Live data from Hacker News

DOJ: Hackers broke into an SEC database and made millions from inside info

cnbc.com

51–60 of 198 posts

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#51

Earlier quoted context omitted.

And yet many services rely on SSN for identity verification in the US (e.g. banks, telecoms, etc.)

You mean they rely solely on someone dictating a SSN number? That's insane. They should ask for a official ID with photo, as the very minimum. Is that something that goes against the American culture? The other day I had to give all 10 fingerprints to renew my driver's license (location: South America) and nobody seemed to care.

That'll be leaked eventually, too.

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#52
post #11
post #9

Earlier quoted context omitted.

Just curious -- why does that matter? In either case there's a single moment wherein people can trade on it. Why is it better for that moment to be at 9:30 instead of say noon?

I guess it prevents people hammering the servers to get the earning reports ASAP. With this, people have a few hours to get the reports which means miliseconds matter less.

...which happens anyway. Starting 5-10 minutes before the official earnings reports come out, investor.google.com gets hammered by bots, requesting every few milliseconds until the actual page is released.

I knew an SRE that wanted to put up a fake earnings report until the official time at which the real one was released, to disincentivize this behavior, but the lawyers nixed that idea really quick.

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#53
post #51

Earlier quoted context omitted.

You mean they rely solely on someone dictating a SSN number? That's insane. They should ask for a official ID with photo, as the very minimum. Is that something that goes against the American culture? The other day I had to give all 10 fingerprints to renew my driver's license (location: South America) and nobody seemed to care.

That'll be leaked eventually, too.

That's a fact of life. I'm talking about how they are determining identity. Just asking for a SSN number is mostly like dealing with anonymous people (thus my question about culture).

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#54
post #22

This isn't hard to believe if you've worked w/ the Edgar system!

Not a security complaint but an annoying experience with the system:

Sat down one Saturday to create a database for their Financial Statement and Notes data set https://www.sec.gov/dera/data/financial-statement-and-notes-...

Located documentation, thought okay this shouldn't be too bad. Ended up taking one day to understand the structure and another to implement the system. Finally got everything loaded in my tables and spot checked against the rendered versions on their website only to discover they truncate the most important text field. It's technically in the documentation that the value field is limited to 2048, but it's also in the documentation that the value field is for 'text analysis applications' and their website literally says: 'The information is presented without change from the "as filed" financial reports submitted by each registrant...' so I managed to gloss over this detail until I had already spent and entire weekend working on it.

I just can't wrap my mind around how they got 99% of the way there and then decided, 'hey lets just truncate this field, it's only the entire purpose of this dataset.'

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#56

Earlier quoted context omitted.

IMO, everyone's SSN should be public. Mine has already be compromised by both my undergrad and grad school. At this point, I operate under the assumption that it is public knowledge for bad actors. Hiding SSNs is false security at best. If they were public, banks would stop hiding behind "identity theft" and would start having to acknowledge that its their responsibility to confirm who they are lending money to.

And yet many services rely on SSN for identity verification in the US (e.g. banks, telecoms, etc.)

And some places "rely" on knowing a full name or just a phone number.

We would call that an error on their part, and I don't see why the same logic doesn't apply here.

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#57
post #40

Earlier quoted context omitted.

SSNs were never designed for, nor intended as, identification. For years, social security cards bore the text "NOT FOR IDENTIFICATION" on the front. https://www.npr.org/2018/03/22/596180023/how-social-security...

My understanding is that that warning applied to the card itself, not to the number. That is, the bearer of that card has no provable relationship to the social security number on the card as it contains no attestable information (like a photograph or general description) so the card cannot be used for identification. The number itself is of course used for identification from the beginning as a unique identifier for…

The problem you see with using the card itself as identification of course also applies to using the number itself as identification.

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#58

Earlier quoted context omitted.

And yet many services rely on SSN for identity verification in the US (e.g. banks, telecoms, etc.)

And some places "rely" on knowing a full name or just a phone number. We would call that an error on their part, and I don't see why the same logic doesn't apply here.

It’s risk management. Some products just have greater risk associated with them.

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#59

Earlier quoted context omitted.

IMO, everyone's SSN should be public. Mine has already be compromised by both my undergrad and grad school. At this point, I operate under the assumption that it is public knowledge for bad actors. Hiding SSNs is false security at best. If they were public, banks would stop hiding behind "identity theft" and would start having to acknowledge that its their responsibility to confirm who they are lending money to.

And yet many services rely on SSN for identity verification in the US (e.g. banks, telecoms, etc.)

that is what wtvanhest is talking about. If everyone has your social, its no longer considered a secret (like a password) its more like a unique identifier (an email address) just like it was intended to be.

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#60

> The New York Stock Exchange has asked the SEC to consider limiting the amount of data collected by the CAT, which would include data on around 58 billion daily trades, as well as the personal details of individuals making the trades, including their Social Security numbers and dates of birth Dropping SSNs for natural persons would be a good idea.

IMO, everyone's SSN should be public. Mine has already be compromised by both my undergrad and grad school. At this point, I operate under the assumption that it is public knowledge for bad actors. Hiding SSNs is false security at best. If they were public, banks would stop hiding behind "identity theft" and would start having to acknowledge that its their responsibility to confirm who they are lending money to.

The problem with identity in the USA has always been a religious problem more than anything else.

All legislation aimed around allowing people to be identified by numbers has been killed due to the whole "mark of the beast" .. "can't buy sell or trade without your number" revelations rhetoric.

As religion has less of an impact on people's daily lives, I expect this to change, but in the past it's been the one thing that's always prevented proper identity management in the USA.

I am curious to know though, if there are other countries that don't identify their citizens with a public id number?

Post reply on HN