SEC announces 'Cyber Unit'
sec.gov
sec.gov
The DHS's restructure after 9/11 seemed to make sense (from my viewpoint as an outsider) even if it looks like they outsourced the branding of it to the 3rd Reich.
The Secret Service has dual roles of protection of certain officials and their families and investigating financial crimes. I understand the Secret Service's history as a sub-department of the Department of the Treasury made sense, but it still seems weird to have two very different, yet very specialized roles.
And then there's this weird new requirement that very many US Government departments have their own tactical officer squads. Can't we just have a National Police (a merged FBI, US Marshals, etc)? The current silo system reeks of each silo budget hoarding.
All of this to say: The SEC now needs to compete with the other branches of government to hire the best InfoSec people at a time when companies are investing more in the same space. If only the NSA was more focused on defending our government's systems, we could free up other government resources to work on the non-redundant functions.
EDIT: I think a while ago (2-3 years maybe) it came out that the EPA had their own SWAT team, which seemed pretty funny.
* The "Carabinieri", a branch of the military which historically which mostly works against normal crime
* The "Polizia di Stato", which became a fully civil force in 1981 and often compete with the Carabinieri
* The smaller "Guardia di Finanza", which is another militarized force but at the direct dependence of the Ministry of Economy, and deal with financial crime and smuggling
Until last year, we also had the State Forestry Corp which was its own corp and was, against many many resistances, absorbed into the Carabinieri.
I'm not so sure of the history, but it's not so crazy that there are 'two' so long as roles are clear etc..
Nation states are funny things. They change slowly :)
One thing is for certain: there should be more control over who gets to be a 'cop' and the training and ultimate badge authority should be centralized at least at the state level.
This idea of 'Universities' hiring their own cops ... with authority to arrest ... who is in charge of them exactly?
I mean, in France they have 'two systems' but as far as I remember that covers everything and there are only 2 kinds of police uniforms that I ever saw. If there is one goofball cop/gendarme, his case will go pretty high up. Not to the 'dean' of the local college or whatever. Or to 'an elected guy' from some village.
In most, and perhaps all, states, there are state-level commissions to handle cases of problem cops. However, I will be the first to admit that they don't always work as intended.
The municipalities have, depending on the state they are in, forces they call police or "police office" but they are for code enforcement, public health and security, etc.
There is also a military police (Feldjäger) but they don't play a role in day to day life.
+ normal police (immediate events such as car accidents, small burglars)
+ legal police (white-collar events such as economic crimes, bribes, traficking)
+ military police (acting as normal police on remote/wide field regions)
+ townhall police (events such as stadium security, car tickets)
+ secret police (mostly to identify society risks before they become problems)
+ military (in case of war/calamity they replace have precedence on all above)
This decentralization works OK. When the agents investigating a specific crime are suspected to be corrupt, at some point you see another agency taking forward the investigation and exposing the dirt. A recent case was the investigation about the criminal fires going in Portugal last summer. The military police was suspected of closing their eyes on the incident where +60 people died and the legal police took the case away from them.
The UK:
https://en.wikipedia.org/wiki/List_of_law_enforcement_agenci...
(I do think a lot of US police forces would benefit from a RUC -> PSNI style reconstruction)
The US is particularly unique in that even amongst countries with relatively decentralised law enforcement, I can't think of another country where most major government departments have their own internal police force ("why is the Department of Education buying shotguns") or so many "primary" federal law enforcement agencies (FBI/DEA/ATF, etc) which would normally be much more consolidated.
They also seem to have a big chip on their shoulder when it comes to law breakers, they take everything personally and in their indignation often do the paperwork wrong. I have a few stories that are shocking, but to protect parties I won't recall them here.
I think the barriers to people with skills joining the force and enriching it with fresh blood are what is preserving it's holier-than-thou attitude to technology and the future while cementing their dumb and archaic process.
I think they could learn a lot from the PSNI, they've being around less than 20 years and seem to be a far more effective and modern organisation.
The bar was pretty low to enter the Gardai https://i.redd.it/fmlp8q1dwiiz.jpg
[1] https://www.washingtonpost.com/national/health-science/at-ep...
On a more serious note, uniforms are so much more drab today. I do wonder if there's some psychological science behind the mundanity of dress uniforms.
I don't suppose you're up on your psychology? I tried Google and can only find the psych behind uniforms, and their effect on others, but no references to why they aren't as extravagant as they used to be.
Neither does your average joe want to put on a garish and fearsome uniform, for fear of being perceived as really believing in their duty-in-uniform ("it's just my job, I'm just like you"), nor does your average joe want there to be much difference in how they fear the average TSA agent than they already do their Starbucks barista :P
I'd never go so far as to suggest we need more people like Gaddafi. No, that would be morally wrong of me to suggest so. By most accounts, he was a horrible man.
But...
That man could wear a uniform. He had enough medals on his uniform to claim the top pedestal at the Special Olympics. He was a man who understood the value of a fancy dress uniform.
And, back on that same topic, I've done way too much reading now. As near as I can tell, nobody has decided why dress uniforms have become more tame. They don't even usually wear fancy hats, with some exceptions. The Swiss and Britons still have some fancy hats.
I really do wonder why the uniforms aren't nearly as fancy as they used to be. I can understand utilitarian needs, but these are dress uniforms. It's not like they are going to be out in a fancy dress ghillie suit.
I bet there's a reason for it and I'd not be surprised if it were related to something psychological. A layman's guess would be that really snazzy uniforms inspire fear and promote ideas of inequality, or a lack of feelings of shared pain and shared service. Which is probably why Gaddafi could get away with it, but Trump can not.
I have spent way too long pondering this and looking for scholarly studies at Google.
I can see how the discussion would diverge from what I envisioned due to the ambiguous nature of how I described it.
'false information spread through electronic and social media'
'violations involving distributed ledger technology and initial coin offerings'
A lot of ico's are pure scams; banning them upfront would limit the number of investors to those who are willing to break the law.
Emulating the Chinese government, which rules a country with a much less developed tradition of civil liberties than the West, would be a giant move backwards.
Careful there.
The origins of that expression come from old Rome, "Caveat Emptor". A culture whose pantheon had a common deity for merchants and thieves.
And while we are on the topic of legalised robbery: every time you see someone discourage regulation in the name of "giving the consumer a choice", keep in mind that they are most likely thinking about a more elaborate Hobson's choice.[0]
On that note, children that are overly sheltered grow up to have problems as adults. The same applies to the investing public. And on top of that, they're not children. It's their right, as adults, to do with their own money what they wish.
Disclosure and false advertising regulations, like what applies to herbal supplements, are fine, as they directly address fraud. The centralization of the securities industry, with IPO-related registration requirements, and onerous and privacy-compromising regulations that have to be met for any securities purchase, is not fine. I understand that most tokens don't qualify as securities, and thus won't be affected by SEC regulations, but that doesn't change the fact that securities regulations have a direct and profound negative effect on personal rights, and set a dangerous precedent for far more of the same.
But creating a centralized gatekeeper, and applying Prior Restraint to anyone that hasn't registered and been approved by that gatekeeper, is not a proportionate and just strategy for combating scams. It's preemptive and punishing to innocent people.
--
[0] - This I base on personal observation sample. The only ICO I've seen so far that clearly wasn't a scam was Filecoin, which was notable for trying to be as legally compliant as possible. Also, the majority of interest in ICOs I witnessed was of a get-rich-quick kind.
I think 90% of projects are poorly planned and reckless expenditures of capital, and will fail. But none of those qualities make them scams. The people organizing said token sales will destroy their own reputation, and no amount of money is worth a person's reputation. A portion of these people will end up attempting to run away with the cryptocurrency they received from investors, and these people, and only these people, should be pursued by legal authorities.
In terms of regulations, I wouldn't mind some generic disclosure requirements for token sale websites, like a simple warning about the highly experimental nature of cryptocurrency and speculative nature of investments in them, but a blanket ban, or a blanket prior restraint type restriction on anything unregistered and unapproved by a centralized gatekeeper? It would be terrible for basic internet rights IMHO, will create a largely counterproductive witch hunt against token sale promoters that will push them further underground where they're less accountable, and will prevent innovation that will produce orders of magnitude more value than the value lost on poor token investments.
I think we defining it in the same way. It's just that I don't believe that 90%+ of ICO's I've seen are "poorly planned" projects. I believe they're cases of asking people for money with no intention whatsoever to deliver anything in exchange.
But yeah, come to think of it, you're right that outright ban is a stupid idea. A better one would be to tighten up regulatory scrutiny a little bit, putting just enough barriers to discourage casual scammers. You're right it's worth to have this experiment in the open, and to see what good things can come out of it.
If someone intends to run away with the cryptocurrency, they've already decided to break the law, with or without regulations. So I don't think adding regulations will dissuade them. I think instead of putting up some kind blanket barrier to entry, which ultimately centralizes an industry, a better track would be to put more resources into enforcing basic fraud laws, to deter would be criminals. Criminals have been putting ads to phishing sites mimicking www.myetherwallet.com on Google for two years. Surely these people can be tracked down.
No-one should have to break the law to bootstrap a crypto network with likeminded people. We reserve the freedom to associate.
I was about to make a "Ministry of Truth" kind of comment until I re-checked the article: "Market manipulation schemes involving false information spread through electronic and social media"
The SEC can and does monitor social media, correlate it to trade data, and takes action based on that data.
http://nypost.com/2017/09/07/ex-amazon-employee-pleads-guilt...
Credit to Matt Levine's Money Stuff Bloomberg article where I originally read about this, but cannot find the article with a bit of Google searching.
Recent example: https://www.bloomberg.com/news/articles/2017-04-10/scammers-...
Market manipulation for financial gain is not at all a grey line.
Was just thinking about how cool it must be for Gibson to have pulled a term like cyberspace out of his head years ago and for it to be such a widely used term now.
Edit, found video interview... https://youtu.be/ae3z7Oe3XF4
Republicans cybervow to 'press on' with cyberhealth care bill in CNN cyberdebate
Trump announces new US economic cybersanctions targeting North Korea over nuclear cyberprogram
etc
Some are a bit over-the-top, there's the odd gem though
1: https://www.theatlantic.com/technology/archive/2016/09/trump...
Serious answer: the SEC doesn't have an opinion on "cryptocurrencies" as such. They don't see them through the paradigm of the internet's crypto-anarchists' assault on the financial establishment that many in the community seem to prefer. They have certain mandates to ensure financial markets are able to function, and they set rules whenever they deem something a threat to that functioning market.
That's why bitcoin has only seen some light regulation, mostly around "know your customers"–rules to guard against tax evasion and money laundering, the two most important ways it could be used illegally. ICO's are now used rather extensively for something between outright investment fraud and a pyramid scheme, so the usual rules about offering investments are applied.
This is why any such legislation needs to come with annual reviews. If it doesn't work as expected after a few years, then it should be repealed.
But of course many of us know that the law was not about cybersecurity at all, despite its misleading name, but about allowing the NSA more direct access to companies' data.
Up until two years ago, that page used to recommend a minimum browser of either IE 5 or Netscape Navigator 3. If you look at the source and use of 'htm' extension, all signals point towards it being created using an extremely old version of Microsoft FrontPage (2000?). And that's not particularly uncommon on the government systems for unsexy tasks like filing regulatory reports. Limited IT staff and budget, paired with an unimaginable amount of red tape, lead to this type of breach. Also good InfoSec talent usually doesn't stay at the Federal space long. Anyone with strong skills within 50mi of the beltway can make $25k+ more per year by going private sector. Finally, let's not forget a much more limited talent pool is available because, in many situations, these jobs require you to be a U.S. citizen.
I would argue that the SEC breach is only a symptom of a much more systemic problem with IT at the Federal level. To fix it will be extremely costly and painful. To do nothing will be extremely costly and painful.
The last few years of the Obama administration, the White House proposed budget included an interesting and useful (IMHO) line item to address this. The gist of it was that any department could draw up a plan to take a loan against their future budgets to pay down IT efficiency projects (including streamlining of processes and improvements to cybersecurity posture). I doubt a Republican Congress would go for larger federal spending now for future savings, but I hope that all "government should be small and efficient" advocates would give this kind of proposal serious thought.
This is good news for your average citizen, and bad news for financial criminals.
In fact, the shameful behavior of all crypto related markets puts the lie to that theory. As we know, the SEC does not result in upstart startups not being able to raise money. It does not result in bigger, established startups monopolizing their markets, or doing anything else inappropriate. We can all found a traditional startup if we want. Literally anyone.
Indeed, the SEC protects investment markets and makes them a safe and sane place to build startups in. It is safer for an investor to hand money to a startup in California, and safer for that startup to accept it (and abide at reasonable expense by the laws there), than anywhere in the world. We know this. That is what this whole site is about.
At the same time, crypto currency markets are wastelands of fraud and crime. In fact, I do not even feel safe posting under my long-established name, because I don't want to be targeted by criminals now or in the future for it. I steer far, far away from this.
This is a 100% genuine comment, I am not being sarcastic, I have no association with the SEC (in fact if anything I'm on the other side in the sense that I'm more of a startup founder), and this isn't shilling of any kind.
I think the SEC does really good and important work. All the (traditional, fiat-based) valuations of startups that we speak of are thanks to the hard work of the SEC in establishing a fair market. How do we know? Because everyone can see the snake oil all over the darkweb, in crypto currency exchanges and markets, in ICO's, and everywhere the SEC hasn't been touching.
I am really thankful for their work and welcome this.