Live data from Hacker News

How LinkedIn detects browser extensions

github.com

61–70 of 113 posts

Re: How LinkedIn detects browser extensions

#61

For anyone who is asking what/who LinkedIn are protecting with this, it's not the users with the extensions installed, it's to protect the other users on the sites. I poked through some of the listed extensions and most are basically bots that you can turn on that will crawl through LinkedIn pages very quickly and either collect info (like email addresses) or send out messages to other LinkedIn users. I found this vi…

In 2015 I wrote and publish and Chrome Extension for LinkedIn that calculated the age of a person and put that age next to the name in their LinkedIn profiles. It quickly went viral and showed up in several places including Product Hunt. Someone from BuzzFeed reached out to me asking questions about it and then later that day wrote an article claiming that LinkedIn had asked me to take it down (until that point they…

C&D letters are written by lawyers. They don't appeal to your empathy over the PII of other users, they state facts and appeal to the legal standing LinkedIn (or $company...) has over the data being used.

That said, I have no idea of the reasons LinkedIn sent you a C&D. It could well be any of the proposed options, or something else entirely. I'm just highlighting that the language in a C&D will rarely give any indication of intent, at least not "well written" ones anyway.

Re: How LinkedIn detects browser extensions

#62

Earlier quoted context omitted.

Here's the full list; they're all spammy recruiting/sales extensions (nothing legit like uBlock or LastPass): daxtra SalesloftProspector SalesLoftCadence discoverly Ecquire Ebstabullhorn EbstaSalesforce ProspectHive talentbin Entelo Nimble amazinghiring colabo extension StepWells(colabo) found.ly datananas Linkedin-Hubspot Connector dux-soup(fixed) data Scraper aevy Lusha Lead Generator Candidate.ai Email Hunter Pros…

>gay2sms That's a malware, isn't it?

No idea, but if it is, and this is about protecting users from malicious addons, why did LinkedIn not just report that extension to Google?

Re: How LinkedIn detects browser extensions

#64
post #48

Ignoring everything else, it seems a bit weird a page can make requests to an extension's assets without originating from that extension.

Imagine an extension modifying a page and adding an image. How would it allow the image to load if that wasn’t possible?

Re: How LinkedIn detects browser extensions

#65
post #42

How is a webpage able to query the local file system? That sounds pretty bad.

It doesn't, it queries the local assets of installed extensions. Chrome (and I guess other browsers?) provide a way to do this, so the HTML etc injected by an extension can reference assets shipped with the extension.

Re: How LinkedIn detects browser extensions

#66
post #2

OK, but why does LinkedIn scan extensions?

To flag accounts that are scraping data or "revealing" email addresses. Negative view: they're blocking people from circumventing their paid features Positive view: they're protecting their other users from getting spammed

A lot of these are used as CRM type applications where people would love it if LinkedIn just charged for access to a more comprehensive API instead. LinkedIns messaging UI sucks, and ironically one of the reasons to want to use CRMs like Nimble to interact with your LinkedIn connections is to be able to better track communication with them so you don't spam. But of course people will use it to spam too.

If LinkedIn offered API access to messaging in a way that let CRMs work with them instead of feel forced to circumvent them I think most who want to use it legitimately would be perfectly happy to have LinkedIn impose various usage limits and peotections even if paid.

They should see this as revenue potential: there are lots of potential to get companies with legitimate reasons for more integration than the current API to upsell their customers on paid LinkedIn features if they are able to offer it in an approved way, and I bet many would be happy to let LinkedIn monitor how it's used.

If they try to block access instead, they'll find more and more companies keep offering the same, but manually.

Re: How LinkedIn detects browser extensions

#67

> LinkedIn violates their own users' privacy in an effort to detect the usage of browser extensions. At the time of writing this, LinkedIn is scanning visitors for 38 different browser extensions. No it is defending against malicious actors from abusing its API.

> No it is defending against malicious actors from abusing its API.

I do not really understand the concept of "abusing an API". If an API is amenable to a "bad" use, it seems entirely to be the fault of the API designers, not of its users. The designers built an API that enabled an usage that they did not want. That is their fault, how could it be otherwise?

Re: How LinkedIn detects browser extensions

#68

The repo says "A look at how LinkedIn spies on its users" I'm not convinced this is LinkedIn spying on users... rather, it's them protecting its users from the spammy people using these extensions. There's not a single extensions on that list that doesn't result in someone getting an unsolicited email.

Here's the full list; they're all spammy recruiting/sales extensions (nothing legit like uBlock or LastPass): daxtra SalesloftProspector SalesLoftCadence discoverly Ecquire Ebstabullhorn EbstaSalesforce ProspectHive talentbin Entelo Nimble amazinghiring colabo extension StepWells(colabo) found.ly datananas Linkedin-Hubspot Connector dux-soup(fixed) data Scraper aevy Lusha Lead Generator Candidate.ai Email Hunter Pros…

> There's not a single extensions on that list that doesn't result in someone getting an unsolicited email.

Nimble is just a CRM. Their extension does not crawl for email addresses, as far as I remember. Why does linkedIn need to "protect its users" from it? Isn't it rather to protect itself against the competition?

Re: How LinkedIn detects browser extensions

#69

The repo says "A look at how LinkedIn spies on its users" I'm not convinced this is LinkedIn spying on users... rather, it's them protecting its users from the spammy people using these extensions. There's not a single extensions on that list that doesn't result in someone getting an unsolicited email.

> result in someone getting an unsolicited email. That's pretty ballsy to bring up in a defense of LinkedIn.

Right. It ought to be "... result in someone getting an unsolicited email that didn't earn income for LinkedIn".

Re: How LinkedIn detects browser extensions

#70
post #28

[deleted]

Could you explain what holes these extensions are using to extract the hidden personal data? Or is it that the personal data is already in plain view and these extensions are just collating it?

Probably the latter.

Otherwise LinkedIn would just fix the holes and not bother blocking extensions.

Post reply on HN