TD Ameritrade breach


How do I feel?

I feel like the justice system has let me down, like the Wall Street protesters who, e.g. want to see the executives of my former employer who lied to congress at least get arrested.

TD Ameritrade (TDA) has refused to pass a security audit, and the attorneys supposedly representing the class are OK with that. If TDA had secured their customer data properly, they would, most certainly, be eager to show their customers and target market.

My friends and I are angry that TDA’s security is still Swiss cheese. Earlier this year, they accidentally admitted that they didn’t even have an IDS or IPS system in place! I hear they still don’t encrypt customer data and still grant staff far more customer data access than is needed to do their jobs. They’re in violation of Massachusetts law. They’re literally making millions serving customers over the Internet that they wouldn’t make without the Internet, but not taking the small steps necessary to protect those customers. They spent millions on attorneys (at one judge-managed mediation session, there were ~30 attorneys present.) Instead of covering up their mistakes, they should be doing the right thing.

They profit off the Internet, but won’t invest in it! Their databases are an open book to gangs and even determined high-school students. They should be hiring and training their staff and deploying resources so that they can pass a security audit. They’ll get hacked again. And when they do, they’ll be back in court. And this warning, which I delivered in court, will haunt them.

The Armstrong court cherry picked which objections in my final filing to address and which to ignore.  The court demonstrated that it doesn’t even understand the 9th District’s own General Order (regarding PDFs) because it’s too technical!  (Even though it’s quite simple.)  There’s no way it understood all the key technical security issues in this case.

There’s been a news blackout with respect to the fact that TD Ameritrade actively covered up the security breach, as the whistleblower-sourced information I’ve published here details.

I’m glad that TD Ameritrade has at least received some bad press for its disgraceful behavior, and that those who filed claims are expected to receive significant compensation.  I’m glad that the bulk of the class is at least somewhat aware of the breach.  Unfortunately, the insignificant cost of this settlement sends the message that executives who underfund the Information Security department and direct the cover-up of a security breach breach are making the right choices, as far as the financial interests of shareholders go.  TDA would need to spend more than it spent settling this case to shore up its security enough to pass a proper audit.

I called the Claims Administrator yesterday, at 1-888-749-8173. The firm is well known in its field: Rosenthal & Co, which part of Computershare.  What a fiasco!

WarningDO NOT USE the information (more…)

NEW: You can review and comment on the key documents, which I’ve posted in editable wiki form at http://caringaboutsecurity.wikispaces.com! Cool, huh?(I’ve not posted the less important documents to the wiki. Just exhibits A, F, and G for now.) Please take a look and provide feedback. Smile

On December 9, 2010, I filed and argued in court against the motion for preliminary approval:

Elvey_Response_to_Kreinder-TDA_offer.pdf describing our concerns.  I’d highlight them thusly:  We pushed for an effective audit.   This settlement proposal notice is misleading and poorly publicized, and so cannot be fair.  It has an audit component that to the untrained or hasty eye is meaningful compensation, but (more…)

AVPageView-05042011-100856.bmp

An actual HMG IS2 Full Accreditation Statement based on an actual ITSHC – an actual security audit by Deloitte, one of the Big Four audit firms – which demonstrates the auditor’s reputation has been put on the line, as well as the legal liability shouldered by such an audit.
Author: George McLeod, National Accreditation Manager, NPIA

Judge Walker has said that the audit component primarily benefits TD Ameritrade, not the class.  Here’s why I think a good audit component substantially benefits the class.  (more…)

The proposed settlement has been thrown out!

What did I think of the decision?

What do I want to see happen?

The media is asleep on the job?

(more…)

THE SNOWJOB TD Ameritrade’s PR goons pulled is unraveling.  UCAN’s Privacy Rights clearinghouse run by Beth Givens has corrected its database entry for the breach.  Attrition.org/datalossdb.org  have corrected their entry.  Both now indicate that social security numbers were compromised.

Today is the hearing on approval of the settlement –  at 10 AM (September 10th) in Courtroom 6, 17th Floor, 450 Golden Gate in San Francisco. Wish me and my Allied Forces luck.   I expect several parties will/won’t speak: (more…)

Ted Frank writes here that

To date, there is no evidence that the spam was connected to Ameritrade, or that a breach of Ameritrade data security that released home addresses for its customers has resulted in any harm, despite Ameritrade seeding databases with dummy spam-catcher e-mail addresses, and multiple analyses of whether identity theft had occurred.

Wow.  Is this guy actually too stupid to be allowed near a computer keyboard, or is he just trying to spin things in the usual AEI way?  This guy has an impressive reality distortion field around his head.  This is totally contradicted by the complaint, and supported by the evidence filed in the case. There is, the complaint explains, ironclad proof from a large number of computer gurus that the spam was connected to TD Ameritrade, namely that the spam was sent to unique email addresses stolen from a core TD Ameritrade customer database.  A database which TD Ameritrade has admitted got broken into and plundered.  That it admitted contained the names, addresses, social security numbers, dates of birth, and account balances of its 6.3 million customers.  But Ted Frank’s ostrich-style thinking is like that of TD Ameritrade a firm that is claiming that it’s plausible that crooks breaking into the equivalent of Fort Knox would leave the gold (the Social Security Numbers) and just take the silver (the email addresses).  That a rash of Identity Theft that began right after the breach was discovered does not constitute evidence connecting the two.

STOP znw-5#%—NO CARRIER
ABORT: -PEBCAK

Thank Yous are due to many folks who helped me in this mission. (more…)

If you have a TD Ameritrade account and use M$ Windows, you should read this Washington Post article.  Kudos to Brian Krebs; he is doing truly excellent work!

I hope to be seeking new counsel soon (i.e. new lawyers to represent me AND the class on a contingency basis). (more…)

I don’t understand why Scott Kamber, Bob Kris, and the rest at KamberEdelson and TD Ameritrade persist in attacking me, as they spent much time doing at the 9/15/08 hearing.   Their attacks to date have consisted of claims that not only are not backed up by evidence, they are actually refuted by it.

Surely, they’re too smart to not realize that persuasion only goes so far in the face of cold hard evidence. (more…)

Next Page »