LinkedIn has successfully defended itself against two lawsuits concerning its practice of scanning users’ browser extensions, with a judge granting the Microsoft subsidiary’s motion to dismiss the cases. The plaintiffs in the lawsuits failed to adequately demonstrate they had legal standing to sue, as neither asserted that they “had browser extensions installed that conveyed private information to LinkedIn,” ruled Judge Vince Chhabria in the US District Court for the Northern District of California.
In his ruling on Tuesday, Chhabria granted the plaintiffs leave to amend their complaints but expressed doubt about their ability to build a plausible case. “Given LinkedIn’s further arguments that users voluntarily download browser extensions, which by their nature intentionally expose data to websites, it seems unlikely that the plaintiffs will ever be able to allege a privacy violation, much less prevail at the end of the day,” Chhabria wrote.
California residents Nicholas Farrell and Jeff Ganan had separately filed class actions against LinkedIn in April, seeking to represent themselves and other LinkedIn users. Ganan’s attorney, J.R. Howell, stated that he is evaluating whether to pursue the claims in a California state court, which has different standing requirements, or to appeal the US district court ruling to the US Court of Appeals for the Ninth Circuit.
“The federal court determined that it lacked jurisdiction to hear the LinkedIn users’ claims,” Howell told Ars today. “The court did not adjudicate whether LinkedIn’s surveillance practices were lawful. The ruling is not a vindication of the mass surveillance program alleged in our complaint.”
“BrowserGate” stems from dispute over scraping
As previously reported, the plaintiffs filed their lawsuits after a report alleged that “LinkedIn Is illegally searching your computer.” LinkedIn did not deny scanning browsers to identify extensions and had already disclosed in its privacy policy that it uses cookies and similar technologies to collect information about each user’s “web browser and add-ons.”
The so-called “BrowserGate” report was issued by a German entity called Fairlinked, which describes itself as a trade association and advocacy group for commercial LinkedIn users. It appeared to be run by the same individuals behind Teamfluence, an Estonian software company that sued LinkedIn in Munich after its CEO was banned by the platform.
Howell, Ganan’s lawyer, also serves as counsel for Fairlinked in the US. In a June court filing, Howell wrote that “my investigative work with Fairlinked e.V. and Browsergate occurred before my office filed the Ganan complaint.”
LinkedIn, in its motion to dismiss, stated that it uses detection systems to identify automated scraping and bot activity similar to that deployed by Teamfluence. LinkedIn informed the court:
Teamfluence, an Estonian platform, is one of those groups that traffics in scraping. It markets a Google Chrome browser plug-in designed to “\Identify 100% of your LinkedIn traffic.” LinkedIn caught it and banned its CEO from the platform, leading to a legal dispute in Germany. A German tribunal recently determined that “\The ‘Teamfluence’ software violates \LinkedIn’s User Agreement,” and that LinkedIn’s “suspending the Claimants’ user accounts is objectively justified overall and not arbitrary.”
Judge: Plaintiffs did not allege concrete harm
Following the German court order, the Teamfluence-linked group Fairlinked released the BrowserGate report, which garnered coverage on several tech news sites.
“No surprise: the founder of Teamfluence sits on Fairlinked’s board,” LinkedIn’s motion stated. “Having been caught for scraping, and held to have violated LinkedIn’s terms, he has now embarked on an international retaliation campaign by manufacturing a fake privacy controversy. But it is Teamfluence that is scraping data without consent.” Teamfluence’s CEO and founder is Steven Morell.
Chhabria’s ruling noted that neither Farrell nor Ganan “alleges that they, specifically, had browser extensions installed that conveyed private information to LinkedIn. Ganan never alleges that he had any extensions installed at all. Farrell alleges that he ‘has long had several browser extensions installed,’ and that, in general, browser extensions ‘often reveal sensitive private information about its users,’ but he never alleges that one of his own browser extensions revealed such information.”
The judge stated that the “allegations are insufficient to confer standing because only ‘those plaintiffs who have been concretely harmed by a defendant’s statutory violation may sue that private defendant over that violation in federal court.’ Identifying categories of private information that hypothetically could be revealed by surveillance of browser extensions is not enough to allege standing ‘particularized to a plaintiff’s circumstances,’” as precedent requires.
Ganan argued in a filing that the harm is “the unpermitted probe, not its yield,” but Chhabria wrote that “a plaintiff must identify ’embarrassing, invasive, or otherwise private information collected by’ the defendant.”
Lawyer vows to continue case
LinkedIn’s motion to dismiss asserted that it uses detection tools “to identify whether a visitor to the platform is operating a browser extension that could threaten the security and integrity of the platform,” and that “LinkedIn detects information that browser extensions openly provide to all websites in order to interact with them. The information is publicly available and in no way private. And LinkedIn’s right to detect this information is disclosed and agreed to by all its members. So is LinkedIn’s right to use security-focused vendors to detect and prevent potential abuse.”
LinkedIn stated that some Chrome browser extensions extract job listings and related data from the company’s website, and that LinkedIn’s terms prohibit extensions that scrape or copy data from the site. LinkedIn’s “rich platform and robust community make LinkedIn a target for opportunistic software developers who seek to scrape its data for their own purposes,” the company said.
Howell told Ars today that the Ganan lawsuit “alleges that LinkedIn deployed code without users’ consent to surveil their internal computing environments, collect information, and route data to third parties.”
“The companies developing and deploying these technologies should not get to decide, on their own, the boundaries of our privacy,” Howell said. “As their ability to observe and profile people expands, meaningful consent and judicial scrutiny become more important. … We intend to pursue these claims in a forum that can adjudicate them on their merits.”
Ars Technica also contacted Farrell’s lawyers regarding the judge’s ruling and will update this article if a response is received. Although Farrell’s lawyers do not appear to have directly coordinated with Fairlinked, the claims in their lawsuit were largely based on the group’s BrowserGate report.




