The brains of investment bankers by nature are not wired for “client-based” thinking. This is the reason why the Glass-Steagall Act, which kept investment banks and commercial banks separate, was originally passed back in 1933: it just defies common sense to have professional gamblers in charge of stewarding commercial bank accounts.
Investment bankers do not see it as their jobs to tend to the dreary business of making sure Ma and Pa Main Street get their $8.03 in savings account interest every month. Nothing about traditional commercial banking – historically, the dullest of businesses, taking customer deposits and making conservative investments with them in search of a percentage point of profit here and there – turns them on.
In fact, investment bankers by nature have huge appetites for risk, and most of them take pride in being able to sleep at night even when their bets are going the wrong way.
Taibbi is receiving some blogospheric pushback, because the term “investment banker” means two very different things depending on the context. On the one hand, there’s investment banking as in M&A advice and old-fashioned merchant banking. A typical sentence would be “traders have replaced bankers in the executive suite at Goldman Sachs”. And then there’s Taibbi’s meaning: investment bankers as opposed to commercial bankers, or people who work at investment banks rather than at commercial banks. These are the people that the Vickers report is scared of.
The fact is that old-fashioned advisory bankers are pretty irrelevant here: the big money in finance has always been where the balance sheet is. And balance sheet is used on the trading floor and in commercial banking. So let’s put the fee-based bankers to one side: it’s absolutely true that investment bankers tend to love risk, even as commercial bankers have historically shunned it.
I’m reading The Devil’s Derivatives right now, Nick Dunbar’s fantastic book about credit derivatives traders. (I’ll have much more on the book when I’m done with it.) In the introduction, he makes this distinction really well, introducing the hotshot traders he dubs “the men who love to win”:
This rare, often admirable, but ultimately dangerous breed of financier isn’t wired like the rest of us. Normal people are constitutionally, genetically, down-to-their-bones risk averse: they hate to lose money. The pain of dropping $10 at the casino craps table far outweighs the pleasure of winning $10 on a throw of the dice. Give these people responsibility for decisions at small banks or insurance companies, and their risk-averse nature carries over quite naturally to their professional judgment. For most of its history, our financial system was built on the stolid, cautious decisions of bankers, the men who hate to lose. This cautious investment mind-set drove the creation of socially useful financial institutions over the last few hundred years. The anger of losing dominated their thinking. Such people are attached to the idea of certainty and stability. It took some convincing to persuade them to give that up in favor of an uncertain bet. People like that did not drive the kind of astronomical growth seen in the last two decades.
Now imagine somebody who, when confronted with uncertainty, sees not danger but opportunity. This sort of person cannot be chained to predictable, safe outcomes. This sort of person cannot be a traditional banker. For them, any uncertain bet is a chance to become unbelievably happy, and the misery of losing barely merits a moment’s consid- eration. Such people have a very high tolerance for risk. To be more precise, they crave it. Most of us accept that risk-seeking people have an economic role to play. We need entrepreneurs and inventors. But what we don’t need is for that mentality to infect the once boring and cautious job of lending and investing money.
When you’re hiring people for the UBS trading floor, you’re hiring men who love to win, congenital risk-takers. And then you surround them with risk-management protocols designed to keep them under some semblance of control. There’s a natural tension there. And if you take the hundreds of thousands of risk-takers working on trading floors in London and Hong Kong and New York and Paris, it’s a statistical inevitability that one or two of them will go rogue every year or so.
Risk-managment protocols are important, but they can never be foolproof, because they’re run by humans. So we really shouldn’t let investment bankers — by which I mean risk-hungry traders with access to billions of dollars of balance sheet — anywhere near the systemically-important balance sheets of our largest commercial banks. Losses like the $2 billion at UBS are manageable. But they’re small beer compared to the entirely legitimate losses made by the likes of Morgan Stanley’s Howie Hubler during the financial crisis. He managed to lose $9 billion, and get paid millions for doing so.
2011年9月15日 星期四
2011年5月5日 星期四
Updated: CCAvenue Payment Gateway Hacked: Report
Additionally, Anon, in the comments, says that “its still possible that someone accessed this backup somewhere in their file system on their server; and asks “if there was no hack, how is company confidential schema, employee data out in the public domain?” Note that Patel told us that it’s not “real live database schema”.
Akash Mahajan points out “Sorry for nitpicking but, Passwords need to be hashed. Hashing means one way encryption. This means once hashed there is no way of getting the original value back. Ideally secure passwords are salted and hashed. This helps in avoiding a dictionary attack against hashed passwords.”
More questions in the comments from asdf
Update 5: Hetal R on Twitter says that when he tried resetting a CCAvenue password, he got the plaintext password, and that is a security hole. He says that “By encrypted, it means non-decryptable. When you click on forgot password, a link should be sent, allowing password reset”. Sounds reasonable enough.
Update 4: Also read this Q&A with Patel, where he addresses some of the questions we received, and some claims made in that hacking report.
Update 3: the account of HackerRegiment.com, it appears, has been suspended. Details, last we checked, were still up at Pluggd.in and ClubHack. We’ve just got more details from Vishwas Patel, who says that the information that was published as ‘hacked’ was incorrect, and there is misinformation being spread. He’s pointed out a few things that point towards incorrect information.
Note that MediaNama is not in a position or qualified to determine hacker intent/claims or CCAvenue claims. We’ll let sides be represented. Take your pick.
Update 2: Patel further clarifies that “More than 85-90% of our transactions are netbanking and non-credit cards related transactions. Those transactions go through the bank server, where the end customer enters usernames and passwords, and we don’t store those. They are entered on the bank servers. There is no payment related info on our servers. CCAvenue is just a redirector in this case.”
Update 1: An initial response from Vishwas Patel, CEO of Avenues India, which owns CCAvenue, who says that he’ll get back to us after they’ve looked into this in detail. On the face of it, this is what he has to say: “From our side, we’ll have to look into it. It is not possible, because of the kind of application level firewalls that we have put up. We don’t store credit card numbers or any other kind of payment details because of the Payment Card Industry Data Security Standards, and there is no credit card or payment related info on our servers. There are new standards that have come in, that is PCI DSS 2.0, which are more stringent than the earlier standards, and we have just completed the assessment under that last week.”
Earlier: CCAvenue, among India’s largest online payment gateway services, has been hacked using “Hidden SQL injection”, according to a report on HackerRegiment.com. Apparently, all admin passwords at CCAvenue have been leaked. HackerRegiment has published a copy of some if the information it received via email from a hacker called d3hydr8 (leetspeak for dehydrate), including a list of databases, some information on tables within the databases, and more importantly, screenshots that suggest that administrator passwords may have leaked. Please note that MediaNama is unable to confirm the veracity of this report – calls, SMS’ and emails to Avenues India CEO Vishwas Patel await a response.
A MediaNama reader informs us that they’ve just made a payment via CCAvenue, so it appears that it is still active. HackerRegiment says it has informed India’s Computer Emergency Response Team. We’ll update in case we get a response from CCAvenue.
Akash Mahajan points out “Sorry for nitpicking but, Passwords need to be hashed. Hashing means one way encryption. This means once hashed there is no way of getting the original value back. Ideally secure passwords are salted and hashed. This helps in avoiding a dictionary attack against hashed passwords.”
More questions in the comments from asdf
Update 5: Hetal R on Twitter says that when he tried resetting a CCAvenue password, he got the plaintext password, and that is a security hole. He says that “By encrypted, it means non-decryptable. When you click on forgot password, a link should be sent, allowing password reset”. Sounds reasonable enough.
Update 4: Also read this Q&A with Patel, where he addresses some of the questions we received, and some claims made in that hacking report.
Update 3: the account of HackerRegiment.com, it appears, has been suspended. Details, last we checked, were still up at Pluggd.in and ClubHack. We’ve just got more details from Vishwas Patel, who says that the information that was published as ‘hacked’ was incorrect, and there is misinformation being spread. He’s pointed out a few things that point towards incorrect information.
Note that MediaNama is not in a position or qualified to determine hacker intent/claims or CCAvenue claims. We’ll let sides be represented. Take your pick.
Update 2: Patel further clarifies that “More than 85-90% of our transactions are netbanking and non-credit cards related transactions. Those transactions go through the bank server, where the end customer enters usernames and passwords, and we don’t store those. They are entered on the bank servers. There is no payment related info on our servers. CCAvenue is just a redirector in this case.”
Update 1: An initial response from Vishwas Patel, CEO of Avenues India, which owns CCAvenue, who says that he’ll get back to us after they’ve looked into this in detail. On the face of it, this is what he has to say: “From our side, we’ll have to look into it. It is not possible, because of the kind of application level firewalls that we have put up. We don’t store credit card numbers or any other kind of payment details because of the Payment Card Industry Data Security Standards, and there is no credit card or payment related info on our servers. There are new standards that have come in, that is PCI DSS 2.0, which are more stringent than the earlier standards, and we have just completed the assessment under that last week.”
Earlier: CCAvenue, among India’s largest online payment gateway services, has been hacked using “Hidden SQL injection”, according to a report on HackerRegiment.com. Apparently, all admin passwords at CCAvenue have been leaked. HackerRegiment has published a copy of some if the information it received via email from a hacker called d3hydr8 (leetspeak for dehydrate), including a list of databases, some information on tables within the databases, and more importantly, screenshots that suggest that administrator passwords may have leaked. Please note that MediaNama is unable to confirm the veracity of this report – calls, SMS’ and emails to Avenues India CEO Vishwas Patel await a response.
A MediaNama reader informs us that they’ve just made a payment via CCAvenue, so it appears that it is still active. HackerRegiment says it has informed India’s Computer Emergency Response Team. We’ll update in case we get a response from CCAvenue.
訂閱:
文章 (Atom)