back
59 comments
Out of curiosity, why does this apply to US and Isreal residents? Is there a legal framework that makes Isarelis eligible for these kinds of settlments automatically?
The settlement potentially includes up to 194 million people, so if even just small part of people asks for money, they'll get just dollars. Situation with Equifax repeats itself.
Good thing we have the option to get free credit monitoring... that we just received from the last time our data was carelessly handled.
Maybe now would be a good time to create a credit monitoring startup.
The only winners in class action lawsuits are the lawyers. It seems like class actions only exist to effectively serve as law enforcement ie the private-sector version of attorneys general.
That's because the point of class actions aren't to make the wronged people whole, it's to form a large enough legal stick to beat large, misbehaving entities about the head with.
How long before an identity thief pays PR Newswire to run a story on <major company> data breach settlement and harvest all the PII requested on these sorts of settlement claim forms?

yahoodatabreachsettlement.com just looks scammy as hell. It's a pity there's not a .gov domain set up for this sort of thing - when there's a settlement, a court order gets issued for yahoo.settlements.gov to get set up.

Yep, it does look scammy as hell. I got an email from Yahoo about this settlement about a week ago and at first I thought it was spam.

From: info@service.comms.yahoo.net

Subject: Yahoo Security Breach Proposed Settlement

If you had a Yahoo account anytime in 2012 through 2016, a pending class action settlement may affect you.

A Class Action Settlement has been proposed in litigation against Yahoo! Inc. (“Yahoo”) and Aabaco Small Business, LLC (together, called “Defendants” in this notice), relating to data breaches (malicious actors got into system and personal data was taken) occurring in 2013 through 2016, as well as to data security intrusions (malicious actors got into system but no data appears to have been taken) occurring in early 2012 (collectively, the “Data Breaches”).

....

Yahoo is a scam in its entirety. Even their support page feels like it exists to funnel personal information to spam databases.
They always do these domains for settlements. It should probably be on .gov but there doesn't seem to have been many issues before.
> They always do these domains for settlements.

I know that. It makes me twitchy every time.

After the big Equifax breach, someone made a spoof site of their informational page, and Equifax themselves accidentally linked to it. (https://www.nytimes.com/2017/09/20/business/equifax-fake-web...)

> there doesn't seem to have been many issues before.

Again, sure. I'm surprised scammers haven't changed that yet.

Credit monitoring is snake oil. These settlements are universally bullshit and mostly benefit snake oil vendors and not consumers.

Also FWIW the damage figures are also nonsense, how much can the equifax leak hurt anyone if their data was already for sale on ssndob? Almost all Americans have had their information compromised in hacks they’ve never heard of.

Am I wrong?

> Credit monitoring is snake oil.

What we really need is to shift the burden of proof from the consumer to the lender. If the lender cannot establish beyond a reasonable doubt that they entered into a contact with the consumer, then the consumer can sue them. Just having the SSN, name, address of the consumer, etc. shouldn't be enough to prove the lender entered into a contact with the consumer.

Just having the SSN, name, address of the consumer, etc. shouldn't be enough to prove the lender entered into a contact with the consumer.

What should be enough? What documentation should banks have to collect before opening, say, a credit card with a $1000 limit for a customer?

They should require several forms of photograph identification such as a drivers license and/or passport. That would make it more difficult to open a line of credit or get a loan, but it would definitely cut down on fraud.
Would it really? You can buy good quality fake scans/photos for like $50.
>then the consumer can sue them

For what? The consumer isn’t responsible anyway if the lender gets defrauded.

Is the fraud in itself not enough of a punishment for the lender?

I’d argue that the real problem here are the regulators who have shaped this broken system. Not the lack of punishments for existing within it.

>Just having the SSN, name, address of the consumer, etc. shouldn't be enough to prove the lender entered into a contact with the consumer.

It isn’t. The lender enters into a contract with a fraudster and gets fucked. The lender is the victim, not the consumer.

I had trouble getting an apartment because of credit fraud. Was I not a victim in the situation? I had to spend hours on the phone over months getting my credit report cleared. I guess I'm being entitled and poor ole Bank of America was the real victim here.
I agree with you in principle, but unfortunately the system has been so perverted that it's the consumer who inevitably suffers.

Here's a pretty entertaining peek (by Micheal Lewis) into what happens because of fraud that the consumer had literally nothing to do with and how the lender (bank) is able to put the onus on him to fix. It's not life or death, at least in this example, but it really shows how obviously unfair the system is. Apparently this happens quite a bit.

https://atrpodcast.com/episodes/the-seven-minute-rule-s1!1c9...

> For what? The consumer isn’t responsible anyway if the lender gets defrauded.

For the hours of phone calls over several weeks/months/years it takes to clear it all up?

The consumer is also the victim because their credit score is impacted by the fraud, which can prevent them from securing a loan (for car, home, apartment, school, etc)
>> then the consumer can sue them

> For what?

For sending a bad report about the consumer they claim to have entered into a contract with to the credit bureaus.

> The consumer isn’t responsible anyway if the lender gets defrauded.

That's true, but the lender is responsible for what they report to the credit bureaus.

> Is the fraud in itself not enough of a punishment for the lender?

If they don't involve the actual consumer in their lack of due diligence, then sure.

> It isn’t. The lender enters into a contract with a fraudster and gets fucked. The lender is the victim, not the consumer.

If the lender involves the consumer by sending a bad report to the bureaus, then they have harmed the consumer.

Class actions are interesting. Basically the lawyer for the class has a dollar value he or she wants before they even send their letter to the company being sued. Then they work towards that. Once they reach that number they don’t really care how the class is reimbursed. And neither do the judges.
Plaintiffs' class action (mostly securities) lawyer here. I have no idea what you are talking about.
Um, NO, that has nothing to do with how it works.

Source: my wife is an attny & worked at a top class-action firm for over a decade. Without breaking confidentiality, I still heard all kinds of interesting stories about the mechanics & internals of how the system works - how multiple firms work together, how cases are started, etc., but never anything remotely related to such a "targeted revenue" concept. Of course there's the obvious requirement that any case specify damages at the outset, but even this number can increase or decrease as the case proceeds.

A law firm can of course make big money with a big case, but it is a big risk that can take many years to return, and it can fail.

"Under the terms of the Settlement, Yahoo has enhanced, or, through its successor in interest, Oath Holdings Inc. (“Oath”), continues to enhance its business practices that will improve the security of its users’ personal information stored on its databases. Defendants will also pay for a Settlement Fund of $117,500,000. The Settlement Fund will provide a minimum of two years of Credit Monitoring Services to protect Settlement Class Members from future harm, or an alternative cash payment for those who verify they already have credit monitoring or identity protection."
Why do judges agree to forcing consumers to have useless product of credit monitoring in place to receive a cash payout?

Can I set up a “virtual” credit monitoring that provides that type of service in name only to cover that requirement? Imagine paying $5 to claim you have credit monitoring for settlement purposes.

> Can I set up a “virtual” credit monitoring that provides that type of service in name only to cover that requirement?

Absolutely. https://creditkarma.com/ is free, and counts.

The appellate courts, including the Supreme Court, have applied doctrines favoring settlements—-which make sense in a normal lawsuit—-in the context of class actions, where they exacerbate the already severe conflict of interest between counsel and the class.

The one thing most District Court judges like least is being overruled on appeal.

But the real blame falls on Congress. They ought to adopt a real regulatory apparatus and put away the class action (vice mass action).

Pretty much every major credit card offers it for free. Most large banks are now offering it as well. You shouldn't need to pay anything if you're using either of these.
I mean, you should have one from one of the many previous breaches. Also, arguably your credit card or mortgage company may be providing you enough monitoring to claim you have it. For those who suffered under TurboTax, Intuit offers a free credit monitoring service as well.

Credit monitoring, like antivirus, is something you should have, but should not be paying for.

It's 2019. "Credit monitoring", like antivirus, is something you simply should not have. Rather, you should take steps to avoid being beholden to broken systems in the first place.

For "credit monitoring" specifically, individuals should not be doing the surveillance bureau's work for them. If lenders don't think it is necessary to do diligence when issuing credit, then why should I make up for it by half-policing [0] use of my public identifiers? The more painful fraud is for lenders, the more incentive they have to actually do some diligence rather than trying to push their lack of responsibility onto everyone else.

[0] If I had total legal control over the use of my public identifiers, I would simply tell the surveillance bureaus to delete all data kept on me. But we are not given this option, which indicates how the surveillance bureaus do not work for us. The less we give them, the better.

I would rather be less involved with these credit companies. I recently spent about a month getting some BS off my Experian account. Whenever you're on hold you need to sit through around 10 minutes of commercials for their data protection services.

Experian.

The company responsible for possibly the biggest data leak in history. Advertising data protection services.

The balls of some companies

If i make a credit inquiry I immediately get a notification from mint, credit karma, chase, my credit union. Im sure, if you use multiple banks, that you can find a place to turn on credit monitoring for free.
Its so that they can give their settlement value. Even if the value is crap.
AIUI, the damages are not punitive. They are meant to cover the actual harms associated with Yahoo's negligence. Unless you've actually had your identity stolen due to the breach, your losses are capped at whatever action you had to take to counteract risks added by the breach. That is, the cost of acquiring credit monitoring services.
The problem is that damages can occur after the settlement, right?
Yeah I would much rather have the $0.37 than credit monitoring.
I’m not sure if you’re sarcastic but I would much prefer $0.37 to credit monitoring.
I'm sure that the lawyers were equally paid in credit monitoring service sbscriptions.
I bet with the right commands (ex:SQL Injection Commands), you could make this settlement fund print out it's records. Look at how unnecessarily verbose and pretty the error message output is: https://yahoodatabreachsettlement.com/x

I haven't tried it but it looks ripe for attack. A security noob could try using SQLMap and Nikto. If that were to happen though, would there be a class action lawsuit against the class action settlement team?

Is it worth it to sign up? I get so many notices for settlements and they all want my SSN, I would rather keep that private rather than give it away for what is likely to be a very small settlement.