Live data from Hacker News

LinkedIn is searching your browser extensions

browsergate.eu

171–180 of 836 posts

Re: LinkedIn is searching your browser extensions

#171
post #14

The headline seems pretty misleading. Here’s what seems to actually be going on: > Every time you open LinkedIn in a Chrome-based browser, LinkedIn’s JavaScript executes a silent scan of your installed browser extensions. The scan probes for thousands of specific extensions by ID, collects the results, encrypts them, and transmits them to LinkedIn’s servers. This does seem invasive. It also seems like what I’d expect…

> I’ve come to mostly expect this behavior from most websites that run advertising code and this is why I run ad blockers. Expecting and accepting this kind of thing is why everyone feels the need to run an ad-blocker. An ad-blocker also isn’t full protection. It’s a cat and mouse game. Novel ideas on how to extract information about you, and influence behavior, will never be handled by ad-blockers until it becomes k…

Regulation is also a cat-and-mouse game. Life is a cat-and-mouse game.

Re: LinkedIn is searching your browser extensions

#173

>The user is never asked. Never told. LinkedIn’s privacy policy does not mention it. OMG is literally every article written with LLMs these days I just can't anymore. It's all so tiring.

Who cares if it’s LLM written or assisted writing?

What matters is the content!

Re: LinkedIn is searching your browser extensions

#174
post #80

Earlier quoted context omitted.

This, to me, seems like the more salient point. A headline like “Major browsers allow websites to see your installed extensions” seems more appropriate here. We’ve known for a long time that advertisers/“security” vendors use as many detectable characteristics as possible to constrict unique fingerprints. This seems like a major enabler of even more invasive fingerprinting and that seems like the bigger issue here.

This is a Chrome thing. It’s a safe bet that if you use Google products you don’t care about privacy anyway. “Google product collects info about you: news at 11.”

Google cares deeply about privacy. Google defines privacy as them not giving your private data that they have collected to anyone else unless you ask them to.

Re: LinkedIn is searching your browser extensions

#176

Earlier quoted context omitted.

This has been covered several times including reverse engineering of the code. The list of extensions they check for doesn’t include common extensions like ad blockers. It’s exclusively full of LinkedIn spamming and scraping type of extensions. They also logically don’t need to fingerprint these users because those people are literally logging in to an account with their credentials. By all appearances they’re just t…

it apparently scans for something like "PQC Checker", an extension for checking if TLS connection is PQC-enabled? how is that a spam extension (and thats just a random one i saw)

Probably compromised extensions or misleading extensions.

It’s common for malware extensions to disguise themselves as something simple and useful to try to trick a large audience into installing them.

That’s why the list includes things like an “Islamic content filter” and “anti-Zionist tagger” as well as “neurodivergent” tools. They look for trending topics and repackage the scraper with a new name. Most people only install extensions but never remove them if they don’t work.

Re: LinkedIn is searching your browser extensions

#178

>The user is never asked. Never told. LinkedIn’s privacy policy does not mention it. OMG is literally every article written with LLMs these days I just can't anymore. It's all so tiring.

I agree that that line reads GPT-like, but it's far from a conclusive tell. One option that I wonder about is if frequent interaction with AI will begin to influence people's organic writing style.

Re: LinkedIn is searching your browser extensions

#179

Earlier quoted context omitted.

it apparently scans for something like "PQC Checker", an extension for checking if TLS connection is PQC-enabled? how is that a spam extension (and thats just a random one i saw)

Probably compromised extensions or misleading extensions. It’s common for malware extensions to disguise themselves as something simple and useful to try to trick a large audience into installing them. That’s why the list includes things like an “Islamic content filter” and “anti-Zionist tagger” as well as “neurodivergent” tools. They look for trending topics and repackage the scraper with a new name. Most people onl…

well if they have evidence why they dont report it? why are these extensions on the store? im sure linkedin has enough motion to report it directly to google

also, having a PQC enabled extension doesnt seem like a good "large user base capture" tactic.

the source code is as usual obfuscated react but that doesnt mean its malicious...

EDIT: i debuged the extension quickly and it doesnt seem to do anything malicious. it only sends https://pqc-extension.vercel.app/?hostname=[domain] request to this backend to which it has permissions. it doesnt seem to exfiltrate anything else. it might get triggered later but it has very limited permissions anyway so it doesnt seem to be a malicious extension. (but im no expert)

Re: LinkedIn is searching your browser extensions

#180
post #82
post #50

Earlier quoted context omitted.

To broaden my point, I think we’d find that many websites we use are doing this. My point isn’t that this is acceptable or that we shouldn’t push back against it. We should. My point is that this doesn’t sound particularly surprising or unique to LinkedIn, and that the framing of the article seems a bit misleading as a result.

> To broaden my point, I think we’d find that many websites we use are doing this. Your point of "I think we’d find that many websites we use are doing this" doesn't make LinkedIn's behavior ok! By your logic, if our privacy rights are invaded which is illegal in most jurisdiction, and then it become ok because many companies do illegal things??

You really need to work on your reading comprehension, dude.
Post reply on HN