LinkedIn beats "BrowserGate" lawsuits over scanning users' Chrome extensions

LinkedIn beat two lawsuits over its practice of scanning users’ browser extensions, with a judge granting the Microsoft subsidiary’s motion to dismiss the cases. The users who sued LinkedIn failed to adequately allege that they have standing to sue because neither asserted that they “had browser extensions installed that conveyed private information to LinkedIn,” ruled Judge Vince Chhabria in US District Court for the Northern District of California.
In his ruling on Tuesday, Chhabria gave the plaintiffs leave to amend their complaints but said he doubts they can make a plausible case. “Given LinkedIn’s further arguments that users voluntarily download browser extensions, which by their nature intentionally expose data to websites, it seems unlikely that the plaintiffs will ever be able to allege a privacy violation, much less prevail at the end of the day,” Chhabria wrote.
California residents Nicholas Farrell and Jeff Ganan separately filed class actions against LinkedIn in April, seeking to represent themselves and other LinkedIn users. Ganan’s attorney, J.R. Howell, said he is evaluating whether to bring the claims in a California state court, which has different requirements on standing, or to appeal the US district court ruling in the US Court of Appeals for the Ninth Circuit.
“The federal court determined that it lacked jurisdiction to hear the LinkedIn users’ claims,” Howell told Ars today. “The court did not adjudicate whether LinkedIn’s surveillance practices were lawful. The ruling is not a vindication of the mass surveillance program alleged in our complaint.”
“BrowserGate” stems from dispute over scraping
As we wrote in April, the plaintiffs filed their lawsuits after a report alleged that “LinkedIn Is illegally searching your computer.” LinkedIn did not deny that it scans browsers to identify extensions and already disclosed in its privacy policy that it uses cookies and similar technologies to collect information about each user’s “web browser and add-ons.”
The so-called “BrowserGate” report was issued by a German entity called Fairlinked, which describes itself as a trade association and advocacy group for commercial LinkedIn users. It appeared to be run by the same people behind Teamfluence, an Estonian software company that sued LinkedIn in Munich after its CEO was banned by LinkedIn.
Howell, Ganan’s lawyer, also serves as counsel for Fairlinked in the US. In a June court filing, Howell wrote that “my investigative work with Fairlinked e.V. and Browsergate occurred before my office filed the Ganan complaint.”
LinkedIn said in a motion to dismiss that it uses detection systems to identify the type of automated scraping and bot activity that Teamfluence was deploying. LinkedIn told the court:
Teamfluence, an Estonian platform, is one of those groups that traffics in scraping. It markets a Google Chrome browser plug-in designed to “[i]dentify 100% of your LinkedIn traffic.” LinkedIn caught it and banned its CEO from the platform, leading to a legal dispute in Germany. A German tribunal recently determined that “[t]he ‘Teamfluence’ software violates [LinkedIn’s User Agreement],” and that LinkedIn’s “suspending the Claimants’ user accounts is objectively justified overall and not arbitrary.”
Judge: Plaintiffs did not allege concrete harm
After the German court order, the Teamfluence-linked group called Fairlinked emerged with the BrowserGate report, which attracted coverage on a number of tech news sites.
“No surprise: the founder of Teamfluence sits on Fairlinked’s board,” LinkedIn’s motion said. “Having been caught for scraping, and held to have violated LinkedIn’s terms, he has now embarked on an international retaliation campaign by manufacturing a fake privacy controversy. But it is Teamfluence that is scraping data without consent.” Teamfluence’s CEO and founder is named Steven Morell.
Chhabria’s ruling said that neither Farrell nor Ganan “alleges that they, specifically, had browser extensions installed that conveyed private information to LinkedIn. Ganan never alleges that he had any extensions installed at all. Farrell alleges that he ‘has long had several browser extensions installed,’ and that, in general, browser extensions ‘often reveal sensitive private information about its users,’ but he never alleges that one of his own browser extensions revealed such information.”
The judge said the “allegations are insufficient to confer standing because only ‘those plaintiffs who have been concretely harmed by a defendant’s statutory violation may sue that private defendant over that violation in federal court.’ Identifying categories of private information that hypothetically could be revealed by surveillance of browser extensions is not enough to allege standing ‘particularized to a plaintiff’s circumstances,’” as precedent requires.
Ganan argued in a filing that the harm is “the unpermitted probe, not its yield,” but Chhabria wrote that “a plaintiff must identify ’embarrassing, invasive, or otherwise private information collected by’ the defendant.”
Lawyer vows to continue case
LinkedIn’s motion to dismiss said it uses detection tools “to identify whether a visitor to the platform is operating a browser extension that could threaten the security and integrity of the platform,” and that “LinkedIn detects information that browser extensions openly provide to all websites in order to interact with them. The information is publicly available and in no way private. And LinkedIn’s right to detect this information is disclosed and agreed to by all its members. So is LinkedIn’s right to use security-focused vendors to detect and prevent potential abuse.”
LinkedIn said that some Chrome browser extensions extract job listings and related data from the company’s website, and that LinkedIn’s terms prohibit extensions that scrape or copy data from the site. LinkedIn’s “rich platform and robust community make LinkedIn a target for opportunistic software developers who seek to scrape its data for their own purposes,” the company said.
Howell told Ars today that the Ganan lawsuit “alleges that LinkedIn deployed code without users’ consent to surveil their internal computing environments, collect information, and route data to third parties.”
“The companies developing and deploying these technologies should not get to decide, on their own, the boundaries of our privacy,” Howell said. “As their ability to observe and profile people expands, meaningful consent and judicial scrutiny become more important. … We intend to pursue these claims in a forum that can adjudicate them on their merits.”
We also contacted Farrell’s lawyers about the judge’s ruling and will update this article if we get a response. Although Farrell’s lawyers don’t appear to have coordinated directly with Fairlinked, the claims in their lawsuit were based largely on the group’s BrowserGate report.
Jon is a Senior IT Reporter for Ars Technica. He covers the telecom industry, Federal Communications Commission rulemakings, broadband consumer affairs, court cases, and government regulation of the tech industry.
KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.
