Live data from Hacker News

U.S. Supreme Court revives LinkedIn bid to shield personal data

reuters.com

31–40 of 85 posts

Re: U.S. Supreme Court revives LinkedIn bid to shield personal data

#31
post #27
post #16

This is a pretty bad headline. I don't know that i would characterize this as revived. The same 9th circuit who held last year that LinkedIn could not block hiQ from scraping public data, just got asked to reconsider the same case, except now there is additional precedent that SCOTUS says if you had permission to access the computer then it's not a violation of the CFAA (even if you are a shady corrupt cop). Hard to…

I disagree with that SCOTUS decision. It completely obliterated CFAA. Imagine if they said nurses/doctors could do that with their terminals and it didn't violate HIPAA. I will say there is a ridiculous amount of redtape around law enforcement using data. Loopholes with third party access is already something that exist. So if it's above board monitoring would be easier... But I'm not sure we have adequate monitoring…

> I disagree with that SCOTUS decision. It completely obliterated CFAA. Imagine if they said nurses/doctors could do that with their terminals and it didn't violate HIPAA.

The court was absolutely correct in their ruling. If you don't want cops using that data for their own purposes, it should be against the law.... it doesn't make sense to use the CFAA as a catch all for stopping people from misusing data they were given access to. If we do, it gives every private company the ability to make breaking their EULA a criminal offense. That is ridiculous.

HIPPA is a good example of how the law should work. You make what you want illegal; it has nothing to do with computers.

Why would the cop using a computer to access the information be against the law but not a cop going and reading a paper file?

Re: U.S. Supreme Court revives LinkedIn bid to shield personal data

#32
post #21
post #11

The headline is misleading. What is happening is that LinkedIn is using user data for its own benefit only and blocking innovation. As a LinkedIn user I want everyone to have access to the data I'm sharing publicly through the service. I can't wait for entrepreneurs to take on LinkedIn. There are a lot of opportunities there.

I'd rather entrepreneurs build on top of LinkedIn. There's so much untapped potential to build upon aggregated markets (of professionals, of jobs, of housing, of singles, of restaurants, etc) rather than building yet another aggregator. The existing aggregator cements its dominant position, can charge rent to connected apps, and attracts rather than repels killer apps. The main problem I see is fears that connected a…

What do you do when you build an entire business on top of LinkedIn, then they decide to completely revoke your access?

We need DE-centralization, so no-one in the world has this type of power over anyone.

Re: U.S. Supreme Court revives LinkedIn bid to shield personal data

#33
The Supreme Court curtailed the broad scope of the CFAA recently in the van Buren case. I personally agree with that decision (and also find it funny as it continues the long trend of Clarence Thomas being on the wrong side of history). While van Buren's actions were obviously problematic he was an authorized user of the computer system.

The issue is the vagueness of the CFAA has been a prosecutor's wet dream and a predictable source of overreach. Case in point: Aaron Swartz.

So here's what's interesting: by taking up this case SCOTUS is potentially going in the other direction. The Appeals Court held that the CFAA didn't apply, allowing hiQ to continue. And here's where (in my layman's view) SCOTUS may choose to act: The Appeals Court stopped LinkedIn taking action to impede hiQ's access.

I personally view this as overreach. There's a difference between not "hacking (in CFAA) terms a website and blocking the information provider impeding bots.

As much as Microsoft/LinkedIn is a nightmare of data misuse and dark patterns (eg to obtain contacts), I think it would be a bad decision to let the current hiQ ruling stand. Disallowing sites from taking action to block scrapers from systematically taking all that information and building a competitor seems like a bad idea.

But given the van Buren ruling, it seems unlikely SCOTUS will reverse course and declare hiQ's actions "hacking" (in CFAA terms). I suspect they'll curtail the remedy.

Re: U.S. Supreme Court revives LinkedIn bid to shield personal data

#35
post #32
post #21

Earlier quoted context omitted.

I'd rather entrepreneurs build on top of LinkedIn. There's so much untapped potential to build upon aggregated markets (of professionals, of jobs, of housing, of singles, of restaurants, etc) rather than building yet another aggregator. The existing aggregator cements its dominant position, can charge rent to connected apps, and attracts rather than repels killer apps. The main problem I see is fears that connected a…

What do you do when you build an entire business on top of LinkedIn, then they decide to completely revoke your access? We need DE-centralization, so no-one in the world has this type of power over anyone.

Totally agree. About 10 years ago I was the first hire of a startup built partially on top of LinkedIn. A Monday we got a cease and desist letter. We had to immeditely stop using their API and had to start crawling the data instead. That almost killed us.

Re: U.S. Supreme Court revives LinkedIn bid to shield personal data

#36
post #22
post #5

2 questions I asked myself after reading this: 1) Do I side with LinkedIn or HiQ? 2) What case law precedent do I think we ought to set? I’m personally conflicted on which way to lean. I see pros and cons to both - this is an interesting case.

I feel strongly that non-commercial scraping should be protected. I think commercial scraping should probably be allowed, but there should be some sort of mandatory maximum retention limit, so deleted (or updated access controls on) content eventually ages out (or gets transferred to a non-commercial custodian for archival purposes).

I don't see why linkedin should be allowed to monetize it if other companies aren't. If they just monetized the website via ads it would be fine, but since they sell your aggregated data to people I don't see why other data brokers shouldn't be able to also sell your publicly available data. Linkedin as a data broker and linkedin as a website are two unrelated businesses, and extending dominance in one to the other is cause for anti competitive action from the government, HiQ already won in lower courts which is why this has gone this far.

Re: U.S. Supreme Court revives LinkedIn bid to shield personal data

#37

It is because I am a strong advocate for privacy that I believe Microsoft is wrong. If Microsoft really wanted to protect user privacy they would restrict access to user data on their platform. This is basic entry level security: apply access control . Microsoft wants to split hairs in order to both maximize revenue and prevent competitor access, which is nothing to do with privacy. If Microsoft wins companies will b…

And let's not forget that Microsoft probably is using that data when it comes to their own hiring decisions and recruiting efforts.

They already sell the data to anyone who wants to pay, they have no moral high ground here at all, the only extra "protection" you'd get is that companies would have to pay Microsoft more money to abuse your data.

Re: U.S. Supreme Court revives LinkedIn bid to shield personal data

#38
I had a strange experience with LinkedIn today: I had to restart my computer, and when my browser started it re-opened all my tabs. This included about 50 LinkedIn tabs, which I opened sometime over the last 3 months (most of them were opened yesterday).

LinkedIn logged me out and accused me of unauthorized use or some such thing, and then locked me out for a period. When I submitted a help request and explained what had happened (browser reopened tabs), they gave a boilerplate answer that was totally non responsive.

I understand they want to defeat scrapers (whether I think they should or not), but outcomes like this are a pretty annoying way to do it. Can they really not tell when a browser is restarting and opening a bunch of tabs that the user has already viewed (and which are all 1st or 2nd degree contacts)?

edit: added context around when tabs were opened, in response to a comment.

Re: U.S. Supreme Court revives LinkedIn bid to shield personal data

#39

I had a strange experience with LinkedIn today: I had to restart my computer, and when my browser started it re-opened all my tabs. This included about 50 LinkedIn tabs, which I opened sometime over the last 3 months (most of them were opened yesterday). LinkedIn logged me out and accused me of unauthorized use or some such thing, and then locked me out for a period. When I submitted a help request and explained what…

Just curious, how many tabs do you normally have open?

Re: U.S. Supreme Court revives LinkedIn bid to shield personal data

#40

I had a strange experience with LinkedIn today: I had to restart my computer, and when my browser started it re-opened all my tabs. This included about 50 LinkedIn tabs, which I opened sometime over the last 3 months (most of them were opened yesterday). LinkedIn logged me out and accused me of unauthorized use or some such thing, and then locked me out for a period. When I submitted a help request and explained what…

It seems possible, but it also seems like a sorta painful problem to solve if locking an account requires dredging through 3+ months of a user's interactions.

At a lot of companies that kind of historical data ends up getting batched and stored in some kind of timeseries datastore (aka S3) and then batch-operated on via Spark, MapReduce, Flink etc in hourly or daily jobs. So instead of implementing account locking and scraping detection at the realtime layer looking at current requests, you have to write some ugly daily aggregate & backfill job, which inevitably ends up super expensive and slow.

Anyway, yes, but I can definitely sympathize with _not_ doing it this way.

Post reply on HN