Live data from Hacker News

LinkedIn loses appeal over access to user profiles

reuters.com

131–140 of 168 posts

Re: LinkedIn loses appeal over access to user profiles

#132
post #129

Earlier quoted context omitted.

> His sentence was vacated after 13 months due to a technicality of the venue; that judge did not address the substantive question on the legality of the site access So the way the American legal system works is: if(venue == correct && facts == bad) { guilty(); } else { not_guilty(); } If the venue is not correct, the facts of the case are not evaluated. If you go read some lawsuits, you'll see that the first page or…

Generally, that is the way it works, but it is foolish to try and understand the legal system like it's software. If the venue is incorrect, the judge may more or less tell them to get lost. That's not the same as "not guilty". A lot of rules are adhered to to make sure that courts don't get gummed up with meaningless cases and to make sure that judges with the appropriate authority handle the appropriate cases.

You are right; I wanted to give a general idea. And if you've ever written software for Itanium, you'd know that relying on evaluation rules in an if statement is a dangerous thing to do!

Re: LinkedIn loses appeal over access to user profiles

#133

I’m a very active user of LinkedIn, effectively cultivating my “professional brand” on it. I’ve been contracting for years and use my network to find gigs. While I don’t have an issue with the business that HiQ are in (informing businesses of employee flight risk), I do believe there’s a qualitative difference between data that I publish for consumption by human eyeballs for free (a use of my data that I’ve authorise…

What HiQ did was scrape public data, so if you have your LI profile set to public, then anyone can access it and do what they will with it, just like if you posted a print out of it on a bulletin board in a mall. It's in the open and is free game for whtever. You can make your entire profile or just aspects of it private, meaning people need to login to LI to see your stuff, which then protects you under the TOS.

I think profiles were default public so you could be found on Google and for SEO purposes for both you and LI.

You'd be hard pressed to find a public profile accessible anymore on LI anyway, even with public settings, you'll hit an authwall 9 out of 10 times.

Re: LinkedIn loses appeal over access to user profiles

#134
> “And as to the publicly available profiles, the users quite evidently intend them to be accessed by others”

How is it evident that the users intend them to be accessed by scrapers and not just humans? Since the ToS forbid scraping, it seems very reasonable to me to imagine users making their profiles public because of that assumption that scraping is not tolerated.

Re: LinkedIn loses appeal over access to user profiles

#135

I’m a very active user of LinkedIn, effectively cultivating my “professional brand” on it. I’ve been contracting for years and use my network to find gigs. While I don’t have an issue with the business that HiQ are in (informing businesses of employee flight risk), I do believe there’s a qualitative difference between data that I publish for consumption by human eyeballs for free (a use of my data that I’ve authorise…

What HiQ did was scrape public data, so if you have your LI profile set to public, then anyone can access it and do what they will with it, just like if you posted a print out of it on a bulletin board in a mall. It's in the open and is free game for whtever. You can make your entire profile or just aspects of it private, meaning people need to login to LI to see your stuff, which then protects you under the TOS. I t…

I understand what HiQ have done. I'm saying I believe there's a material difference between public data for consumption by individual human beings, and systematic commercial harvesting. I appreciate that in the US, there may be no legal distinction between types of consumption of public data. Public data is public. However, I'm arguing that any commercial use or of my data beyond fair-use, should require my permission and an explanation of how my data will be stored and treated, so that I can be assured that my rights (over further unauthorised use) are preserved.

EDIT: It occurs to me that HiQ's success over LinkedIn does not necessarily imply they would be successful against actual LI users in a GDPR-like jurisdiction. Also, what if LI turned around and allowed each user to specify a style of CC license under which their specific data is published (by LI on behalf of the user). If I specified a non-commercial license variant, would that disallow HiQ's actions (without seeking permission)?

Re: LinkedIn loses appeal over access to user profiles

#136

Earlier quoted context omitted.

Eh. I want my picture and name uploaded to LinkedIn, since it's a professional network and people use it to find me for good reasons. It may seem dumb, however not having a LinkedIn with a good picture can genuinely hurt your career. I do NOT want my picture run through facial recognition software, or my name/email sold to marketers who will add it to a drip campaign.

Then don't make the data public. You can't have the cake and eat it too. Scraping is irrelevant here - a human can just as well take your picture from your LinkedIn page and include it in their face-recognition DB.

No they can't, not legally.

Re: LinkedIn loses appeal over access to user profiles

#137
post #87
post #70

Earlier quoted context omitted.

If I enter my employment record and my profile pic, birthdate, etc, I don't think that is the ip of linkedin. Maybe the way they display it or if they are transforming it in some way it could be considered ip. But if someone scrapes all that user entered data and then displays it somewhere else in a different format, I can't imagine LinkedIn being able to claim their ip has been infringed.

I think this all of this should be the user's choice since every company should put the user at the center of these decisions. If I want my data to be shared in any way I can simply tick a box and allow that. If I don't then keep it just for me and the people I chose to share it on that platform. It should also be made clear to the users if that data is being used as payment for the services provided by mentioning ex…

I think (hope?) that's what this decision did. LinkedIn must allow scraping publicly available data, but not private data that a third party wouldn't have access to normally.

Re: LinkedIn loses appeal over access to user profiles

#138
post #66

What cracks me up about this is how these massive companies go to such lengths to call themselves mere platforms in order to avoid liability for content, and then when someone actually takes the content in this case they cry, "Foul! That's ours !" Can't have it both ways.

Linkedin tried to argue that if they put data behind a login wall, then it no longer falls under the wide umbrella of "public data" and so it's "theirs". Previous cases already established that if a crawler can see the data without any session cookies then its okay. This ruling extended that to any data that can reasonably be accessed by any member of the public. There will probably be more cases like this as the upp…

> Previous cases already established that if a crawler can see the data without any session cookies then its okay.

I'm interested in this, but I'm not sure how to learn more - can you give me a hint?

Re: LinkedIn loses appeal over access to user profiles

#139

Earlier quoted context omitted.

Then don't make the data public. You can't have the cake and eat it too. Scraping is irrelevant here - a human can just as well take your picture from your LinkedIn page and include it in their face-recognition DB.

No they can't, not legally.

How's that? Obviously they can't keep the photo. But I don't see what would stop them from "viewing" the publicly available photo and saving markers that let them recognize the face again. After all, that's what any person does when they look at a photo.

Re: LinkedIn loses appeal over access to user profiles

#140
post #88

Earlier quoted context omitted.

Maybe it's more accurate to say "any publicly linked URL"? IIRC, charges have been successfully brought against people for e.g. iterating through user identifiers in URLs to gain access to other users' data. (Do correct me if I'm wrong on that count!)

Some kid was charged for that but in my opinion it was stupid. URL to me means part of the UX. If you search on Google using a query parameter directly instead of entering the query in their search box, should that count as wrongful use?

If I guess your password in the password form input, should that count as wrongful use?

If I rifle through your personal papers because your door was open, should that count as wrongful use?

Post reply on HN