7 min read

The strange story of EiM’s LinkedIn block

When this very website was flagged as unsafe, getting it fixed meant following a two-week trail from a LinkedIn support worker to an intelligence company based in Vietnam. Here’s what happened and why it makes me worried about AI moderation

I'm Ben Whitelaw, the founder and editor of Everything in Moderation*. I'm standing in for Alice in this week's Trust & Safety Insider while she's on a well-earned holiday.

I've been meaning to write about today's topic for more than two years. It's a slightly strange and, at times, technical account of a takedown incident that bears little significance in the grand scheme of things.

However, many T&S won't have experienced being on the receiving end of the systems that they build, buy or help enforce. And I learnt a lot about the potential pitfalls of automated moderation systems, users' limited redress mechanisms and often obscured supply chain of safety decisions.

Drop me a line if if you've experienced something similar or if this raises questions inside your own team. In honour of my T&S Insider co-writer, here we go! — Ben


The moderation newsletter gets moderated

Why this matters: In February 2024, Everything in Moderation’s LinkedIn page was blocked from posting links for reasons that weren’t immediately clear. I’ve talked about it on the Ctrl-Alt-Speech podcast, but this is the full account of what happened, how I got it fixed and why it left me worried about the growing role of automated moderation.

What happened

It was a typical week. I had just sent a new edition of Week in Review and, as I often do, I went to LinkedIn to post about it to whoever the algorithm would deign to show it to. Except this time, no dice. LinkedIn showed a “cannot display preview” warning and said I should try another link.

LinkedIn error message showing "cannot display preview" when posting Everything in Moderation article
The error message I was confronted with on LinkedIn

Odd. I hadn't changed anything on the site and didn’t see why that would be the case. I had posted dozens of (let’s be honest) anodyne updates about my niche newsletter many times before without issue. 

One possible explanation was that EiM had written about child sexual abuse material or the content policies of, say, OnlyFans or Pornhub. Perhaps that was enough to trigger an automated system or lead a disgruntled subscriber to report me to an email service provider? But the edition in question led on the US Supreme Court and previous editions were about the Digital Services Act, the Oversight Board and Taylor Swift. Hardly controversial.

So, I reached out to LinkedIn via its case management page to ask what was happening.

‘Contact our browsing partner’

three screengrabs showing with LinkedIn agent regarding the malware issue
Back and forth with LinkedIn agent regarding the malware issue

Credit to LinkedIn, a support agent came back to me within a few hours and tried to replicate the issue. After a bit of back and forth in which I tried different browsers, cleared my cache, and disabled various extensions, it was escalated to LinkedIn’s internal research team. Then, a breakthrough.

One of its partners, VirusTotal, had apparently blacklisted the everythinginmoderation.co domain for reasons that were not apparent. VirusTotal is an intelligence service headquartered in Spain that provides signals to companies about whether a domain, file or IP address could be malware. It was bought by Google in 2012 and is now part of Google Security Operations, a subsidiary of the search giant.

To clarify: it wasn’t LinkedIn that said my domain was dangerous, but a third-party company that I had never heard of and that wasn’t even a content moderation vendor in the way most EiM subscribers would understand. But that was where I went next.

On 7 March, I contacted VirusTotal, which explained that it “only aggregates data from a variety of vendors” and produces “no verdicts of our own”. I was asked to rescan the EiM domain and then reach out to a list of vendors if I believed there was a false positive.

VirusTotal's rescan system

Either I was too enraged about the situation to follow instructions, or the rescan didn't yield anything because I reached out again, wondering what the problem was. The message came back: speak to a company called CyRadar. At which point, the story became more interesting.

Get access to the rest of this edition of EiM and 200+ others by becoming a paying member