Live data from Hacker News

LinkedIn checks for 2953 browser extensions

github.com

11–20 of 263 posts

Re: LinkedIn checks for 2953 browser extensions

#11
post #5
post #2

[removed]

This is a security vulnerability and should be patched. Sorry, LinkedIn. (Alternatively extension developers can modify their extensions to block these requests!)

No kidding. I am shocked this works.

Does Firefox have a similar weakness?

Re: LinkedIn checks for 2953 browser extensions

#13
post #5
post #2

[removed]

This is a security vulnerability and should be patched. Sorry, LinkedIn. (Alternatively extension developers can modify their extensions to block these requests!)

Is there no browser setting to defend against this attack? If not, there should be, versus relying on extension authors to configure or enable such a setting.

Re: LinkedIn checks for 2953 browser extensions

#14
post #9

Curious question: why would they check for installed extensions on one's browser?

most automations for sales and marketing use browser extensions... linkedIn wants you using their tools not 3rd party

Their own tools suck, that’s the issue.

Re: LinkedIn checks for 2953 browser extensions

#15
Skimming the list, looks like most extensions are for scraping or automating LinkedIn usage. Not surprising as there's money to be made with LinkedIn data. Scraping was a problem when I worked there, the abuse teams built some reasonably sophisticated detection & prevention, and it was a constant battle.

Re: LinkedIn checks for 2953 browser extensions

#16

Skimming the list, looks like most extensions are for scraping or automating LinkedIn usage. Not surprising as there's money to be made with LinkedIn data. Scraping was a problem when I worked there, the abuse teams built some reasonably sophisticated detection & prevention, and it was a constant battle.

Wont someone think of poor little LinkedIn, a subsidiary of one of the largest data brokers in the world?

Re: LinkedIn checks for 2953 browser extensions

#17
post #2

[removed]

If this is true, it's insane that this would work:

- why does CWS respond to cross-site requests?

- why is chrome sending the credentials (or equivalent) in these requests?

- why is the button enabled server-side and not via JS? Google must be confident in knowing the exact and latest state of your installed extensions enough to store it on their servers, I guess

Re: LinkedIn checks for 2953 browser extensions

#19

Skimming the list, looks like most extensions are for scraping or automating LinkedIn usage. Not surprising as there's money to be made with LinkedIn data. Scraping was a problem when I worked there, the abuse teams built some reasonably sophisticated detection & prevention, and it was a constant battle.

Wont someone think of poor little LinkedIn, a subsidiary of one of the largest data brokers in the world?

Why frame what you are trying to say like that? Businesses of all sizes deserve the ability to protect their businesses from abuse.

Re: LinkedIn checks for 2953 browser extensions

#20

Skimming the list, looks like most extensions are for scraping or automating LinkedIn usage. Not surprising as there's money to be made with LinkedIn data. Scraping was a problem when I worked there, the abuse teams built some reasonably sophisticated detection & prevention, and it was a constant battle.

Wont someone think of poor little LinkedIn, a subsidiary of one of the largest data brokers in the world?

I mean, regardless of who they are or even if you don’t like what LinkedIn does themselves with the data people have given them, the random third parties with the extensions don’t additionally deserve to just grab all that data too, do they?
Post reply on HN