Live data from Hacker News

DOJ: Hackers broke into an SEC database and made millions from inside info

cnbc.com

71–80 of 198 posts

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#71
post #40

Earlier quoted context omitted.

SSNs were never designed for, nor intended for, secrecy. They're names, not passcodes.

SSNs were never designed for, nor intended as, identification. For years, social security cards bore the text "NOT FOR IDENTIFICATION" on the front. https://www.npr.org/2018/03/22/596180023/how-social-security...

> In order to make Social Security work, the government needed a way to identify every single worker and keep track of their earnings every single year for the rest of their lives.

According to the article it seems that it was intended to be used for identification, just only for one purpose.

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#72

Earlier quoted context omitted.

...which happens anyway. Starting 5-10 minutes before the official earnings reports come out, investor.google.com gets hammered by bots, requesting every few milliseconds until the actual page is released. I knew an SRE that wanted to put up a fake earnings report until the official time at which the real one was released, to disincentivize this behavior, but the lawyers nixed that idea really quick.

Why didn't they just decide to delay the posting by 30 seconds? It's not like that would deter regular users but it completely eliminates the high speed trading case.

Uncertain - I'm not exactly the decision-maker. But I can think of two reasons:

1) They say that earnings will come out at a certain time, so they better be out at that time or else the SEC comes after them. If they just posted earnings as coming out at say 12:00:30 instead of 12:00:00, that just shifts the problem 30 seconds later.

2) The bots will just run for an extra 30 seconds, and will still have the advantage over ordinary people.

(Something I'm not clear on: regular Google - and Hacker News, for that matter - will sometimes just make a user's connection slower if they repeatedly hit it with traffic. Why not use that on bots that hammer the investor relations site? It completely disincentivizes these bots if the 100 requests you made at 11:58:30 mean that you get stuck with a 5 minute delay and don't get the information until 12:03:30. Or maybe they do use this approach and the SRE in question just didn't bother to tell me.)

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#73
post #45

Earlier quoted context omitted.

I'm not disagreeing with you because I have no clue about this stuff, but man that is an odd usage of the word 'theft'. Sounds more like improper use to me, e.g., getting a speeding ticket while using a company truck. I didn't steal the truck, but I used it in a way which is unlawful.

It's more like you were authorized to drive the truck to make deliveries, but you used it to pick up your kids from school and go grocery shopping without your employer's permission, causing wear and tear on the truck that caused economic damage to your employer without their permission.

Ok, but the point is that, in either case, the driver isn't going to be charged with motor vehicle theft.

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#74
post #45
post #28

Earlier quoted context omitted.

That’s theft from the corporation they work for. GP is 100% correct in this case. Just read Matt Levine’s Money Stuff. He goes over this stuff a lot.

I'm not disagreeing with you because I have no clue about this stuff, but man that is an odd usage of the word 'theft'. Sounds more like improper use to me, e.g., getting a speeding ticket while using a company truck. I didn't steal the truck, but I used it in a way which is unlawful.

[deleted]

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#75
post #13

> said the same criminals also stole advance press releases sent to three newswire services Yeah I remember the charges against those people too Basically newswire services get hacked and people get the earnings reports beforehand SEC gets hacked and people get the earnings reports beforehand I think public resources shouldnt be spent on that. Prosecute the hacking but just drop the “trading on material non public in…

Insider trading is a balance. On the one hand, we want market prices to be accurate. This means we want people with material information to trade on that information. On the other hand, we need some fairness in a market. This is mostly to ensure people keep trading. In a world were inside-info is commonplace, trading without it is just stupid. This would cut off a lot of people from investing. The line needs to be dr…

>This is mostly to ensure people keep trading. In a world were inside-info is commonplace, trading without it is just stupid.

I find this line of reasoning hard to swallow. As an individual I have significantly less info than hedge funds and other professionals but that doesn't change the fact that I want to buy Apple or whatever because I think it will grow over the next 5 years.

Now if you add in the scenario where all of the Apple employees are buying and selling based on unreleased earnings, that doesn't change my want to buy the stock at all.

How does Tim Cook buying some Apple shares right before good earnings change anything for a regular investor?

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#76
People make money off advance information all the time. Often you can see that in the price action -- take this for example: https://imgur.com/mJq1OcY

Three days before a positive press release, demand pressure beings to drive up the price. Coincidence? I'm too jaded to believe that.

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#79

People make money off advance information all the time. Often you can see that in the price action -- take this for example: https://imgur.com/mJq1OcY Three days before a positive press release, demand pressure beings to drive up the price. Coincidence? I'm too jaded to believe that.

It's worth noting that trading spikes in advance of public availability of news doesn't necessarily imply illegal activity. Overheard conversations between strangers, for example, are fair game.

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#80

> The New York Stock Exchange has asked the SEC to consider limiting the amount of data collected by the CAT, which would include data on around 58 billion daily trades, as well as the personal details of individuals making the trades, including their Social Security numbers and dates of birth Dropping SSNs for natural persons would be a good idea.

IMO, everyone's SSN should be public. Mine has already be compromised by both my undergrad and grad school. At this point, I operate under the assumption that it is public knowledge for bad actors. Hiding SSNs is false security at best. If they were public, banks would stop hiding behind "identity theft" and would start having to acknowledge that its their responsibility to confirm who they are lending money to.

Why don't they just assign a new one from time to time? It's just a number after all, much easier to change than fingerprints.
Post reply on HN