By reaffirming that order, the appeals court keeps alive the legal distinction at the heart of the case: scraping publicly visible profiles is not 'unauthorized access' under CFAA-style reasoning, even when a platform says no. The stakes run well past one startup — the same court recently ruled Facebook must face an Illinois biometric privacy class action, so platforms are losing on both the access question and the data-use question.
First-order effects
hiQ Labs can resume building its talent-analytics products on scraped public LinkedIn profiles without injunction risk, while LinkedIn must either remove or leave dormant its blocking technology for now.
Second-order effects
Other platforms watching this case lose their cheapest enforcement tool — technical walls backed by CFAA threats — pushing them toward contract-based terms of service, rate-limiting, or licensing deals as the way to control who uses their data.
Rival professional-data vendors gain cover to build on public profile data, eroding LinkedIn's de facto monopoly over its own members' information and pressuring its data-licensing economics.
Third-order effects
If the pattern holds through the appellate process — including any revisit after Supreme Court-level review — the industry norm shifts from 'platforms own their public pages by default' to a negotiated permission boundary for publicly accessible data, with courts rather than terms of service drawing the line.
The trend: Platform control over publicly accessible data is being redefined by courts from absolute ownership toward a narrower permission boundary, forcing social networks to compete on contracts and product rather than legal lockout.
The panel was rightly sensitive to the competition backdrop. From the opinion: “[G]iving companies like LinkedIn free rein to decide, on any basis, who can collect and use data . . . risks the possible creation of information monopolies that would disserve the public interest.”
Ninth Circuit: CFAA does not prevent mass scraping of public data. Huge limit on a cybercrime law that many civil-liberties advocates say has been repeatedly abused. http://cdn.ca9.uscourts.gov/ ... https://twitter.com/...
A variety of entities from LinkedIn to fake Twitter accounts that can't remember how many children they have seem to believe that analysis of public Internet posts is an invasion of privacy. Looks like the courts ain't havin' none of it. cc: @ZellaQuxiote https://arstechnica.com/…
Today's 9th Circuit decision in hiQ v. LinkedIn is huge for CFAA reform. It's also huge for tech competition. The panel recognized that firms might establish *affirmative rights* to scrape and repurpose public data from competitors and platforms. http://cdn.ca9.uscourts.gov/ ...
Ninth Circuit: “We . . . look to whether the conduct at issue is analogous to ‘breaking and entering,’” and when “access is open to the general public and permission is not required,” then the B&E analogy “has no application, and the concept of ‘without authorization’ is inapt.”
I remember when one of the top VCs laughed me out of the room when I told them that Linkedin is going to lose the case. I will forever remember his words: Reid [Hoffman] will wipe the floor with them. Here we go. 3-0 decision. https://www.reuters.com/...
For context: cease and desist letters followed by civil action or criminal CFAA referrals are one of the few legal tools available to large providers looking to stop spammers or scrapers. It looks like these ToS violations are no longer enforceable with CFAA.
This is the right decision and I wish this had been the national standard when the Massachusetts US Attorney was hounding Aaron Swartz. It does, however, raise interesting policy questions when considered in context of current privacy debates. https://twitter.com/...
Is it a privacy violation when data that was posted for individual public use is aggregated without permission? Do we want big companies to be able to stop this behavior? The technical options to limit scraping aren't great, so do we need a legal regime that stops scraping?
If so, then we probably don't want that enforcement to only be in the hands of private actors, but barring a US GDPR there is no US entity to enforce. CFAA shouldn't be used to solve this problem, but that doesn't mean that there isn't a real privacy problem to be solved.
Many recent privacy scandals have revolved around public data being collected by 3rd parties (and then often left lying around in S3 or insecure databases). Phone numbers, for example, are low-entropy and easily guessed. Any app that allows phone search will be scrapable.