Live data from Hacker News

9th Circuit holds that scraping a public website does not violate the CFAA [pdf]

cdn.ca9.uscourts.gov

101–110 of 293 posts

Re: 9th Circuit holds that scraping a public website does not violate the CFAA [pdf]

#101

Considering the kind of private scraping and selling tactics LinkedIn has been chronically guilty of (and not just the ordinary "growth hack" stuff: "LinkedIn violated data protection by using 18M email addresses of non-members to buy targeted ads on Facebook" [1]), it's satisfying to see LinkedIn lose this. [1] https://techcrunch.com/2018/11/24/linkedin-ireland-data-prot...

I feel like this is a really common theme I've seen several times. Something like "Music Lyric site X sues Google for embedding their lyrics in the results directly" which is funny because site X got the lyrics by scraping them from other sites. Plus Google only exists from scraping content, but I believe their TOS includes "don't scrape our content". I find it really funny that the scrapers are battling scrapers - l…

Well, setting up so-called Barriers to Entry[0] is econ 101.

[0] https://en.wikipedia.org/wiki/Barriers_to_entry

Re: 9th Circuit holds that scraping a public website does not violate the CFAA [pdf]

#102
post #22

This action does more than that. The court left the preliminary injunction against LinkedIn in place: "The district court granted hiQ’s motion. It ordered LinkedIn to withdraw its cease-and-desist letter, to remove any existing technical barriers to hiQ’s access to public profiles, and to refrain from putting in place any legal or technical measures with the effect of blocking hiQ’s access to public profiles." So Lin…

[deleted]

Re: 9th Circuit holds that scraping a public website does not violate the CFAA [pdf]

#103

Earlier quoted context omitted.

This analogy is faulty and congress really needs to clarify what they meant the CFAA to protect against. Opening a website is making a request, technically speaking. That is not equivalent to breaking into someone's home and taking information. The equivalent would be if the head of the household told you not to stand outside and ask someone inside to give you something from the house. You haven't trespassed, you're…

A website isn't a person and the law doesn't expect them to act as such. It's a tool. Making a 'request' to a web server is more like turning the knob on a door: maybe the owner installed a lock, or maybe it just opens without there being a lock. But even if there isn't a lock, the law doesn't absolve you of trespassing against the door's owner just because the door itself didn't have the sentience to refuse your req…

But it's a door handle that is MEANT to be turned by the public at large. It's like putting a big "Order Inside" sign above the door to a restaurant and being surprised when people try to gain entry.

You also never entered the server. The server got your request and served something back you to. You did not go inside the house and read the contents of a book on the shelf, it was read aloud to you while you are still outside the house.

I'm not saying that websites shouldn't have recourse against people taking all the contents of their sites, just that the CFAA is the wrong tool.

Re: 9th Circuit holds that scraping a public website does not violate the CFAA [pdf]

#104

Earlier quoted context omitted.

I feel like this is a really common theme I've seen several times. Something like "Music Lyric site X sues Google for embedding their lyrics in the results directly" which is funny because site X got the lyrics by scraping them from other sites. Plus Google only exists from scraping content, but I believe their TOS includes "don't scrape our content". I find it really funny that the scrapers are battling scrapers - l…

Well, setting up so-called Barriers to Entry[0] is econ 101. [0] https://en.wikipedia.org/wiki/Barriers_to_entry

Creating barriers to entry is an antisocial tactic that harms consumers and society at large.

It is the responsibility of moral consumers to avoid spending their money with companies that use these regressive tactics.

Re: 9th Circuit holds that scraping a public website does not violate the CFAA [pdf]

#105
post #35

Earlier quoted context omitted.

Nobody leaked any data here. These were public profiles that were "controlled" by a robots.txt file. The judge appears to question whether robots.txt is sufficient to prevent scraping, or if a proper authorization step would be required. The best real-world analogy I can come up with... I post a No Trespassing sign on my garden, but don't fence/gate the property. Is it ok to access the property and take my tomatoes?…

It's more like a store putting up a no shoes no shirt no service sign and then trying to sue for trespass when a beachgoer comes in to shop anyway. LinkedIn is a business with publicly accessible assets they want to be frequented, but they want to control how you do that. However they are finding the laws regulating the rights people have in respect to frequenting places open to the public apply.

jep. it's more like having a public store and only letting some people into it. like only males, no womans. because they clearly allowed the google bot.

Re: 9th Circuit holds that scraping a public website does not violate the CFAA [pdf]

#107
post #86

Earlier quoted context omitted.

Until the ADA comes along and demands you create an accessible to the blind site. I've often wondered when the laws would start to be applied and I think its coming

I have a website that's a full page map. I care about accessibility - is there any way I can make this meaningfully accessible to the blind?

I suspect you're being glib, but you could look at https://wiki.openstreetmap.org/wiki/OSM_for_the_blind

Re: 9th Circuit holds that scraping a public website does not violate the CFAA [pdf]

#108

Earlier quoted context omitted.

A website isn't a person and the law doesn't expect them to act as such. It's a tool. Making a 'request' to a web server is more like turning the knob on a door: maybe the owner installed a lock, or maybe it just opens without there being a lock. But even if there isn't a lock, the law doesn't absolve you of trespassing against the door's owner just because the door itself didn't have the sentience to refuse your req…

But it's a door handle that is MEANT to be turned by the public at large. It's like putting a big "Order Inside" sign above the door to a restaurant and being surprised when people try to gain entry. You also never entered the server. The server got your request and served something back you to. You did not go inside the house and read the contents of a book on the shelf, it was read aloud to you while you are still…

>But it's a door handle that is MEANT to be turned by the public at large.

No it isn't. That's the crux of the case.

>It's like putting a big "Order Inside" sign above the door to a restaurant and being surprised when people try to gain entry.

It's like putting a big "order inside" sign above the door to a restaurant, and then also having a separate door in the back of the restaurant that clearly is used only by employees to go to the back office, and not being happy when non-employees keep trying to walk into the back office claiming "well there's a sign outside...".

>You also never entered the server. The server got your request and served something back you to. You did not go inside the house and read the contents of a book on the shelf, it was read aloud to you while you are still outside the house.

According to the courts, you did 'go inside the house' because the electronic signals that you sent to the server as part of the request are enough to constitute the 'physical contact' part of trespassing.

Again, trespassing isn't just about you physically having your body on someone else's property. It also can be your interaction with someone else's property (which can be land, or a door, or web servers) through the use of tools or intermediaries.

Re: 9th Circuit holds that scraping a public website does not violate the CFAA [pdf]

#109

Earlier quoted context omitted.

You misunderstand basic law terminology. A preliminary injunction is considered very strong. So it's not that "nothing is final here", it's actually almost pretty much final unless something comes out of left field.

The injunction was to stop LinkedIn from blocking access while the case is ongoing, not to stop them from arguing that hiQ violated the CFAA. The trial court could hear the arguments and say "hiQ is wrong, they did violate the CFAA". Maybe that's not likely, but it also is not yet decided. So what exactly did I misunderstand and why do you think this is final?

I think you missed that this injunction is the case?

You are saying "the injunction was to stop LinkedIn from blocking access while [the injunction request] is ongoing".

If the court didn't think hiq had a strong case they would not have granted the initial injunction, then reaffirmed it on this appeal.

Re: 9th Circuit holds that scraping a public website does not violate the CFAA [pdf]

#110
In short, even if some users retain some privacy interests in their information notwithstanding their decision to make their profiles public, we cannot, on the record before us, conclude that those interests—or more specifically, LinkedIn’s interest in preventing hiQ from scraping those profiles—are significant enough to outweigh hiQ’s interest in continuing its business, which depends on accessing, analyzing, and communicating information derived from public LinkedIn profiles.

Reasonable. If a platform helps you make information of an individual public, then why it should matter for the platform how the market uses that public information?

Post reply on HN