From their [terms and conditions](https://www.ashleymadison.com/app/public/tandc.p?c=1) that you have to agree to:
19. ARBITRATION AND CLASS ACTION WAIVER
....
D. Class and Consolidated Claims Waiver
It is agreed that neither party shall have the right
to participate as a class representative or class
member with respect to any Disputes subject to
arbitration under this Agreement or any Dispute
between the parties. The parties also waive any
right to assert consolidated claims with respect to
any Disputes subject to arbitration under this
Agreement or any Dispute between the parties.
Such clauses are generally enforceable in the United States, as far as I can tell from a bit of Googling. It looks like in Canada, enforceability depends on whether the alleged misdeeds of the defendant arise from a violation of common law or a violation of specific consumer protection acts.The "Disputes subject to arbitration under this Agreement" seem to be set out in 19.A, which is titled "Scope", and the TL;DR of that section would be "everything, except Ashley Madison can use the courts instead of arbitration if they wish to sue you over intellectual properties, confidential information, or illegal activity".
They do have one exception, given in 19.C, titled "Small Claims", which says:
Both parties retain the right to file any claim that
is not aggregated with the claim of any other
persons and whose amount in controversy is properly
within the jurisdiction of a court which is limited
to adjudicated small claims.I see the need for privacy at all level of our lives. Unless we all make a democratic and informed choice to drop this value. But since this requires enormous maturity, society might be ready for this in a couple of hundred years.
Risk can be difficult to quantify, and if the focus is on chasing the short-term, you might be told to damn the torpedoes and get the product launched.
There is no reason any authentication process has to use more than a single request + single response (and a single request and immediate reply from the auth server). The usual concerns like replay attacks, allowing third parties to relay data for the auth server can all be solved using encryption. In 15 years of working as a developer, I have encountered one company that actually does this both correct and fast. Security departments demanding that user authentication happen over an LDAP+Kerberos connection, for example, are commonplace and this is stupid and very slow, for no good reason.
Who is this marketing VP who covers data breach insurance with their marketing budget? Now they're the ones making product decisions?
Having worked on a company that sold multifactor auth software in the mid 2000's, I can tell you most companies won't pay for software until there is a breach.
This is not unlike home owners installing alarms until after a breakin has occured in the neighborhood.
"It’s a valid business decision to accept the risk” said Jason Spaltro, who is now Sony Pictures' senior vice president of information security, in the interview. “I will not invest $10 million to avoid a possible $1 million loss."
[1] http://mashable.com/2014/12/05/sony-hack-infosec-comments/