Criminals had gained ongoing access TD Ameritrade’s customer database back in October, 2005. This database contains 6.3 million+ customers’ names, addresses, mailing addresses, email addresses, trading histories, account numbers, dates of birth – oh, and social security numbers too. AMTD knew of and failed to fix the problem for TWO YEARS. How do I know this?

Notes for new readers:

  • If you’re new here or found this useful, or just want to offer your support, please add a comment. I will keep the comment private, if you prefer.
  • This article is sticky; it always appears at the top. Other articles appear below this one, newest first.
  • Like on many blogs, only part of each article on the site appears son the main page. (The whole article becomes viewable if you click the title.) The bulk of the article becomes viewable if you click the “(more…)” tag after reading to the end of the teaser text. Like this:

(more…)

The proposed settlement has been thrown out!

What did I think of the decision?

What do I want to see happen?

The media is asleep on the job?

(more…)

THE SNOWJOB TD Ameritrade’s PR goons pulled is unraveling.  UCAN’s Privacy Rights clearinghouse run by Beth Givens has corrected its database entry for the breach.  Attrition.org/datalossdb.org  have corrected their entry.  Both now indicate that social security numbers were compromised.

Today is the hearing on approval of the settlement -  at 10 AM (September 10th) in Courtroom 6, 17th Floor, 450 Golden Gate in San Francisco. Wish me and my Allied Forces luck.   I expect several parties will/won’t speak:

  1. Gretchen M. Nelson of the law firm of Kreindler & Kreindler LLP will speak on behalf of objector Richard Holober, and will be seeking to replace KamberEdelson as lead plaintiff’s counsel.
  2. Theodore “Ted” Frank, formerly of the American Enterprise Institute, will be arguing again, I expect, that despite the judgments of experts at PRC and DLDB linked to above, and the overwhelming, heavily corroborated direct evidence, that there is no evidence emails, let alone SSNs, were compromised.
  3. Other objectors may speak directly or through counsel.  We won’t hear from Glennis V. Bell, who excluded himself.  He thinks the breach didn’t affect him because he doesn’t use or have a computer!  His objection is strong evidence that the notice was inadequate; that thought is nonsensical, since the case is about not just spam, but identity theft and identity fraud using compromised SSNs and other data.  It seems Virginia Brault, Jack Tanner and Rebecca A. Borgman think the same, i.e. appear to have been successfully misled into thinking that this case is simply about stock spam.  Their notices to the court are very strong evidence that the notice was inadequate.
  4. David and/or Elli Weinstein will probably speak about their interesting objections.
  5. I’ll be represented as before by Greg Beck of Public Citizen and Mark Chavez of Chavez Gertler.
  6. KamberEdelson’s and TD Ameritrade’s attorneys will be arguing for final approval of the settlement.
  7. California Attorney General Edmund G. Brown Jr is too busy running for governor to do his job by filing (directing his staff to file) an objection; please call his office at (800) 952-5225 about this; let me know if you do.

Thank Yous are due to many folks who helped me in this mission. (more…)

If you have a TD Ameritrade account and use M$ Windows, you should read this Washington Post article.  Kudos to Brian Krebs; he is doing truly excellent work!

I hope to be seeking new counsel soon (i.e. new lawyers to represent me AND the class on a contingency basis). (more…)

I don’t understand why Scott Kamber, Bob Kris, and the rest at KamberEdelson and TD Ameritrade persist in attacking me, as they spent much time doing at the 9/15/08 hearing.   Their attacks to date have consisted of claims that not only are not backed up by evidence, they are actually refuted by it.

Surely, they’re too smart to not realize that persuasion only goes so far in the face of cold hard evidence. (more…)

Much is on the record now.  I just filed this brief and this declaration with the court, prepared by my new counsel.

We shred the proposed settlement.  We mention (more…)

Help!  I’m hoping a whistleblower will step up to provide additional info regarding the extent of the TD Ameritrade breach. (more…)

This IS a good piece of software.

I’ve used it, and found it was roughly comparable to similar suites from the big guys: Norton/Symantec and McAffee. (Like all of them, it will cause problems on some PCs.)

However, as a component of the settlement there are significant issues: (more…)

Welcome to Trials and Tribulations, a.k.a. caringaboutsecurity.wordpress.com, a.k.a. AMTD.elvey.com.

I’ve finally (belatedly!) started a blog where I can post about my case.  I want a place where I can say things in my own words.  I want to avoid spin, misquotations and misrepresentations.  The issues in this case are often complicated.  I’ve put too much of my heart and soul into this case to have things thrown off course.  I have literally put months of my time into researching and bringing the complaint, and consistently following and attempting to fulfill my duties as class rep to the best of my ability.

Wired has some coverage and some commentary on the case from yours truly (read all the way to the bottom of the wired threat level page).  I’ll put up links to Google and google news and usenet and so forth as needed…

Read of my efforts to be an exemplary class rep. in the Elvey v. TD Ameritrade, Inc. pump-n-dump spam and Identity Theft litigation.

I discovered the information security breach by which the Social Security Numbers of all 6.3 million AMTD customers were compromised and proved that criminals, namely identity thieves, had gained access to the database they were in.

There are about a dozen settlement components I’d like to comment on, or have already commented on.  I welcome your feedback; just use the form on the bottom of most pages on the site, including this one.