Live data from Hacker News

Yahoo Customer Data Security Breach Litigation Settlement

yahoodatabreachsettlement.com

1–10 of 67 posts

Re: Yahoo Customer Data Security Breach Litigation Settlement

#2
"Under the terms of the Settlement, Yahoo has enhanced, or, through its successor in interest, Oath Holdings Inc. (“Oath”), continues to enhance its business practices that will improve the security of its users’ personal information stored on its databases. Defendants will also pay for a Settlement Fund of $117,500,000. The Settlement Fund will provide a minimum of two years of Credit Monitoring Services to protect Settlement Class Members from future harm, or an alternative cash payment for those who verify they already have credit monitoring or identity protection."

Re: Yahoo Customer Data Security Breach Litigation Settlement

#3
Credit monitoring is snake oil. These settlements are universally bullshit and mostly benefit snake oil vendors and not consumers.

Also FWIW the damage figures are also nonsense, how much can the equifax leak hurt anyone if their data was already for sale on ssndob? Almost all Americans have had their information compromised in hacks they’ve never heard of.

Am I wrong?

Re: Yahoo Customer Data Security Breach Litigation Settlement

#4

"Under the terms of the Settlement, Yahoo has enhanced, or, through its successor in interest, Oath Holdings Inc. (“Oath”), continues to enhance its business practices that will improve the security of its users’ personal information stored on its databases. Defendants will also pay for a Settlement Fund of $117,500,000. The Settlement Fund will provide a minimum of two years of Credit Monitoring Services to protect…

I'm sure that the lawyers were equally paid in credit monitoring service sbscriptions.

Re: Yahoo Customer Data Security Breach Litigation Settlement

#5

"Under the terms of the Settlement, Yahoo has enhanced, or, through its successor in interest, Oath Holdings Inc. (“Oath”), continues to enhance its business practices that will improve the security of its users’ personal information stored on its databases. Defendants will also pay for a Settlement Fund of $117,500,000. The Settlement Fund will provide a minimum of two years of Credit Monitoring Services to protect…

Why do judges agree to forcing consumers to have useless product of credit monitoring in place to receive a cash payout?

Can I set up a “virtual” credit monitoring that provides that type of service in name only to cover that requirement? Imagine paying $5 to claim you have credit monitoring for settlement purposes.

Re: Yahoo Customer Data Security Breach Litigation Settlement

#7
post #3

Credit monitoring is snake oil. These settlements are universally bullshit and mostly benefit snake oil vendors and not consumers. Also FWIW the damage figures are also nonsense, how much can the equifax leak hurt anyone if their data was already for sale on ssndob? Almost all Americans have had their information compromised in hacks they’ve never heard of. Am I wrong?

Class actions are interesting. Basically the lawyer for the class has a dollar value he or she wants before they even send their letter to the company being sued. Then they work towards that. Once they reach that number they don’t really care how the class is reimbursed. And neither do the judges.

Re: Yahoo Customer Data Security Breach Litigation Settlement

#8
post #5

"Under the terms of the Settlement, Yahoo has enhanced, or, through its successor in interest, Oath Holdings Inc. (“Oath”), continues to enhance its business practices that will improve the security of its users’ personal information stored on its databases. Defendants will also pay for a Settlement Fund of $117,500,000. The Settlement Fund will provide a minimum of two years of Credit Monitoring Services to protect…

Why do judges agree to forcing consumers to have useless product of credit monitoring in place to receive a cash payout? Can I set up a “virtual” credit monitoring that provides that type of service in name only to cover that requirement? Imagine paying $5 to claim you have credit monitoring for settlement purposes.

I mean, you should have one from one of the many previous breaches. Also, arguably your credit card or mortgage company may be providing you enough monitoring to claim you have it. For those who suffered under TurboTax, Intuit offers a free credit monitoring service as well.

Credit monitoring, like antivirus, is something you should have, but should not be paying for.

Re: Yahoo Customer Data Security Breach Litigation Settlement

#9
post #3

Credit monitoring is snake oil. These settlements are universally bullshit and mostly benefit snake oil vendors and not consumers. Also FWIW the damage figures are also nonsense, how much can the equifax leak hurt anyone if their data was already for sale on ssndob? Almost all Americans have had their information compromised in hacks they’ve never heard of. Am I wrong?

> Credit monitoring is snake oil.

What we really need is to shift the burden of proof from the consumer to the lender. If the lender cannot establish beyond a reasonable doubt that they entered into a contact with the consumer, then the consumer can sue them. Just having the SSN, name, address of the consumer, etc. shouldn't be enough to prove the lender entered into a contact with the consumer.

Re: Yahoo Customer Data Security Breach Litigation Settlement

#10
post #9
post #3

Credit monitoring is snake oil. These settlements are universally bullshit and mostly benefit snake oil vendors and not consumers. Also FWIW the damage figures are also nonsense, how much can the equifax leak hurt anyone if their data was already for sale on ssndob? Almost all Americans have had their information compromised in hacks they’ve never heard of. Am I wrong?

> Credit monitoring is snake oil. What we really need is to shift the burden of proof from the consumer to the lender. If the lender cannot establish beyond a reasonable doubt that they entered into a contact with the consumer, then the consumer can sue them. Just having the SSN, name, address of the consumer, etc. shouldn't be enough to prove the lender entered into a contact with the consumer.

>then the consumer can sue them

For what? The consumer isn’t responsible anyway if the lender gets defrauded.

Is the fraud in itself not enough of a punishment for the lender?

I’d argue that the real problem here are the regulators who have shaped this broken system. Not the lack of punishments for existing within it.

>Just having the SSN, name, address of the consumer, etc. shouldn't be enough to prove the lender entered into a contact with the consumer.

It isn’t. The lender enters into a contract with a fraudster and gets fucked. The lender is the victim, not the consumer.

Post reply on HN