SEC Discloses Edgar Corporate Filing System Was Hacked in 2016
wsj.com
wsj.com
Could you share a link showing exponential increase in the use of EDGAR?
Index - Q1 1994 - 3mb - https://www.sec.gov/Archives/edgar/full-index/1994/QTR1/form...
Index - Q1 2017 - 45mb - https://www.sec.gov/Archives/edgar/full-index/2017/QTR1/form...
[1] https://www.sec.gov/structureddata/what-is-structured-data
1994,3153191
1995,4813587
1996,7539137
1997,13755958
1998,16107028
1999,15935643
2000,17548021
2001,16873202
2002,18904001
2003,27723307
2004,47116841
2005,47982675
2006,50672891
2007,51322342
2008,49635521
2009,45312542
2010,45384720
2011,46455461
2012,46733150
2013,45842099
2014,47065954
2015,48112988
2016,46636963
2017,47037415The public filings themselves are also a nightmare of hard to follow formatting.
I like the bare-to-the-bones simplicity. In contrast to "better designed" portals of some other countries, I can usually point even the most technically-illiterate executive to the filing portal and expect to get something useful out the other end.
Disclaimer: I am not a lawyer. Please consult a securities lawyer before preparing and/or filing anything with the SEC.
Edit: Worth mentioning here that EDGAR's ease of use makes sites like BamSEC simple to create. Probably EDGAR's time is best spent focusing on the institutional intermediary. That allows competition to iterate on the best UX/UI for browsing these filings without imposing the cost on the filers themselves as discussed above.
Disclosure: Last10K.com is a side project of mine
2. Multiple open data formats, including TXT
3. Easy-to-follow organization (CIK), minimal indirection
4. No Javascript required, no gratuitous frameworks*
5. Bulk downloads of quarterly data (FTP up until 2016)
*not to mention gratuitous iframes (BamSEC)
Thanks to #5 anyone not satisified with the "UI/UX" can take the data and go build their own "UI".
When data is tied up in layer upon layer of indirection, Javascript, iframes, enormous overstuffed URLs, binary formats (e.g. PDF, XLS), then others cannot as easily take the data and build their own interfaces.
Not a good approach for public data nor good use of public expenditure, IMO.
I am grateful to Carl Malamud for creating EDGAR.
Btw, hackers accessing this info could possibly explain something I tweeted to them about 10 days ago:
To be fair, I've used EDGAR and it is <cough> very legacy. So no question it was going to be completely compromised.
I'd say the mistake was putting non-public information on it in the first place. The risk assessment for private data exposure was extreme.
the united states has protected trade secrets by law far longer than its been on the transparency train.
there are reasons for that, and the corporate disclosure requirements has had no effect on creating a "fair market"
Your answer does not give faith in your business practices, as a client or as an investor. I suggest you work on communication, even with strangers on the internet.
I think this goes to show that any data collection is dangerous, even if government thinks they're the good guys (when in fact they're naively collecting data that could be weaponized against them very easily). The EU is on to it as well with MiFID II granular reporting of financial market transactions starting effectively next year.
Though I'm not sure the Brits are going to play along (where the majority of trading happens in Europe); after all, why should they go through the trouble of implementing MiFID/MiFIR when leaving EU anyway?
Edit: preventing insider trading
Broadly and vaguely trusting in surveillance isn't convincing at all. The usefulness of surveillance must be weighed and re-evaluated against risks, as demonstrated by this incident.
It also takes time to coordinate investigating multiple different asset class transactions, in the event, say, equity derivatives are used.
And no, we don’t have info on what happened and what was taken, and certainly nothing about any regulatory investigations.
"The report’s findings raise fresh questions about a 2016 cyber breach into the SEC’s corporate filing system known as “EDGAR.”"
"... it shows that even after the SEC says it patched “promptly” the software vulnerability after the 2016 hack, critical vulnerabilities still plagued the regulator’s systems."
http://www.reuters.com/article/us-sec-cyber-weaknesses-exclu...
https://www.sec.gov/news/public-statement/statement-clayton-...
Think about the number of people in the financial world who are looking to get a percentage of a second advantage with high-speed trading. Hard to believe they'd pass this up if they knew about it.
https://www.nytimes.com/aponline/2017/09/21/us/ap-us-sec-cyb...
> The Securities and Exchange Commission says its corporate filing system was hacked last year and the intruders may have used the nonpublic information they obtained to profit illegally.
This is the most problematic part.
https://www.facebook.com/l.php?u=https://www.wsj.com/article...