Live data from Hacker News

LinkedIn is searching your browser extensions

browsergate.eu

51–60 of 836 posts

Re: LinkedIn is searching your browser extensions

#51
post #22
post #3

It seems it scans your extensions not your system - reading the details. The intro made it a bit unclear.

Still pretty annoying browsers haven't patched that yet.

There's nothing to patch, scanning is not possible.

It's either the extension's choice to become detectable ("externally_connectable" is off by default) or it makes unique changes to websites that allow for its detection.

Re: LinkedIn is searching your browser extensions

#53
post #14

The headline seems pretty misleading. Here’s what seems to actually be going on: > Every time you open LinkedIn in a Chrome-based browser, LinkedIn’s JavaScript executes a silent scan of your installed browser extensions. The scan probes for thousands of specific extensions by ID, collects the results, encrypts them, and transmits them to LinkedIn’s servers. This does seem invasive. It also seems like what I’d expect…

I disagree, I think we should push back hard on behavior like this. What business is it of LinkedIn's what browser extensions I have installed? I think the framing for this is appropriate.

Why is it possible for a web site to determine what browser extensions I have installed? If there are legitimate uses, why isn't this gated behind a permission prompt, like things like location and camera?

Re: LinkedIn is searching your browser extensions

#54

Interesting. I didn't know a extension’s web-accessible resource (e.g. chrome-extension:// /...) could be abused to learn about the user's installed extensions by checking whether it resolves or not.

You would need to use use_dynamic_url: true in the manifest to create a unique one.

Re: LinkedIn is searching your browser extensions

#55
post #14

The headline seems pretty misleading. Here’s what seems to actually be going on: > Every time you open LinkedIn in a Chrome-based browser, LinkedIn’s JavaScript executes a silent scan of your installed browser extensions. The scan probes for thousands of specific extensions by ID, collects the results, encrypts them, and transmits them to LinkedIn’s servers. This does seem invasive. It also seems like what I’d expect…

> The scan probes for thousands of specific extensions by ID, collects the results, encrypts them, and transmits them

And probably also vibe-coded therefore 2 tabs of LinkedIn take up 1GB of RAM (was on the front page a few days back).

Re: LinkedIn is searching your browser extensions

#56
post #31
post #23

How a web site can search one's computer?

TFA explains it is looking for installed browser extensions (which sites are allowed to do)

https://browsergate.eu/how-it-works/: “Every time you open LinkedIn in a Chrome-based browser, LinkedIn’s JavaScript executes a silent scan of your installed browser extensions”

⇒ which Chrome allows sites to do.

Re: LinkedIn is searching your browser extensions

#57
post #31
post #23

How a web site can search one's computer?

TFA explains it is looking for installed browser extensions (which sites are allowed to do)

Allowed to do? Not prevented from by technical measures, but certainly not allowed to do.

Considering the goal is to identify people, this is undeniably PII. As the article demonstrates, it also pertains sensitive information.

Re: LinkedIn is searching your browser extensions

#58
Sounds like containers and potentially adblocking and js blocking prevent this. For my part, I use linked in on my "god dammnit I hate corporate websites so much" browser which is used only for medical bill pay and amazon / wal mart purchases and then monthly bills. Could LinkedIn get something from me there? Potentially, but they're also not really following me around the web. I think given this I'll go install a 3rd browser for linkedin only, or maybe finally just delete my account. It never got me a job and it's a cesspool.

Re: LinkedIn is searching your browser extensions

#59
post #31
post #23

How a web site can search one's computer?

TFA explains it is looking for installed browser extensions (which sites are allowed to do)

Well, they're able to do it; “allowed” to do it is an ambiguous enough phrasing that it's practically begging to have an argument whose crux is fundamentally about a differing interpretation.

Re: LinkedIn is searching your browser extensions

#60
I can’t take an article seriously that starts:

> Every time any of LinkedIn’s one billion users visits linkedin.com, hidden code searches their computer for installed software

and then proceeds not to explain how it’s doing that to me, a Safari user.

Because, spoiler: it isn’t. Or, it might try to search, and fail, and nothing will be collected.

Post reply on HN