/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Federal appeals court rejects LinkedIn's effort to stop hiQ Labs from scraping public profile data, reaffirming a ruling from August 2017

Jonathan Stempel / Reuters :

Reuters Jonathan Stempel

Context & Ripple Effects

This ruling extends a fight that began in 2016, when LinkedIn invoked the Computer Fraud and Abuse Act against anonymous scrapers and then sent hiQ Labs a cease-and-desist letter — a move a judge answered in 2017 by ordering LinkedIn to remove the technical blocks it had erected against the analytics startup.

By reaffirming that order, the appeals court keeps alive the legal distinction at the heart of the case: scraping publicly visible profiles is not 'unauthorized access' under CFAA-style reasoning, even when a platform says no. The stakes run well past one startup — the same court recently ruled Facebook must face an Illinois biometric privacy class action, so platforms are losing on both the access question and the data-use question.

First-order effects

  • hiQ Labs can resume building its talent-analytics products on scraped public LinkedIn profiles without injunction risk, while LinkedIn must either remove or leave dormant its blocking technology for now.

Second-order effects

  • Other platforms watching this case lose their cheapest enforcement tool — technical walls backed by CFAA threats — pushing them toward contract-based terms of service, rate-limiting, or licensing deals as the way to control who uses their data.
  • Rival professional-data vendors gain cover to build on public profile data, eroding LinkedIn's de facto monopoly over its own members' information and pressuring its data-licensing economics.

Third-order effects

  • If the pattern holds through the appellate process — including any revisit after Supreme Court-level review — the industry norm shifts from 'platforms own their public pages by default' to a negotiated permission boundary for publicly accessible data, with courts rather than terms of service drawing the line.

The trend: Platform control over publicly accessible data is being redefined by courts from absolute ownership toward a narrower permission boundary, forcing social networks to compete on contracts and product rather than legal lockout.

Discussion

  • @orinkerr Orin Kerr on x
    From later in the opinion. pic.twitter.com/4DHwIoXzZT
  • @jonathanmayer Jonathan Mayer on x
    The panel was rightly sensitive to the competition backdrop. From the opinion: “[G]iving companies like LinkedIn free rein to decide, on any basis, who can collect and use data . . . risks the possible creation of information monopolies that would disserve the public interest.”
  • @ericgeller Eric Geller on x
    Ninth Circuit: CFAA does not prevent mass scraping of public data. Huge limit on a cybercrime law that many civil-liberties advocates say has been repeatedly abused. http://cdn.ca9.uscourts.gov/ ... https://twitter.com/...
  • @conspirator0 Conspirador Norteo on x
    A variety of entities from LinkedIn to fake Twitter accounts that can't remember how many children they have seem to believe that analysis of public Internet posts is an invasion of privacy. Looks like the courts ain't havin' none of it. cc: @ZellaQuxiote https://arstechnica.com/…
  • @deliprao Delip Rao on x
    Aaron Swartz 😕 https://twitter.com/...
  • @jonathanmayer Jonathan Mayer on x
    Today's 9th Circuit decision in hiQ v. LinkedIn is huge for CFAA reform. It's also huge for tech competition. The panel recognized that firms might establish *affirmative rights* to scrape and repurpose public data from competitors and platforms. http://cdn.ca9.uscourts.gov/ ...
  • @acmccosker Anthony McCosker on x
    How significant is this for digital methods research? “Web scraping doesn't violate anti-hacking law, appeals court rules” https://arstechnica.com/...
  • @orinkerr Orin Kerr on x
    Ninth Circuit: “We . . . look to whether the conduct at issue is analogous to ‘breaking and entering,’” and when “access is open to the general public and permission is not required,” then the B&E analogy “has no application, and the concept of ‘without authorization’ is inapt.”
  • @synopsi Rasty Turek on x
    I remember when one of the top VCs laughed me out of the room when I told them that Linkedin is going to lose the case. I will forever remember his words: Reid [Hoffman] will wipe the floor with them. Here we go. 3-0 decision. https://www.reuters.com/...
  • @alexstamos Alex Stamos on x
    For context: cease and desist letters followed by civil action or criminal CFAA referrals are one of the few legal tools available to large providers looking to stop spammers or scrapers. It looks like these ToS violations are no longer enforceable with CFAA.
  • @alexstamos Alex Stamos on x
    This is the right decision and I wish this had been the national standard when the Massachusetts US Attorney was hounding Aaron Swartz. It does, however, raise interesting policy questions when considered in context of current privacy debates. https://twitter.com/...
  • @alexstamos Alex Stamos on x
    Is it a privacy violation when data that was posted for individual public use is aggregated without permission? Do we want big companies to be able to stop this behavior? The technical options to limit scraping aren't great, so do we need a legal regime that stops scraping?
  • @alexstamos Alex Stamos on x
    If so, then we probably don't want that enforcement to only be in the hands of private actors, but barring a US GDPR there is no US entity to enforce. CFAA shouldn't be used to solve this problem, but that doesn't mean that there isn't a real privacy problem to be solved.
  • @alexstamos Alex Stamos on x
    Many recent privacy scandals have revolved around public data being collected by 3rd parties (and then often left lying around in S3 or insecure databases). Phone numbers, for example, are low-entropy and easily guessed. Any app that allows phone search will be scrapable.