Live data from Hacker News

DOJ: Hackers broke into an SEC database and made millions from inside info

cnbc.com

91–100 of 198 posts

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#91

Earlier quoted context omitted.

And yet many services rely on SSN for identity verification in the US (e.g. banks, telecoms, etc.)

You mean they rely solely on someone dictating a SSN number? That's insane. They should ask for a official ID with photo, as the very minimum. Is that something that goes against the American culture? The other day I had to give all 10 fingerprints to renew my driver's license (location: South America) and nobody seemed to care.

We don't require a full set of fingerprints to renew your driver's license, but we do require proof of citizenship and residence. As a practical matter, for most people that means birth certificate and a utility bill with their address on it.

I assume the fingerprints thing is for future crime solving?

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#93

I'm more curious about how they hacked into the SEC database? Did they use an email trojan? Exploit an existing flaw or backdoor? If they did this via e-mail, who did they send the mail to?

> The hackers used malicious software sent via email to SEC employees. Then, after planting the software on the SEC computers, they sent the information they were able to gather from the EDGAR system to servers in Lithuania, where they either used it or distributed the data to other criminals, Carpenito said.

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#94

How did they do this and only make a few million?...

Matt Levine discussed this topic in Money Stuff today: https://www.bloomberg.com/opinion/articles/2019-01-16/even-c...

Long-story short is that it's not always obvious how the market will react to releases. Some of the hackers only traded with a ~70% win-rate after holding the releases.

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#96

Earlier quoted context omitted.

IMO, everyone's SSN should be public. Mine has already be compromised by both my undergrad and grad school. At this point, I operate under the assumption that it is public knowledge for bad actors. Hiding SSNs is false security at best. If they were public, banks would stop hiding behind "identity theft" and would start having to acknowledge that its their responsibility to confirm who they are lending money to.

The problem with identity in the USA has always been a religious problem more than anything else. All legislation aimed around allowing people to be identified by numbers has been killed due to the whole "mark of the beast" .. "can't buy sell or trade without your number" revelations rhetoric. As religion has less of an impact on people's daily lives, I expect this to change, but in the past it's been the one thing t…

Religious concerns were only a minor factor. Other objections to having a national identifier include: wasteful "big government" spending, encroachment on states' rights, potential for civil liberties abuses, and lack of consensus over whether it's a real problem that needs to be solved.

I don't necessarily agree with those objections but there have been multiple reasons.

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#97

> The New York Stock Exchange has asked the SEC to consider limiting the amount of data collected by the CAT, which would include data on around 58 billion daily trades, as well as the personal details of individuals making the trades, including their Social Security numbers and dates of birth Dropping SSNs for natural persons would be a good idea.

IMO, everyone's SSN should be public. Mine has already be compromised by both my undergrad and grad school. At this point, I operate under the assumption that it is public knowledge for bad actors. Hiding SSNs is false security at best. If they were public, banks would stop hiding behind "identity theft" and would start having to acknowledge that its their responsibility to confirm who they are lending money to.

[deleted]

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#98

Related reading: today's Matt Levine piece on how hard it is to make money even with this info. https://www.bloomberg.com/opinion/articles/2019-01-16/even-c...

They make successful trades 77% of the time they had insider information and 45% when they didnt. That clearly is an advantage.

I would never expect a 90% success rate because of how random Wall Street is, but 77% over a period of time definitely is an advantage.

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#99
post #94

How did they do this and only make a few million?...

Matt Levine discussed this topic in Money Stuff today: https://www.bloomberg.com/opinion/articles/2019-01-16/even-c... Long-story short is that it's not always obvious how the market will react to releases. Some of the hackers only traded with a ~70% win-rate after holding the releases.

70% is still very very high. They didnt make billions because they probably started with little capital.

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#100
post #59

Earlier quoted context omitted.

And yet many services rely on SSN for identity verification in the US (e.g. banks, telecoms, etc.)

that is what wtvanhest is talking about. If everyone has your social, its no longer considered a secret (like a password) its more like a unique identifier (an email address) just like it was intended to be.

When you think about it that way & then combine it with some type of 2FA, it starts to make a lot of sense.
Post reply on HN