Live data from Hacker News

DOJ: Hackers broke into an SEC database and made millions from inside info

cnbc.com

191–198 of 198 posts

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#192

Earlier quoted context omitted.

Why didn't they just decide to delay the posting by 30 seconds? It's not like that would deter regular users but it completely eliminates the high speed trading case.

Uncertain - I'm not exactly the decision-maker. But I can think of two reasons: 1) They say that earnings will come out at a certain time, so they better be out at that time or else the SEC comes after them. If they just posted earnings as coming out at say 12:00:30 instead of 12:00:00, that just shifts the problem 30 seconds later. 2) The bots will just run for an extra 30 seconds, and will still have the advantage…

Oh, I’m sorry. I thought you were referring to the finance information on finance.google.com, not investor information about google itself.

For the latter, companies are not required to release reports on their website in a timely manner. That’s what EDGAR is for.

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#193
post #116

Earlier quoted context omitted.

America historically was not very federalized, and being able to just abandon your life and move out west is a key part of the country's mythology, if not the DNA of the country. So there have always been attempts to resist a national ID system, and the SSN was originally not supposed to be used for this purpose. Of course in 2019 this is basically a moot point if you want to be integrated into society, but even then…

I have thought about this a little bit. If this is something Americans believe in, its time to make it official. Make a legal proceeding where you can "start again", so that nobody from your old life can trace you.

From what I can tell you can go to California and say you are an immigrant and get an ID under any arbitrary name. It seems you can do anything with this so it's essentially a new identity.

https://www.nerdwallet.com/blog/banking/undocumented-immigra...

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#194

Earlier quoted context omitted.

You mean they rely solely on someone dictating a SSN number? That's insane. They should ask for a official ID with photo, as the very minimum. Is that something that goes against the American culture? The other day I had to give all 10 fingerprints to renew my driver's license (location: South America) and nobody seemed to care.

SSN is often used as an account verification, which is a problem because social engineers can get your SSN pretty easily. It's hard for a phone bank operator to ask for a photo ID.

I used to give out fake SSNs to everyone that insisted on one (normally I just leave that part of a form blank). The first time someone asked for the last four digits of one of my fakes I had to scramble to remember what random number I had given out. I never considered that might actually be better security.

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#196
post #154

Earlier quoted context omitted.

Matt Levine has written extensively on how squishy the line can be: https://www.bloomberg.com/opinion/articles/2015-07-31/when-c...

> So it's illegal "when an insider makes a gift of confidential information to a trading relative or friend." But if you read that too literally, you run right back into the first problem. There you are, at your job, talking on the phone with a company's investor relations department. The IR guy helps you with some questions about your model. You get off the phone convinced that the company is a buy. You go to buy st…

So don't give confidential information to outsiders of the company, whether they are friends or not?

I don't see the issue.

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#197
post #196
post #154

Earlier quoted context omitted.

> So it's illegal "when an insider makes a gift of confidential information to a trading relative or friend." But if you read that too literally, you run right back into the first problem. There you are, at your job, talking on the phone with a company's investor relations department. The IR guy helps you with some questions about your model. You get off the phone convinced that the company is a buy. You go to buy st…

So don't give confidential information to outsiders of the company, whether they are friends or not? I don't see the issue.

"Confidential" is a big word. There is a lot of internal information about a company that is not strictly labeled "confidential." Putting that aside, I think Levine's point, which he makes in the piece I linked and has made in several other columns, is relevant:

> Er. Um. Sure. But another component of effective professional analysis of the value of a company's stock is talking to the company. There's a reason that companies have earnings calls. There's a reason that, when analysts get into the weeds on those calls, the companies say things like, "We'll follow up with you individually afterwards." There's a reason that companies selling stocks or bonds do one-on-one meetings with potential buyers. There's a reason that companies not selling stocks and bonds also do one-on-one meetings with current and potential investors. There's a reason that companies have investor relations departments full of people who talk to current and potential investors.

All of this gets to a point Levine has also made many times over, which is there is no explicit statute outlawing insider trading. Which seems crazy! People go to prison over it. But when you sit down and try to define it, it becomes even more of a mess, so here we are.

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#198

Earlier quoted context omitted.

SSN is often used as an account verification, which is a problem because social engineers can get your SSN pretty easily. It's hard for a phone bank operator to ask for a photo ID.

I used to give out fake SSNs to everyone that insisted on one (normally I just leave that part of a form blank). The first time someone asked for the last four digits of one of my fakes I had to scramble to remember what random number I had given out. I never considered that might actually be better security.

Downside of this solution is that many companies ask for it so they can do a credit check. Giving them a fake number could technically be fraud.
Post reply on HN