Live data from Hacker News

LinkedIn is searching your browser extensions

browsergate.eu

621–630 of 836 posts

Re: LinkedIn is searching your browser extensions

#621
post #480

Earlier quoted context omitted.

>the average person's response is "nah, that would take at least a couple of minutes of my time, As a data point I, a technical person who tweaks his computer a lot, was against adblocking for moral reasons (as a part of perceived social contract, where internet is free because of ads). Only later I changed mi mind on this because I became more privacy aware.

The social contract was "your ads aren't annoying or invasive, and don't waste my time, so I earn you some money" But ads are all of those things now, so I feel no obligation. I only got an ad blocker around the time ads were becoming excessively irritating.

I remember how I felt the first time I saw an ad come across my browser, it seems so long ago - I guess it was more than a quarter century ago now. I knew it was going to be downhill from there, and it has been.

Re: LinkedIn is searching your browser extensions

#622

Earlier quoted context omitted.

How is probing your browser for installed extensions not "scanning your computer"? Calling the title misleading because they didn't breach the browser sandbox is wrong when this is clearly a scenario most people didn't think was possible. Chrome added extensionId randomization with the change to V3, so it's clearly not an intended scenario. > vs. something inherently sinister (e.g. “they’re checking to see if you’re…

> How is probing your browser for installed extensions not "scanning your computer"? I think most people would interpret “scanning your computer” as breaking out of the confines the browser and gathering information from the computer itself. If this was happening, the magnitude of the scandal would be hard to overstate. But this is not happening. What actually is happening is still a problem. But the hyperbole underm…

> I think most people would interpret “scanning your computer” as breaking out of the confines the browser and gathering information from the computer itself.

Which they would, if they could.

They are scanning users' computers to the maximum extent possible.

Re: LinkedIn is searching your browser extensions

#623
post #182

Earlier quoted context omitted.

Ad blockers focus on ads, not fingerprinting.

"Ad blockers" nowadays do much more. From the horse’s mouth, which describes itself as a “wide-spectrum content blocker” [1]: “uBlock Origin (uBO) is a CPU and memory-efficient wide-spectrum content blocker for Chromium and Firefox. It blocks ads, trackers, coin miners, popups, annoying anti-blockers, malware sites, etc., by default using EasyList, EasyPrivacy, Peter Lowe's Blocklist, Online Malicious URL Blocklist,…

Appreciate the clarification, I would clarify to say the origin story of Ad blockers are ads, and the underlying behaviours may not capture everything that fingerprinting may do where people don't advertise.

Ublock is great, but I am finding fingerprinting that gets past it and that's what I'm referring to.

Re: LinkedIn is searching your browser extensions

#624

Earlier quoted context omitted.

> I’ve come to mostly expect this behavior from most websites that run advertising code and this is why I run ad blockers. Expecting and accepting this kind of thing is why everyone feels the need to run an ad-blocker. An ad-blocker also isn’t full protection. It’s a cat and mouse game. Novel ideas on how to extract information about you, and influence behavior, will never be handled by ad-blockers until it becomes k…

LinkedIn's whole business model is gatekeeping their database. They're scanning your extensions to make sure you aren't using third party tools to scrape LinkedIn. It's stupid, but they're trying to stop people from making money on LinkedIn when they feel like they're the only ones that should be able to do that.

Has anyone published useful parts of their database? It'd be kinda nice to use a rolodex that wasn't slimed with the rest of LI's taint.

Re: LinkedIn is searching your browser extensions

#626

Earlier quoted context omitted.

> How is probing your browser for installed extensions not "scanning your computer"? I think most people would interpret “scanning your computer” as breaking out of the confines the browser and gathering information from the computer itself. If this was happening, the magnitude of the scandal would be hard to overstate. But this is not happening. What actually is happening is still a problem. But the hyperbole underm…

> I think most people would interpret “scanning your computer” as breaking out of the confines the browser and gathering information from the computer itself. Yes, but I also think that most people would interpret "Getting a full list of all the Chrome extensions you have installed" as a meaningful escape/violation of the browser's privacy sandbox. The fact that there's no getAllExtensions API is deliberate. The fact…

> Yes, but I also think that most people would interpret "Getting a full list of all the Chrome extensions you have installed" as a meaningful escape/violation of the browser's privacy sandbox.

I don't think so, because most people understand that extensions necessarily work inside of the sandbox. Accessing your filesystem is a meaningful escape. Accessing extensions means they have identification mechanisms unfortunately exposed inside the sandbox. No escape needed.

It's extremely unfortunate that the sandbox exposes this in some way.

Microsoft should be sued, but browsers should also figure out how to mitigate revealing installed extensions.

Re: LinkedIn is searching your browser extensions

#628

Earlier quoted context omitted.

> The gathering not being targeted is not an excuse for gathering the data in the first place. I’m not saying it is. My point is that they appear to be trying to accomplish something like getInstalledExcentions(), which is meaningfully different from a small and targeted list like isInstalled([“Indeed.com”, “DailyBibleVerse”, “ADHD Helper”]). One could be reasonably interpreted as targeting specific kinds of users. W…

Calling out the fingerprinting users' extensions is not hyperbolic. Defending that action is.

Calling out the fingerprinting of extensions is appropriate and can be achieved without hyperbole.

As I’ve stated clearly throughout this thread, the fingerprinting they’re doing is a problem.

Calling it “searching your computer” is also a problem.

> Defending that action is

Nowhere have I defended what LinkedIn is doing.

Re: LinkedIn is searching your browser extensions

#629
post #552

Earlier quoted context omitted.

It's one thing if they have a shadow profile on you (and dozens of companies almost certainly do), but it's another thing if you give them meaningful info about you to enrich that profile with. They can figure out roughly what block you live on, OK fine, but unless you're in a rural area with no neighbors they might not be able to do much better than that.

> They can figure out roughly what block you live on Its nothing to do with the specific house you live in, and everything to do with the activity being grouped together with all other activity you have done, which they know from fingerprinting and IP addresses. They dont need to know where you live to have a very accurate personal and psychological profile opn you, and switching browsers is not going to help that in…

Yes and no. If you block Linkedin SDK scripts on 3rd party sites, it's likely that Linkedin specifically doesn't actually have a good profile on you.

Realistically you're probably exposed and identified. But if you're meticulous and careful, you might not be, or at least not as completely as someone who is unaware or not careful. But it's not at all the same as if, say, a state actor was motivated to spy on you specifically.

Re: LinkedIn is searching your browser extensions

#630

Earlier quoted context omitted.

if they do a better job at showing me an ad that might be relevant to me, how is that disgusting? if I have to see an ad at all I at least want them to give it their best shot

It's not just about ads. The same data and tech is also about locking you up and identifying you for deportation you if this admin thinks you are in the USA without permission.

And laundering responsibility. If the government uses a contractor to identify deportation candidates using this data, and they get it wrong, the government can at least try to shrug it off and blame the contractor, whose job is in part to absorb public outrage for these sorts of things. Whereas if the FBI wiretaps you and still gets it wrong, it's a lot harder to deflect blame.
Post reply on HN