Skip to content
 

Please change your passwords. Please direct your trades to IEX.

Sometimes it goes up. Sometimes it goes down. Yesterday it went up. No logic. No reason.
Last year the S&P went up 32%. This first quarter it went up 1.81%. Things are changing. It’s still doing well against its 200-day moving average:
S&POverTwoYears
On the other hand, APO has breached its 200-day moving average and looks positively sick. I’m out of APO.
APOTwoYear
But I’m still largely in BX, which has a much better chart and some nice broker analyst recommendations (price target $40).
BXOvertwoyears
Going with Limit orders. There are two reasons to use limit orders:
1. You may snag a “buy” more cheaply.
2. You’re protected from being sold out cheaply in the next flash crash.
Lately, I’ve found that limit orders — especially those to buy a stock — don’t seem to work. I put in an order  — even at the offer price — and suddenly, the price goes higher.
I watch my screen incredulous at how I’m being screwed.
If you read Michael Lewis’ book, Flash Boys, (and you should), you’ll find that things mysteriously happen when you indicate to the market that you want to buy or sell. That mysteriousness costs you (and everybody else) billions on dollars. You are front-runned by high frequency traders. Which is why I’m strongly recommending that everyone direct their trades to IEX, a new exchange mentioned in Michael’s book.
So far, two retail brokers — Interactive Brokers and TradeStation Securities — have announced they’ll allow you to direct your trades to IEX. I’m guessing the next one will be Schwab, based on this amazing statement from Schwab (bolding added by me.):
Charles Schwab Logo Company Statement

High-frequency trading is a growing cancer that needs to be addressed

April 3, 2014

Schwab serves millions of investors and has been observing the development of high-frequency trading practices over the last few years with great concern. As we noted in an opinion piece in the Wall Street Journal last summer, high-frequency trading has run amok and is corrupting our capital market system by creating an unleveled playing field for individual investors and driving the wrong incentives for our commodity and equities exchanges. The primary principle behind our markets has always been that no one should carry an unfair advantage. That simple but fundamental principle is being broken.

High-frequency traders are gaming the system, reaping billions in the process and undermining investor confidence in the fairness of the markets. It’s a growing cancer and needs to be addressed.  If confidence erodes further, the fuel of our free-enterprise system, capital formation, is at risk. We can’t allow that to happen. For sure, we still believe investing in equities is a primary path to long-term wealth creation, and we believe in the long-term structural integrity of the markets to deliver that over time for individual investors, which is all the more reason to be vigilant in removing anything that creates unfair advantage or undermines investor confidence.

On March 18, New York Attorney General Eric Schneiderman announced his intention to “continue to shine a light on unseemly practices in the markets,” referring to the practices of high-frequency trading and the support they receive from other parties including the commodities and equities exchanges. He has been a consistent watchdog on this matter. We applaud his effort and encourage the SEC to raise the urgency on the issue and do all they can to stop this infection in our capital markets. Investors are being harmed, and they shouldn’t have to wait any longer.

As Michael Lewis shows in his new book Flash Boys, the high-frequency trading cancer is deep. It has become systematic and institutionalized, with the exchanges supporting it through practices such as preferential data feeds and developing multiple order types designed to benefit high-frequency traders. These traders have become the exchanges favored clients; today they generate the majority of transactions, which create market data revenue and other fees. Data last year from the Financial Information Forum showed this is no minor blip. High-frequency trading pumped out over 300,000 trade inquiries each second last year, up from just 50,000 only seven years earlier. Yet actual trade volume on the exchanges has remained relatively flat over that period. It’s an explosion of head-fake ephemeral orders – not to lock in real trades, but to skim pennies off the public markets by the billions. Trade orders from individual investors are now pawns in a bigger chess game.

The United States capital markets have been the envy of the world in creating a vibrant, stable and fair system supported by broad public participation for decades. Technology has been a central part of that positive story, especially in the last 30 years, with considerable benefit to the individual investor. But today, manipulative high-frequency trading takes advantage of these technological advances with a growing number of complex institutional order types, enabling practitioners to gain millisecond time advantages and cut ahead in line in front of traditional orders and with access to market data not available to other market participants.

High-frequency trading isn’t providing more efficient, liquid markets; it is a technological arms race designed to pick the pockets of legitimate market participants. That flies in the face of our markets’ founding principles. Historically, regulation has sought to protect investors by giving their orders priority over professional orders. In racing to accommodate and attract high-frequency trading business to their markets, the exchanges have turned this principle on its head. Through special order types, enhanced data feeds and co-location, professionals are given special access and entitlements to jump ahead of investor orders. Last year, more than 95 percent of high-frequency trader orders were cancelled, suggesting something else besides trading is at the heart of the strategy. Some high-frequency traders have claimed to be profitable on over 99 percent of their trading days. Our understanding of statistics tells us this isn’t possible without some built in advantage. Instead of leveling the playing field, the exchanges have tilted it against investors.

Here are examples of the practices that should concern us all:

  • Advantaged treatment: Growing numbers of complex order types afford preferential treatment to professional traders’ orders, most notably to jump ahead of retail limit orders.
  • Unequal access to information: Exchanges allow high-frequency traders to purchase faster data feeds with detailed information about market trading activity and the specific trading of various types of market participants. This further tilts the playing field against the individual investor, who is already at an informational disadvantage by virtue of the slower Consolidated Data Stream that brokers are required by rule to purchase or, even worse, the 15- to 20-minute-delayed quote feed they have public access to.
  • Inappropriate use of information: Professionals are mining the detailed data feeds made available to them by the exchanges to sniff out and front-run large institutions (mutual funds and pension funds), which more often than not are investing and trading on behalf of individual investors.
  • Added systems burdens, costs and distortions of rapid-fire quote activity: Ephemeral quotes, also called “quote stuffing,” that are cancelled and reposted in milliseconds distort the tape and present risk to the resiliency and integrity of critical market data and trading infrastructure.  The tremendous added costs associated with the expanded capacity and bandwidth necessary to support this added data traffic is ultimately borne in part by individual investors.

There are solutions. Today there is no restriction to pumping out millions of orders in a matter of seconds, only to reverse the majority of them. It’s the life-blood of high-frequency trading. A simple solution would be to establish cancellation fees to discourage the practice of quote stuffing. The SEC and CFTC floated the idea last year. It has great merit. Make the fees high enough and they will eliminate high-frequency trading entirely. But if the practice is simply a scam, as we believe it is, an even better solution is to simply make it illegal. And exchanges should be neutral in the market. They should stop the practice of selling preferential access or data feeds and eliminate order types that allow high-frequency traders to jump ahead of legitimate order flow. These are all simply tools for scamming individual investors.

The integrity of the markets is at the heart of our economy. High-frequency trading undermines that integrity and causes the market to lose credibility and investors to lose trust. This hurts our economy and country. It is time to treat the cancer aggressively.

Charles Schwab, Founder and Chairman
Walt Bettinger, President and CEO

Check your sites. Click here.

You should probably be worried about the Heartbleed Bug. Harry’s advice:

1. Don’t freak because the media is freaking. It’s just another computer bug, albeit a big one.

2. Check you haven’t lost anything. Then change all your passwords with all your online banks and brokerage accounts.  Do not wait for these bumbling institutions to get their act together and fix their systems.

If you want to learn what the fuss is all about, read this:

Here’s How To Protect Yourself From The Massive Security Flaw That’s Taken Over The Internet
Kyle Russell of Business Insider

It’s been a while since there was a computer security bug we all had to worry about.

Unfortunately, it seems like we may all have been facing one for two years and not even realized it.

Yesterday, security researchers announced a security flaw in OpenSSL, a popular data encryption standard, that gives hackers who know about it the ability to extract massive amounts of data from the services that we use every day and assume are mostly secure.

This isn’t simply a bug in some app that can quickly be updated. The vulnerability is in the machines that power services that transmit secure information, such as Facebook and Gmail.

We’ve put together the following guide to the so-called Heartbleed bug for those who want to understand what all the fuss is about, and how they can protect themselves.

What is the Heartbleed bug?

Heartbleed is a flaw in OpenSSL, the open-source encryption standard used by the majority of websites that need to transmit the data that users want to keep secure. It basically gives you a secure line when you’re sending an email or chatting on IM.

Encryption works by making it so that data being sent looks like nonsense to anyone but the intended recipient.

Occasionally, one computer might want to check that there’s still a computer at the end of its secure connection, and it will send out what’s known as a heartbeat, a small packet of data that asks for a response.

Because of a programming error in the implementation of OpenSSL, the researchers found that it was possible to send a well-disguised packet of data that looked like one of these heartbeats to trick the computer at the other end into sending data stored in its memory.

The flaw was first reported to the team behind OpenSSL by Google security researcher Neel Mehta, and independently found by security firm Codenomicon. According to the researchers who discovered the flaw, the code has been in OpenSSL for about two years, and using it doesn’t leave a trace.

How bad is that?

It’s really bad. Web servers can keep a lot of information in their active memory, including usernames, passwords, and even the content that users have uploaded to a service. According to Vox.com’s Timothy Lee, even credit-card numbers could be pulled out of the data sitting in memory on the servers that power some services.

But worse than that, the flaw has made it possible for hackers to steal encryption keys – the codes used to turn gibberish-encrypted data into readable information.

With encryption keys, hackers can intercept encrypted data moving to and from a site’s servers and read it without establishing a secure connection. This means that unless the companies running vulnerable servers change their keys, even future traffic will be susceptible.

Am I affected?

Probably, though again, this isn’t simply an issue on your personal computer or your phone – it’s in the software that powers the services you use. Security firm Codenomicon reports:

You are likely to be affected either directly or indirectly. OpenSSL is the most popular open source cryptographic library and TLS (transport layer security) implementation used to encrypt traffic on the Internet. Your popular social site, your company’s site, commercial site, hobby site, sites you install software from or even sites run by your government might be using vulnerable OpenSSL.

According to a recent Netcraft web server survey that looked at nearly 959,000,000 websites, 66% of sites are powered by technology built around SSL, and that doesn’t include email services, chat services, and a wide variety of apps available on every platform.

So what can I do to protect myself?

Since the vulnerability has been in OpenSSL for about two years and using it leaves no trace, assume that your accounts may be compromised. You should change your online passwords, especially for services where privacy and security are major concerns. However, many sites likely haven’t upgraded to software without the bug, so immediately changing them still might not help.

The researchers who discovered the flaw let the developers behind OpenSSL know several days before announcing the vulnerability, so it was fixed before word got out yesterday. Most major service providers should already be updating their sites, so the bug will be less prevalent over coming weeks.

I get “offers”. They offer me rewards like this:

EbayBucksCertificate

But it’s total bullsh*t. I know because I look at who sent the email. Does that look like someone from eBay?

EbayBucksSender

If I hit the Redeem Certificate button, I’ll load my computer with more viruses than Carter had liver pills.

I have recently received “rewards” from PayPal, Amazon, eBay and a zillion other wonderful companies whose good names and reputations are being ripped off.

In short, beware.

Hoisted on one’s own petard. I bought a pair of loafers. It would be easier to get through airline security, I figured.

But now I’m part of the TSA PreCheck program, I don’t have to take my shoes off (or remove my laptop from its comfy bag). Enrol here.

Favorite recent New Yorker cartoons.

Neighbors

Deadlines

IgnoreHim

HarryNewton
Harry Newton who eyes the good news on real estate: It’s bouncing back.

BouncingBack

O.K. I admit. It’s a feeble pun. I didn’t draw it. Someone sent it. Some people have too much time on their hands.

460 Comments

  1. Darrell says:

    There was no Redeem Certificate button to push…..it was a “Reedem” Certificate button. LOL

  2. bruuno says:

    The advice I’ve seen that makes some sense is to change passwords on all accounts, and do it now. Afterwards you can sort it out- find out which sites had upgraded and which not. You may have to change twice for some sites this way but you are less vulnerable to the possibility of having a compromised account.

  3. Fderfler says:

    Harry, you should add that if a Website offers a second form of authentication, such as a pin in addition to a password, you should elect to use it. As another comment says, it does no good to change unless you are sure the Website has updated. The password business is coming to this….

  4. devon says:

    Harry – you have to make sure your institution has corrected the SSL issue before you change your password, otherwise you are not protecting yourself.

    • Harry Newton says:

      Yes, true. And I’ve tried emailing my banking contacts about their site. But they usually know little. They are checking, endlessly.