Live data from Hacker News

LinkedIn is searching your browser extensions

browsergate.eu

101–110 of 836 posts

Re: LinkedIn is searching your browser extensions

#101
post #14

The headline seems pretty misleading. Here’s what seems to actually be going on: > Every time you open LinkedIn in a Chrome-based browser, LinkedIn’s JavaScript executes a silent scan of your installed browser extensions. The scan probes for thousands of specific extensions by ID, collects the results, encrypts them, and transmits them to LinkedIn’s servers. This does seem invasive. It also seems like what I’d expect…

> I’ve come to mostly expect this behavior from most websites that run advertising code and this is why I run ad blockers.

We should not normalise nor accept this behaviour in the first place.

Re: LinkedIn is searching your browser extensions

#103
post #59
post #31

Earlier quoted context omitted.

TFA explains it is looking for installed browser extensions (which sites are allowed to do)

Well, they're able to do it; “allowed” to do it is an ambiguous enough phrasing that it's practically begging to have an argument whose crux is fundamentally about a differing interpretation.

The author suggests a legal remedy instead of a technical one.

Which is weird, because that is undeniably the hard way. Lobby Google to add protections to Chromium.

Re: LinkedIn is searching your browser extensions

#104
post #14

The headline seems pretty misleading. Here’s what seems to actually be going on: > Every time you open LinkedIn in a Chrome-based browser, LinkedIn’s JavaScript executes a silent scan of your installed browser extensions. The scan probes for thousands of specific extensions by ID, collects the results, encrypts them, and transmits them to LinkedIn’s servers. This does seem invasive. It also seems like what I’d expect…

> i.e. no available getAllExtensions() or somesuch) vs. something inherently sinister (e.g. “they’re checking to see if you’re a Muslim”

But I bet they could reliably guess your religious affiliation based on the presence of some specific browser extensions.

Re: LinkedIn is searching your browser extensions

#105
post #53

Earlier quoted context omitted.

I disagree, I think we should push back hard on behavior like this. What business is it of LinkedIn's what browser extensions I have installed? I think the framing for this is appropriate.

Why is it possible for a web site to determine what browser extensions I have installed? If there are legitimate uses, why isn't this gated behind a permission prompt, like things like location and camera?

It does two things:

1. Do a request to `chrome-extension:///`. It's unclear to me why this is allowed.

2. Scan the DOM, look for nodes containing "chrome-extension://" within them (for instance because they link to an internal resource)

It's pretty obvious why the second one works, and that "feels alright" - if an extension modifies the DOM, then it's going to leave traces behind that the page might be able to pick up on.

The first one is super problematic to me though, as it means that even extensions that don't interact with the page at all can be detected. It's unclear to me whether an extension can protect itself against it.

Re: LinkedIn is searching your browser extensions

#106
post #92
post #64

I alway use LinkedIn and Meta websites in a different browser altogether. I hope browsers in the future will need to ask for permission before doing any of that.

If you use both from the same IP without using a VPN… the profiles are most certainly grouped. There are commercial datasets on IP addresses with almost 100% accuracy with tags like “school”, “house”, “apartment block” etc. Furthermore, if you ever logged into both sites from within the same browser by accident, the link by fingerprinting was made right there and then. The final profile on you may not be 100% accurat…

It's one thing if they have a shadow profile on you (and dozens of companies almost certainly do), but it's another thing if you give them meaningful info about you to enrich that profile with. They can figure out roughly what block you live on, OK fine, but unless you're in a rural area with no neighbors they might not be able to do much better than that.

Re: LinkedIn is searching your browser extensions

#109
post #53

Earlier quoted context omitted.

I disagree, I think we should push back hard on behavior like this. What business is it of LinkedIn's what browser extensions I have installed? I think the framing for this is appropriate.

Why is it possible for a web site to determine what browser extensions I have installed? If there are legitimate uses, why isn't this gated behind a permission prompt, like things like location and camera?

Who makes browsers? Ad companies.

Of course Google is going to back door their browser.

Re: LinkedIn is searching your browser extensions

#110
post #82
post #50

Earlier quoted context omitted.

To broaden my point, I think we’d find that many websites we use are doing this. My point isn’t that this is acceptable or that we shouldn’t push back against it. We should. My point is that this doesn’t sound particularly surprising or unique to LinkedIn, and that the framing of the article seems a bit misleading as a result.

> To broaden my point, I think we’d find that many websites we use are doing this. Your point of "I think we’d find that many websites we use are doing this" doesn't make LinkedIn's behavior ok! By your logic, if our privacy rights are invaded which is illegal in most jurisdiction, and then it become ok because many companies do illegal things??

Absolutely not. At no point am I saying this is ok.

I’m saying that the framing of the article makes this sound like LinkedIn is the Big Bad when the reality is far worse - they’re just one in a sea of entities doing this kind of thing.

If anything, the article undersells the scale of the issue.

Post reply on HN