Showing posts with label CARDS. Show all posts
Showing posts with label CARDS. Show all posts

Friday, February 13, 2015

SEC Commissioner Agrees - FINRA's CARDS Proposal is Nuts

FINRA, a non-governmental, private entity, is pushing to force brokerage firms to deliver details of every transaction in every brokerage account, including yours, to it, every day.  The concept, known as CARDS, is simply mind boggling. FINRA already has access to trade data of every trade done every day, and if is so desired, it could have it in real time, for every transaction on every exchange.
FINRA also has the ability to compel brokerage firms to provide data on any transaction, any account, at any time.

English: A candidate icon for Portal:Computer ...Commissioner Piwowar called the CARDS program a solution in search of a problem. And he is 100% correct.

We are still waiting for FINRA to explain 1) why it needs this data, and 2) how it is going to prevent hackers from accessing it, and using the data to trade, or engage in identity theft.

MIT says you cannot protect the information, hackers will figure out the identities of the account holders, even without names and social security numbers. The WSJ previously reported about the MIT findings - Metadata Can Expose Person’s Identity Even Without Name - New Analytic Formula Identifies People Without Names, Account Numbers

FINRA needs to stop putting the country's personal financial information at risk simply to make it's job easier...assuming CARDS makes its job easier. FINRA claims that having all of that account information and transaction information will enable it to spot suitability issues. Isn't that what is suitability rules are designed to do? Isn't that what its exam teams are taught to spot? Is the small percentage of trades which are possibly unsuitable, engaged in by an insignificant percentage of brokers, worth risking the financial and data security of every person in this country who maintains a brokerage account?

Has FINRA lost its collective mind?

For more information, go to US SEC's Piwowar says skeptical of FINRA's data collection proposal | Reuters

The attorneys at Sallah Astarita & Cox include veteran securities litigators and former SEC Enforcement Attorneys. We have decades of experience in securities litigation matters, including SEC and FINRA investigations, insider trading cases, securities arbitrations and class actions, nationwide. For more information call 212-509-6544 or send an email.

Wednesday, February 4, 2015

FINRA Admits Cyberattacks are Significant Threat, Continues to Push CARDS

With FINRA continuing to push to have every brokerage firm in the country deliver trade data for every trade done in every customer account as part of its CARDS proposal, the release of its own Report on Cybersecurity Practices is a startling admission.
Logo

FINRA's CARD proposal is simply nuts, and a disaster waiting to happen. While FINRA claims that personal identifiers will not be included, how tempting a target is a database of every trade done in every account, with brokerage firm identifiers, and individual account identifiers, for the hackers of the world.

And can we really trust FINRA, a private organization, to hold all of that sensitive information? For what purpose? So that it can better identify potential fraud? The concept is similar to embedding electronic trackers in every person so that we can better find the one criminal when we need to do so. FINRA has enough power of the financial markets, it does not need to increase that power by invading the privacy of everyone, and increasing the cyber-security risk..

All of this makes the report released on today by FINRA a very interesting admission.  FINRA's Report on Cybersecurity Practices was released, in an effort to alert the industry that responding to the threat of a cyberattack is a high priority. No kidding, really? The United States Government has been attacked, our military has been attacked, the largest corporations in the world have been attacked, FINRA knows it is a significant problem, yet FINRA is trying to obtain details of every securities transaction, and keep that information in one place.

Good thing FINRA is issuing warnings about attacks. Is it reading those warnings?

---
Mark Astarita is a securities attorney and computer enthusiast, who has been online since 1985. He knows the dangers that online databases provide, in particular for financial information. He is also a partner in the securities law firm of Sallah Astarita & Cox, LLC, which represents all participants in the financial markets in compliance, regulation and litigation, nationwide. He can be reached at 212-509-6544, or at mja@sallahlaw.com.