US National WireUS NATIONAL WIRE
TechOpinion

The 'BrowserGate' Dismissal is a Blueprint for Corporate Surveillance

Portrait of Dana Kessler
Dana Kesslercybersecurity & privacySep 11AI
The 'BrowserGate' Dismissal is a Blueprint for Corporate Surveillance

AI-generated image · US National Wire

A federal judge just told LinkedIn that scanning your browser extensions isn't a privacy violation unless you can prove exactly what was stolen—effectively greenlighting the vacuuming of local environments.

OPINION: Let’s be clear about what just happened in the U.S. District Court for the Northern District of California, as reported by Ars Technica. By tossing the 'BrowserGate' lawsuits, the court has essentially signaled to every data-hungry corporation that they can probe your local environment with impunity, provided they don't trigger a specific, predefined alarm that the user can prove in court. This is a terrifying precedent for anyone who believes their browser should be a private gateway, not a corporate sensor array.

As first reported by Ars Technica, Judge Vince Chhabria granted a motion to dismiss two class-action lawsuits filed in April by California residents Nicholas Farrell and Jeff Ganan. The lawsuits targeted LinkedIn (a Microsoft subsidiary) for its practice of scanning users' browser extensions.

LinkedIn didn't even deny the practice. Instead, the company argued it uses detection systems to spot automated scraping and bot activity. Specifically, LinkedIn pointed to Teamfluence, an Estonian software company founded by CEO Steven Morell, which markets a Chrome plug-in to identify LinkedIn traffic. LinkedIn claims it caught Teamfluence scraping data, leading to a German tribunal ruling that the software violated LinkedIn's User Agreement and that suspending the associated accounts was justified.

But the real horror is in the legal reasoning. Judge Chhabria ruled that the plaintiffs lacked standing because they couldn't prove they were concretely harmed. Ars Technica reports that Ganan never alleged he even had extensions installed, and while Farrell claimed to have several, he didn't specify that any of them actually conveyed private information to LinkedIn.

When Ganan’s attorney, J.R. Howell, argued that the harm is the 'unpermitted probe' itself—regardless of what the probe found—the court rejected the premise. Chhabria wrote that a plaintiff must identify specific 'embarrassing, invasive, or otherwise private information collected' by the defendant.

From a defender's mindset, this is a disaster. It means the 'probe' isn't the violation; only the 'yield' is. LinkedIn is now free to scan for 'security and integrity' threats, claiming the information is 'publicly available,' while the burden of proof shifts entirely to the user to figure out exactly what was vacuumed up from their machine.

Howell, who also serves as counsel for Fairlinked (the advocacy group that issued the original 'BrowserGate' report), told Ars Technica that the ruling is not a vindication of LinkedIn's surveillance practices, as the court lacked jurisdiction rather than adjudicating the lawfulness of the scans. Howell is currently evaluating whether to appeal to the U.S. Court of Appeals for the Ninth Circuit or move the claims to California state court.

Sources

More from Dana Kessler