Budget leak [pdf]

#100
post #92

Earlier quoted context omitted.

Yes, I have had the corporate training on leaks and insider trading, too... Trading on public information is fit and proper (Edit: Indeed, a technical term, but that does not make my statement incorrect, or does it?) I think you may have skipped the part of leak to whom . If it is a leak to you then it is still not public and indeed insider trading. But if leaked to the public then it is different (and also how do yo…

> Yes, I have had the corporate training on leaks and insider trading, too... by a regulated investment firm? specifically on UPSI? "fit and proper" is a technical term in the FCA manual I would not risk my regulator not considering me as such by trading on this information if you would: provide your reference number, and we can ask them if they agree!

Well if you are an expert that's great as you will be able to explain how using a leak to the public and/or something that is public information can be construed as improper. That was my previous point and question.
Post reply on HN