back

by sensanaty·3y ago·view on hn ↗
If it weren't so depressing it'd be incredibly hilarious how blatant and open the corruption here is, as if anyone on planet earth is gonna buy this BS story.

The fines for these types of accidents should be starting with the letter B and ending with illions, lets see how often these types of mistakes happen in the future afterwards.

8 comments
I find the story or incorrect archive settings/setup to be reasonably plausible and even likely. I work in finance and misconfiguration of systems are not that uncommon. Testing and reviewing archive settings is often not very thorough.

For example, I was working on a system that handles holdings and trading information at the fund level which covers AUM that starts with a T and ends in rillions. There was an SQL injection vulnerability with schema owner access. Luckily this was an internal app, but still there are trade desk devs who could accidentally paste a drop table statement with a name collison. Anyways, I brought all this up to the principal. I was told this isn't a real big deal because they have real-time backups. I asked if they ever tested the backups... no. Do they have procedures for restoring from backups... no. They go nuts if there's a 5 minute outage, so how long would it take to restore... no idea.

Trust me ignorance is very believable, even in regulated industries.

> I find the story or incorrect archive settings/setup to be reasonably plausible and even likely. I work in finance and misconfiguration of systems are not that uncommon. Testing and reviewing archive settings is often not very thorough.

GP's point stands: they should be fined to a degree that it becomes clear to management that these "not uncommon" practices must become very uncommon.

> they should be fined to a degree that it becomes clear to management that these "not uncommon" practices must become very uncommon

Why? Fining isn’t done for fetish, it’s done proportional to harm.

The article mentions twelve civil suits (four independent). JPMorgan will lose those. Any lawyer worth their salt, meanwhile, will be looking for claims which could reasonably involve the evidence which was deleted to file. In this way, the people actually harmed get compensated versus a government agency, which mitigates corruption concerns.

Don't get stuck on the word "fine'. The fines cans be judgment at court. The cost of doing business this way must go up, way up, so that these critical institutions are legally transparent* and motivated by a strong desire to avoid drastic haircuts.

*for example, no more "the dog ate our homework" excuses.

100%

Allowing "smart" individuals to play dumb to benefit themselves is not smart at all at a societal level.

Strategists at these companies examine the costs of failure or cheating, and simply see that it's worth it to cut corners or pile on risk. Just look at JP Morgans history in getting fined for market manipulation.

I'm not saying they shouldn't. But it's a leap to attribute to malice what is easily explained by ignorance.
>I asked if they ever tested the backups... no.

THIS.

I briefly worked for a major European bank. There was a system that was backed up on tape. The way they checked the backups was to visually look at the tape spool - before sending the tapes off to a mountain to be preserved.

One day, they needed something from a back up. Sure enough, the tapes were simply blank due a bug in the back up script.

"The way they checked the backups was to visually look at the tape spool"

Lol

Why fines ?

Fines for this type of accident should be the permanent removal of the banking license.

What kind of company can you trust if evidence can be deleted "by accident" ?

JP Morgan is the very definition of 'too big to fail'. Any actions against them to that degree would be self-sabotaging by any country. I'm not saying it's a good thing, but that's the reality right now.
That's easily corrected: split them up. Chase and JP Morgan should have never been allowed to merge in the first place.
Why ?

There aren't any bank to take on their market ?

Individuals and companies won't stop having accounts or buying home or investmenting in equipment because 1 bank 'gracefully' shuts down. Another one will take on.

But risking a crash like Lehman Brothers, Wirecard (a journalist nearly got charged with market manipulation in Germany for covering what really happened in this firm), FTX,... is the real self sabotaging for a country.

"Too big to jail" is not a service for the common good. It's just protecting friends.

We need real investigations into how this bank is run, and how others are run as well. If this was genuinely just an IT incident, that's fine. But it raises questions obviously.

> JP Morgan is the very definition of 'too big to fail'

If the government revoked the license for a local lawn care company on the basis of a records retention mistake, I’m fairly sure they’d have a case for reversal in the courts. I get we’re technically minded, and so technical mistakes rank up with mortal sins, but let’s keep a sense of perspective.

Governments do not just "remove the banking license" of JP Morgan.
Yes, this is precisely the problem.
Does this sometimes lead to "we are immortals, can do whatever we want"?

Actually not whatever. But apparently some borders are quite thin.

Shame

I have never just deleted millions of emails and pieces of evidence in a listed company, especially one that falls under the SOX act (it implies some governance.)

Did they have the IT governance or not ?

Proportionl fines that dent seriously into their profits ensures this does not happen again. But usually the fines end up being slaps on wrists which ensures continuity of these schemes
Do you really think JP Morgan, which has about 300,000 employees, has a secret network of corrupt actors at an administrative level to carry out something like this on purpose without someone blowing the whistle?

I think this is more likely: https://www.sec.gov/news/press-release/2021-262

There doesn't have to be a "network". This probably reached the highest executive levels and a few of them discussed it and said let's accidentally delete this and take the fine. You're incredibly naive if you think this wasn't intentional.
I run a very small public company, and can say from first hand experience it would be extremely difficult to do something like this let alone do it and not get caught.

All emails and code changes are up for discovery and I don’t work with individual contributors directly so I’m not even sure how I would be able to give an instruction like this without many people wondering what was up.

In the early days sure, I could go ask X person to access things directly but after a couple hundred people it doesn’t work that way. Think about an org of hundreds of thousands with the most strict compliance rules in existence.

And doing something willful here would be jail time so why would someone already wealthy risk this? Even in a corrupt system people balance risk reward. A fine for the bank, fine, but life ruined forever stretches credulity given the limited upside.

> highest executive levels and a few of them discussed it and said let's accidentally delete this

So you think a few C-level execs went to 8,700 mail boxes and deleted 47 million messages to remove the EXACT evidence that was being subpoenaed?

As someone who does this work, I agree. This sounds like a IT Operations messed something up on its way to the people who do the lawyer work. Never had it happen to us, but I could see me handing something off to others in the Operations Org and having accidents happen.
This sounds like something that would occur in an industry not heavily regulated. That's not JPM.
Have a hard time believing you. Do you work in a area requiring compliance for PCI or Sarbox? This should never "just happen" with any competent team.
I'm not even sure there needs to be a secret network of corrupt actors. Investment banking is rotten to the core, has been for decades.

https://archive.is/z6Uer

How relevant are the 300,000 employees? Do they all had access to this information?
The scale of record keeping in a place like JP Morgan is enormous. Just payments transactions are about $10 trillion a day. Unless documents are ring fenced from the start and not many systems and people have access to it, it is highly unlikely that someone is able to destroy it in all the right places without anybody noticing.

If you read the link in my previous comment, you'll see this isn't the first time they got fined for bad record keeping practices. In that instance, $125m.

Yes
Yes.
No need to fine them, if this stuff is needed in a lawsuit just let the other side make adverse inferences by default whenever the data could have been deleted.
Fines? You mean detention.
Can’t you pay to get out of detention in the US?
Do you mean bail? The only thing bail does is get the defendant out of jail until the trial, and the only (Constitutional) reason to jail someone before trial is to make sure they show up.

E.g. Elizabeth Holmes got out on bail, but just recently went in to serve her sentence.

Taking away many billions from billionaires is worse for them than detention.
no, it's just a cost to do business. They still have billions after you charged them billions.

And charging companies with fines is ridiculous IMO. There are always humans who made decisions ultimately. And charging companies (not them) is just a "get out of jail and enjoy Hawaii" card for them.

After they cheated, they probably had the promotions, money, golden parachutes, and left the company after bleeding it out and hurting it anyway. So why would you charge the company a second time ? Why not them ?

Why not both?
Do establish in what way these fines are at all reasonable or appropriate. I don't think you know to what level this data loss is if you're being this reactionary.
> reasonable or appropriate

That's the point, they shouldn't be "reasonable" nor "appropriate" for an entity as large and with as many resources as JPM. Surely with the 300k employees they have and the literal infinite well of money they have, there's a few competent individuals working there to prevent these sort of "mistakes" from happening, and if not then they should either find some competent people, or cease to exist.

What's reasonable about charging them 4 million? It's not even a drop in the bucket, it's a singular molecule of water getting inserted into the bucket if we're talking about JPM.

So, you want the fine to be unreasonable, and inappropriate? That's your stance? Why should anyone care for your opinion, your ideas, or your morals?
In a regulated industry, the regulator would absolutely issue fines and threats of license if gross incompetence led to them not upholding their regulatory duties... Well in some ideal world that would happen, but ha, not likely.

Instead they'll just have to have some 'extra' meetings with the regulator and report on their remediations later.

I say the penalty should start with J and end with ail.
First of all: your current society has no chance at a future, AI overlords, mogul trillionaires, climate change and so on being the least currently concerning of your issues.

Nevertheless, one counter-intuitive policy which would end corporate control [1] (hence will never be implemented, again, no future for you) is supra-unitary taxation: effectively, tax rates above 100%, ensuring that the corporation has by default a lifetime (like a person they wish to be). Once the forever-in-debt corporation gets past a certain level of debt, it gets liquidated. Of course, corporations affected by this would have a certain scale (above $10 trillion, let's say) and a certain domain of activity (embedded AI, synthetic biology, nuclear fusion, asteroid mining, and similar).

[1] 2023, Claire Provost, Matt Kennard, Silent Coup. How Corporations Overthrew Democracy, Bloomsbury Academic, https://www.bloomsbury.com/uk/silent-coup-9781350270008