The fines for these types of accidents should be starting with the letter B and ending with illions, lets see how often these types of mistakes happen in the future afterwards.
The fines for these types of accidents should be starting with the letter B and ending with illions, lets see how often these types of mistakes happen in the future afterwards.
For example, I was working on a system that handles holdings and trading information at the fund level which covers AUM that starts with a T and ends in rillions. There was an SQL injection vulnerability with schema owner access. Luckily this was an internal app, but still there are trade desk devs who could accidentally paste a drop table statement with a name collison. Anyways, I brought all this up to the principal. I was told this isn't a real big deal because they have real-time backups. I asked if they ever tested the backups... no. Do they have procedures for restoring from backups... no. They go nuts if there's a 5 minute outage, so how long would it take to restore... no idea.
Trust me ignorance is very believable, even in regulated industries.
THIS.
I briefly worked for a major European bank. There was a system that was backed up on tape. The way they checked the backups was to visually look at the tape spool - before sending the tapes off to a mountain to be preserved.
One day, they needed something from a back up. Sure enough, the tapes were simply blank due a bug in the back up script.
Lol
GP's point stands: they should be fined to a degree that it becomes clear to management that these "not uncommon" practices must become very uncommon.
Why? Fining isn’t done for fetish, it’s done proportional to harm.
The article mentions twelve civil suits (four independent). JPMorgan will lose those. Any lawyer worth their salt, meanwhile, will be looking for claims which could reasonably involve the evidence which was deleted to file. In this way, the people actually harmed get compensated versus a government agency, which mitigates corruption concerns.
*for example, no more "the dog ate our homework" excuses.
All fines are subject to court supervision. This sentence makes no sense.
> cost of doing business this way must go up, way up
We want regulators thinking of the public, not randomly increasing the cost of business. This seems more motivated by hatred for a thriving industry than claims to specific damages. Regulators who pursue this path are rightfully overturned by courts for acting capriciously.
The wealth inequality gap is widening and it's due to pussyfooted enforcement on white collar crime and strategic negligence.
You can’t fine a business just to reduce inequality. Any jurisdiction that starts ruling that way fails basic definitions for rule of law. (This is in part what ruined Argentina.)
Also, in what universe would larger fines for banks decrease income inequality? The history of enforcement is capricious penalties increase incentives for cover-ups. If a record retention mistake means personal bankruptcy, you have zero incentive to correct mistakes. In practice, this leads to corruption among regulators, who are now the de facto commanders of private business.
> due to pussyfooted enforcement on white collar crime
Where is the crime here? The SEC investigated and found no wilful wrongdoing. Those twelve private plaintiffs are going to win judgements, as will everyone else who brings claims which could reasonably by covered by the missing records.
As for what we can do, the possibilities are endless. We shape society however we like, and that is the highest form of art humans engage in.
The SEC is a civil agency. No crimes.
> organization is required to be run properly
It’s that easy? Just require good organization and you’ll get it by diktat? This entire thread seems to require a reading of Argentinian and modern Egyptian and Russian economic history.
I'm confused by your point regarding the SEC, how are they allowed to fine a company without legal basis? If my use of the word "crime" means something different to you, I mean "crime" as anything that breaks the law.
Nobody argued as much.
> I mean "crime" as anything that breaks the law
This isn’t what “crime” means. Painting your house the wrong colour may be against code, but it isn’t a crime. Legally, the difference is starker, as nobody was shown to have done anything wrong here beyond the benefit of doubt.
This is what I was responding to. You seemed to be insinuating that I didn't understand that laws or rules are not sufficient deterrents.
> nobody was shown to have done anything wrong here beyond the benefit of doubt
I'm still confused as to how the SEC was able to fine someone for not committing any wrongdoing, exact definition of the word "crime" which I have clarified I used to mean "general rule breaking" aside.
There is a legal basis: retention requirements of the Securities Exchange Act of 1934.
From the SEC order: “As a result of the conduct described above, JPMorgan willfully violated Section 17(a) of the Exchange Act and Rule 17a-4(b)(4) thereunder, which require brokerdealers to preserve for at least three years originals of all communications received and copies of all communications sent relating to its business as such.”
Allowing "smart" individuals to play dumb to benefit themselves is not smart at all at a societal level.
Strategists at these companies examine the costs of failure or cheating, and simply see that it's worth it to cut corners or pile on risk. Just look at JP Morgans history in getting fined for market manipulation.
Fines for this type of accident should be the permanent removal of the banking license.
What kind of company can you trust if evidence can be deleted "by accident" ?
I have never just deleted millions of emails and pieces of evidence in a listed company, especially one that falls under the SOX act (it implies some governance.)
Did they have the IT governance or not ?
Actually not whatever. But apparently some borders are quite thin.
part of their strength is their size.
There aren't any bank to take on their market ?
Individuals and companies won't stop having accounts or buying home or investmenting in equipment because 1 bank 'gracefully' shuts down. Another one will take on.
But risking a crash like Lehman Brothers, Wirecard (a journalist nearly got charged with market manipulation in Germany for covering what really happened in this firm), FTX,... is the real self sabotaging for a country.
"Too big to jail" is not a service for the common good. It's just protecting friends.
We need real investigations into how this bank is run, and how others are run as well. If this was genuinely just an IT incident, that's fine. But it raises questions obviously.
It's not a matter of whether there's other banks that can take on the business. It's a matter of government intervention to that degree would rock confidence and cause a negative shockwave through the markets, which would most definitely affect you no matter how much or how little you have invested in the bank in question. New backers for loans made to the largest corporations and countries on earth, easily reaching billions if not trillions of dollars would need to be accounted for and reorganized. A primary source of funding for housing, infrastructure projects, etc. would be eliminated.
I think you fail to see how deeply entrenched the largest financial institutions in the world are with modern society. Our governments literally depend on them to function because of the complexities of globalization.
If the government revoked the license for a local lawn care company on the basis of a records retention mistake, I’m fairly sure they’d have a case for reversal in the courts. I get we’re technically minded, and so technical mistakes rank up with mortal sins, but let’s keep a sense of perspective.
Sure. My point is this has nothing to do with too big to fail.
Also, what is the impact of these records being deleted? If you have a claim that reasonably involves them, it is basically cashable due to the error. If nobody can show damages, it’s hard to argue this mistake had a wide impact.
I think this is more likely: https://www.sec.gov/news/press-release/2021-262
The implementers and auditors themselves get bogged down by red tape and/or the game of telephone between various departments, leading to information and Acceptance Criterias falling between the cracks.
If you read the link in my previous comment, you'll see this isn't the first time they got fined for bad record keeping practices. In that instance, $125m.
It's kinda either/or. It's either possible that someone can get full admin privileges and deletes it off-the-record or they've got enough safeguards in place that the accidental deletion isn't possible either.
I don't think your argument works unless the article is wrong.
the thing we're discussing is deleting A LOT of records which INCLUDE the ones being subpoenaed, which is obviously easily possible, intentionally or otherwise
so, no stretch of the imagination required
So you think a few C-level execs went to 8,700 mail boxes and deleted 47 million messages to remove the EXACT evidence that was being subpoenaed?
I'm not saying that's what happened, I find the sequence of events described by JP Morgan believable. But the same process issues that allowed this to happen accidentally would allow it to happen maliciously.
I mean, I live this personally. When legal tells me to delete or retain something, I don't go get a law degree, and then insist that they let me have all the details to come to my own independent opinion about whether or not we need to delete or retain something. That is every bit as nonfunctional as when I tell them that the task they're asking for will take three weeks and they go get a programming degree and then come over and learn the exact environment we are working in so they can verify that we are telling them the correct estimate.
Part of the SEC’s process is peppering these people with pamphlets explaining how their testifying this happened is a $10+ million whistleblower payday.
Not a chance. NOTHING gets done at JPMorgan without a mountain-load of direction and a grip of meetings. This would have had to wipe out both the data and records of that direction. Because the layers of tape are so thick you can't travel floor to floor without an access card coding and used to log your time and that even these simple systems don't work all the time (which generates even more busy work, yay), it's a form of friction against any sort of "secret" dealings within the company. If your keycard/dev env/database access/wiki edits/etc are so chaotically managed, it's unlikely that you will leave 0 evidence behind. Note that there was enough information to reconstruct what happened, to some degree.
I would bet someone didn't communicate the arcane symbol column that meant "do not delete for legal reasons", in some SQL. It's that chaotic, which reinforces the paranoia about the legal consequences that are foisted on every employee, routinely. If you have a shoplifting conviction (a record that hasn't been purged), you aren't getting hired. Viewed from the inside, it's strangely dystopian, but far from subtle.
How did the bureaucracy let this happen if it's as big and bureaucratic as you claim? And there's other examples too.
Not to brag, but I skirted company policies at JPMC. I had been tasked with writing a solution for a specific process that integrated a freeform type of data. I didn't use customer data or even sensitive company information, but did cobble something together that worked as a prototype over 6 months, in addition to my application workload. Due to some unannounced hardware refresh, my laptop was to be wiped. I decided to mail a zipfile of the custom javascript code (all open source or hand-written), to myself. There was a proper application (OneDrive) to normally store this kind of data, but it wasn't on my machine...which was probably part of the reason some laptops were being nuked. So, against, company policy I "mishandled source code" and got a 2-week-long wrist-slap over it. Was this "letting employees use email to evade company policies", or is it simply something that happens because there's no practical way to prevent me from doing it and still maintain standard business operation? It's important to read between the lines sometimes.
Anything that requires participation of lower level employees, is different because they have to have explicit instructions and action plans to do anything...according to multiple policies and processes. If someone walked in and said "this is the SQL to use to delete this data for this JIRA ticket", it would be written down in a Confluence, JIRA, email, git, for starters. You would also have to have to account for the rollback as well, or it doesn't play.
All emails and code changes are up for discovery and I don’t work with individual contributors directly so I’m not even sure how I would be able to give an instruction like this without many people wondering what was up.
In the early days sure, I could go ask X person to access things directly but after a couple hundred people it doesn’t work that way. Think about an org of hundreds of thousands with the most strict compliance rules in existence.
And doing something willful here would be jail time so why would someone already wealthy risk this? Even in a corrupt system people balance risk reward. A fine for the bank, fine, but life ruined forever stretches credulity given the limited upside.
0 - https://unlimitedhangout.com/2023/04/investigative-series/cr...
1 - https://trendingpoliticsnews.com/breaking-attorney-general-t...
2 - https://news.ycombinator.com/item?id=35959865
3 - https://www.cftc.gov/PressRoom/PressReleases/8260-20
4 - https://www.counterpunch.org/2020/09/22/3-count-felon-jpmorg...
Now there's a reliable source!
If you can point out anything specific in there that's provably wrong, I'd genuinely love to hear it.
While there are many statements one can confirm, such as "took up boxing", they are surrounding nuggets like this: "After being selected by a mix of powerful businessmen, many of whom shared connections to intelligence and/or organized crime", a statement which is so vague as to be highly suspicious.
And don't even get me started on the author feeling the need to point out that all these organized crime and banking folks are Jewish - what's the relevance? Only to double down on stereotypes - the other people in the story aren't called out for their ancestry or religion...
Making things out to be anti-semitic when they're not, such as happened to Corbyn, is a popular smear tactic. It's pretty disgusting though, and many Jewish people have pointed out that it's a very harmful and anti-semitic thing to do.
That ship has long sailed in the US. I don't see this behavior stopping in earnest until the greater populace stops giving any credibility to the claims due to repetitional damage. In fact right now they have become emboldened after the 2020 elections. Meanwhile there is a real rise in anti-semitism that is likely occurring among the far-right.
Change is starting to happen online in that every single thread i've been seeing on Reddit/HN that calls out Israel also tends to completely swat away the anti-Semitic claims thrown out when any criticism of Israel typically occurs. Whether this translates into real world changes remains to be seen but we are starting to see it in the voting patterns of Millennials and Gen-Z(them supporting comments made by "the Squad" and electing more reps that don't shy away). It very will likely be a generational shift as Israel continues to damage its reputation in the US due to its tactics.
By only denouncing this Dangerous Anti-Semitism and ignoring the equally deplorable Anti-Italianism, you've outed yourself as an Anti-Italian Romanophobe whose opinions may be summarily dismissed. Checkmate.
If you read the article, you'll notice "Italian" occurring once, but not in relation to a specific person...
However, in the opening paragraphs of the "SuperMob" they're sure to mention which specific individuals are Jewish:
Crown Prince of the “Super Mob”
Henry Krinsky was born in 1896 in the city of Chicago. His father, a Jewish immigrant from Lithuania, worked as a sweatshop foreman and changed the family name to Crown when Henry was a child. After dropping out of school in the 8th grade, Crown started a steel business with his older brother, Sol Crown, in 1915, creating S.R. Crown & Company. A few years later, in 1919, another brother, Irving Crown, joined the company, which became Material Service Corporation (MSC), a sand, gravel, lime and coal business that was prominent in Chicago’s construction industry.
Henry Crown developed an early relationship with Jake Arvey, a notorious political fixer for the Democrats in Chicago who, like Crown, was the son of poor Jewish immigrants. Arvey had deep ties to the Chicago mob, including the circles around notorious gangster Al Capone
Now, I know also that you're saying I'm being overly sensitive, but I'm trying to point out (when I was asked to disprove the article) that these are signals that I think the article is not to be trusted on face value.
The article seemed pretty clear about where evidence was lacking; and is more densely packed with links than >95% of mainstream news articles.
Even if one were to completely dismiss everything fta that was even slightly suspect, you'd still have more insight into why JP Morgan might intentionally delete tens of millions of emails.
Forty-seven million emails. 47,000,000.
"Accidentally". Even if you could believe this - wow - even if you could take that at face value, the fine worth ~45 minutes or so of profit is still preposterous.
How many emails do you think JPM receives a year?
The problem is that most "reliable sources" aren't very reliable on the important topics - war, money, culture, etc.
E.g. Elizabeth Holmes got out on bail, but just recently went in to serve her sentence.
Not thankful for the downvoters although they probably thought I was cynical or something… but hey better have knowledge than points.
Well cynicism is definitely called for wrt bail, because it's regularly used for a very different purpose. It's normal for people accused of crimes to have to wait over a year for their trial in this country, and the courts often intentionally set bail so high that the accused can't possibly afford it. They are forced to choose between sitting in jail that whole time while their life evaporates, or they can plea guilty to a crime they may or may not have committed; the actual punishment is often less severe than being found innocent at trial. The prosecution can repeatedly push back the trial to keep the pressure on. Since healthcare access is almost always tied to employment, people plead guilty to crimes they didn't commit every day in this country so that their kids don't lose their access to healthcare. Just the sort of systemic, everyday corruption that we're supposed to pretend can't happen here.
And charging companies with fines is ridiculous IMO. There are always humans who made decisions ultimately. And charging companies (not them) is just a "get out of jail and enjoy Hawaii" card for them.
After they cheated, they probably had the promotions, money, golden parachutes, and left the company after bleeding it out and hurting it anyway. So why would you charge the company a second time ? Why not them ?
That's the point, they shouldn't be "reasonable" nor "appropriate" for an entity as large and with as many resources as JPM. Surely with the 300k employees they have and the literal infinite well of money they have, there's a few competent individuals working there to prevent these sort of "mistakes" from happening, and if not then they should either find some competent people, or cease to exist.
What's reasonable about charging them 4 million? It's not even a drop in the bucket, it's a singular molecule of water getting inserted into the bucket if we're talking about JPM.
Tell me, what exactly is reasonable or appropriate or fair about such a pittance of a fine for such blatant corruption? We're not talking about some random mom & pop shop, we're talking about the largest fucking bank in the States and arguably the entire world here. Someone in the thread already did some rough back-of-the-napkin math, this 4 million is a bit less than 20 minutes of income for them, in what universe is that a reasonable fine?
Instead they'll just have to have some 'extra' meetings with the regulator and report on their remediations later.
Nevertheless, one counter-intuitive policy which would end corporate control [1] (hence will never be implemented, again, no future for you) is supra-unitary taxation: effectively, tax rates above 100%, ensuring that the corporation has by default a lifetime (like a person they wish to be). Once the forever-in-debt corporation gets past a certain level of debt, it gets liquidated. Of course, corporations affected by this would have a certain scale (above $10 trillion, let's say) and a certain domain of activity (embedded AI, synthetic biology, nuclear fusion, asteroid mining, and similar).
[1] 2023, Claire Provost, Matt Kennard, Silent Coup. How Corporations Overthrew Democracy, Bloomsbury Academic, https://www.bloomsbury.com/uk/silent-coup-9781350270008