LinkedIn beat two lawsuits over its practice of scanning usersâ browser extensions, with a judge granting the Microsoft subsidiaryâs motion to dismiss the cases. The users who sued LinkedIn failed to adequately allege that they have standing to sue because neither asserted that they âhad browser extensions installed that conveyed private information to LinkedIn,â ruled Judge Vince Chhabria in US District Court for the Northern District of California.
In his ruling on Tuesday, Chhabria gave the plaintiffs leave to amend their complaints but said he doubts they can make a plausible case. âGiven LinkedInâs further arguments that users voluntarily download browser extensions, which by their nature intentionally expose data to websites, it seems unlikely that the plaintiffs will ever be able to allege a privacy violation, much less prevail at the end of the day,â Chhabria wrote.
California residents Nicholas Farrell and Jeff Ganan separately filed class actions against LinkedIn in April, seeking to represent themselves and other LinkedIn users. Gananâs attorney, J.R. Howell, said he is evaluating whether to bring the claims in a California state court, which has different requirements on standing, or to appeal the US district court ruling in the US Court of Appeals for the Ninth Circuit.
âThe federal court determined that it lacked jurisdiction to hear the LinkedIn usersâ claims,â Howell told Ars today. âThe court did not adjudicate whether LinkedInâs surveillance practices were lawful. The ruling is not a vindication of the mass surveillance program alleged in our complaint.â
âBrowserGateâ stems from dispute over scraping
As we wrote in April, the plaintiffs filed their lawsuits after a report alleged that âLinkedIn Is illegally searching your computer.â LinkedIn did not deny that it scans browsers to identify extensions and already disclosed in its privacy policy that it uses cookies and similar technologies to collect information about each userâs âweb browser and add-ons.â
The so-called âBrowserGateâ report was issued by a German entity called Fairlinked, which describes itself as a trade association and advocacy group for commercial LinkedIn users. It appeared to be run by the same people behind Teamfluence, an Estonian software company that sued LinkedIn in Munich after its CEO was banned by LinkedIn.
Howell, Gananâs lawyer, also serves as counsel for Fairlinked in the US. In a June court filing, Howell wrote that âmy investigative work with Fairlinked e.V. and Browsergate occurred before my office filed the Ganan complaint.â
LinkedIn said in a motion to dismiss that it uses detection systems to identify the type of automated scraping and bot activity that Teamfluence was deploying. LinkedIn told the court:
Teamfluence, an Estonian platform, is one of those groups that traffics in scraping. It markets a Google Chrome browser plug-in designed to â[i]dentify 100% of your LinkedIn traffic.â LinkedIn caught it and banned its CEO from the platform, leading to a legal dispute in Germany. A German tribunal recently determined that â[t]he âTeamfluenceâ software violates [LinkedInâs User Agreement],â and that LinkedInâs âsuspending the Claimantsâ user accounts is objectively justified overall and not arbitrary.â
Judge: Plaintiffs did not allege concrete harm
After the German court order, the Teamfluence-linked group called Fairlinked emerged with the BrowserGate report, which attracted coverage on a number of tech news sites.
âNo surprise: the founder of Teamfluence sits on Fairlinkedâs board,â LinkedInâs motion said. âHaving been caught for scraping, and held to have violated LinkedInâs terms, he has now embarked on an international retaliation campaign by manufacturing a fake privacy controversy. But it is Teamfluence that is scraping data without consent.â Teamfluenceâs CEO and founder is named Steven Morell.
Chhabriaâs ruling said that neither Farrell nor Ganan âalleges that they, specifically, had browser extensions installed that conveyed private information to LinkedIn. Ganan never alleges that he had any extensions installed at all. Farrell alleges that he âhas long had several browser extensions installed,â and that, in general, browser extensions âoften reveal sensitive private information about its users,â but he never alleges that one of his own browser extensions revealed such information.â
The judge said the âallegations are insufficient to confer standing because only âthose plaintiffs who have been concretely harmed by a defendantâs statutory violation may sue that private defendant over that violation in federal court.â Identifying categories of private information that hypothetically could be revealed by surveillance of browser extensions is not enough to allege standing âparticularized to a plaintiffâs circumstances,ââ as precedent requires.
Ganan argued in a filing that the harm is âthe unpermitted probe, not its yield,â but Chhabria wrote that âa plaintiff must identify âembarrassing, invasive, or otherwise private information collected byâ the defendant.â
Lawyer vows to continue case
LinkedInâs motion to dismiss said it uses detection tools âto identify whether a visitor to the platform is operating a browser extension that could threaten the security and integrity of the platform,â and that âLinkedIn detects information that browser extensions openly provide to all websites in order to interact with them. The information is publicly available and in no way private. And LinkedInâs right to detect this information is disclosed and agreed to by all its members. So is LinkedInâs right to use security-focused vendors to detect and prevent potential abuse.â
LinkedIn said that some Chrome browser extensions extract job listings and related data from the companyâs website, and that LinkedInâs terms prohibit extensions that scrape or copy data from the site. LinkedInâs ârich platform and robust community make LinkedIn a target for opportunistic software developers who seek to scrape its data for their own purposes,â the company said.
Howell told Ars today that the Ganan lawsuit âalleges that LinkedIn deployed code without usersâ consent to surveil their internal computing environments, collect information, and route data to third parties.â
âThe companies developing and deploying these technologies should not get to decide, on their own, the boundaries of our privacy,â Howell said. âAs their ability to observe and profile people expands, meaningful consent and judicial scrutiny become more important. ⦠We intend to pursue these claims in a forum that can adjudicate them on their merits.â
We also contacted Farrellâs lawyers about the judgeâs ruling and will update this article if we get a response. Although Farrellâs lawyers donât appear to have coordinated directly with Fairlinked, the claims in their lawsuit were based largely on the groupâs BrowserGate report.

