Live data from Hacker News

LinkedIn: It’s illegal to scrape our website without permission

arstechnica.com

291–300 of 303 posts

Re: LinkedIn: It’s illegal to scrape our website without permission

#291

Earlier quoted context omitted.

I wasn’t aware that robots.txt had any legal meaning. Am I wrong?

I'd talk to a lawyer. There are presumably some legal arguments that might apply. There definitely have been cases revolving around it, but I have no idea what the outcomes were. From a moral point of view: robots.txt states an intent, and intentionally ignoring that is not a nice thing. And often, "not a nice thing" translates into legal action. So, if this matters to you, you should find an expert :)

> From a moral point of view: robots.txt states an intent, and intentionally ignoring that is not a nice thing.

As a lawyer asked inane questions by friends, a common answer is: "I am no sure if its legal to do, but I'm absolutely sure you're a asshole if you do it."

Re: LinkedIn: It’s illegal to scrape our website without permission

#292
post #156

Earlier quoted context omitted.

> So it's fine to mess with them, even illegally, just because you don't like them? If it's not illegal, then scummy behaviour against a scummy company doesn't exactly set my moral compass off. You reap what you sow.

An eye for an eye, a tooth for a tooth. Very good. That way the whole world will be blind and toothless. --Tevye, Fiddler on the Roof If you allow yourself to act as badly as others act, you don't have much of a moral compass. The world can only improve when we hold ourselves to a higher standard than we see, as it's too easy to rationalize our own behavior, and harshly judge others' actions.

As a sheep, you can take the moral high ground against a wolf, but you'll still get eaten. Companies generally don't care about holding themselves to higher standards of behaviour, unless it hurts their bottom line. Institutions don't understand shame, right, or wrong. The only thing they understand is power.

Re: LinkedIn: It’s illegal to scrape our website without permission

#293

Earlier quoted context omitted.

> it is very clear to me that a search engine is > operating on the legal equivalent of thin ice, We may be saying similar things but from a metaphor I think of search engines operating on 'thick' ice. It has been litigated so much that there is a bevy of case law to refer to at all levels. Eric Goldman's blog used to have a pretty good list of the number of suits of various kind and the searchengine blog covered man…

yuummm Torte law. (It's tort, and tort law is generally considered to be distinct from contract law, because in tort rights and duties come from common law whereas in contract law they come from acts of agreement between two parties).

Chocolate Torte is my favorite :-) Thanks for the clarification, in the various articles I've read over the years on this topic they refer to tort law (no doubt because much of the argument references common law and the way in which the relations are argued) and I made the leap to 'contracts' which was incorrect.

Re: LinkedIn: It’s illegal to scrape our website without permission

#294
post #244

Earlier quoted context omitted.

Agree. The number of times I've received LinkedIn emails from people I no longer speak to who I'm confident would have no actual inclination to connect with me is certainly in the double digits. They've all been conned into giving LinkedIn their email password, and LinkedIn is going crazy as result. This probably happened a lot more a few years ago. Is perhaps 2FA making this harder these days?

Are they still doing that? I haven't seen a request from LinkedIn for email access credentials in a while. Still a pretty sketchy thing to do IMO. I wonder if Google, Yahoo, MS etc have done anything like watch for requests from LinkedIn with correct credentials, block them, and reset the user's password and give them a warning that they just gave their account password to a third party and this is a Very Bad Idea.

> Are they still doing that? I haven't seen a request from LinkedIn for email access credentials in a while.

Literally yesterday I got, for the first time for that user, one of the spams sent "on behalf of" a user who clearly hadn't given out my e-mail address, so I guess they still are up to these no-good deeds.

Re: LinkedIn: It’s illegal to scrape our website without permission

#295
post #255

Earlier quoted context omitted.

A whole bunch of other sites ask for your Google, etc credentials instead of using the SSO API. I've even seen some tax software ask for your Bank login. It's really a bad practice but LinkedIn isn't the worst offender.

Speaking of offenders, I just noticed that the seemingly popular Venmo payments app asks for the web login credentials to any bank you try to link it to. Hell no I'm not giving some random app login credentials to any of my bank accounts.

Yes, this is maddening. I had a Craigslister who would only pay for a transaction via Venmo. (She was willing to make the transaction in my presence and wait for it to confirm; it wasn't a scam on her part.) With great reluctance (I needed the transaction at the time), I changed my bank password to something else, signed up for Venmo, got the money, de-enrolled from Venmo, and changed my bank password back.

I think that they used to have some FAQ entry explaining why worrying about this is silly and nothing bad could happen, but I can't find it any more (probably because it's nonsense). However, just because they should be shamed for this whenever possible, here's a Slate article on their overall security: http://www.slate.com/articles/technology/safety_net/2015/02/... .

Re: LinkedIn: It’s illegal to scrape our website without permission

#296
post #204

Earlier quoted context omitted.

Scraping would be forbidden via TOS; theoretically it would be the users giving access to linked in (who actually is bound by the terms) who would be liable, not linked in.

If it's illegal to scrape without permission, that makes the behavior of scraping illegal. They are not claiming it's a TOS violation, they're claiming it's a CFAA violation, which is a federal statue and (theoretically) applies equally to everyone.

My point is that someone with permission gave them access.

Re: LinkedIn: It’s illegal to scrape our website without permission

#297
post #212

Earlier quoted context omitted.

everything comes down to a moral compass of some kind. Your comment expects some sort of objective measurement of good and evil, but I don't see any. The law can be, and is often, in the wrong. Most people seem to think this law (if it is held up in court) is wrong and should be changed. You might say, oh well, we have a democratic right to change or influence our laws. But a princeton study has found no correlation…

Thank you for taking the time to reply, this is good to chew on.

thank you for reading. There are studies that contradict the one I posted, in one way or another, so I'm saying these things for sure

Re: LinkedIn: It’s illegal to scrape our website without permission

#298
post #204

Earlier quoted context omitted.

If it's illegal to scrape without permission, that makes the behavior of scraping illegal. They are not claiming it's a TOS violation, they're claiming it's a CFAA violation, which is a federal statue and (theoretically) applies equally to everyone.

My point is that someone with permission gave them access.

Having "permission" is not an applicable defense to a federal criminal charge, the law supersedes some random person (i.e. a LinkedIn user) saying "oh yeah, that's okay."

Re: LinkedIn: It’s illegal to scrape our website without permission

#299
post #251
post #230

Earlier quoted context omitted.

That argument works, insofar as it does, only for more recognizable bots and browsers. If I write a client of some sort that identifies itself as: Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Snackmaster Pro/666.0.666 What do you do? I also tell my browser to lie about what it is sometimes, due to sites that are malfunctioning, but whose owners choose to document the errors instead of fixing th…

In your first case, if you are running on Windows NT 6.1 using WebKit on a new browser for humans called 'Snakemaster Pro', then you aren't doing anything wrong. If by client you mean a robot, then you are pretending to be a browser and you are accessing the service without permission. Let me ask you a question, say your client was hitting my service with that user agent, 100 times a second, crawling through urls seq…

I very rarely use robots, and think I've only been "abusive" (not really abusive, in my book) once.

What if I send a null UA? Or use it as an opportunity to share my favorite quote?

What if the behavior of my software doesn't attack like a robot, does keep the request volume reasonable (use whatever you think is reasonable here) but also doesn't do what you might expect a human clicking around to do?

Re: LinkedIn: It’s illegal to scrape our website without permission

#300

Earlier quoted context omitted.

Sounds like an Intellectual Property violation to me. You don't have to hide your IP in order to protect it: there are laws that deal with this.

What IP is contained within LI?

I wasn't talking about LI, I was talking about the photo scenario from the comment I was replying to.
Post reply on HN