Skip to content
Tech News
← Back to articles

LinkedIn beats "BrowserGate" lawsuits over scanning users' Chrome extensions

read original get Yubico YubiKey 5 NFC Security Key → more articles
Why This Matters

A federal judge tossed two class actions accusing LinkedIn of improperly scanning users' Chrome extensions, finding the plaintiffs never alleged that any installed extension actually leaked private data to LinkedIn — so they lacked standing. The dismissal is procedural rather than a ruling on legality, but the judge's skepticism signals that browser-extension detection, a common anti-scraping and fingerprinting technique, will be hard to attack in court. Plaintiffs may refile in California state court, where standing rules are looser.

Key Takeaways
Worth a Look

Yubico YubiKey 5 NFC Security Key — Browser-privacy headlines like this one are a good nudge to lock down the accounts you actually care about. The YubiKey 5 NFC plugs into USB-A or taps your phone over NFC to add hardware two-factor authentication to LinkedIn, Google, Microsoft and more, so a password leak alone can't get anyone in. It's a small, keychain-friendly way to take account security into your own hands.

See Yubico YubiKey 5 NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

LinkedIn beat two lawsuits over its practice of scanning users’ browser extensions, with a judge granting the Microsoft subsidiary’s motion to dismiss the cases. The users who sued LinkedIn failed to adequately allege that they have standing to sue because neither asserted that they “had browser extensions installed that conveyed private information to LinkedIn,” ruled Judge Vince Chhabria in US District Court for the Northern District of California.

In his ruling on Tuesday, Chhabria gave the plaintiffs leave to amend their complaints but said he doubts they can make a plausible case. “Given LinkedIn’s further arguments that users voluntarily download browser extensions, which by their nature intentionally expose data to websites, it seems unlikely that the plaintiffs will ever be able to allege a privacy violation, much less prevail at the end of the day,” Chhabria wrote.

California residents Nicholas Farrell and Jeff Ganan separately filed class actions against LinkedIn in April, seeking to represent themselves and other LinkedIn users. Ganan’s attorney, J.R. Howell, said he is evaluating whether to bring the claims in a California state court, which has different requirements on standing, or to appeal the US district court ruling in the US Court of Appeals for the Ninth Circuit.

“The federal court determined that it lacked jurisdiction to hear the LinkedIn users’ claims,” Howell told Ars today. “The court did not adjudicate whether LinkedIn’s surveillance practices were lawful. The ruling is not a vindication of the mass surveillance program alleged in our complaint.”

“BrowserGate” stems from dispute over scraping

As we wrote in April, the plaintiffs filed their lawsuits after a report alleged that “LinkedIn Is illegally searching your computer.” LinkedIn did not deny that it scans browsers to identify extensions and already disclosed in its privacy policy that it uses cookies and similar technologies to collect information about each user’s “web browser and add-ons.”

The so-called “BrowserGate” report was issued by a German entity called Fairlinked, which describes itself as a trade association and advocacy group for commercial LinkedIn users. It appeared to be run by the same people behind Teamfluence, an Estonian software company that sued LinkedIn in Munich after its CEO was banned by LinkedIn.