Live data from Hacker News

LinkedIn is searching your browser extensions

browsergate.eu

241–250 of 836 posts

Re: LinkedIn is searching your browser extensions

#241

Earlier quoted context omitted.

Probably compromised extensions or misleading extensions. It’s common for malware extensions to disguise themselves as something simple and useful to try to trick a large audience into installing them. That’s why the list includes things like an “Islamic content filter” and “anti-Zionist tagger” as well as “neurodivergent” tools. They look for trending topics and repackage the scraper with a new name. Most people onl…

well if they have evidence why they dont report it? why are these extensions on the store? im sure linkedin has enough motion to report it directly to google also, having a PQC enabled extension doesnt seem like a good "large user base capture" tactic. the source code is as usual obfuscated react but that doesnt mean its malicious... EDIT: i debuged the extension quickly and it doesnt seem to do anything malicious. i…

> well if they have evidence why they dont report it? why are these extensions on the store?

We had a browser extension for our product. A couple times a month someone would clone it, add some data scraping or other malware to it, and re-upload it with the same or similar name.

We set up automated searches to find them. After reporting it could take weeks to get them removed, some times longer. That’s for extensions with clear copyright problems!

The extensions may not be breaking any rules of the extension stores if they’re just scraping a website. Many of the extensions on the list are literally designed to do that as their headline feature.

If you think sending data from a page to a server would disqualify an extension from an extension store then think again. Many of the plugins listed even have semi-plausible reasons for uploading the scraped data, like the “anti-Zionist tagger” extension on the list or the ones that claim to blur things that are anti-Islam. Manufacturing a reason to send data to their servers gives them cover.

Re: LinkedIn is searching your browser extensions

#242

Earlier quoted context omitted.

Majority of people use their mobile devices these days to browse the Internet. Installing an ad blocker on your iPhone is a significantly bigger challenge than on desktop.

Not anymore. You can just find one on the app store and install it, almost exactly the same as you do in a browser's extension "store". It won't be as good as uBlock but it certainly works fine even in Safari.

Which do you use? I was unaware that Apple even let such apps on the App Store. I always assumed that their ToS would strictly prohibit it.

Re: LinkedIn is searching your browser extensions

#243
post #14

The headline seems pretty misleading. Here’s what seems to actually be going on: > Every time you open LinkedIn in a Chrome-based browser, LinkedIn’s JavaScript executes a silent scan of your installed browser extensions. The scan probes for thousands of specific extensions by ID, collects the results, encrypts them, and transmits them to LinkedIn’s servers. This does seem invasive. It also seems like what I’d expect…

I disagree, I think we should push back hard on behavior like this. What business is it of LinkedIn's what browser extensions I have installed? I think the framing for this is appropriate.

If I had to guess, LinkedIn would be primarily searching for extensions that violate their terms of service (e.g. something that could be used to scrape data). They put a lot of effort into circumventing automated data collection. I could be wrong.

Re: LinkedIn is searching your browser extensions

#244

Earlier quoted context omitted.

> this is why I run ad blockers. It's pretty wild that we live in a world where the actual FBI has recommended we use ad blockers to protect ourselves, and if everyone actually listened, much of the Internet (and economy) as we know it would disappear. The FBI is like "you should protect yourself from the way that the third largest company in the world does business", and the average person's response is "nah, that w…

Majority of people use their mobile devices these days to browse the Internet. Installing an ad blocker on your iPhone is a significantly bigger challenge than on desktop.

1Blocker has been great for me and includes blocking of many/most (almost all?) in-app trackers too.

Re: LinkedIn is searching your browser extensions

#246

Earlier quoted context omitted.

LinkedIn is a job board as much as Facebook is picture-sharing website

Not in Lithuania. While it's not the No1 or 2,3 platform for job advertisements, it's still very popular, especially for IT and management jobs. So this probably depends on the country.

Sorry, I meant more like vast majority of people daily on LinkedIn are not there cause they are unemployed and looking for work

Re: LinkedIn is searching your browser extensions

#247
post #94

this is a massive violation of trust > The scan doesn’t just look for LinkedIn-related tools. It identifies whether you use an Islamic content filter (PordaAI — “Blur Haram objects, real-time AI for Islamic values”), whether you’ve installed an anti-Zionist political tagger (Anti-Zionist Tag), or a tool designed for neurodivergent users (simplify).

Almost certainly they are using that for audience segmentation and ad targeting. Clever and disgusting. This isn't the invention of some evil moustache-twirling executive, this was the invention of an employee or group of employees who value money more than morals. We should think of such employees as henchmen.

if they do a better job at showing me an ad that might be relevant to me, how is that disgusting? if I have to see an ad at all I at least want them to give it their best shot

Re: LinkedIn is searching your browser extensions

#248
All I'm seeing is that Chrome apparently is failing to properly sandbox websites against extension fingerprinting.

Sure, this can be solved at the legal layer, but in this case, there seems to be a much simpler and more effective technical solution, so why not pursue that instead?

Re: LinkedIn is searching your browser extensions

#249
post #14

The headline seems pretty misleading. Here’s what seems to actually be going on: > Every time you open LinkedIn in a Chrome-based browser, LinkedIn’s JavaScript executes a silent scan of your installed browser extensions. The scan probes for thousands of specific extensions by ID, collects the results, encrypts them, and transmits them to LinkedIn’s servers. This does seem invasive. It also seems like what I’d expect…

> this is why I run ad blockers. It's pretty wild that we live in a world where the actual FBI has recommended we use ad blockers to protect ourselves, and if everyone actually listened, much of the Internet (and economy) as we know it would disappear. The FBI is like "you should protect yourself from the way that the third largest company in the world does business", and the average person's response is "nah, that w…

[flagged]

Re: LinkedIn is searching your browser extensions

#250
post #31
post #23

How a web site can search one's computer?

TFA explains it is looking for installed browser extensions (which sites are allowed to do)

"allowed" by the web browser, but almost certainly not by the end user. The law is pretty clear on this in the US:

> 'the term “exceeds authorized access” means to access a computer with authorization and to use such access to obtain or alter information in the computer that the accesser is not entitled so to obtain or alter;'

The problem, of course, is that by clicking on a LinkedIn link, you agree to a non-negotiated contract that can change at any time, and that you have never seen. If that weren't allowed, then this sort of crap would correctly be considered "unauthorized access":

https://www.law.cornell.edu/uscode/text/18/1030

Post reply on HN