Live data from Hacker News

Citigroup fined $7m after legit transactions mistaken for test data for 15 years

theregister.co.uk

101–110 of 114 posts

Re: Citigroup fined $7m after legit transactions mistaken for test data for 15 years

#101

I've never understood how these fines are meant to benefit anyone. If no one is affected, then why is there a fine? Who is this money going to for damages to be repaid? Also, why are you not allowed to use real data for testing purposes?

The SEC was not impressed and said in a statement announcing the fine that the "failure to discover the coding error and to produce the missing data for many years potentially impacted numerous Commission investigations."

Re: Citigroup fined $7m after legit transactions mistaken for test data for 15 years

#102
I suspect the bugs like this come about because of a patch not because of the original development. Devs and dev teams tend to get sloppy after the first push and budgets tend to shrink dramatically.

One time I found a bug that was running for a few years and the result of it was the company was under reporting by millions of dollars per quarter (the running total was near to $100mm, and im sure it crossed it after my contract ended).

This was VERY well tested software in the beginning (one of the best test suites i've seen actually) and audited up to high heaven. The problem started when the patches rolled in and those, are not tested anywhere near as much.

Re: Citigroup fined $7m after legit transactions mistaken for test data for 15 years

#103

Earlier quoted context omitted.

Interesting. Windows CE? Are there any glaring technical issues you've run into over the years? What processors are the ATMs using?

I took this in the UK two years ago: https://4z2.de/atm_windows.jpg - I don't know enough about how the various versions of Windows look but maybe this helps. It also doesn't look very trust-inspiring.

You need to trust the bank's network security more than you trust the ATM itself.

There were some high profile breaches at some retailers in the past couple years that exploited some 0days. How can you defend your POS/ATM against a 0day if the retailer/bank has bad network security practices?

Re: Citigroup fined $7m after legit transactions mistaken for test data for 15 years

#104
post #52

Earlier quoted context omitted.

Interesting. Windows CE? Are there any glaring technical issues you've run into over the years? What processors are the ATMs using?

I guess these machines are not connected to the Internet, and have a very limited user interface surface. Flaws are less important.

In the US, we have private leased lines to connect with some of the major banks. But the banks most likely use something else to connect to the ATMs.

Most attacks are physically breaking into the cash safe but there were some attacks a couple years ago where people were plugging into the USB port and getting money or something.

Re: Citigroup fined $7m after legit transactions mistaken for test data for 15 years

#105

Synopsis: SEC sends clear message to tech people in finance: shut the fuck up if you find something, silently fix it, and sweep the remaining crumbs under the rug, or else your company will be fined millions.

$7m is basically nothing to someone like Citigroup. If they had tried to cover it up and the information leaked out some other way they could be facing a real fine.

A $7m fine for someone like Citigroup is basically a parking ticket.

Re: Citigroup fined $7m after legit transactions mistaken for test data for 15 years

#106
post #97

Earlier quoted context omitted.

> Directors of companies have legal responsibilities to provide these reports to the government. What if you don't tell the directors, but just fix the problem you have discovered? Is everyone off the hook then, or does that also amount to breaking the law (in some country)?

Why you're in Operations or Technology in large financial companies, you're confronted with 'could do better' issues all of the time. All of the time. The more issues the greater the legacy of the system you're working on, as in this case, functionality has been altered from the original vanilla system (here, alphanumeric field type replacing a numerical feed type, the the documentation not being updated/references/o…

> nothing $7billion big; something $7million big is nothing, they know their boss knows this and will get a thank you for it being raised.

Further, this was obviously discussed with the boss before it was raised.

Re: Citigroup fined $7m after legit transactions mistaken for test data for 15 years

#107

Earlier quoted context omitted.

I'm not sure complicated reporting is how banks are maintaining margins. They're diverting billions into complying with these requirements, for very little gain.

And anyone entering their business would have to as well. The large banks are happy to have these regulations in some ways as it makes it hard for midsized banks to grow and compete with them.

Yes. Or for scrappy upstarts to compete from their garage.

Re: Citigroup fined $7m after legit transactions mistaken for test data for 15 years

#108
post #88

Earlier quoted context omitted.

That sounds linear to me, which is not correct. Injury level is exponential with temperature: http://www.ncbi.nlm.nih.gov/pubmed/18226454 Injury time is logarithmic: http://www.accuratebuilding.com/services/legal/charts/hot_wa...

> That sounds linear to me What? Absolutely not. I'm just saying that it sounds reasonable to believe that burns increase with temperature, as opposed to being high in a range of temperatures and lower below and above that range. Figure 4 in your first link agrees with this common-sense guess.

The guy said "in a temperature range where burns are more likely". I'm not sure why you're objecting; there are certainly ranges where burns are less likely; that's what the paper I posted is about.

I think it's also pretty clear just from the burn time curve. If it takes you a second or two to notice the heat and move away, then anything above ~155F is going to make a burn much more likely. At 180F, the burn is basically instantaneous. Whereas at 140F, having five seconds to respond gives you a lot of time to move, shake off the liquid, et cetera.

Re: Citigroup fined $7m after legit transactions mistaken for test data for 15 years

#109
post #30

Totally unrelated, but I am not surprised. I once logged into my Citi credit card account and was granted access to another user's account. Certain places were off limits but I was able to view a lot of details. Pretty scary! I never heard back after reporting the issue.

Did you collect proper snapshot? Did you report it to the right official authorities?

Re: Citigroup fined $7m after legit transactions mistaken for test data for 15 years

#110

Earlier quoted context omitted.

> That sounds linear to me What? Absolutely not. I'm just saying that it sounds reasonable to believe that burns increase with temperature, as opposed to being high in a range of temperatures and lower below and above that range. Figure 4 in your first link agrees with this common-sense guess.

The guy said "in a temperature range where burns are more likely". I'm not sure why you're objecting; there are certainly ranges where burns are less likely; that's what the paper I posted is about. I think it's also pretty clear just from the burn time curve. If it takes you a second or two to notice the heat and move away, then anything above ~155F is going to make a burn much more likely. At 180F, the burn is basi…

> The guy said "in a temperature range where burns are more likely".

Which makes it sound like there is a lower and an upper bound for this range. That's the issue.

Post reply on HN