Live data from Hacker News

DOJ: Hackers broke into an SEC database and made millions from inside info

cnbc.com

81–90 of 198 posts

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#81

People make money off advance information all the time. Often you can see that in the price action -- take this for example: https://imgur.com/mJq1OcY Three days before a positive press release, demand pressure beings to drive up the price. Coincidence? I'm too jaded to believe that.

That data does not look suspicious at all. A very quick google search shows this article [1] that was published around the same time as the start of that growth.

[1]: https://www.fool.com/investing/2019/01/09/why-canopy-growth-...

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#82
post #80

Earlier quoted context omitted.

IMO, everyone's SSN should be public. Mine has already be compromised by both my undergrad and grad school. At this point, I operate under the assumption that it is public knowledge for bad actors. Hiding SSNs is false security at best. If they were public, banks would stop hiding behind "identity theft" and would start having to acknowledge that its their responsibility to confirm who they are lending money to.

Why don't they just assign a new one from time to time? It's just a number after all, much easier to change than fingerprints.

The whole point is that it's not supposed to change, unlike your name, address, gender, occupation, and everything else.

Which makes it all the more ridiculous that as an immutable identifier, it's also supposed to be a secret.

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#83

People make money off advance information all the time. Often you can see that in the price action -- take this for example: https://imgur.com/mJq1OcY Three days before a positive press release, demand pressure beings to drive up the price. Coincidence? I'm too jaded to believe that.

It's worth noting that trading spikes in advance of public availability of news doesn't necessarily imply illegal activity. Overheard conversations between strangers, for example, are fair game.

There is probably also magnification effects from bots scanning the market for anomalies and piling on.

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#84

> The New York Stock Exchange has asked the SEC to consider limiting the amount of data collected by the CAT, which would include data on around 58 billion daily trades, as well as the personal details of individuals making the trades, including their Social Security numbers and dates of birth Dropping SSNs for natural persons would be a good idea.

> Dropping SSNs for natural persons would be a good idea.

It would but it isn't the SEC's decision to make and the Treasury Department & DOJ would never allow it. This is one of the primary means of investigating the flow of dirty money through the financial system.

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#85

Earlier quoted context omitted.

And yet many services rely on SSN for identity verification in the US (e.g. banks, telecoms, etc.)

You mean they rely solely on someone dictating a SSN number? That's insane. They should ask for a official ID with photo, as the very minimum. Is that something that goes against the American culture? The other day I had to give all 10 fingerprints to renew my driver's license (location: South America) and nobody seemed to care.

SSN is often used as an account verification, which is a problem because social engineers can get your SSN pretty easily.

It's hard for a phone bank operator to ask for a photo ID.

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#86
post #80

Earlier quoted context omitted.

Why don't they just assign a new one from time to time? It's just a number after all, much easier to change than fingerprints.

The whole point is that it's not supposed to change, unlike your name, address, gender, occupation, and everything else. Which makes it all the more ridiculous that as an immutable identifier, it's also supposed to be a secret.

It is supposed to change. The Social Security Administration explicitly allows people to obtain new SSNs in limited circumstances.

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#87
post #54
post #22

This isn't hard to believe if you've worked w/ the Edgar system!

Not a security complaint but an annoying experience with the system: Sat down one Saturday to create a database for their Financial Statement and Notes data set https://www.sec.gov/dera/data/financial-statement-and-notes-... Located documentation, thought okay this shouldn't be too bad. Ended up taking one day to understand the structure and another to implement the system. Finally got everything loaded in my tables…

> I just can't wrap my mind around how they got 99% of the way there and then decided, 'hey lets just truncate this field, it's only the entire purpose of this dataset.'

I'm willing to bet this is because they haven't made any significant changes to the system since it was implemented in 1996.

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#88

Earlier quoted context omitted.

The problem with identity in the USA has always been a religious problem more than anything else. All legislation aimed around allowing people to be identified by numbers has been killed due to the whole "mark of the beast" .. "can't buy sell or trade without your number" revelations rhetoric. As religion has less of an impact on people's daily lives, I expect this to change, but in the past it's been the one thing t…

If its primarily a religious problem why do countries less religious than the US have similar concepts? SINs in Canada, NINs in the UK, etc. etc

NIN is rarely used in the UK. You need one for student financing... and later for your employer to correctly relay your taxes to HMRC. Certainly it's not needed for banks/credit cards/phones/brokerages/etc.

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#89
post #40

Earlier quoted context omitted.

SSNs were never designed for, nor intended as, identification. For years, social security cards bore the text "NOT FOR IDENTIFICATION" on the front. https://www.npr.org/2018/03/22/596180023/how-social-security...

My understanding is that that warning applied to the card itself, not to the number. That is, the bearer of that card has no provable relationship to the social security number on the card as it contains no attestable information (like a photograph or general description) so the card cannot be used for identification. The number itself is of course used for identification from the beginning as a unique identifier for…

Also, the card has zero anti-forgery technology built into it. Anybody with a printer can make a near-perfect fake.
Post reply on HN