Product1 publisher3 min readPublished
Chhabria dismisses the BrowserGate suits because neither plaintiff named an extension
A federal judge granted LinkedIn's motion to dismiss for lack of standing and gave the plaintiffs leave to amend, while writing in the same order that he doubts they can allege a privacy violation at all. LinkedIn never denied the scanning.
The Product Desk · Product desk

What happened
- A federal judge granted Microsoft subsidiary LinkedIn's motion to dismiss two lawsuits over its practice of scanning users' browser extensions.
- Judge Vince Chhabria of the US District Court for the Northern District of California found the plaintiffs lacked standing because neither asserted that installed extensions had conveyed private information to LinkedIn.
- The Tuesday ruling gave the plaintiffs leave to amend their complaints, and Chhabria said in the same order that he doubts they can make a plausible case.
- California residents Nicholas Farrell and Jeff Ganan had each filed class actions in April, seeking to represent themselves and other LinkedIn users.
- Ganan's attorney, J.R. Howell, said he is evaluating whether to bring the claims in California state court, which has different standing requirements, or to appeal to the Ninth Circuit.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- capability A site that enumerates which extensions are present, and says so in its policy in add-ons language, now has a federal dismissal to hand its lawyers. That dismissal stops short of a site that ingests what those extensions carry.
- exposure Getting back into federal court requires pleading standing: putting the extension he installed, and what it passed along, into a public filing.
- contradiction Chhabria's aside about voluntary downloads reads as a preview of the merits, while Howell says the court settled only jurisdiction. A privacy reviewer relying on one of those readings reaches a different answer than one relying on the other.
An extension that rewrites your LinkedIn feed has to put a script into the page to do the rewriting. The page can then ask what is sitting there. LinkedIn did not deny that it scans browsers to identify extensions [9]. A commenter in Ars Technica's thread on the ruling gave the developer's version of the defense: "if you inject scripts in to my web page, my page should be allowed to see what those script are" [13].
Chhabria went past the jurisdictional question in one sentence. "Given LinkedIn's further arguments that users voluntarily download browser extensions, which by their nature intentionally expose data to websites, it seems unlikely that the plaintiffs will ever be able to allege a privacy violation, much less prevail at the end of the day," Chhabria wrote [4]. That sentence sits in an order that also grants leave to amend [3].
Ganan's attorney, J.R. Howell, reads the order narrowly. "The federal court determined that it lacked jurisdiction to hear the LinkedIn users' claims," Howell told Ars [7]. "The court did not adjudicate whether LinkedIn's surveillance practices were lawful. The ruling is not a vindication of the mass surveillance program alleged in our complaint," he said [8].
One pleading gap disposed of both cases [14]. The amendment Chhabria left open has a price for whoever files it: clearing the standing bar means naming, in a public filing, the extension you installed and the private information it conveyed to LinkedIn [2].
For a team shipping extension detection, the order separates two behaviors that usually arrive on the same ticket. Detecting that an extension is present is one. Receiving what the extension holds is the other. Two tests decide where a given script sits: whether a user could name an extension of theirs whose contents reached your servers, and whether your policy names add-ons in words a user could match to what your JavaScript does. LinkedIn's privacy policy already disclosed that it uses cookies and similar technologies to collect information about each user's "web browser and add-ons" [9].
The report that started the suits came from a party with its own quarrel with LinkedIn. The plaintiffs filed after a report alleged that "LinkedIn Is illegally searching your computer" [10]. That report came from Fairlinked, a German entity that describes itself as a trade association and advocacy group for commercial LinkedIn users and appeared to be run by the same people behind Teamfluence, the Estonian software company that sued LinkedIn in Munich after its CEO was banned [11]. According to a passage quoted in Ars Technica's discussion thread on the ruling, a German tribunal determined that "[t]he 'Teamfluence' software violates [LinkedIn's User Agreement]," and that LinkedIn's "suspending the Claimants' user accounts is objectively justified overall and not arbitrary" [12].
What to watch
- An amended complaint that names a specific installed extension and the private data it conveyed to LinkedIn.
- Whether other sites rewrite privacy policies to name extensions explicitly instead of relying on an add-ons clause.
- Any German ruling that reaches LinkedIn's extension scanning itself rather than Teamfluence's software.