Live data from Hacker News

LinkedIn is searching your browser extensions

browsergate.eu

151–160 of 836 posts

Re: LinkedIn is searching your browser extensions

#152
post #44

Earlier quoted context omitted.

> Every time you open LinkedIn in a Chrome-based browser, LinkedIn’s JavaScript executes a silent scan of your installed browser extensions. It's not clear though, either they only tested against chrome-based browsers or Firefox isn't enabling them to do so. edit: I answered before I go fully through the article but it does say it's only Chrome based. > The extension scan runs only in Chrome-based browsers. The isUse…

What is a Chrome-based browser? Isn't Chrome Google's Chromium based browser? How many are based on Chrome?

> This means every user visiting LinkedIn with Chrome, Edge, Brave, Opera, Arc, or any other Chromium-based browser is subject to the scan.

Re: LinkedIn is searching your browser extensions

#154
post #22

Earlier quoted context omitted.

Still pretty annoying browsers haven't patched that yet.

They have! It's these developers either not knowing or not caring about it which is the issue! I did a blog post about this a while back showing how they do it, and how you can get around it, it's not very complex for the devs. https://www.linkedin.com/pulse/how-linkedin-knows-which-chro...

> Chrome have fortunately recently released a "extension side panel" mode, and since only DOM changes can be easily identified, using the chrome extension side panel would be virtually un-detectable however this is far less intuitive to use and requires the user to perform some action to open the sidepanel every time they want to use the extension.

As an end user I could not find an option to open the side panel

Re: LinkedIn is searching your browser extensions

#155

this is a massive violation of trust > The scan doesn’t just look for LinkedIn-related tools. It identifies whether you use an Islamic content filter (PordaAI — “Blur Haram objects, real-time AI for Islamic values”), whether you’ve installed an anti-Zionist political tagger (Anti-Zionist Tag), or a tool designed for neurodivergent users (simplify).

Many extensions designed to scrape data from social media websites are disguised as simple extensions that do something else.

If I had to guess: I sought that automatic content blurrer, neurodivergent website simplifier, or anti-Zionist tagger actually work. They’re all just piggybacking on trending topics to get users to install them and then forget about them, then they exfiltrate the data when you visit LinkedIn.

Re: LinkedIn is searching your browser extensions

#156
post #14

The headline seems pretty misleading. Here’s what seems to actually be going on: > Every time you open LinkedIn in a Chrome-based browser, LinkedIn’s JavaScript executes a silent scan of your installed browser extensions. The scan probes for thousands of specific extensions by ID, collects the results, encrypts them, and transmits them to LinkedIn’s servers. This does seem invasive. It also seems like what I’d expect…

There is clear rules around what you can and can't do to fingerprint users. if it's being done overtly, covertly, obscurely, indirectly, all for the same result through direct or indirect or correlated metadata it ends up with the same outcome.

My understanding is the rules and laws are to prevent the outcome, by any means, if it's happening.

Re: LinkedIn is searching your browser extensions

#157
post #104
post #14

The headline seems pretty misleading. Here’s what seems to actually be going on: > Every time you open LinkedIn in a Chrome-based browser, LinkedIn’s JavaScript executes a silent scan of your installed browser extensions. The scan probes for thousands of specific extensions by ID, collects the results, encrypts them, and transmits them to LinkedIn’s servers. This does seem invasive. It also seems like what I’d expect…

> i.e. no available getAllExtensions() or somesuch) vs. something inherently sinister (e.g. “they’re checking to see if you’re a Muslim” But I bet they could reliably guess your religious affiliation based on the presence of some specific browser extensions.

They already have so much telemetry from your phone, IP, etc.

God forbid they make an educated guess based on your actual LinkedIn connections, name, interests, etc.

Re: LinkedIn is searching your browser extensions

#158

>The user is never asked. Never told. LinkedIn’s privacy policy does not mention it. OMG is literally every article written with LLMs these days I just can't anymore. It's all so tiring.

Reading (and even more so, using the tools to produce) a bunch of LLM-output writing also affects one’s writing style. Ever sat down and blown through 3-4 books by a favorite author, then written something and found yourself using similar structure, word choice, style…? This could very well be a human author that’s been exposed to a lot of LLM output (ie 95% of this site’s audience).

I find myself doing this a lot, and I’m sure even more slips without my notice.

Re: LinkedIn is searching your browser extensions

#159

Earlier quoted context omitted.

How is probing your browser for installed extensions not "scanning your computer"? Calling the title misleading because they didn't breach the browser sandbox is wrong when this is clearly a scenario most people didn't think was possible. Chrome added extensionId randomization with the change to V3, so it's clearly not an intended scenario. > vs. something inherently sinister (e.g. “they’re checking to see if you’re…

When "the browser is the OS", scanning that is a pretty big chunk of "your computer".

And I spend a lot of my time at home on my computer. The article should have said LinkedIn is searching my house.

Re: LinkedIn is searching your browser extensions

#160
post #14

The headline seems pretty misleading. Here’s what seems to actually be going on: > Every time you open LinkedIn in a Chrome-based browser, LinkedIn’s JavaScript executes a silent scan of your installed browser extensions. The scan probes for thousands of specific extensions by ID, collects the results, encrypts them, and transmits them to LinkedIn’s servers. This does seem invasive. It also seems like what I’d expect…

This has been covered several times including reverse engineering of the code. The list of extensions they check for doesn’t include common extensions like ad blockers. It’s exclusively full of LinkedIn spamming and scraping type of extensions. They also logically don’t need to fingerprint these users because those people are literally logging in to an account with their credentials. By all appearances they’re just t…

it apparently scans for something like "PQC Checker", an extension for checking if TLS connection is PQC-enabled? how is that a spam extension (and thats just a random one i saw)
Post reply on HN