Given the thirty minute window between copying the file to the server and the SEC posting the URL, I figure they guessed the URL from an easily predicted sequence.
DOJ: Hackers broke into an SEC database and made millions from inside info
191–198 of 198 posts
Re: DOJ: Hackers broke into an SEC database and made millions from inside info
#192Earlier quoted context omitted.
Why didn't they just decide to delay the posting by 30 seconds? It's not like that would deter regular users but it completely eliminates the high speed trading case.
Uncertain - I'm not exactly the decision-maker. But I can think of two reasons: 1) They say that earnings will come out at a certain time, so they better be out at that time or else the SEC comes after them. If they just posted earnings as coming out at say 12:00:30 instead of 12:00:00, that just shifts the problem 30 seconds later. 2) The bots will just run for an extra 30 seconds, and will still have the advantage…
For the latter, companies are not required to release reports on their website in a timely manner. That’s what EDGAR is for.
Re: DOJ: Hackers broke into an SEC database and made millions from inside info
#193Earlier quoted context omitted.
America historically was not very federalized, and being able to just abandon your life and move out west is a key part of the country's mythology, if not the DNA of the country. So there have always been attempts to resist a national ID system, and the SSN was originally not supposed to be used for this purpose. Of course in 2019 this is basically a moot point if you want to be integrated into society, but even then…
I have thought about this a little bit. If this is something Americans believe in, its time to make it official. Make a legal proceeding where you can "start again", so that nobody from your old life can trace you.
https://www.nerdwallet.com/blog/banking/undocumented-immigra...
Re: DOJ: Hackers broke into an SEC database and made millions from inside info
#194Earlier quoted context omitted.
You mean they rely solely on someone dictating a SSN number? That's insane. They should ask for a official ID with photo, as the very minimum. Is that something that goes against the American culture? The other day I had to give all 10 fingerprints to renew my driver's license (location: South America) and nobody seemed to care.
SSN is often used as an account verification, which is a problem because social engineers can get your SSN pretty easily. It's hard for a phone bank operator to ask for a photo ID.
Re: DOJ: Hackers broke into an SEC database and made millions from inside info
#195Re: DOJ: Hackers broke into an SEC database and made millions from inside info
#196Earlier quoted context omitted.
Matt Levine has written extensively on how squishy the line can be: https://www.bloomberg.com/opinion/articles/2015-07-31/when-c...
> So it's illegal "when an insider makes a gift of confidential information to a trading relative or friend." But if you read that too literally, you run right back into the first problem. There you are, at your job, talking on the phone with a company's investor relations department. The IR guy helps you with some questions about your model. You get off the phone convinced that the company is a buy. You go to buy st…
I don't see the issue.
Re: DOJ: Hackers broke into an SEC database and made millions from inside info
#197Earlier quoted context omitted.
> So it's illegal "when an insider makes a gift of confidential information to a trading relative or friend." But if you read that too literally, you run right back into the first problem. There you are, at your job, talking on the phone with a company's investor relations department. The IR guy helps you with some questions about your model. You get off the phone convinced that the company is a buy. You go to buy st…
So don't give confidential information to outsiders of the company, whether they are friends or not? I don't see the issue.
> Er. Um. Sure. But another component of effective professional analysis of the value of a company's stock is talking to the company. There's a reason that companies have earnings calls. There's a reason that, when analysts get into the weeds on those calls, the companies say things like, "We'll follow up with you individually afterwards." There's a reason that companies selling stocks or bonds do one-on-one meetings with potential buyers. There's a reason that companies not selling stocks and bonds also do one-on-one meetings with current and potential investors. There's a reason that companies have investor relations departments full of people who talk to current and potential investors.
All of this gets to a point Levine has also made many times over, which is there is no explicit statute outlawing insider trading. Which seems crazy! People go to prison over it. But when you sit down and try to define it, it becomes even more of a mess, so here we are.
Re: DOJ: Hackers broke into an SEC database and made millions from inside info
#198Earlier quoted context omitted.
SSN is often used as an account verification, which is a problem because social engineers can get your SSN pretty easily. It's hard for a phone bank operator to ask for a photo ID.
I used to give out fake SSNs to everyone that insisted on one (normally I just leave that part of a form blank). The first time someone asked for the last four digits of one of my fakes I had to scramble to remember what random number I had given out. I never considered that might actually be better security.