10 ms·
Why Not Insider Trade on Every Company?
- random_rr 11y agoThe tone of this article was really, like, interrupted by a prolific use of "likes." I wish it were so simple to hand-wave all security risks. Mr. Levine's ability to find a MySQL tutorial was quite impressive, but his dismissal of very real security concerns is childish. It's like saying cars are known to crash, so quit crashing cars. It's so, like, simple!
- fixermark 11y agoI think you got distracted from the point by all the likes. Granted, they make it easy to get distracted. The thrust of the article seems to be that it was the people in charge of these myriad wire systems who were disregarding the security risks, demonstrably to their detriment. As he states: "But I feel like part of it has to be that the people in charge of those databases, like me until today, had a disenchanted view of the financial world. These systems didn't hold the nuclear launch codes. They held press releases -- documents that, by definition, would be released publicly within a few days at most. Speed, convenience and reliability were what mattered, not top-notch security." ... which is essentially the refrain for every major, embarassing security breach: speed, convenience, and reliability trump security concerns. We have year after year of examples of innocuous systems being compromised to form elaborate weapons (at a seemingly increasing rate year-over-year), but security is still not a maximum priority. And the reasons are as Levine notes: speed, convenience, and reliability over security.
- mtsmith85 11y agoI love reading Matt Levine's writing; I enjoy the humorous tone. A bit of Louis CK for the financial world. But I didn't get that he was dismissing the security concerns. I read it as he was dismissing the idea that some aspects of the hacking could have been more easily thwarted. For example, two factor authentication is a relatively straightforward protection. Now he may have been underselling how complex it is to implement, but I would have to agree that items like two factor authentication are relatively straight forward tools at this point.
- ZoFreX 11y ago2 factor authentication has nothing to do with this, though, and would do absolutely nothing to protect against this occurrence or similar ones. 2 factor authentication is great in certain situations... but only when your code is operating correctly. If someone has achieved arbitrary code execution (even if only at the SQL layer) it's game over. 2FA won't save you.
- juliangregorian 11y agoDid you read the article? Not only was sql injection found, logins were brute forced. 2fa absolutely would have helped with that.
- thefreeman 11y agothey also brute forced employee accounts (likely the sql injection was in the employee facing section of the site)
- danielweber 11y agoThe gist is that he, knowing absolutely nothing about security, could figure out the exploit. His finance audience doesn't want to know the details of the security problems, nor do they need to. However, it's valuable for them to realize how this information is just sitting around on a company DB for anyone who can Google "SQL injection" to steal.
- schneems 11y agoI appreciated the tone of the article. I found it very easy to read. Though I agree the "likes" were a bit over the top. There were several times he used "like" and I mentally paused as if it were a comma only to realize he was using the word to compare two things.
- XJOKOLAT 11y agoI couldn't take the entire article seriously when he started it off with "So". What is with "So" these days. I get that it's helps conversational flow but I regularly now see it as a way to start an article. Sorry, rant over.
- nostromo 11y agoIt's actually still possible to perform a specific type of legal insider trading. Example: you are an executive at E Corp and the company will announce its acquisition in two months. You had previously set up planned trades to sell x number of shares each month before then. Because the acquisition is at a premium on the current price, you will make much less money if you go forward with your trades before the announcement. So, what do you do? You cancel the trades. Was this insider trading according to the SEC? Surprisingly, no! Even though you're profiting from insider information, the SEC rules are such that for insider trading to occur, you actually need a trade. https://en.wikipedia.org/wiki/SEC_Rule_10b5-1#A_possible_loophole:_canceling_plans https://en.wikipedia.org/wiki/SEC_Rule_10b5-1#A_possible_loo... Martha Stewart did exactly this before her company was acquired earlier this year: http://i.imgur.com/ZikHCpP.jpg http://i.imgur.com/ZikHCpP.jpg
- cespare 11y agoSo a "trade canary", then.
- mmanfrin 11y agoI wonder if it would be possible to track the continual sales of stock by large shareholders, use that to buy options based on the canary trades disappearing. This would then lead to the question: am I an insider trader if I am basing my options off of the lack of sales of insiders?
- airza 11y agoNo! Matt levine's articles (which I recommend reading) give an excellent description of this.
- hueving 11y agoTheir sales are very sporadic so it's not as reliable as you would think. Sometimes they need cash to pay for a new house, hitmen, etc. Other times they let the stock vest for longer because they don't need the money.
- tokenadult 11y agoI think I will end up upvoting every share of this Bloomberg View columnist's columns here on Hacker News. The author, Matt Levine, thinks like a hacker in the best sense, by pushing ideas to their extremes and seeing what the consequences might be. He adopts a humorous tone, but his columns are full of food for thought. http://www.bloombergview.com/contributors/matt-levine http://www.bloombergview.com/contributors/matt-levine
- myblake 11y agoYeah seriously he's incredibly smart and funny.
- hkmurakami 11y agoYou should also take a look at his writing at Dealbreaker, where he used to write before joining Bloomberg View. http://dealbreaker.com/author/mlevine/ http://dealbreaker.com/author/mlevine/
- fitzwatermellow 11y agoI've been noticing a lot of spikes across assets lately. Always timed a minute or two before the official release print. That used to constitute a somewhat unusual occurrence. One expects relative calm before the storm. Now it seems to happen with every bit of data. It could be chalked up to algos pre-positioning in anticipation. But many times if you are tracking fellow traders on your twitter feed as well as the price action, you'll notice a cry of "Leaked!" coupled with the price swings. I always assumed something far more nefarious and insidery was taking place. Powerful forces manipulating markets for various geo-political ends and so forth. So am somewhat relieved to see ordinary everyday greed to be the culprit. Am waiting for a Nanex style expose on this phenomenon.
- nomailing 11y agoI am wondering if this centralized infrastructure for financial news is actually a good idea. This could always happen again and again. All the employees in these news companies could get a mass of insider information which they could sell. Isn't maybe an alternative decentralized news publishing service a better idea? Couldn't the CEO of a company publish their financial news only on their own website at the given publication date? Why is it necessary for these news to be stored in some central news database days before their publishing date? And I mean these as honest questions because I have really no idea what the advantage would be? And another related question: wouldn't it make sense with today's Internet infrastructure to reduce the interval between earnings reports. Maybe it could even be something like a continous automatic publishing of these company finances. Always when some financials change it could directly be published. That way all investors would at all times have the same information as the insiders, so everyone would be on the same level. Of course some extraordinary news like mergers or acquisitions might still give some people insider information who prepare the deal, but at least the quarterly earnings could not be insider information.
- jedberg 11y ago> Why is it necessary for these news to be stored in some central news database Amusingly it's because of the hedge funds. They want to have a limited list of places to check for news to make sure no one gets there ahead of them. This is why they were so upset when the Netflix CEO made something public on Facebook -- because they weren't watching his Facebook page for news (but they sure are now!). The SEC actually has a very limited set of places that you can release financial news because of this.
- acconsta 11y agoI mean, hedge funds have the resources to monitor thousands of websites. Joe Retail Investor doesn't. Reg FD was introduced to level the playing field.
- pdeuchler 11y agoI was under the impression that it was because financial news is an extremely sensitive business. Twitter has the power to move the market now, and we already know the damage simple, fake websites can do[0]. There's a lot of power in publishing public financial information (as the article demonstrates) and that is why we have regulation. People need confidence in their information if they are to have confidence in their market. [0] http://www.theverge.com/2015/7/14/8962433/fake-bloomberg-news-twitter-stock-scam http://www.theverge.com/2015/7/14/8962433/fake-bloomberg-new...
- dmourati 11y agoI enjoyed the tone and the piece. His assessments of brute-forcing and SQL injections were quite accurate.
- pbreit 11y agoWould it be so bad if insider trading laws just went away? Information is spreading faster than ever. So a few Mak outsized gains on some inside info. Is it that big a deal?
- Quanticles 11y agoCorporations are supposed to operate on the behalf of their shareholders - insider trading is in direct conflict with that
- pbreit 11y agoHow is that? Set up a private mailing list for shareholders, then.
- jamesjyu 11y agoNot all the upcoming announcements can be shared with all shareholders. Too much risk in leaking.
- kasey_junk 11y agoShareholders have non-criminal recourse to deal with corporations not operating on their behalf.
- gnopgnip 11y agoInsider trading is taking advantage of the rest of the market. If there was nothing done to prevent it, it could cause prevent many investors from entering the market.
- Taek 11y agoPerhaps someone will change my mind, but I see the block on insider trading and spoofing as harmful to the financial industry overall. Someone starts shorting a ton of Apple stock? That probably means something big is happen at Apple, and it's not good. It's information. Spoofing as a technique can be used to combat and inhibit other types of trading, and is in some sense an algorithm to 'keep the opponent honest'. As best as I can tell, the biggest reason that we as a culture are against insider trading is because 'it's not fair'. (happy to read a response that adds more depth to my understanding). It isn't fair, and the people with insider information are going to make a lot of money. But in the process of making that money they bring the information to everyone else. And insider trading incentivizes knowing as much as possible so that you can have an edge on the competition.
- javert 11y agoYou are absolutely right. "Insider trading" is like the war on drugs.
- wavefunction 11y agoIndeed, a slap on the wrist applied very rarely to those white collar criminals unfortunately politically unconnected to face punitive actions and another government initiative that also rarely applies any sort of punishment to the rich and connected. Meanwhile, on the other side of the tracks - snatched some swisher sweets? That's a shootin. Sass me while black? That's another shootin. You got a likky stik of collie and minoritous in nature? You going down: hard!!!
- deleted 11y ago[deleted]
- javert 11y ago> Indeed, a slap on the wrist applied very rarely to those white collar criminals unfortunately politically unconnected to face punitive actions and another government initiative that also rarely applies any sort of punishment to the rich and connected. I don't believe this is even remotely accurate. > Meanwhile, on the other side of the tracks - snatched some swisher sweets? That's a shootin. Sass me while black? That's another shootin. You got a likky stik of collie and minoritous in nature? You going down: hard!!! I don't deal with sarcasm and vulgarity. If you want to make a point, make it politely and directly.
- uptown 11y agoReplace hackers with the NSA. Imagine the trades one could make with access to the world's email inboxes.
- Uhhrrr 11y agoGiven the number of NSA employees who have confessed to abusing their access to LOVEINT, it must have been tried already.
- bbcbasic 11y agoThen there is the story of the really sophisticated guys who didn't get caught. Unfortunately that's a story you won't be reading online, but will just have to imagine. It really makes me question the sanity of doing this illegal trading. For as much effort you could do something legal and make money. Maybe not as much but surely without the risk of going to prison.
- raisincakes 11y agoSadly, insider trading is pervasive on wall street. You don't read about the guys that don't get caught, and there are a lot of them. Remember, if you can't spot the sucker at the table, you're the sucker. That's why I keep my money far away from the stock market except for index funds.
- kasey_junk 11y agoIf you believe that the entirety of the market is rigged, what possible reason is there to make an exception for index funds?
- raisincakes 11y agoBecause individual stocks can be rigged in either direction (for or against your position), but at the level of sector or index funds all of that activity balances out.
- bbcbasic 11y ago> That's why I keep my money far away from the stock market except for index funds. I think the sucker at the table is the amateur day trader who thinks they can out-smart the market, but really they are gambling. On the other hand spotting an undervalued stock and buying it and holding for the long term, especially with a portfolio to protect you isn't too suckerish and should be quite immune from whatever the insider traders and high frequency algo guys are doing.
- MichaelGG 11y agoThat's simply not true. Having certain knowledge can put you in a vastly asymmetrical position as far as white or black hat goes. I'm in that position myself. I've enough attacks and some 0days that I could retire off a rather small bit of work (I discovered one guy making $30k/mo recurring off of an amateur attack). Instead, I'm trying to start a security company. It's loads more work and probably not as much reward, at least easily. In fact, it would not be hard to find people where you might say the opposite: they're insane for not being a criminal.
- cheez 11y agoWhat blows my mind is that these people don't encrypt their emails with some form of plausible deniability envelope. I mean, if you're smart enough to set up servers for customers of your illegal activities, you should be smart enough to know what to avoid.
- erikb 11y agoNot really, especially in East European countries where the legal system is weak. When everybody hacks everybody every day and nobody gets sued then you stop to worry about hiding.
- tgpc 11y agoI believe if you become a member of the US Congress you are explicitly excluded from insider trading laws. So you could always stand for office. Sigh.