Live data from Hacker News

LinkedIn: It’s illegal to scrape our website without permission

arstechnica.com

251–260 of 303 posts

Re: LinkedIn: It’s illegal to scrape our website without permission

#251
post #230
post #205

Earlier quoted context omitted.

True, but in making the request, you will provide information on who is making that request. If you say, "I am a bot!", and they grant you permission, your request is legal. But if you say, 'I am NOT a bot', like spoofing a browser's user agent string, but you are a bot, then you are requesting access under a pretense, in order to circumvent their terms of service. Kinda feels morally wrong, and illegal.

That argument works, insofar as it does, only for more recognizable bots and browsers. If I write a client of some sort that identifies itself as: Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Snackmaster Pro/666.0.666 What do you do? I also tell my browser to lie about what it is sometimes, due to sites that are malfunctioning, but whose owners choose to document the errors instead of fixing th…

In your first case, if you are running on Windows NT 6.1 using WebKit on a new browser for humans called 'Snakemaster Pro', then you aren't doing anything wrong.

If by client you mean a robot, then you are pretending to be a browser and you are accessing the service without permission.

Let me ask you a question, say your client was hitting my service with that user agent, 100 times a second, crawling through urls sequentionaly. Lets say I added it to my robots.txt deny list and starting blocking that user agent. Would you change the user agent and continue?

If someone creates a site that says, 'Access to this site is for 640x480 browsers only, any other use is forbidden'. Then I think its pretty clear that its a stupid site but also that faking your screen resolution is accessing a site without consent. There is no slope, someone (Linkedin) putting explicit terms on their website is pretty clear.

Re: LinkedIn: It’s illegal to scrape our website without permission

#252
post #156

Earlier quoted context omitted.

* That being said, I hate LinkedIn as a company and I fully support anyone trying to mess with them So it's fine to mess with them, even illegally, just because you don't like them? * convinces people to willingly provide personal information Convincing is not forcing, and in fact, you say "willingly" yourself. Any business convinces you to willingly give them money or other value. * sell at ridiculously high prices…

> So it's fine to mess with them, even illegally, just because you don't like them? If it's not illegal, then scummy behaviour against a scummy company doesn't exactly set my moral compass off. You reap what you sow.

An eye for an eye, a tooth for a tooth.

Very good. That way the whole world will be blind and toothless. --Tevye, Fiddler on the Roof

If you allow yourself to act as badly as others act, you don't have much of a moral compass.

The world can only improve when we hold ourselves to a higher standard than we see, as it's too easy to rationalize our own behavior, and harshly judge others' actions.

Re: LinkedIn: It’s illegal to scrape our website without permission

#253
post #156

Earlier quoted context omitted.

* That being said, I hate LinkedIn as a company and I fully support anyone trying to mess with them So it's fine to mess with them, even illegally, just because you don't like them? * convinces people to willingly provide personal information Convincing is not forcing, and in fact, you say "willingly" yourself. Any business convinces you to willingly give them money or other value. * sell at ridiculously high prices…

> So it's fine to mess with them, even illegally, just because you don't like them? If it's not illegal, then scummy behaviour against a scummy company doesn't exactly set my moral compass off. You reap what you sow.

[deleted]

Re: LinkedIn: It’s illegal to scrape our website without permission

#254

Earlier quoted context omitted.

Actually, no. It's more like complaining about others selling tickets to view said painting from the sidewalk. HiQ repackages and sells data it scrapes from LinkedIn.

Actually, no. It's like taking pictures of the paintings from the street, and reselling those pictures. If they don't like that... that the painting down. Simple.

That is an interesting analogy. It reminds me of my experience visiting the Alamo in San Antonio. Once inside you cannot take photos. I cannot say for sure but I think there are armed guards that made sure cameras were not used.

Personally I think anything I can see I should be able to take a photo of for sentimental purposes.

Re: LinkedIn: It’s illegal to scrape our website without permission

#255
post #244

Earlier quoted context omitted.

Are they still doing that? I haven't seen a request from LinkedIn for email access credentials in a while. Still a pretty sketchy thing to do IMO. I wonder if Google, Yahoo, MS etc have done anything like watch for requests from LinkedIn with correct credentials, block them, and reset the user's password and give them a warning that they just gave their account password to a third party and this is a Very Bad Idea.

A whole bunch of other sites ask for your Google, etc credentials instead of using the SSO API. I've even seen some tax software ask for your Bank login. It's really a bad practice but LinkedIn isn't the worst offender.

Speaking of offenders, I just noticed that the seemingly popular Venmo payments app asks for the web login credentials to any bank you try to link it to. Hell no I'm not giving some random app login credentials to any of my bank accounts.

Re: LinkedIn: It’s illegal to scrape our website without permission

#256
> HiQ scrapes data about thousands of employees from public LinkedIn profiles, then packages the data for sale to employers worried about their employees quitting

Screw both of these companies. One runs a shitty "professional" social network (data collection tool) and the other scoops up their data droppings and makes it their core business. I just can't have sympathy for either side.

Re: LinkedIn: It’s illegal to scrape our website without permission

#257

Earlier quoted context omitted.

* That being said, I hate LinkedIn as a company and I fully support anyone trying to mess with them So it's fine to mess with them, even illegally, just because you don't like them? * convinces people to willingly provide personal information Convincing is not forcing, and in fact, you say "willingly" yourself. Any business convinces you to willingly give them money or other value. * sell at ridiculously high prices…

I would replace the word "convinces" with "deceives". If you deceive a person into, for example, giving them access and permission to use your personal contact list however they please, then proceed to do just that, you don't have anything to complain about.

I'm lucky my dad uses a different password for his gmail account than his linkedin login (using said gmail address). He was stuck for a while complaining that he couldn't log in. Turned out he was already logged in, and LinkedIn was just presenting him with a "put your gmail password in here so we can raid your contacts" box. It looks just like the login page, so he kept putting in his LinkedIn (not gmail) password and it kept saying "your password is incorrect."

What a shitty thing to do.

Re: LinkedIn: It’s illegal to scrape our website without permission

#259
post #244

Earlier quoted context omitted.

Agree. The number of times I've received LinkedIn emails from people I no longer speak to who I'm confident would have no actual inclination to connect with me is certainly in the double digits. They've all been conned into giving LinkedIn their email password, and LinkedIn is going crazy as result. This probably happened a lot more a few years ago. Is perhaps 2FA making this harder these days?

Are they still doing that? I haven't seen a request from LinkedIn for email access credentials in a while. Still a pretty sketchy thing to do IMO. I wonder if Google, Yahoo, MS etc have done anything like watch for requests from LinkedIn with correct credentials, block them, and reset the user's password and give them a warning that they just gave their account password to a third party and this is a Very Bad Idea.

It's a few years ago now .. but it definitely happened.

Agree with you that giving your account password to any third party is madness, even more so actually soliciting it.

Post reply on HN