Court, Explained
U.S. Federal District Courts
Back to docket
N.D. Cal.Procedural orderFiled Apr. 7, 2020

Brodsky v. Apple Inc.

Judge
Lucy Koh
Docket
5:19-cv-00712
Court
U.S. District Court · Northern District of California
Pages
36
Civil ProcedureMotion to Dismiss
In one sentence

In Brodsky v. Apple Inc., Judge Koh dismissed with prejudice a putative class action challenging Apple’s two-factor authentication under several laws.

Who this affects

The six named plaintiffs and the proposed nationwide class of Apple users were affected because the court dismissed all five asserted claims with prejudice and ended the case as pleaded.

What happened

In Brodsky v. Apple Inc., six plaintiffs claimed Apple’s two-factor authentication login process unlawfully interfered with their devices, privacy, computer access, and paid services. They sought to represent a nationwide class of Apple users who wanted to disable the feature but could not.

The plaintiffs brought claims for trespass to chattels, violation of the California Invasion of Privacy Act, the federal Computer Fraud and Abuse Act, the California Computer Crime Law, and unjust enrichment. The court said the amended complaint still did not adequately allege unauthorized access, legally sufficient harm, intercepted communications, unauthorized computer access, required losses, or a valid unjust-enrichment theory.

Judge Koh granted Apple’s motion to dismiss with prejudice. The court also ruled that some claims were inadequately dated under the pleading rules and that certain claims were barred by statutes of limitations; the plaintiffs were not given another opportunity to amend.

The detailed version

For law students, journalists, and other readers who want the full reasoning

Case
Brodsky v. Apple Inc. · No. 5:19-cv-00712
Judge
Lucy Koh
Date
Apr. 7, 2020

Background

Six plaintiffs—Jay Brodsky, Brian Tracey, Alex Bishop, Brendan Schwartz, William Richardson, and John Kyslowsky—brought a proposed class action against Apple Inc. They alleged that Apple’s two-factor authentication system, or 2FA, unlawfully interfered with their Apple devices, Apple services, and access to third-party applications. 2FA requires a user to enter a password, receive a six-digit code on a trusted Apple device, and enter that code before accessing Apple services.

The plaintiffs alleged that 2FA was enabled when users turned it on, created a new Apple ID, or installed a software update. They claimed that 2FA added two to five or more minutes to the login process and sometimes caused longer lockouts when users lost access to a trusted device or could not remember a password. The Second Amended Complaint asserted five claims: trespass to chattels, violation of the California Invasion of Privacy Act, violation of the federal Computer Fraud and Abuse Act, violation of the California Computer Crime Law, and unjust enrichment.

The court had previously dismissed all five claims in the First Amended Complaint but allowed the plaintiffs to amend. The plaintiffs filed the Second Amended Complaint, adding two named plaintiffs and allegations about the plaintiffs’ states of residence, choice of law, third-party applications, and revocation of authorization for 2FA. Apple again moved to dismiss under Federal Rule of Civil Procedure 12(b)(6), which permits dismissal when a complaint does not allege enough facts to state a legally plausible claim.

Trespass to chattels

Under California law, trespass to chattels is an unauthorized intentional interference with personal property that causes harm. The court held that the plaintiffs still did not allege that Apple enabled 2FA without authorization. The complaint stated that 2FA was enabled through voluntary activation, software updates, or creation of a new Apple ID, but did not provide facts showing that those methods were unauthorized.

The court also held that the plaintiffs did not adequately plead harm. A two-to-five-minute login delay did not damage the devices, impair their functioning, or substantially deprive the plaintiffs of their use. The longer lockouts described for some plaintiffs were attributed to events outside Apple’s control, such as losing a trusted device or forgetting a password. The court therefore granted Apple’s motion to dismiss the trespass claim with prejudice.

California Invasion of Privacy Act

The California Invasion of Privacy Act, or CIPA, generally requires an unauthorized interception of the contents of an electronic communication. The court held that the plaintiffs did not allege that Apple was a third party to the communications at issue. The alleged login activities were communications sent to Apple’s servers, so Apple was already a party to those communications rather than an outside interceptor.

The court separately held that the plaintiffs did not identify the contents of any intercepted communication. User names, passwords, and requests to access applications were treated as record information rather than communication contents. The court also rejected the plaintiffs’ theory that preventing access to applications or Apple services amounted to intercepting communications, because a user who cannot access a service has not created a communication for Apple to intercept. The court granted dismissal of the CIPA claim with prejudice.

Computer Fraud and Abuse Act

The Computer Fraud and Abuse Act, or CFAA, is a federal anti-hacking statute that requires unauthorized access or access beyond authorization, along with other statutory requirements. The court held that the plaintiffs’ allegations challenged the way Apple handled login activities through 2FA, not whether Apple was authorized to access those activities. The plaintiffs’ statement that they revoked authorization concerned 2FA as a method of access and did not withdraw authorization for Apple to access their login activities through other Apple ID login methods.

The court also held that the plaintiffs did not plead the required loss of more than $5,000 during a one-year period. The alleged value of the devices, subscriptions, and third-party applications could not be treated as losses caused by a two-to-five-minute login delay. The court further rejected the theory that the plaintiffs lost the economic value of personal information, relying on Ninth Circuit authority concerning the CFAA’s limited definition of loss. The court granted dismissal of the CFAA claims with prejudice.

California Computer Crime Law

The California Computer Crime Law, also called the California Comprehensive Computer Data Access and Fraud Act, prohibits certain computer access or disruptions without permission. The court held that the plaintiffs challenged only Apple’s method of access—2FA—while continuing to authorize Apple’s access to their login activities through other methods. That was insufficient to allege access without permission.

The court also found that the complaint largely repeated the statute’s language without supplying supporting facts. For example, the complaint alleged that Apple used or caused the use of Apple services and third-party applications without explaining how Apple could use an application on devices to which the plaintiffs were allegedly locked out. The court granted dismissal of the California Computer Crime Law claims with prejudice.

Unjust enrichment

The court held that California does not recognize unjust enrichment as a separate cause of action, although some claims labeled unjust enrichment may be treated as requests for restitution under a quasi-contract theory. A quasi-contract theory generally cannot proceed when an enforceable contract covers the same subject unless the plaintiff alleges that the contract may be invalid or unenforceable.

The complaint alleged that the plaintiffs had a contract with Apple through Apple’s terms of use and did not allege that the contract was invalid or unenforceable. The court therefore granted dismissal of the unjust-enrichment claim with prejudice.

Pleading dates and statutes of limitations

The court separately ruled that Bishop, Schwartz, Richardson, and Kyslowsky did not satisfy the basic pleading requirement of giving approximate dates for when 2FA was enabled. Because Apple raised plausible statute-of-limitations defenses, the missing dates prevented Apple from adequately defending itself and the court from evaluating timeliness. The court dismissed those plaintiffs’ CIPA, CFAA, and California Computer Crime Law claims with prejudice.

The court also held that Brodsky’s CIPA, CFAA, and California Computer Crime Law claims were time-barred based on his allegation that 2FA was enabled in September 2015. The court held that Tracey’s CIPA claim was time-barred based on his allegation that 2FA was enabled in September 2017. The court rejected the plaintiffs’ reliance on continuous accrual, continuing violation, and delayed discovery theories, and granted dismissal of those claims with prejudice.

Disposition

The court concluded that the Second Amended Complaint did not cure the deficiencies identified in the earlier order. It granted Apple’s motion to dismiss with prejudice, ending the plaintiffs’ asserted claims in this action as pleaded.

The authoritative version

Read the full 36-page opinion on CourtListener, the free public archive maintained by the Free Law Project.

Open opinion PDF →
Summary written with AI assistance. See how summaries are made. Spot something wrong? Tell us.