Adkins v. Facebook, Inc.

District Court, N.D. California·Decided November 15, 2020·No. 3:18-cv-05982·Unknown

Opinion

NORTHERN DISTRICT OF CALIFORNIA

STEPHEN ADKINS, on behalf of himself and those similarly situated, No. C 18-05982 WHA Plaintiffs,

v.

FACEBOOK, INC., PRELIMINARY SETTLEMENT APPROVAL Defendant.

INTRODUCTION In this data-breach class action, plaintiffs move for preliminary approval of a class settlement agreement. The proposal appearing non-collusive and within the realm of approvable, the motion is GRANTED. This case arises from the September 2018 hack of Facebook. A prior order detailed the facts (Dkt. No. 153). In brief, certain access tokens permitted access to Facebook users’ accounts, but a previously unknown vulnerability made these tokens sometimes visible to strangers. Hackers exploited this flaw in September 2018 to access 300,000 accounts. Once inside, the hackers ran two search queries. The first yielded the names and telephone numbers and/or e-mail addresses of fifteen million users worldwide (2.7 million in the United States). The second yielded more sensitive information on fourteen million users worldwide (1.2 million in the United States), including the original 300,000. In February 2019, five named plaintiffs filed a consolidated complaint asserting several claims. Following consolidation and motion practice, in August 2019, only one named plaintiff, Stephen Adkins, and two claims remained. Six months later, plaintiff Adkins sought to certify a class of affected Facebook users. The motion outlined three classes under Rule 23(b)(2), Rule 23(b)(3), and Rule 23(c)(4). A November 2019 order certified a worldwide class for injunctive purposes only (Dkt. No. 260). One month later, on the parties’ motion, a December 19 order limited the injunctive class to users within the United States and removed the requirement of class notice via first-class mail (Dkt. No. 271). The certified class for injunctive purposes only became:

All current Facebook users residing in the United States whose personal information was compromised in the data breach announced by Facebook on September 28, 2018. On January 8, under the supervision of Chief Magistrate Judge Joseph Spero, the parties reached a settlement in principle (Dkt. No. 281). During the settlement conference, the parties discussed potential security commitments Facebook could make as part of a settlement. Following those discussions, with the assistance of plaintiff’s expert, the parties reached a final set of security commitments and came to a proposed settlement agreement. Plaintiff now moves for preliminary approval of the settlement agreement and to direct notice of the settlement. This order follows briefing and oral argument. Our court of appeals maintains a “strong judicial policy” in favor of settlement of “complex class action litigation.” Class Plaintiffs v. City of Seattle, 955 F.2d 1268, 1276 (9th Cir. 1992). But a class settlement must offer fair, reasonable, and adequate relief. Lane v. Facebook, Inc., 696 F.3d 811, 818 (9th Cir. 2012). Preliminary approval is appropriate if “the proposed settlement appears to be the product of serious, informed, non-collusive negotiations, has no obvious deficiencies, does not improperly grant preferential treatment to class Tableware Antitrust Litig., 484 F. Supp. 2d 1078, 1079 (N.D. Cal. 2007) (Chief Judge Vaughn Walker). The proposed settlement imposes a battery of security commitments to prevent future similar attacks. Facebook will certify that the vulnerability exploited in the breach has been eliminated, that it is no longer possible to generate access tokens in the manner that was done in the breach, and that all access tokens generated through the vulnerability have been invalidated. Then, for the next five years, Facebook will adopt the following security commitments to prevent future attacks:

(1) Increase the frequency of integrity checks on session updates to detect account compromises. (2) Implement new tools to detect suspicious patterns in the generation and use of access tokens across Facebook.

(3) Implement new tools to help Facebook promptly contain a security incident involving the improper issuance of access tokens. (4) Implement automatic alerts for specified types of suspicious activity to ensure prompt response.

(5) Undergo annual SOC2 Type II security assessments.

(6) Limit the capabilities of applications that rely on access tokens. (7) Eliminate “NoConfidence authentication proofs” and require cryptographic proofs of valid logins before generating credentials.

(8) Employ at least one senior security executive with direct reporting authority and obligations to Facebook’s Board of Directors.

Free access — add to your briefcase to read the full text and ask questions with AI

Adkins v. Facebook, Inc., (N.D. Cal. 2020).

Adkins v. Facebook, Inc. (Adkins v. Facebook, Inc.) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Mullane v. Central Hanover Bank & Trust Co.
339 U.S. 306 (Supreme Court, 1950)
Ginger McCall v. Facebook, Inc.
696 F.3d 811 (Ninth Circuit, 2012)
In Re Tableware Antitrust Litigation
484 F. Supp. 2d 1078 (N.D. California, 2007)
Center for Auto Safety v. Chrysler Group, LLC
809 F.3d 1092 (Ninth Circuit, 2016)
Class v. City of Seattle
955 F.2d 1268 (Ninth Circuit, 1992)