Live data from Hacker News

DOJ: Hackers broke into an SEC database and made millions from inside info

cnbc.com

41–50 of 198 posts

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#41

> The New York Stock Exchange has asked the SEC to consider limiting the amount of data collected by the CAT, which would include data on around 58 billion daily trades, as well as the personal details of individuals making the trades, including their Social Security numbers and dates of birth Dropping SSNs for natural persons would be a good idea.

IMO, everyone's SSN should be public. Mine has already be compromised by both my undergrad and grad school. At this point, I operate under the assumption that it is public knowledge for bad actors. Hiding SSNs is false security at best. If they were public, banks would stop hiding behind "identity theft" and would start having to acknowledge that its their responsibility to confirm who they are lending money to.

And yet many services rely on SSN for identity verification in the US (e.g. banks, telecoms, etc.)

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#44
post #13

Earlier quoted context omitted.

Insider trading is a balance. On the one hand, we want market prices to be accurate. This means we want people with material information to trade on that information. On the other hand, we need some fairness in a market. This is mostly to ensure people keep trading. In a world were inside-info is commonplace, trading without it is just stupid. This would cut off a lot of people from investing. The line needs to be dr…

> On the other hand, we need some fairness in a market American insider trading law has nothing to do with fairness. It is based on theft of information. In this case, the hacker’s stole information from the SEC that belonged to the reporting companies. (This is a commonly misunderstood alley of securities law.)

Not sure why you got downvoted, this is correct. If you, for example, overhear an executive on the street discussing how his company is going to bomb their earnings report, you wouldn't get in trouble for trading on that (if you somehow got "caught"). It's unfair in a sense because you just got lucky and stumbled into material, non-public information, but you also didn't really do anything wrong.

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#45
post #28

Earlier quoted context omitted.

if that were the case, it would be legal for a company director to trade on information they gleaned from an internal meeting. Which, as far as I understand, it isn't.

That’s theft from the corporation they work for. GP is 100% correct in this case. Just read Matt Levine’s Money Stuff. He goes over this stuff a lot.

I'm not disagreeing with you because I have no clue about this stuff, but man that is an odd usage of the word 'theft'. Sounds more like improper use to me, e.g., getting a speeding ticket while using a company truck. I didn't steal the truck, but I used it in a way which is unlawful.

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#46
post #40

Earlier quoted context omitted.

SSNs were never designed for, nor intended for, secrecy. They're names, not passcodes.

SSNs were never designed for, nor intended as, identification. For years, social security cards bore the text "NOT FOR IDENTIFICATION" on the front. https://www.npr.org/2018/03/22/596180023/how-social-security...

My understanding is that that warning applied to the card itself, not to the number. That is, the bearer of that card has no provable relationship to the social security number on the card as it contains no attestable information (like a photograph or general description) so the card cannot be used for identification.

The number itself is of course used for identification from the beginning as a unique identifier for your "account" in the social security administration.

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#47

Earlier quoted context omitted.

IMO, everyone's SSN should be public. Mine has already be compromised by both my undergrad and grad school. At this point, I operate under the assumption that it is public knowledge for bad actors. Hiding SSNs is false security at best. If they were public, banks would stop hiding behind "identity theft" and would start having to acknowledge that its their responsibility to confirm who they are lending money to.

And yet many services rely on SSN for identity verification in the US (e.g. banks, telecoms, etc.)

You mean they rely solely on someone dictating a SSN number? That's insane. They should ask for a official ID with photo, as the very minimum.

Is that something that goes against the American culture? The other day I had to give all 10 fingerprints to renew my driver's license (location: South America) and nobody seemed to care.

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#48

> The New York Stock Exchange has asked the SEC to consider limiting the amount of data collected by the CAT, which would include data on around 58 billion daily trades, as well as the personal details of individuals making the trades, including their Social Security numbers and dates of birth Dropping SSNs for natural persons would be a good idea.

SSNs were never designed for, nor intended for, secrecy. They're names, not passcodes.

Like biometrics but worse.

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#50

> The New York Stock Exchange has asked the SEC to consider limiting the amount of data collected by the CAT, which would include data on around 58 billion daily trades, as well as the personal details of individuals making the trades, including their Social Security numbers and dates of birth Dropping SSNs for natural persons would be a good idea.

IMO, everyone's SSN should be public. Mine has already be compromised by both my undergrad and grad school. At this point, I operate under the assumption that it is public knowledge for bad actors. Hiding SSNs is false security at best. If they were public, banks would stop hiding behind "identity theft" and would start having to acknowledge that its their responsibility to confirm who they are lending money to.

This is actually a great idea, as long as the government makes clear the plan to do this, and gives banks et al time to adjust.
Post reply on HN