Setting the Record Straight on False Accusations
blog.linkedin.com
blog.linkedin.com
From the inside of a business, it might seem like a proper business behavior to have the Senior Director, Litigation at LinkedIn publicly address a class-action lawsuit, but the source doesn't do much to assuage LinkedIn-users' concerns, and the source's defensive role in the situation could be interpreted as an indication impropriety.
A response from the CEO, CTO or someone in charge of user experience or user relations would have been much better if LinkedIn wanted to "(set) the record straight" w/ their users.
This case sorta-kinda reminds me of the class action where people are saying that when you mail someone at Gmail, Google "intercepts" the message. There's always going to be class actions like that one. Whatever a lawyer can dream up, he can litigate as a civil action.
if I give you permission that I did not realise
or understand, it's not really permission.
if I give you permission to do something, and the
way you do it is so out of whack with my expectations
it's not really permission.
The lawsuit is about one or both of these happening. neither has any realistic legal hope without legislation, but that's not the point. LinkedIn, one of the great professional business hopes for a real revolution in how we find and work with others, is a spammy marketeer. And worse, they don't realise it.nb - you don't have to be a spammy marketeer all the time for it to be an accurate description. just as you don't have to beat your wife every night to be accurately described as a wife beater. you might think you are being a good husband tonight - she is just waiting for the next round
a long winded way to say you have lost my trust LinkedIn. One day a viable alternative will appear and you will discover the meaning of freefall. in the meantime have my monthly subscription darn it
> if I give you permission that I did not realise or understand, it's not really permission.
Yes, that's true, but it's also true in a legal sense. At least in the U.S., if you enter into a contract that includes conditions that no reasonable person would agree to, those are called "unconscionable" conditions, they have no force, and therefore the contract has no force.
http://www.legalmatch.com/law-library/article/what-is-an-unc...
Quote: "What is an Unconscionable Contract? An unconscionable contract is one that is so one-sided that it is unfair to one party and therefore unenforceable under law. It is a type of contract that leaves one party with no real, meaningful choice, usually due to major differences in bargaining power between the parties."
Yes, one sees that. Unfortunately, a contract that includes such statements, designed to avoid the consequences of unconscionable terms, are themselves unconscionable.
My point is that you can't put language into a contract that contradicts contract law, and the idea of invalidating a contract based on unconscionable terms, terms no rational person would agree to, is part of contract law.
Just speaking from experience, and IANAL.
I'm going to dive into LinkedIn OAuth this week, so I might get a better insight soon.
So they now can speak the half-truth that those malcontents who are suing them didn't find the opt-out option, therefore it was all right to exploit their contact lists.
One more thing. Given that a lawsuit is pending, it's extremely unwise to reveal one's defense in advance of the proceedings -- that can only help the other side. When a lawyer tells you to say nothing publicly about an upcoming legal action, you really should listen to him. This tells me that LinkedIn either doesn't have competent counsel, or they're in the habit of ignoring wise advice.
A best case scenario for us will greatly limit the way and extent companies access our data.
That makes sense. But they have to weigh the pros of arguing the case in public, versus the cost of exposing their reasoning, such as it is.
Also, by saying they had the right to mine people's address books, but without explaining how they think they acquired the right, they risk a pretty big public backlash.
He never said that they do not show you a form that tricks you into thinking that you are logging into LinkedIn but in reality you are handing over your email password.
Why should they be logging into anyone's email account, at all, ever?
This might as well be an admission of guilt.
The issue is that they are trying to get as many people to agree as possible, so they are being sneaky about it. People don't know what they're going to do, even though they clicked on a box. Legally correct, yet scummy.
I'm just trying to argue that why should a company even be trying to get access to your email account? They shouldn't be trying to defend the practice.
What does this mean for all of the email providers out there who in their own TOS say that they're providing a service and that you can't give any other party permission to access your account? Can LinkedIn be absolved of blame fot accessing something you were never allowed to give them access to to begin with?
I'm not a fan of social networks— but Likedin seems like an actually reasonable idea... However, I've never made an account there because before I ever got to it the floods of invites (many clearly not intended) provided ample evidence to me that this wasn't something that I wanted anything to do with.
What it's actually doing is prompting you to give them your email password so that they can login and scrape contacts. I know this because I've nearly fallen for it myself in the last couple of months. Thankfully I have some internet savvy. The folks who are suing probably saw "please enter a password" and entered one and just happened to use the same password for LinkedIn as their email; LinkedIn thus "hacked" their emails.
I think LinkedIn should have to face some heat for this for deceiving people, though I don't believe what they're doing is technically hacking.
Social engineering is often considered hacking.
I guess when I said "not technically hacking" what I meant was that I don't believe they're doing XSS or brute-force or SQL injection or something along those lines.
LinkedIn does seem to be guilty of violating the same statute most "hackers" are prosecuted under, making it a felony to access a computer without authorization.
Really, what they're doing is textbook password phishing.
In reality I have no idea where this opt-in occurs, nor how to opt-out; I'm (somewhat)surprised it isn't easily accessible.
I literally don't know what "pretending to be you" means.
(That and clicking on ads on Google and other SE, they make it extremely hard to distinguish between ads and content. If we had an FTC that stuff would end after threats of lawsuits and billion dollar fines.)