Skip to content
 

Great unemployment numbers. What to do if your bank is hacked

It’s Sell on Rosh Hashanah (nine days ago), buy on Yom Kippur, which begins tonight at sundown. Here’s the last ten days:

SPEXTENDays

Don’t blame the Jews. Tonight and tomorrow we’ll get plenty of time to atone for our sins of the last ten days.

And we all did a bit better yesterday. And we’ll do better today.

S&PINtraddayOctober2

I’ve been watching Cramer recently. He suffers the same problem I do — every day he has to figure something intelligent to say. He’s actually well-educated and smart. But the pressure of filling one whole hour makes him say things that are often half-baked. So, I ignore them, but pick up on his good ideas. His philosophy is lacking is two major respects: He doesn’t seem to believe in an inviolate stop loss rule. For example, last night on his show he said ESV was “the worst performer in our portfolio” (his charitable trust).

ESVThisYear

ESV’s 52-week was $62.25. With a ten percent stop loss, he should have dumped the stock at $56, not be still holding it at last night’s close of $39.30 — that’s 37% lower.

When I ran Technology Investor Magazine, we did an exhaustive study: Did an inviolate stop loss order of 15% make sense? The answer was an unequivocal YES. These days are more volatile. And I prefer 8% to 10%.

He should also occasionally recommend selling short. ESV would have been a perfect short. I do understand why he doesn’t go on TV and recommend short selling. It’s dangerous.

I haven’t sold short recently. Nor did I sell much — I took profits in AGIO and I dumped HPQ and BX. HPQ is taking too long and BX is too volatile.

JPMorgan’s expanding disaster.

When hackers attacked this website a few months ago, we quickly put in two factor authentication. That means that when I want in, I have to put in a userID, then a password. That gets me in one door. Then I need another userID and another password to to get into this site and be able to change it.

Doubly hard for me to get in, and much, much harder for the hackers who went elsewhere and left this site alone. They never got in to wreak their mischief.

When the hackers attacked JPMorgan Chase (today’s BIG news), they found it much easier. Just one userID and just one password.

I have been begging JPMorgan Chase, one of my banks, for months to institute two factor authentication. Sadly, they didn’t listen. And the results are evident in today’s news:

Hackers use computers to guess userIDs and passwords. Computers are great because they can guess userIDs and passwords. And once into a system, they can use software to troll around inside and grab whatever they want — shipping it to a computer outside or even to a USB thumb drive attached surreptitiously to a  bank computer.

JPMorgan Chase says the hackers got contact information, but didn’t steal money. So the money I have at JPMorgan is safe. If I were the leader of the hackers that got in, I wouldn’t steal the customer money either (too easy to get caught), I’d go after the credit cards. There are a zillion sites on the Internet you can sell those credit cards on. The more information you have about the cards — like their security codes, their security codes and their billing zip codes, the more valuable the stolen credit cards are. You can easily get $100 a card. And now the hackers have 76 million or so of them — the number of households JPMorgan says have been affected by this breakin.

Actually the reality is that JPMorgan has really little idea of what the hackers did, or wanted, or why. As background for that statement — look at the fact tha NSA still has no idea what Edward Snowden got, nor how he got to all the NSA’s servers and what he copied. For proof on that read the cover story on him in the September  issue of Wired Magazine. The story was written by James Bamford, who’s written more books on the NSA than anyone and is considered among the most knowledgeable writer-person outside on the NSA on the NSA.

If you bank with JPMorgan, as I do, here are some lessons from this horrendous disaster:

1. Change your JPMorgan Chase userID and password today. Do it.

2. Beg your contacts at JPM for JPMorgan to institute two factor password authentication.

3. Try to find out — by logging on or calling them on the phone — what actual information they have of you. You should certainly change the email address they have on file for you. You should change your JPMorgan-issued credit and debit cards. I don’t know if you can change your social security number.

4. Check your account every day for signs of strange transactions. I don’t think you’ll find any. Remember it’s your credit cards they’re after.

5. You need several bank accounts. I also bank with Santander and Deutsche Bank. Susan has a Citibank account.

OH, yes, don’t go near JPM, the stock. I have no idea what more we’ll learn about JPMorgan’s latest disaster. All I know is it won’t be good. JPM has become what I call a cockroach stock, meaning the only thing we know is there’ll be more bad news. When you discover one cockroach (and kill it), you know that soon you’ll see his brother or his sister. New York City, where I live, has more cockroaches than people, so I know.

Earlier this week Warren Buffett was on CNBC professing his love for banks in today’s recovering economy, including his favorite Wells Fargo. I remember him saying, “There are more banks than there are bankers.” Boy was he right. And most banks have lousy under-funded, computer and networking security.

Dear reader, please don’t dismiss my recommendations as idle journalism scare mongering. Hacking, telecommunications networks and computer servers are subjects I know something about. In three weeks, the 29th edition of my Newton’s Telecom Dictionary will be printed. It has extensive entries on all this stuff. I’ll send Jamie Dimon a copy. He can use it.

Last night I received this email from John Duffy, CEO,  and Kelly C. Coffey, Deputy Chief Officer, both of the J.P. Morgan U.S. Private Bank

Dear Harry,

As you may know, Chase recently was the victim of a sophisticated cyber attack. Since then, we have been conducting a comprehensive investigation of the incident and have found no evidence that client account information was compromised.

Our detailed review has found no evidence that account numbers, passwords, dates of birth and Social Security numbers were compromised. We therefore do not believe you need to take any action related to your account. The information that was compromised was contact information – names, addresses, phone numbers and email addresses for users of Chase.com, J.P. Morgan Online, Chase Mobile and J.P. Morgan Mobile, as well as internal JPMorgan Chase information relating to such users.

We want to assure you that we take this incident very seriously, and have no evidence that the attackers are still in our systems. These kinds of attacks are frequent, and while this one was sophisticated, we stopped it and continue to invest in preventing future attacks. It is important to note that we have not seen any unusual fraud activity across all of our accounts, and you are not liable for any unauthorized transactions on your account that you promptly alert us to.

We regret this incident happened. As always, your J.P. Morgan advisor and client service team are available to discuss any questions or concerns.

Sincerely,

In short, they have no idea. Which is sad.

By the way, they knew about the hacking in July and only figured some of it out in the last few days! You can read more about the disaster in today’s New York Times. Click here.
HarryNewton
Harry Newton who’s ecstatic about today’s employment numbers.

Old Yom Kippur stories:

“Hi. This is Sarah Palin. Is Senator Lieberman in?”

“No, governor. He’s out today. This is Yom Kippur.”

“Well, hello, Yom. Can I leave a message?” …..

On the morning of Yom Kippur as the congregation was filing into the sanctuary, Rabbi Feldman noticed little Jacob standing in the foyer of the synagogue staring up at a large plaque. It was covered with names with small American flags mounted on either side of it. The six-year old had been staring at the plaque for some time, so the rabbi walked up, stood beside the little boy.

“Rabbi Feldman, what is this?’ the little boy asked, pointing to the plaque.

The good Rabbi tenderly put his arm around Max’s shoulder and said, ‘ Well son, it’s a memorial to all the young men and women who died in the service. ‘

Soberly, they just stood together, staring at the large plaque.

Finally, little Jacob, in a voice barely audible and trembling with fear asked: ‘Which service, Rosh Hashanah or Yom Kippur?’ ….

Rastas and Moses are outside the synagogue on Yom Kippur.

They hear a strange sound.

Rastas: “What’s that sound?”

Moses: “Why that’s the sound of the Jews blowing the shofar.”

Shofar

Rastas: “Boy, them Jews really treat their hired help well.”

3 Comments

  1. laughnow says:

    Harry so that youre not ‘too’ ecstatic about the ‘improved’ labor rate, here are some facts from ZH to ground you:

    While by now everyone should know the answer, for those curious why the US unemployment rate just slid once more to a meager 5.9%, the lowest print since the summer of 2008, the answer is the same one we have shown every month since 2010: the collapse in the labor force participation rate, which in September slid from an already three decade low 62.8% to 62.7% – the lowest in over 36 years, matching the February 1978 lows. And while according to the Household Survey, 232,000 people found jobs, what is more disturbing is that the people not in the labor force, rose to a new record high, increasing by 315,000 to 92.6 million!

    In other words, if the BLS wasn’t monkeying with the labor force participation rate but left it at the peak level from 1998 to 2000, the unemployment rate would be 11.7 percent.

  2. Fderfler says:

    I’m hearing that the JPMorgan information was used primarily to try social exploits through email. As the letter you received says, they didn’t get quite enough to be dangerous, but if they get one more factor, an SSN for instance, then they have enough to fake an ID. It’s difficult to prove unless you have some way to correlate an increase in spam.

  3. Cliff says:

    nice to see you’ve finally come around to my thinking on Cramer. Half-baked indeed. THat’s a nice way of putting it. Harry there’s hope for you yet.