5 ms·
I don't understand how Facebook got a $5B fine, yet Equifax gets a ~$650m fine. The data breached in the Equifax case seems to cause far more direct harm, and a
by FlyingLawnmower 7y ago
I don't understand how Facebook got a $5B fine, yet Equifax gets a ~$650m fine. The data breached in the Equifax case seems to cause far more direct harm, and affected many more Americans. It feels like the 10x difference should go the other way.
Can someone more educated in how these fines work teach me about how these numbers are calculated?
- cameronbrown 7y agoProbably because FB is politically charged, disliked by both parties, consumers and the wider industry. The fine represents the public's anger at large.
- samstave 7y ago" You're good, You're good, You're good, You're good, FUCK YOU IN PARTICULAR You're good, You're good, You're good,"
- paulddraper 7y agoAnd Equifax ISN'T?
- cameronbrown 7y agoLet's be honest, the average American barely knows what Equifax is.
- pmiller2 7y agoLet's be even more honest: if they did know what Equifax is, what they do, and how long they've been doing it, they would certainly hate them more than Facebook.
- ineedasername 7y agoLooks like you got downvoted a bit on this, but it's an excellent point. I fully think FB deserved what they got, and would not have balked at more. But Equifax, even with a fine higher than FB's relative to market cap, still seems to have gotten off lighter.
- harryh 7y agoThe FB fine was due to violating a previously existing consent decree with the FTC due to previous violations. The "2nd offense" nature of the offense probably contributed significantly to the higher number.
- rudyfink 7y agoFacebook's market cap is $566B (common stock) and Equifax's is $16.6B. The ratio of market cap differences is about 34:1. If Facebook's fine is adjusted to Equifax's it would be a $22.1B fine instead of $5B. So, from a market cap perspective Equifax's fine is ~4x Facebook's.
- paulddraper 7y agoI'm confused why that would have anything to do with it. If you cause $100 in damages, you pay $100 (plus any punitive awards). Doesn't matter what your shares happen to be trading at that day.
- shortandsweet 7y agoBecause you want to teach them a lesson, not put them out of business.
- ericd 7y agoWhy not?
- MereInterest 7y agoAgain, why? The lesson is for the industry as a whole to learn, not for an individual company.
- freeflight 7y agoThat's like saying society has a whole lot to learn but not individual humans.
- dogsgobork 7y agoPutting them out of business would teach them a lesson, one perhaps other companies might actually learn as well.
- 7y ago
- hourislate 7y agoI would imagine that Equifax was able to prove that they at least met the prudent man rule. The prudent man rule which requires senior executives to take personal responsibility for ensuring the due care that ordinary, prudent individuals would exercise in the same situation. This rule, developed in the realm of fiscal responsibility, now applies to information security as well. The intent was to patch the system but they experienced some sort of issue that prevented the timely action. From what I understand, you only have to show the courts that we tried to do the right thing and had the right intention. Plus they aren't involved in any election scandals which certainly helps.... The one positive thing that came out of all this is that you can lock down your credit for free and open it again for free when you need to . Basically no one could ever open an account or credit card in your name if the offering party tries to run a credit report.
- pmiller2 7y agoAssuming I buy your argument, to me, it just implies that the prudent man rule is inadequate here. Intent doesn't secure my data. As far as I'm concerned, they can intend in one hand and shit in the other and see which one fills up first. When the consequences of failure are the compromise of the financial lives of virtually every American adult, you need to be more than prudent about it.
- ineedasername 7y agoYes, intent minus execution equals some level of incompetence. Which (I guess?) is better than never having the intent to begin with, but it's sort of a distinction without a difference. "I wanted to fix my brakes but the brake shop was closed, that's why I got into a car crash" isn't really an endearing argument to the other parties involved or the regulators (Police in this case) that deal with the fallout.
- ineedasername 7y agoPlus they aren't involved in any election scandals which certainly helps.... Yes, plus their perceived censoring of right-leaning content (real or imagined). But between the election stuff and their attempt to setup a currency whose monetary policy would be governed by a group of wealthy corps and partly based in another country regulated by a foreign body... these are things that touch on the sovereignty of the US, and no government wants internal competition on that front.
- JumpCrisscross 7y ago> The data breached in the Equifax case seems to cause far more direct harm Facebook breached a consent decree with the FTC [1]. Demonstrating harm was simple—they breached a settlement. Equifax’s harm is potentially great. But demonstrating damages is difficult. TL; DR Facebook is a repeat offender. [1] https://www.ftc.gov/news-events/press-releases/2011/11/facebook-settles-ftc-charges-it-deceived-consumers-failing-keep https://www.ftc.gov/news-events/press-releases/2011/11/faceb...
- pmiller2 7y ago> ...demonstrating damages is difficult. I still don't see how less than $5 per person who's data was compromised constitutes a reasonable settlement.
- tyre 7y agoin addition to demonstrating harm, regulators really hate it if you defy them. Repeat offenses carry a significant penalty as you're seen to be thumbing your nose at them. That's what's frustrating about most of Elon's crap. Don't test the patience of the SEC with _tweeting_. Put your phone away and save that social capital for when you actually need it. FB is more strategic but still repeatedly misleads congress, the FCC, etc. After a while, they're sick of being made to look a fool. Notice that FB isn't getting the "trust us" benefit of the doubt with Libra (nor should they.)
- ineedasername 7y agoYes. The other most significant aggregator of data, Google, is by no means a saint in this space, but I think they would get a bit more "trust us" points than Facebook. Their settlement over childrens' privacy on the youtube platform is a salient example here. To my view, the rapid emergence of children vloggers turning it into a career and causing COPPA issues is probably something they should have twigged to earlier, but it doesn't smack of the blatant & extreme exploitation & carelessness of user data seen by Facebook. That said, Google is probably only one decent sized data scandal away from that territory, and hopefully takes FB's fine and increased scrutiny as instructive in being more careful themselves.
- dd36 7y agoEquifax offered free credit protection to mitigate damages.
- stefco_ 7y agoIIRC you had to agree not to join class action suits to take advantage. Seems like a pretty self-serving tactic given that we're the ones who have to deal with their idiocy.
- recursive 7y agoI got one of those letters. It seemed like a cruel joke to me. "We're sorry that we leaked all your personal data. But we have a great opportunity for you today! Send us some more personal data, and we'll monitor your file or something. For free! Trust us, it's gonna be great!"
- deleted 7y ago[deleted]