The Timeline Nobody Wants to Handicap
Did Anyone hear Anything About a Venezuelan Betting Coup?
I hate piling on. I hate it even more when I think everyone may be piling on the wrong person.
That doesn’t mean HISA gets a pass. It doesn’t mean Lisa Lazarus gets a pass. It certainly doesn’t mean Marshall Gramm is guilty of everything HISA alleges simply because HISA put it in a press release. It means something much simpler.
Follow the timeline.
Facts have an annoying habit of getting in the way of a good lynch mob. On June 15, Lisa Lazarus made a statement that today looks bad. There is no getting around it and I won’t try.
Asked about the custom past performances circulating with confidential veterinary information, Lazarus said they “could not have come from the HISA Portal” because some of the information was different from what was contained in the portal. HISA said it had reviewed the potential source and shared its conclusion with other entities that might have been responsible. Today we know that conclusion was wrong. Stop there and you can write a hell of a tweet.
She knew.
She lied.
Cover-up.
Fire her.
There’s only one problem. The story didn’t stop there. Neither did the investigation.
Ten Days Later
On June 25, TDN went back to HISA with follow-up questions. If you are fair and want the truth, this is important.
HISA described what its initial internal technology review had actually examined. According to Lazarus, HISA reviewed its monitoring and vulnerability systems, its portal systems and six months of API calls looking for unauthorized access. Then came the important part. HISA said it was continuing and expanding its investigation to determine whether someone who was authorized to use the system had accessed information that person was not authorized to access.
Read that again.
June 15:
We don’t believe it came from our portal.
June 25:
We found no unauthorized outsider, but we’re now looking at whether an authorized user accessed restricted information.
August 17:
HISA charges Marshall Gramm, an authorized user, with exploiting the system to access confidential information he was not entitled to see. HISA says the investigation included interviews, internal and outside investigators and independent forensic cybersecurity analysis. That timeline creates some serious problems. Just not necessarily the problems Twitter/X thinks it does.
Was Lisa Lazarus Wrong?
On June 15? Apparently. Her statement was too definitive based upon what we now know. I wouldn’t have said it that way, and with the benefit of hindsight I’m sure she wishes she hadn’t either. But wrong and lying are two very different things. A lie requires something more. Knowledge. You have to know what you’re saying is false when you say it. Where is the evidence of that?
I’ve seen people I like, people I respect and people I consider friends, dear friends, say Lazarus lied. Jenine Sahadi essentially offered the choice: misleading or lies. Louis Masry, who has been one of HISA’s most vocal critics and someone whose opinion I value even when we disagree, believes HISA’s vulnerability was inexcusable. Fair enough. But I’m not ready to make the jump from “the June 15 statement turned out to be wrong” to “Lisa Lazarus knowingly lied.” Not remotely. And neither should anyone else without considerably more evidence than I’ve seen.
There Is Another Possibility Nobody Wants To Discuss
There is something else we don’t know. What did the investigators know, and when did they know it? I have dealt with serious investigators and investigations in my life. Fortunately or unfortunately. Good ones don’t conduct investigations on Twitter. They don’t announce every lead. They don’t identify every person they’re looking at. They don’t tell potential subjects what evidence they have. They don’t disclose sources, methods or investigative theories simply because somebody on social media demands transparency before breakfast.
Sometimes public statements during active investigations are incomplete. Sometimes they’re deliberately vague. Sometimes investigators allow people to continue believing things that are useful for investigators to have them believe. That’s Investigation 101. Was that happening here? I don’t know. And neither do you. That’s the point. At least some of the HISA investigators are former FBI agents. You may not know Investigation 101, I am betting they do. They may even know 102, 3 nd 4. If you believe any part of this case was “solved” or influenced by tweets or social media comments, so be it, I just hope you are a bettor, a bigger one than Marshall Gramm. Welcome to the pools.
I’m not going to manufacture an investigative scenario to defend HISA any more than I’m going to manufacture a cover-up to attack it. Maybe Lazarus simply got it wrong on June 15. Maybe HISA’s technology people initially looked for the wrong thing, an outside intrusion, found none and drew the wrong conclusion. Maybe by June 25 investigators had developed information that changed the direction of the investigation. Maybe investigators knew more than they were saying publicly. Those possibilities aren’t mutually exclusive. What we do know is that by June 25, weeks before Gramm was publicly charged, HISA publicly stated that its investigation had moved specifically toward the possibility of an authorized user accessing restricted information. That’s not speculation. That’s the timeline.
Then There Are Those Past Performances
Here’s another hole in the “Lisa lied” theory that nobody seems particularly interested in discussing. The past performances circulating publicly contained information that wasn’t in the HISA Portal. We know that. That fact was actually part of the reason Lazarus originally concluded the information hadn’t come from HISA. Among the information appearing on those PPs were Ragozin figures. Those aren’t HISA data as far as I know. So whatever created the finished product involved more than somebody simply opening a HISA page, taking a screenshot and sending it to his buddies. HISA now alleges a far more complicated process involving the acquisition and manipulation of enormous amounts of information.
If the public-facing document was assembled using information from multiple sources, then looking at that document in June and concluding this isn’t a HISA document isn’t exactly evidence of Watergate. It may simply have been wrong. There’s that pesky word again. Wrong. Not necessarily corrupt. Not necessarily dishonest. Wrong.
Four Million Records Per Tom Ryan Changes the Conversation
If HISA’s allegations are established, and that number is accurate, we’re not talking about somebody accidentally stumbling through an unlocked door. We’re talking about a lot of records. We’re talking about confidential veterinary information. We’re talking about someone HISA says was simultaneously involved in horse ownership, claiming, wagering and handicapping contests. And we’re talking about information that potentially had value to somebody competing against other horseplayers.
Yet somehow a sizable portion of the horseplayer community has decided the real victim here is the person HISA charged. Amazing.
The same horseplayers who complain endlessly about computer-assisted wagering, rebates, late odds changes, information asymmetry and whales having advantages they don’t have are suddenly remarkably philosophical about a fellow bettor allegedly possessing confidential veterinary information they didn’t have. You can’t make this crap up.
What Happened To The Data?
Tom Ryan asked what may be the best question I’ve seen since this started. What happened to the millions of records? His number, not mine. Were they deleted? Where were they stored? Were copies made? Who had access to the finished database? Who received information derived from it? Who received the custom past performances? And most importantly to me as a horseplayer:
Was any of that information ever used against us in a pari-mutuel pool or handicapping contest?
I don’t know.
Neither does Peter Fornatale. At least I hope not.
Neither does Ray Paulick. That I am sure of.
Neither does Twitter.
And unless somebody has evidence I haven’t seen, nobody should be declaring that question answered.
I read Fornatale’s piece carefully. Some of it is thoughtful and some of the questions he raises about HISA’s security are legitimate. Then he tells us Gramm didn’t use this information in the computer modeling behind most of his pari-mutuel wagering and that it wasn’t a factor in his Belmont Betting Challenge wager. That’s quite an assertion. Maybe it’s true. I’d simply like to see the evidence before cashing that ticket. To any sharp gambler, that is called a bet against.
We seem to have developed a curious journalistic standard in racing where allegations against HISA require proof beyond a reasonable doubt while explanations favorable to somebody we know can occasionally get past the windows on reputation alone. Sorry. No free squares on this board.
And Ray Paulick’s sudden fascination with everyone else’s relationships and conflicts has produced some entertaining theater of its own. There are legitimate questions involving relationships throughout this story. Ask them. Ask all of them. Just don’t confuse asking questions with answering them.
The Horseplayer Is Being Forgotten Again
This is the part that is annoying. Everybody has picked a horse. HISA haters have HISA. HISA defenders have HISA. Friends of Gramm have Gramm. Enemies of Gramm have Gramm. People who hate The Jockey Club have The Jockey Club. People who hate Lisa Lazarus have Lisa. Media people have other media people. Everybody has a frigging horse in the race. Except apparently the horseplayer. What about us?
If Gramm possessed information unavailable to the betting public while wagering into the same pools we were wagering into, I want to know exactly what he had, when he had it and what he did with it. If he played handicapping contests while possessing information unavailable to his competitors, I want that investigated. If HISA can establish he didn’t use it for wagering, fine. Show me. If Gramm can establish he didn’t use it, even better. Show me. Until then, I am not accepting somebody’s assurance because he’s a good guy, a respected handicapper, a professor, somebody’s friend or a terrific podcast guest. I’ve been gambling too long for that.
HISA Has Questions To Answer Too
Don’t misunderstand me. The vulnerability existed. That’s on HISA. They collected confidential information and had an obligation to protect it. If an authorized user could manipulate the system to obtain information he wasn’t entitled to see, that’s a security failure. Fix it, if not already fixed. Explain it. They have. Determine whether anybody else exploited it. Audit all of it to ne end. HISA doesn’t get to say, we caught the guy, everybody go home.
But here’s where racing has completely lost its mind. A security failure does not transfer moral responsibility from the person who allegedly exploited it to the person who failed to prevent him from exploiting it. Both things can be wrong. Apparently that concept has become too complicated for social media. I’m not surprised there.
Again, for those in the back, if I pick a lock and rob a bank, the bank may have crummy security. Change the locks. Improve the security. Find out why. Audit the bank.
But when I stand before the judge, I’m probably not going very far with: Your Honor, in my defense, that was a really shitty lock.
There is also now an argument that HISA has contradicted itself by first saying this was not simply a matter of changing a horse number in a URL, and later acknowledging Gramm manually changed a URL. I don’t see the contradiction. Saying this was not simply changing a number in a URL is entirely consistent with saying that may have been how the door was first discovered, but what allegedly happened after that is the issue. HISA can and should answer for a portal that apparently allowed an unauthorized user through that door. That does not answer for the person who, according to the allegations, walked through it repeatedly, automated the process, accumulated the information and made it useful. Those are two different questions, and conflating them has become one of the more convenient ways of discussing this story without discussing what Gramm is actually accused of doing. Weak. Just weak.
The Irony Nobody Wants To See
For years this industry failed to adequately police itself. That failure is a large part of why HISA exists.
Racing screamed that nobody caught the bad guys. Now HISA catches someone it alleges committed one of the most serious integrity violations we’ve seen involving wagering information, and half the industry screams: How dare HISA catch him when its system allowed him to do it? GTFOH. Criticize the vulnerability. I have. Criticize the original June statement. I just did, but accurately. Demand answers about the data. I’m demanding them. Demand HISA establish its allegations through due process. Absolutely. It appears they intend to. But don’t turn the accused into the victim and the people who investigated him into the criminals because you didn’t like HISA before Marshall Gramm’s name ever entered the conversation. That’s not analysis. That’s handicapping the race after you’ve already decided which horse you want to win. It certainly isn’t journalism or reporting.
Apply One Standard
Here’s mine. Make HISA prove its case against Marshall Gramm. Make HISA explain how the vulnerability existed and what it has done to prevent it from happening again. Make HISA determine whether anyone else exploited it.
Make Gramm answer for what HISA alleges he did. Make anyone claiming the information wasn’t used for wagering or contests show us how they know that.
And if you’re going to accuse Lisa Lazarus of knowingly lying to the industry, show me that too. Not a tweet. Not an inference. Not everybody knows. Not calling statements conflicting because it sounds strong and mimics a gotcha where there is none.
Evidence. Because here’s the part some people apparently forgot. The June 15 statement isn’t the end of the timeline. June 25 exists. And June 25 is a gigantic problem for the theory that HISA simply knew what happened and was trying to bury it.
Ten days after Lazarus made the statement everybody is waving around as proof of a cover-up, HISA publicly announced it was investigating whether an authorized user had accessed information that user wasn’t authorized to access. Then it investigated. Then it says it found one. Then it charged him. Maybe evidence will eventually show Lazarus knew the complete story on June 15 and knowingly told the public something false. If that happens, I’ll write it. I’ll be first in line. If a legit reason exists for it I’ll write that to. But I’m not hanging her today because everybody else brought rope. I’ve seen this movie before. And sometimes the loudest people in the room aren’t the ones who know the most. They’re just the ones with the biggest megaphones.