Live data from Hacker News

Yahoo Customer Data Security Breach Litigation Settlement

yahoodatabreachsettlement.com

41–50 of 67 posts

Re: Yahoo Customer Data Security Breach Litigation Settlement

#41
post #38
post #37

Earlier quoted context omitted.

Just having the SSN, name, address of the consumer, etc. shouldn't be enough to prove the lender entered into a contact with the consumer. What should be enough? What documentation should banks have to collect before opening, say, a credit card with a $1000 limit for a customer?

They should require several forms of photograph identification such as a drivers license and/or passport. That would make it more difficult to open a line of credit or get a loan, but it would definitely cut down on fraud.

Would it really? You can buy good quality fake scans/photos for like $50.

Re: Yahoo Customer Data Security Breach Litigation Settlement

#42
post #39
post #38

Earlier quoted context omitted.

They should require several forms of photograph identification such as a drivers license and/or passport. That would make it more difficult to open a line of credit or get a loan, but it would definitely cut down on fraud.

So people without passports (roughly 2/3rds of Americans) shouldn't be able to get loans?

According to https://www.finder.com/personal-loan-documents, lenders require at least two forms of government issued identification. Also, applying for and keeping a passport requires one to pay about $110 every decade.

In my experience, having a passport makes it much easier to do various things that require identification.

Re: Yahoo Customer Data Security Breach Litigation Settlement

#43
post #41
post #38

Earlier quoted context omitted.

They should require several forms of photograph identification such as a drivers license and/or passport. That would make it more difficult to open a line of credit or get a loan, but it would definitely cut down on fraud.

Would it really? You can buy good quality fake scans/photos for like $50.

Perhaps, but when the creditor/lender needs to provide proof that they interacted with the consumer and shows a copy of the faked identification as "proof", it should be easy enough for the consumer to hold the lender liable for the bad credit report.

Re: Yahoo Customer Data Security Breach Litigation Settlement

#44
post #5

Earlier quoted context omitted.

Why do judges agree to forcing consumers to have useless product of credit monitoring in place to receive a cash payout? Can I set up a “virtual” credit monitoring that provides that type of service in name only to cover that requirement? Imagine paying $5 to claim you have credit monitoring for settlement purposes.

I mean, you should have one from one of the many previous breaches. Also, arguably your credit card or mortgage company may be providing you enough monitoring to claim you have it. For those who suffered under TurboTax, Intuit offers a free credit monitoring service as well. Credit monitoring, like antivirus, is something you should have, but should not be paying for.

It's 2019. "Credit monitoring", like antivirus, is something you simply should not have. Rather, you should take steps to avoid being beholden to broken systems in the first place.

For "credit monitoring" specifically, individuals should not be doing the surveillance bureau's work for them. If lenders don't think it is necessary to do diligence when issuing credit, then why should I make up for it by half-policing [0] use of my public identifiers? The more painful fraud is for lenders, the more incentive they have to actually do some diligence rather than trying to push their lack of responsibility onto everyone else.

[0] If I had total legal control over the use of my public identifiers, I would simply tell the surveillance bureaus to delete all data kept on me. But we are not given this option, which indicates how the surveillance bureaus do not work for us. The less we give them, the better.

Re: Yahoo Customer Data Security Breach Litigation Settlement

#46
post #5

"Under the terms of the Settlement, Yahoo has enhanced, or, through its successor in interest, Oath Holdings Inc. (“Oath”), continues to enhance its business practices that will improve the security of its users’ personal information stored on its databases. Defendants will also pay for a Settlement Fund of $117,500,000. The Settlement Fund will provide a minimum of two years of Credit Monitoring Services to protect…

Why do judges agree to forcing consumers to have useless product of credit monitoring in place to receive a cash payout? Can I set up a “virtual” credit monitoring that provides that type of service in name only to cover that requirement? Imagine paying $5 to claim you have credit monitoring for settlement purposes.

AIUI, the damages are not punitive. They are meant to cover the actual harms associated with Yahoo's negligence. Unless you've actually had your identity stolen due to the breach, your losses are capped at whatever action you had to take to counteract risks added by the breach. That is, the cost of acquiring credit monitoring services.

Re: Yahoo Customer Data Security Breach Litigation Settlement

#47
post #5

Earlier quoted context omitted.

Why do judges agree to forcing consumers to have useless product of credit monitoring in place to receive a cash payout? Can I set up a “virtual” credit monitoring that provides that type of service in name only to cover that requirement? Imagine paying $5 to claim you have credit monitoring for settlement purposes.

AIUI, the damages are not punitive. They are meant to cover the actual harms associated with Yahoo's negligence. Unless you've actually had your identity stolen due to the breach, your losses are capped at whatever action you had to take to counteract risks added by the breach. That is, the cost of acquiring credit monitoring services.

The problem is that damages can occur after the settlement, right?

Re: Yahoo Customer Data Security Breach Litigation Settlement

#48
post #29
post #10

Earlier quoted context omitted.

>then the consumer can sue them For what? The consumer isn’t responsible anyway if the lender gets defrauded. Is the fraud in itself not enough of a punishment for the lender? I’d argue that the real problem here are the regulators who have shaped this broken system. Not the lack of punishments for existing within it. >Just having the SSN, name, address of the consumer, etc. shouldn't be enough to prove the lender en…

>> then the consumer can sue them > For what? For sending a bad report about the consumer they claim to have entered into a contract with to the credit bureaus. > The consumer isn’t responsible anyway if the lender gets defrauded. That's true, but the lender is responsible for what they report to the credit bureaus. > Is the fraud in itself not enough of a punishment for the lender? If they don't involve the actual c…

While you're right from basic legal principles, I've had it pointed out to me that the FCRA actually shields the surveillance bureaus from charges of libel/slander. So that kind of direct action has already been regulatory-captured away.

Re: Yahoo Customer Data Security Breach Litigation Settlement

#49
post #3

Credit monitoring is snake oil. These settlements are universally bullshit and mostly benefit snake oil vendors and not consumers. Also FWIW the damage figures are also nonsense, how much can the equifax leak hurt anyone if their data was already for sale on ssndob? Almost all Americans have had their information compromised in hacks they’ve never heard of. Am I wrong?

Class actions are interesting. Basically the lawyer for the class has a dollar value he or she wants before they even send their letter to the company being sued. Then they work towards that. Once they reach that number they don’t really care how the class is reimbursed. And neither do the judges.

Um, NO, that has nothing to do with how it works.

Source: my wife is an attny & worked at a top class-action firm for over a decade. Without breaking confidentiality, I still heard all kinds of interesting stories about the mechanics & internals of how the system works - how multiple firms work together, how cases are started, etc., but never anything remotely related to such a "targeted revenue" concept. Of course there's the obvious requirement that any case specify damages at the outset, but even this number can increase or decrease as the case proceeds.

A law firm can of course make big money with a big case, but it is a big risk that can take many years to return, and it can fail.

Re: Yahoo Customer Data Security Breach Litigation Settlement

#50
post #18
post #10

Earlier quoted context omitted.

>then the consumer can sue them For what? The consumer isn’t responsible anyway if the lender gets defrauded. Is the fraud in itself not enough of a punishment for the lender? I’d argue that the real problem here are the regulators who have shaped this broken system. Not the lack of punishments for existing within it. >Just having the SSN, name, address of the consumer, etc. shouldn't be enough to prove the lender en…

I agree with you in principle, but unfortunately the system has been so perverted that it's the consumer who inevitably suffers. Here's a pretty entertaining peek (by Micheal Lewis) into what happens because of fraud that the consumer had literally nothing to do with and how the lender (bank) is able to put the onus on him to fix. It's not life or death, at least in this example, but it really shows how obviously unf…

>I agree with you in principle, but unfortunately the system has been so perverted that it's the consumer who inevitably suffers.

Isn't that just the fault of the system, not the individual participant being defrauded?

Post reply on HN