A pump and dump would require the same entity to be doing the buying, pumping up, and then dumping the asset.
The SEC didn’t buy, nor did it sell, nor did it pump up the price (someone pretending to be the SEC pumped up the price).
Even assuming that the “largest pump and dump” claim is correct, at most, the SEC was used for that purpose and isn’t “responsible” for it.
Which may or may not be true, if they were using "password123" then sure that's negligent and they'd bear some of the responsibility, but it might not have been the SEC's fault at all.
It seems like SEC didn't even have some basic protections in place for their Twitter account, like having 2nd-factor enabled. That feels kind of negligent already, even if they had a very secure password.
How do we know it's not an inside job? Pretty tempting to pull a twitter account takeover and make potentially millions if you a lonely cog in the SEC wheel.
These guys hacked the SEC, made huge announcement tweet, and only got a 3% move from that. More over, they only had a 10 minute window to close whatever positions they had before BTC crashed through it's pre-hack price.
There is a fair chance that they actually lost money on this play, lol.
As you say though 10 mins is a small window, but they could have easily set a Conservative stop on doubling their money with only a 1% gain.
There was already some for radio/early news, but the landscape has changed so much, and it bothers me a ton that these platforms are being used.
1. The government owns it's own top level domain(s) to be a primary source
and
2. There is the general media who can turn that into stories, and use whatever private companies they need.
This delineates official statement from general news, which people will be slightly more skeptical of.
What kind of legislation? There's a whole lot of existing law that applies in that domain (both statute and Constitutional case law), but if you think we need different laws, it probably helps to at least present the general shape of the law you want rather than just that it should in some way touch impact government using private platforms for announcements.
Whatever X is or becomes, as owned by private interests, is trusted with nothing more than scraping and rebroadcasting the original and authentic source.
A solution with less developer and user overhead ma ybe that government webs host a list of public keys by which any "gray or blue check mark" type of authenticatuon signal capability on any private service can be validated against, and the government can revoke keys at any time if for some reason there's a suspicion that a counterfeit message is being distributed via these private services. Maybe repurpose the creaky old atomic clock time sync radio signal that is deployed almost everywhere as a means to distribute a rotating secondary factor. just old PKI tactics proven to work for two plus decades.
But this approach is still open to exploiting human tendency to trust things that have been trustworthy for a long time, until they aren't. So I still think hosting official messaging feeds directly from a government run server, accessible by any barebones http client capable of displaying plain text with basic paragraph/item formatting at most, is the gold standard.
The current situation, where X or meta or google or even a mastodon instance is entrusted with the entire conduit from human input to broadcast output, is a terrible precedent to normalize.
https://www.sec.gov/about/sec-rss
So it looks like they're already doing exactly what you suggest: they post official announcements on their website which you can subscribe to using the standard way to do that (RSS), and they also rebroadcast on Twitter by linking back to the original source. What should they be doing differently? Periodically tweet reminders that you can subscribe directly to their RSS feeds? Stop posting to Twitter at all and leave only a message that you can find official news on their website?
For what it's worth though, I think the solution to that is people should have some real amount of education about the function and potential dangers of the internet before getting on it.
Twitter and Instagram could repost the government feeds.
(full opinion here): https://int.nyt.com/data/documenthelper/1365-trump-twitter-s...
which while resolved, really opens more questions than it solves (which is fine because legislating from the bench shouldn't be the norm...)
There need to be very clear laws about how social media and modern tech is used to present information. Hell for the first time the government should have the ability to directly release information and not be reliant on normal privately owned distribution, and that should be investigated as well.
This whole thing is a giant can of legal worms anyways, and it only gets worse because our legislative branch has decided to devolve into high school popularity contests and just let the judiciary sort it all out.
What laws? “There should be laws about X” is a bunch of words with no substance unless you can say what the laws should, at least in general terms, require and/or prohibit.
> Hell for the first time the government should have the ability to directly release information and not be reliant on normal privately owned distribution
The government is able to do so, and has done for... quite a long time, though until recently wide distribution was a problem. Now, you can get information directly from the websites of most government agencies.
They also release information via private conventional media (via several mechanisms) and social media (via government run accounts), but they aren't exclusively reliant on such media.
The big issue is you can't be banned from newspapers, radio, and news channels. And there was still some question about "can you just announce this on the news or is that going to be unfair to people who don't own TV's". You can absolutely be banned from twitter.
There's also the standard of keeping records. The government is supposed to have immaculate records of these sorts of things with a whole shitload of legal nonsense involved in it. Twitter has complied with this under recent presidents but it's a big question of "do they need to?" and "what happens if they don't?".
For starters it like violates the FOIA, which is a serious thing.
https://en.wikipedia.org/wiki/Government_gazette
going back even further in time you had the town crier:
After reading said announcement on Twitter, the first thing I’d do (if I cared about it) would be to head on over to sec.gov or use a search engine to find the official SEC site, then from navigate to find the official announcement. Any reputable news source should include a link in their announcement to the official announcement to save you this verification step.
At some point there may be so much targeted disinformation/misinformation out there that we need legislation to help protect against it but I don’t think we’re there yet.
> This account is verified because it is a government or multilateral organization account.
Along with a link to "Learn More"[0]
[0] https://help.twitter.com/en/rules-and-policies/profile-label...
"The grey checkmark indicates that an account represents a government/multilateral organization or a government/multilateral official. Eligibility criteria to receive a complimentary grey checkmark are listed below. Additional government and multilateral accounts can receive grey checkmarks through Verified Organizations.
Eligible government organizations at the national level may include: Main executive office accounts, agency accounts overseeing specific areas of policy, main embassy and consulate accounts, and parliamentary or equivalent institutional and committee accounts. Eligible government organizations at the state and local level include: Main executive office accounts and main agency accounts overseeing crisis response, public safety, law enforcement, and regulatory issues.
Eligible government individuals may include: Heads of state (presidents, monarchs and prime ministers), deputy heads of state (vice presidents, deputy prime ministers), national-level cabinet members or equivalent, the main official spokesperson for the executive branch or equivalent, and individual members of all chambers of the supranational or national congress, parliament, or equivalent.
Eligible multilateral organizations may include: the main headquarters-level, regional-level, and country-level institutional accounts. Eligible multilateral individuals include: The head and deputy-head or equivalent of the multilateral organization.
US only: Accounts of current US state governors and senior military leaders are also eligible.
Eligible accounts may apply here. (link)
Any government or multilateral accounts that do not qualify under our current grey checkmark criteria can see if they’re eligible under our Verified Organizations feature."
Lol, I can't believe this is really what they ended up with: multicolored stars to indicate different things? I thought it was a joke at first, but no, that's really how it works now. What a strange world...
What's the issue with it?
Whereas it used to be just. Blue check mark = this is probably the real person I think it is.
(But in this case it don’t matter anyway. They were hacked and even if we still had only blue check marks their account would have been hacked all the same.)
but really it'd be better if they didn't, since it opens them up to liability, "the website said this is a government account and they verified it, what do you mean someone was impersonating the SEC"
Old blue check = ~90% confidence that this is the person/org I think it is. Yes, mistakes happened, but by and large the verification added trust.
New blue check = This person was insecure enough to pay for a symbol. Most of them are frauds.
New grey/yellow/green/whatever check = I already forgot. Some are real, some are frauds, some are hacked, the whole system is untrustworthy.
Twitter paywalls 2FA to premium users, and even then it's SMS only
not a serious company, anyone who trusts a tweet for official information should think twice before trading on it
"We continue to be committed to keeping people safe and secure on Twitter, and a primary security tool we offer to keep your account secure is two-factor authentication (2FA). Instead of only entering a password to log in, 2FA requires you to also enter a code or use a security key. This additional step helps make sure that you, and only you, can access your account. To date, we have offered three methods of 2FA: text message, authentication app, and security key.
While historically a popular form of 2FA, unfortunately we have seen phone-number based 2FA be used - and abused - by bad actors. So starting today, we will no longer allow accounts to enroll in the text message/SMS method of 2FA unless they are Twitter Blue subscribers. The availability of text message 2FA for Twitter Blue may vary by country and carrier.
Non-Twitter Blue subscribers that are already enrolled will have 30 days to disable this method and enroll in another. After 20 March 2023, we will no longer permit non-Twitter Blue subscribers to use text messages as a 2FA method. At that time, accounts with text message 2FA still enabled will have it disabled. Disabling text message 2FA does not automatically disassociate your phone number from your Twitter account. If you would like to do so, instructions to update your account phone number are available on our Help Center.
We encourage non-Twitter Blue subscribers to consider using an authentication app or security key method instead. These methods require you to have physical possession of the authentication method and are a great way to ensure your account is secure."
(I don't have an account, cannot confirm current state of MFA auth story)
Certainly you will admit at some size, responsibility and level of funding the organization should take responsibility for protecting itself from hacks. If the Department of Defense got hacked and nuclear secrets were leaked, I certainly hope people would get fired rather than sympathized with.
The DOD doesn't use Twitter, a social media platform, as the mechanism for launching nukes... what are you talking about?
more than that. all the alts went up too
If they have any reason to be concerned about the security of their account (and it looks like they should have at least from now on), they should arguably reconsider their choice of platform.
And if it's actually important, a third source from a trusted media outlet wouldn't hurt either.
Something big can happen and only a very little information can reveal it to have happened. That is the power of speed of information and the scale.
There have been many flash crashes in traditional markets bigger than that, triggered by similarly stupid events.
That's just as possible with regular stocks, which Twitter's owner has (unrelatedly) demonstrated multiple times in the past with both Tesla and Twitter... or, a bit slower, in the early covid months.
Stock markets are insanely sensitive to "insider" information and breaking news in general, which is why the regulations around them are so strict.