Live data from Hacker News

How LinkedIn detects browser extensions

github.com

21–30 of 113 posts

Re: How LinkedIn detects browser extensions

#21

Earlier quoted context omitted.

Can you link to where they say that? I would figure someone doing something so helpful for users would at least document it. There's no reason to be surreptitious when doing such a favor. One wonders if they'll start offering a LinkedIn AntiVirus download with such an altruistic approach towards protecting users from what they have installed.

I think you're misunderstanding. LinkedIn isn't protecting the people with the extensions installed; they're protecting users FROM the people with the extensions.

Ah, as an anti-scraper/anti-bot method, every user has all these local network requests made? Maybe it's the true reason, maybe not. Transparency is key here to assume anything more than the worst. Of course any of the rest of us with a modicum of smarts would just side load a custom extension via CLI args (or we'd just browser automate, headless if not detected). Even given the most generous justification, it reeks of careless decision makers playing whack-a-mole (likely fruitlessly) with the users in the crossfire.

Re: How LinkedIn detects browser extensions

#22

The repo says "A look at how LinkedIn spies on its users" I'm not convinced this is LinkedIn spying on users... rather, it's them protecting its users from the spammy people using these extensions. There's not a single extensions on that list that doesn't result in someone getting an unsolicited email.

Here's the full list; they're all spammy recruiting/sales extensions (nothing legit like uBlock or LastPass): daxtra SalesloftProspector SalesLoftCadence discoverly Ecquire Ebstabullhorn EbstaSalesforce ProspectHive talentbin Entelo Nimble amazinghiring colabo extension StepWells(colabo) found.ly datananas Linkedin-Hubspot Connector dux-soup(fixed) data Scraper aevy Lusha Lead Generator Candidate.ai Email Hunter Pros…

iMacros is a legit extension. But yeah, I guess there are recruiters using it to spam people.

Re: How LinkedIn detects browser extensions

#23

Earlier quoted context omitted.

I think you're misunderstanding. LinkedIn isn't protecting the people with the extensions installed; they're protecting users FROM the people with the extensions.

Ah, as an anti-scraper/anti-bot method, every user has all these local network requests made? Maybe it's the true reason, maybe not. Transparency is key here to assume anything more than the worst. Of course any of the rest of us with a modicum of smarts would just side load a custom extension via CLI args (or we'd just browser automate, headless if not detected). Even given the most generous justification, it reeks…

I think it's a cat and mouse game. The more that Linkedin publishes about their anti-spam techniques, the more information spammers have to try to evade those anti-spam techniques.

Re: How LinkedIn detects browser extensions

#24
post #23

Earlier quoted context omitted.

Ah, as an anti-scraper/anti-bot method, every user has all these local network requests made? Maybe it's the true reason, maybe not. Transparency is key here to assume anything more than the worst. Of course any of the rest of us with a modicum of smarts would just side load a custom extension via CLI args (or we'd just browser automate, headless if not detected). Even given the most generous justification, it reeks…

I think it's a cat and mouse game. The more that Linkedin publishes about their anti-spam techniques, the more information spammers have to try to evade those anti-spam techniques.

It can seem that way with server-side anti-scraping techniques with brute force detection and the like. But at some point you have to accept that playing the game on the client-side needs to stop escalating once you're making dozens of local extension resource requests in a user's browser. It makes me want to publish and maintain a legit scraper for LinkedIn that replicates human interaction. They'd DMCA the repo I'm sure, but it goes to show who fights against the open web. I see a "get X, Y, and Z features for free when you use LinkedIn Desktop instead of the website" coming.

Re: How LinkedIn detects browser extensions

#25

The repo says "A look at how LinkedIn spies on its users" I'm not convinced this is LinkedIn spying on users... rather, it's them protecting its users from the spammy people using these extensions. There's not a single extensions on that list that doesn't result in someone getting an unsolicited email.

Well, another good reason for LinkedIn to thi is to protect their revenues. I heard of headhunters who don’t want to pay their (high) monthly subscription fees and instead “hack” their system. I guess “hacking” includes using these extensions.

Re: How LinkedIn detects browser extensions

#27

The repo says "A look at how LinkedIn spies on its users" I'm not convinced this is LinkedIn spying on users... rather, it's them protecting its users from the spammy people using these extensions. There's not a single extensions on that list that doesn't result in someone getting an unsolicited email.

Here's the full list; they're all spammy recruiting/sales extensions (nothing legit like uBlock or LastPass): daxtra SalesloftProspector SalesLoftCadence discoverly Ecquire Ebstabullhorn EbstaSalesforce ProspectHive talentbin Entelo Nimble amazinghiring colabo extension StepWells(colabo) found.ly datananas Linkedin-Hubspot Connector dux-soup(fixed) data Scraper aevy Lusha Lead Generator Candidate.ai Email Hunter Pros…

>gay2sms

That's a malware, isn't it?

Post reply on HN