Live data from Hacker News

LinkedIn is scanning browser extensions

404privacy.com

211–220 of 226 posts

Re: LinkedIn is scanning browser extensions

#211

Earlier quoted context omitted.

CORS is a server setting to tell the browser not to load its data from potentially unsafe origins. If you set a server to send access-control-allow-origin: *, then your browser will happily load these resources for you regardless of where you currently are. And chrome extensions need to be loadable from everywhere to be able to inject code or images into pages, so enabling CORS for them would defeat their main purpos…

From the other end, yes extensions access all page data, but pages shouldn't access extension data at all; it feels like that should be the CORS violation.

You have it backwards. For an extension to work on a page, it's data/code needs to be accessible from said page. If your extension server in chrome enforced CORS to prevent access from tabs on other websites, extensions wouldn't work anywhere.

Re: LinkedIn is scanning browser extensions

#212

Earlier quoted context omitted.

You want the unemployed to pay? Or do you want the employers to pay? If you want the employers to pay, how do you attract enough attractive unemployed to your site?

Employers pay, unemployed will go where there are places to get jobs. But this assumes employers are unsatisfied with LinkedIn somehow. Are they?

Well I guess we have a possible reason why LI is still relevant.

This suggest then that the relevance of any solution would need to appease the employers... yet here we are trying to build/design something for employees first.

Re: LinkedIn is scanning browser extensions

#213
post #206

Earlier quoted context omitted.

This is the same source - 404 story lists browsergate.eu (linked by Chris) as the original source

I did do my own independent audit, though. Sorry, I just checked back today and was not expecting this to get the traction it did.

That's what I mean, this article has its own audit, it's not a dupe of the other

Re: LinkedIn is scanning browser extensions

#214
"Then, I saw the browsergate story drop on mastodon and thought "no way," lo-and-behold, there's a lawsuit in the works for it." - un-nf

Farrell v LinkedIn Corporation 4:26-cv-02953-KAW (N.D. Cal. Apr. 6, 2026)

https://ia601503.us.archive.org/33/items/gov.uscourts.cand.4...

Re: LinkedIn is scanning browser extensions

#215

Earlier quoted context omitted.

It's a different primary source though

It's not clear to me what "[dupe]" means on HN anymore It is being used, e.g., by this commenter, where the URLs and the target page content for each submission differ Moreover, HN allows duplicate submissions under some circumstances, where the URLs are exactly the same. If the submissions are relatively far apart in time sometimes the moderator or a commenter will reply with "Previous discussion". More recently, a…

Dupe means duplicate, but that's normally if both links point to the same article or both articles are secondaries pointing to the same primary article

Re: LinkedIn is scanning browser extensions

#216

Earlier quoted context omitted.

It's a different primary source though

It's not clear to me what "[dupe]" means on HN anymore It is being used, e.g., by this commenter, where the URLs and the target page content for each submission differ Moreover, HN allows duplicate submissions under some circumstances, where the URLs are exactly the same. If the submissions are relatively far apart in time sometimes the moderator or a commenter will reply with "Previous discussion". More recently, a…

Dupe isn't about the url (except when it obviously is), it's about the duplicate discussion. Just flipping through most of this thread here it's all the repeated comments and points from the rather large thread on the source from earlier in the month. In this url's case it was written the same week as the source, maybe it brings a bit more analysis to the topic, but it's from then. It's not fresh. If it had been shared then it probably would have been merged into the main discussion (or could have been shared there at the time).

Not pointless at all, keeps things fresh and rolling. Stops some of us having to see the same topic over and over, and directs those who missed things to where the main discussion happened or is still happening. Stuff moves pretty fast around here.

You might see multiple submissions (a regular offender of submitting a ton of duplicates yourself) but they don't go anywhere, don't make it to front page or eyeball traction (say >20 upvotes). Most don't need specific dupe flagging because there's no discussion forming. Sharing the link helps casual readers find the discussion. And directs the recognition and attention to the original posters and story especially when stories are barely hours old.

As if you haven't been around here for awhile enough to be clearer on this. Striving to keep the feed fresh and discussion together helps us all, you could do better to contribute that way.

Re: LinkedIn is scanning browser extensions

#217

Earlier quoted context omitted.

Employers pay, unemployed will go where there are places to get jobs. But this assumes employers are unsatisfied with LinkedIn somehow. Are they?

Well I guess we have a possible reason why LI is still relevant. This suggest then that the relevance of any solution would need to appease the employers... yet here we are trying to build/design something for employees first.

Right, the website being annoying doesn't really matter compared to the network quality.

One thing I've considered, what if there were a site where you could rep trusted people anonymously? Then employers (or buyers etc) can see if there's some path from themselves to the candidate, at least to know they aren't some total rando who could be a scammer. The thing is, it's hard to obfuscate the reps if you're answering those queries, and it all falls apart once someone can prove that they gave or received rep.

Re: LinkedIn is scanning browser extensions

#218

Earlier quoted context omitted.

I suppose that depends on where you go and what you expect. Older communities are better populated than younger ones. (Not age-wise but topic-wise).

where's a good irc chat these days?

It depends on the time of day, but #emacs, #nethack, #archlinux, #lobsters, #security, #openbsd usually have enough users for good convos. It depends on what you are into, really.

Re: LinkedIn is scanning browser extensions

#219
post #197

In fairness, their privacy policy DOES explicitly say that they collect this information. See https://www.linkedin.com/legal/privacy-policy?ref=cms.hondas... > 1.5 Your Device and Location > We receive data through cookies and similar technologies When you visit or leave our Services (including some plugins and our cookies or similar technology on the sites of others), we receive the URL of both the site you came fro…

That's them worming themselves out of legal responsibility and makes them look even worse.

Re: LinkedIn is scanning browser extensions

#220
So if you must use LinkedIn, the answer then is to use Firefox, and create a locked down profile with ublock origin installed with webrtc disabled in advanced mode and block everything be default. Then navigate to linkedin and only whitelist the minimum scripts needed to run the site.
Post reply on HN