Live data from Hacker News

Citigroup fined $7m after legit transactions mistaken for test data for 15 years

theregister.co.uk

111–114 of 114 posts

Re: Citigroup fined $7m after legit transactions mistaken for test data for 15 years

#111

Earlier quoted context omitted.

The guy said "in a temperature range where burns are more likely". I'm not sure why you're objecting; there are certainly ranges where burns are less likely; that's what the paper I posted is about. I think it's also pretty clear just from the burn time curve. If it takes you a second or two to notice the heat and move away, then anything above ~155F is going to make a burn much more likely. At 180F, the burn is basi…

> The guy said "in a temperature range where burns are more likely". Which makes it sound like there is a lower and an upper bound for this range. That's the issue.

Not to me, so I'd say it's more "your issue" than "the issue". Industry articles on serving temperatures are all about ranges, so I presume he's just talking about those.

But even with your interpretation, it's true. The upper bound is 212F. A cup of steam is not a significant burn risk, that being something like 0.16 ml of water.

Re: Citigroup fined $7m after legit transactions mistaken for test data for 15 years

#112
post #22
post #15

Earlier quoted context omitted.

> Citigroup failing to send information on 26,810 transactions in over 2,300 such requests. 26810 requests, do you think they made more than $7m on this? It's about proportional fines. Just because they're a giant company doesn't mean we should find then $1b for forgetting to put a handicapped parking space at one of their offices.

There is a school of thought that punitive fines should be a proportion of company value/earnings rather than an absolute dollar figure to exact an equal amount of discomfort. I think Finnish speeding fines are a percent of income.

For me it's not as much about fining them as it is holding the correct people responsible (not just throwing some junior engineer under the bus as usually happens) and making sure it cannot happen again or gets noticed much more quickly

Re: Citigroup fined $7m after legit transactions mistaken for test data for 15 years

#113
post #30

Totally unrelated, but I am not surprised. I once logged into my Citi credit card account and was granted access to another user's account. Certain places were off limits but I was able to view a lot of details. Pretty scary! I never heard back after reporting the issue.

Did you collect proper snapshot? Did you report it to the right official authorities?

I did grab a few screens and contacted the only available "support" link I could find easily on their site, but after a few weeks with no response I eventually deleted the files.

Re: Citigroup fined $7m after legit transactions mistaken for test data for 15 years

#114
post #81

Synopsis: SEC sends clear message to tech people in finance: shut the fuck up if you find something, silently fix it, and sweep the remaining crumbs under the rug, or else your company will be fined millions.

$7m is a slap on the wrist for the sort of thing we're talking about, and coming clean shouldn't be a get out of jail free card either, which brings with it all sorts of pathological behaviours as well

Would you like someone to actually slap you on the wrist every time you make an innocent mistake in which there are no actual damages and nobody is hurt?

This is not a case where the company failed to transfer money owed to the government. And even in such a case, the appropriate remedy would be actual damages plus interest, where the interest is at some punitive rate.

Because some transactions were innocently concealed, the damage is that the government may have lost some opportunities to catch some people laundering money through those branches of the bank. But that is very indirect. In any case, in those cases they would probably have existing suspicions, right? And they would notice that, oops, that person is using a branch for which we have no data from Citigroup: how come?

The SEC didn't catch this error precisely because they were not investigating any user of those branches for which data were missing.

They only lost the opportunity represented by situations in which the data is the primary source of the initial suspicion of wrong-doing. That is all. As in, something in the numbers raises a red flag, and then they investigate and uncover something.

Well, they have the data now; they could comb through it, right? This 15 year period, or at least most of it, should be well within the statutes of limitations that they could still prosecute cases uncovered by the data.

Post reply on HN