Live data from Hacker News

LinkedIn is searching your browser extensions

browsergate.eu

421–430 of 836 posts

Re: LinkedIn is searching your browser extensions

#421
post #14

The headline seems pretty misleading. Here’s what seems to actually be going on: > Every time you open LinkedIn in a Chrome-based browser, LinkedIn’s JavaScript executes a silent scan of your installed browser extensions. The scan probes for thousands of specific extensions by ID, collects the results, encrypts them, and transmits them to LinkedIn’s servers. This does seem invasive. It also seems like what I’d expect…

>vs. something inherently sinister

This is inherently sinister.

Re: LinkedIn is searching your browser extensions

#423

Earlier quoted context omitted.

How is probing your browser for installed extensions not "scanning your computer"? Calling the title misleading because they didn't breach the browser sandbox is wrong when this is clearly a scenario most people didn't think was possible. Chrome added extensionId randomization with the change to V3, so it's clearly not an intended scenario. > vs. something inherently sinister (e.g. “they’re checking to see if you’re…

> How is probing your browser for installed extensions not "scanning your computer"? I think most people would interpret “scanning your computer” as breaking out of the confines the browser and gathering information from the computer itself. If this was happening, the magnitude of the scandal would be hard to overstate. But this is not happening. What actually is happening is still a problem. But the hyperbole underm…

> Alongside thousands of other extensions. If they were scanning for a dozen things and this was one of them, I’d tend to agree with you. But this sounds more like they enumerated known extension IDs for a large number of extensions because getting all installed extensions isn’t possible.

If that's all it takes to fool you then its pretty trivial way to hide your true intentions.

Re: LinkedIn is searching your browser extensions

#424
post #340

Earlier quoted context omitted.

> I think most people would interpret “scanning your computer” as breaking out of the confines the browser and gathering information from the computer itself. That is exactly how I interpreted it, and that is why I clicked the link. When I skimmed the article and realized that wasn't the case, I immediately thought "Ugh, clickbait" and came to the HN comments section. > To reiterate, at no point am I saying this is g…

But LinkedIn is the one social network many people literally cannot escape to put food on the table. I don't care about how much spying is going on in ESPN. I can ditch it at the shadow of a suspicion. Not so with LinkedIn. This is very alarming, and pretending it's not because everyone else does it sounds disingenuous to me.

That sounds problematic and is only supported by people mindlessly agreeing to it. I know someone who got jobs at google and apple with no linkedin, and he wasn't particularly young. What do you do in the face of it? I say quit entirely. It was an easy decision because I got nothing out of it during the entire time I was on it.

Re: LinkedIn is searching your browser extensions

#425

Earlier quoted context omitted.

It does two things: 1. Do a request to `chrome-extension:// / `. It's unclear to me why this is allowed. 2. Scan the DOM, look for nodes containing "chrome-extension://" within them (for instance because they link to an internal resource) It's pretty obvious why the second one works, and that "feels alright" - if an extension modifies the DOM, then it's going to leave traces behind that the page might be able to pick…

> 1. Do a request to `chrome-extension:// / `. It's unclear to me why this is allowed. Big +1 to that. The charitable interpretation is that this behavior is simply an oversight by Google, a pretty massive one at that, which they have been slow to correct. The less-charitable interpretation is that it has served Google's interests to maintain this (mis)feature of its browser. Likely, Google or its partners use simila…

> This would be in the same vein as Google Chrome replacing ManifestV2 with ManifestV3, ostensibly for performance- and security-related purposes, when it just so happens that ManifestV3 limits the ability to block ads in Chrome… the major source of revenue for Google.

uBlock Origin Lite (compatible w/ ManifestV3) works quite well for me, I do not see any ads wherever I browse.

Re: LinkedIn is searching your browser extensions

#426
post #323

Earlier quoted context omitted.

I would love to get something more akin to a monthly print issue of BYTE, Omni, Starlog, Reality Hackers, WIRED and Dr Dobbs Journal without blinky, shouty ads that cause the content to re-render every 10 seconds. I would pay money for that.

E-ink is getting cheaper and cheaper, there's a lot of 6" screen devices for $100. If it dropped to $100 for a 11" screen, that would be a respectable size for a magazine. I cite eink as most are distraction free, or can be, and are very easy on the eyes. Such content would also suck with flashy ads too. It's pretty easy tech I think, it's just never hit a flash point. But it could.

You miss the point.

We literally had all of this. We had regular, affordable, high quality printed media for every hobby and interest and industry, that you could get delivered to your home address and collect in your own archive if you want, and your local library could do the same.

Those pieces of paper could not track anything about you. They tried, selling their subscriber lists, but that was the best tracking they could provide! You could easily ignore ads, and in return they had to make ads interesting enough in various ways that you might look at them anyway, or they had to make their ads directed at people who went looking for whatever you were selling.

It was an objectively better system in every way.

The Sears catalog was worlds better than Amazon. You weren't going to buy a fraudulent item for one.

Tech is a failure. It has made so much worse. It has only served to allow businesses to cut costs while extracting money from every single local community that used to allow such cash to circulate locally.

We should ban all internet advertising.

Re: LinkedIn is searching your browser extensions

#427

Earlier quoted context omitted.

> this is why I run ad blockers. It's pretty wild that we live in a world where the actual FBI has recommended we use ad blockers to protect ourselves, and if everyone actually listened, much of the Internet (and economy) as we know it would disappear. The FBI is like "you should protect yourself from the way that the third largest company in the world does business", and the average person's response is "nah, that w…

YT made sure adblockers ruin the experience. We really need a good YT alternative, as it has become AI slop (shorts) and most new videos are of real poor quality.

You’re not going to get a YT alternative if it can’t make money with ads.

Re: LinkedIn is searching your browser extensions

#428
post #80
post #53

Earlier quoted context omitted.

Why is it possible for a web site to determine what browser extensions I have installed? If there are legitimate uses, why isn't this gated behind a permission prompt, like things like location and camera?

This, to me, seems like the more salient point. A headline like “Major browsers allow websites to see your installed extensions” seems more appropriate here. We’ve known for a long time that advertisers/“security” vendors use as many detectable characteristics as possible to constrict unique fingerprints. This seems like a major enabler of even more invasive fingerprinting and that seems like the bigger issue here.

Well it would be more appropriate headline if it would be about broken browser behavior.

But this is about major corporation sneakily abusing this to ilegally extract specific sensitive data which they are abusing.

Re: LinkedIn is searching your browser extensions

#429
LinkedIn also violates SPAM regulations on a regular basis. Despite of me having disabled all emails from this service I consistently receive promotional emails. LinkedIn defines a new "type of promotional email" for which it assumes it has implicit consent to send unsolicited emails and proceeds to do so. It then has a fake compliance apparatus by allowing the victim to once again "unsubscribe" from the newly created email subscription which they never consented to on the first place. I really hope there is a class action and these scumbags get fined.

Re: LinkedIn is searching your browser extensions

#430

Earlier quoted context omitted.

> this is why I run ad blockers. It's pretty wild that we live in a world where the actual FBI has recommended we use ad blockers to protect ourselves, and if everyone actually listened, much of the Internet (and economy) as we know it would disappear. The FBI is like "you should protect yourself from the way that the third largest company in the world does business", and the average person's response is "nah, that w…

>the average person's response is "nah, that would take at least a couple of minutes of my time, As a data point I, a technical person who tweaks his computer a lot, was against adblocking for moral reasons (as a part of perceived social contract, where internet is free because of ads). Only later I changed mi mind on this because I became more privacy aware.

Duckduckgo is free and with ads.
Post reply on HN