8 ms·
Intel was aware of the chip vulnerability when its CEO sold off company stock
- QAPereo 9y agoWell, then I guess the CEO is going to prison, and someone at the SEC is going to make their career on this.
- dna_polymerase 9y agoDon't know why you are being downvoted so much. That's actually what should happen. He probably will stay out of prison but there is no way they can keep him as CEO. This is a textbook example of insider trading from an CEO.
- downrightmike 9y agoThey'll probably nail him, but not the Equifax C-suite.
- QAPereo 9y agoThe laws around PII breaches due to carelessness are largely nonexistent in the US. Laws around insider trading have had more than a century to develop their pointy end.
- craftyguy 9y agoWell that's a problem. PII breaches should have pointed ends as pointed, if not more, than insider trading.
- ars 9y agoThat's really hard to do. PII breaches are virtually always by mistake (irrelevant if that mistake is negligence). Insider trading is intentional. You can't really legislate serious penalties for mistakes, and negligence is really really hard to prove.
- craftyguy 9y ago> You can't really legislate serious penalties for mistakes, and negligence is really really hard to prove. You can legislate serious penalties for negligence, of which a great number of PII breaches would, IMHO, be candidates for.
- theptip 9y agoThe EU already has legislated serious penalties for data breaches, and AFAIK whether it was a "mistake" or negligence is irrelevant: https://en.wikipedia.org/wiki/General_Data_Protection_Regulation#Data_breaches https://en.wikipedia.org/wiki/General_Data_Protection_Regula... The US doesn't seem to have much appetite for this kind of regulation though.
- DoofusOfDeath 9y agoIt's worth distinguishing the US congress and executive branch from the US citizenry, in cases like this.
- theptip 9y agoVery true. I'd be interested to know how this issue polls in the US, I haven't seen any data on that.
- rosser 9y agoNegligence is not "really really hard to prove". In the US, negligence as a tort is a four-pronged test. In the case of Equifax, did they have a duty to protect your PII? Did they breach that duty? Was that breach the proximate cause of your PII being disclosed? Did that disclosure result in an injury?
- QAPereo 9y agoAbsolutely, and there needs to be a statutory value placed on PII so that the Equifaxes of the world will have to be insured, and insurers will perform due diligence. Until then...
- chatmasta 9y agoI think `downrightmike was referencing the alleged insider trading at equifax around the PII breach, not the PII breach itself. Some top executives unloaded stock just before the breach was revealed. So you're both referring to insider trading laws. Honestly the two situations seem very similar. One is a vulnerability leading to PII, the other leading to performance degradation. Both could have negative impact on stock price, and both had executives unloading stock just before their announcement.
- rosser 9y agoRather damning: "Krzanich's [Rule 10b5-1(c)] plan was created on October 30 and by Intel's own admission, the company learned of the chip vulnerability in June."
- balthasar 9y agoTo the gulag with him.
- colemannugent 9y agoThis looks really bad from a PR perspective. Huge performance effecting security vulnerability and their CEO might have traded on insider info, doesn't look good. I hope their lawyers have been productive these last few months before this all went public.
- dna_polymerase 9y agoHow do you hope for them. They fucked us. They fucked us all really good and deep. Seriously there is no more distgusting tech company right now than Intel. They screwed everyone with the fucking Management Engine and now that people are getting aware of the clusterfuck that IntelME is this shit happens. The CEO actually knew what would happen and choose to flee the sinking ship, by selling everything he could, instead of going public about it. It was security researchers and careful observations from the OSS world that made this public, not Intel. This fucking company screws their customers over and over again. I really hope that Amazon, Google, and all the Cloud Providers sue the shit out of them for this. And even more I hope that people wake the fuck up and stop buying their BS processors.
- foota 9y agoIntel was informed by others of the vulnerabilities.
- sverhagen 9y agoLet's say this were a company that you're very sympathetic toward. Or not. In either case, couldn't it still be a honest bug (as in, an "honest mistake"). They should still take their responsibility, held responsible, in court if necessary, but let any one of us who is without bugs, throw the first stone? Or is Intel somehow special? I sincerely ask you.
- dna_polymerase 9y agoSure there can be honest mistakes, but what exactly is honest about dumping your shares knowing about the bug without disclosing it? Intel just flushed the last bit of credibility down the drain by this. I really hope AMD can profit long-term from this, we really need more players in this game.
- JumpCrisscross 9y agoGoogle discloses the vulnerability to Intel in June. On October 26th, Intel files its quarterly numbers and makes no mention of Project Zero or the word "vulnerability" and fails, in Item 1A, to disclose any new risk factors [1]. On October 30th, Krzanich puts in trading instructions [2]. On November 29th, the trades occur; on December 1st, their confirmations are disclosed [2]. I'm not an expert on the sale of stock in public companies by insiders. But implementing sale instructions after finding a material risk factor and a filing that fails to reveal it looks shady. (I continue to default to the assumption of sloppiness over bad intent, though even that is harshly punishable, albeit with fines versus jail time.) [1] https://www.sec.gov/Archives/edgar/data/50863/000005086317000048/a2017q3-10qdocument.htm#sEC4B4E5BB2945CE9B97383143D9B5368 https://www.sec.gov/Archives/edgar/data/50863/00000508631700... [2] https://www.sec.gov/Archives/edgar/data/50863/000112760217033679/xslF345X03/form4.xml https://www.sec.gov/Archives/edgar/data/50863/00011276021703... Explanation 1
- wereHamster 9y agoThe CEO, by virtue of being the CEO, can always be accused of insider trading.
- djsumdog 9y agoExcept when you're Equifax?
- JumpCrisscross 9y ago> The CEO, by virtue of being the CEO, can always be accused of insider trading The proper way to do this involves: (a) timing instructions alongside public filings and (b) having a long gap--the longer the better--between instructions being submitted and trades being executed. Disclaimer: I am not a lawyer. This is not legal nor any other kind of advice. Consult with a lawyer before selling or buying shares as an insider.
- discoursism 9y agoGiven the news did not seriously affect the price of the stock (3-4% is a little more than typical volatility, but not much), it seems like his defense would be very simple. "I did not consider this to be material non-public information, and indeed, it has turned out as I expected." In fact, he'd have been better off to wait until after the disclosure to sell based on the current price (45.3) and the price when he sold (44.8).
- omarforgotpwd 9y agoThe stock seems to be doing fine. Overvalued even perhaps. A P/E of 42 when you have Nvidia hitting them on the high end, Apple and ARM hitting them on the low end, and AMD continuing to commoditize their offerings? I personally would not buy or hold at that price. I don't think there's anything illegal about selling the shares as soon as he executed on them, as he'll need to at least sell some to cover the tax liability, I think.
- mythz 9y agoINTC only has a P/E Ratio of 15.86 https://www.google.com/search?q=NASDAQ:INTC&tbm=fin https://www.google.com/search?q=NASDAQ:INTC&tbm=fin
- omarforgotpwd 9y agoAh my mistake I must have misread.
- IncRnd 9y ago> A P/E of 42 You're confusing Price and P/E.
- jcranmer 9y agoOne major counterpoint: What would have happened if the AMD developer on the LKML hadn't said "AMD chips aren't affected by [one of the bugs]" before the big public post? The big headlines would have all been about "major class of speculative execution bugs that cause data exfiltration on ARM, AMD, and Intel hardware." Only one of the bugs is Intel-specific (admittedly, the worst one), but even the Project Zero blogpost points out that it mostly focused on attacking Haswell microarchitecture. So while Intel does have some egg on its face, ARM and AMD aren't exactly out of the woods yet. Side-channel attacks as a result of speculative execution are sort of a well-known idea, but the main big news is that they are practical to exploit and exfiltrate data. I would not be surprised to see more exploits of this type affecting different hardware vendors come out over the next year. The reason why there's so much focus on Intel is because people trying to reverse-engineer the exploit found the message saying "AMD not affected" and didn't realize that AMD is affected by some of the bugs. Quite likely, whatever internal announcements that would have filtered up to the CEO would have focussed on the fact that other vendors are seeing some impact from these bugs (if nothing else, professional ass-covering). So it's hard to see how the CEO would actually find this information out even internally. Edit: to put it more succinctly, Intel appears to have been preparing for an announcement of "Major class of speculative execution vulnerabilities [with particular impact to Intel]." However, the way the announcement came out was "Apparent major bug... that's Intel-specific... oh, here's the details of this bug [with related bugs affecting everybody]." That doesn't scream insider trading to me.
- theptip 9y agoFor the question of insider trading, it's irrelevant whether other companies were affected by this bug. As long as the information was not public (in this case presumably it was an embargoed secret under NDA), and that information is material (this information clearly is as Intel's stock is down about 3% today) then it's illegal to trade on that information.
- jcranmer 9y agoWell, the question is whether one would expect that Intel would be particularly affected. If the message is "everyone is boned," then there's no reason to expect Intel's share price to fall. That the message ended up being "Intel is boned" doesn't mean that insiders expected that to be the message. To clarify: it smells bad enough to be investigated... but I wouldn't vote to convict solely on the evidence presented.
- Decabytes 9y agoOne day CEO's will be held accountable for their companies actions.
- yuhong 9y agoI wonder if that many people actually care. It is a timing attack only AFAIK.
- sevenfive 9y agoInteresting to compare the reactions in this thread from 1 day ago: "Intel's CEO Just Sold a Lot of Stock" https://news.ycombinator.com/item?id=16055851 https://news.ycombinator.com/item?id=16055851
- pas 9y agoNew evidence (Google disclosed the vuln to Intel in 2017 June), means new behavior.
- stevemk14ebr 9y agoSerious question unrelated to the article. Why are half of these comments being flagged?
- grzm 9y agoNit: I don't see any that are flagged. There are some that are downvoted. My mind-reading skills aren't what they used to be. Some of those downvoted are arguably off-topic or unsubstantive, both of which are frowned upon by HN members. Others, who knows. But then again, this is all speculation.
- jumbopapa 9y agoIsn't this a case that describes the benefits of insider trading? Him being able to sell his stock in the company alerted everyone that something may be up.
- JdeBP 9y agoWhat alerted people that something may be up were discussions on LWN and the patch commentaries in Linux kernel code commits. * http://pythonsweetness.tumblr.com/post/169166980422/the-mysterious-case-of-the-linux-page-table http://pythonsweetness.tumblr.com/post/169166980422/the-myst... * https://news.ycombinator.com/item?id=16046636 https://news.ycombinator.com/item?id=16046636
- mrmondo 9y agoIf nothing else, it sends a clear message of “I wouldn’t trust our product”.
- randyrand 9y agolooks like he made about 4% more than he should have. Pretty insignificant in the grand scheme of things.
- notacoward 9y agoMaterial + non public = insider trading. Anything else is an excuse, not a defense. This should be an open-and-shut case.
- fwdpropaganda 9y ago> Material + non public = insider trading. Anything else is an excuse, not a defense Except you're wrong. Material and non-public are not sufficient conditions for a trade to be considered insider. I know the name and common lore seems to imply it, but legally there's many other details attached.
- DennisP 9y agoCan you give an example?
- notacoward 9y agoThere are details of how "material" and "non public" are defined, but those are the two criteria. Don't call people wrong when you have zero facts on your side.
- fwdpropaganda 9y agoA counter-example is enough to prove me right. I could give you at least one counter-example, ie a real court case from 2017 where two specific entities secretly coordinated a trade for stock in one of them on material and non-public information and was determined legal. (Obviously it went to court because people like you abound, who believe that a complex matters like inside trading come down to "material" and "non-public".) I'm not going to give you that example though, because I take issue with your arrogance, ie authoritatively claiming that someone has zero facts on their side when you have no idea what you're talking about :-)
- erikb 9y agoDo we already have hints who's doing a power play here? I mean even the leak was a surprise to companies like Google as I see it. Is there someone who wants to become CEO at Intel or a bigger company that wants to become a majority stake holder?
- jenscow 9y agoIt looks like there will be a surge of purchases of new CPUs. He should have kept hold.