
Siding with LinkedIn, a federal judge has
dismissed two class-action complaints alleging that the company scans users' browsers to learn which extensions have been installed.
In a three-page ruling issued Tuesday, U.S.
District Court Judge Vince Chhabria in the Northern District of California said the plaintiffs in both cases lacked "standing" because they didn't allege that their browsers actually had extensions
that transmitted private data to LinkedIn.
One plaintiff, California resident Jeff Ganan, "never alleges that he had any extensions installed at all," Chhabria wrote.
The other, California's Nicholas Farrell, alleged he had "several" extensions, but didn't allege that they revealed sensitive private information about him to LinkedIn, according to
Chhabria.
advertisement
advertisement
The order comes in litigation that began in April, when Ganan and Farrell claimed in separate lawsuits that LinkedIn violates California privacy laws as well as the
anti-hacking laws that prohibit companies from accessing computers without authorization.
Farrell alleged in his complaint that LinkedIn "executes hidden scripts" that can scan
users' browsers for extensions, and then "transmits that data to third parties without users’ consent or knowledge."
The suits were based on a report titled
"BrowserGate," which alleged that the Microsoft-owned platform searches users' browsers for more than 6,000 different extensions.
That
report, by the German entity "Fairlinked," which describes itself as an association of commercial LinkedIn users, also alleged that the scans enable LinkedIn to deduce additional information about
users and their employers.
Bleeping Computer reported in April that it tested LinkedIn and independently confirmed
that the platform scanned users' browsers for extensions, but couldn't verify claims regarding LinkedIn's use of that data.
LinkedIn says in its privacy policy that it obtains information about users' networks and devices, including "web browser and add-ons."
Soon
after the BrowserGate report was published, LinkedIn publicly acknowledged that it looks for "extensions that scrape data without
members’ consent or otherwise violate LinkedIn’s Terms of Service" in order to protect users' privacy and "ensure site stability."
The company added that it does
not use the data "to infer sensitive information about members."
In June, LinkedIn urged Chhabria to dismiss the cases at an early stage, arguing that the allegations, even if
proven true, wouldn't show that the company violated users' privacy.
"Nothing in either complaint supports a plausible inference that LinkedIn or its vendors use personal data
purportedly derived from browser extension detection information to generate profits -- nor that any users suffered an invasion of privacy," the company argued.
LinkedIn added
that browser extensions "can degrade website function and enable fraud and abuse," adding, "the purpose of LinkedIn’s systems is to identify whether a visitor to the platform is operating a
browser extension that could threaten the security and integrity of the platform."
The company also argued that the plaintiffs lacked a reasonable expectation of privacy
because they voluntarily installed extensions -- and browser extensions are designed to interact with publisher sites.
Chhabria said the plaintiffs could attempt to beef up
their allegations and file amended complaints by September 22, but added that it was unlikely that they would be able to move forward.
"Given LinkedIn’s further arguments
that users voluntarily download browser extensions, which by their nature intentionally expose data to websites, it seems unlikely that the plaintiffs will ever be able to allege a privacy violation,
much less prevail at the end of the day," he wrote.