Live data from Hacker News

LinkedIn is searching your browser extensions

browsergate.eu

551–560 of 836 posts

Re: LinkedIn is searching your browser extensions

#551
A few years ago, intentionally fingerprinting or tracking your users without disclosure was spyware and unethical. Alas, here we are.

Anyway, what they're calling "spectroscopy", is a combination of extension probing and doing residue detection (looking for what extensions might leave behind in the DOM).

An ad blocker is not necessarily equipped to help since the script is embedded with the application code. Since they're targetting Chrome, switching browsers will help with the probing but not the detection part and you'll still be fingerprinted.

The only way forward is for browser vendors to offer a real privacy or incognito mode where sites are sandboxed by default. When the default profile is identical across millions of users there won't be anything unique to fingerprint.

Re: LinkedIn is searching your browser extensions

#552
post #92

Earlier quoted context omitted.

If you use both from the same IP without using a VPN… the profiles are most certainly grouped. There are commercial datasets on IP addresses with almost 100% accuracy with tags like “school”, “house”, “apartment block” etc. Furthermore, if you ever logged into both sites from within the same browser by accident, the link by fingerprinting was made right there and then. The final profile on you may not be 100% accurat…

It's one thing if they have a shadow profile on you (and dozens of companies almost certainly do), but it's another thing if you give them meaningful info about you to enrich that profile with. They can figure out roughly what block you live on, OK fine, but unless you're in a rural area with no neighbors they might not be able to do much better than that.

> They can figure out roughly what block you live on

Its nothing to do with the specific house you live in, and everything to do with the activity being grouped together with all other activity you have done, which they know from fingerprinting and IP addresses.

They dont need to know where you live to have a very accurate personal and psychological profile opn you, and switching browsers is not going to help that in the slightest Im afraid.

Re: LinkedIn is searching your browser extensions

#553

Earlier quoted context omitted.

> this is why I run ad blockers. It's pretty wild that we live in a world where the actual FBI has recommended we use ad blockers to protect ourselves, and if everyone actually listened, much of the Internet (and economy) as we know it would disappear. The FBI is like "you should protect yourself from the way that the third largest company in the world does business", and the average person's response is "nah, that w…

Every browser should have ad blocking technology included and enabled by default. I do not understand why Apple in particular has not pushed this with Safari, as they like to portray that they care about privacy. I get why Chrome doesn't, and that's why you should not use it. But Netscape? Edge? What is stopping them? Browsing the web without an ad blocker is a miserable experience. Users who have never tried or don'…

Browsing the web without a web blocker for me is a wonderful experience every day and has been since the beginning. Diff'rent strokes.

Re: LinkedIn is searching your browser extensions

#554

Earlier quoted context omitted.

I disagree, I think we should push back hard on behavior like this. What business is it of LinkedIn's what browser extensions I have installed? I think the framing for this is appropriate.

> What business is it of LinkedIn's what browser extensions I have installed? The list of extensions they scan for has been extracted from the code. It was all extensions related to spamming and scraping LinkedIn last time this was posted: Extensions to scrape your LinkedIn session and extract contact info for lead lists, extensions to generate AI message spam. That seems like fair game for their business.

> The list of extensions they scan for has been extracted from the code. It was all extensions related to spamming and scraping LinkedIn

Not according to the website which says:

The scan doesn’t just look for LinkedIn-related tools. It identifies whether you use an Islamic content filter (PordaAI — “Blur Haram objects, real-time AI for Islamic values”), whether you’ve installed an anti-Zionist political tagger (Anti-Zionist Tag), or a tool designed for neurodivergent users (simplify). Under GDPR Article 9, processing data that reveals religious beliefs, political opinions, or health conditions requires explicit consent. LinkedIn obtains none.

It also scans for every major competitor to Microsoft’s own products — Salesforce, HubSpot, Pipedrive — building company-level intelligence on which businesses use which software. Because LinkedIn knows your name, employer, and role, each scan aggregates into a corporate technology profile assembled without anyone’s knowledge.

Re: LinkedIn is searching your browser extensions

#555

Earlier quoted context omitted.

This. Do not install any extension unless you absolutely need. Assume they all leak your browsing data. Not familiar with Google but if you can just vibe code your own extension then do that.

Vibe supply chain attacks are coming btw.

Wdym? You vibe code your software. Are you saying the LLM will spit out malware?

Re: LinkedIn is searching your browser extensions

#556

Earlier quoted context omitted.

> What the article describes sounds like what many devs would land on given the browser APIs available. > To reiterate, at no point am I saying this is good or acceptable. I think there’s a massive privacy problem in the tech industry that needs to be addressed. These two sentences highlight the underlying problem: Developers without an ethical backbone, or who are powerless to push back on unethical projects. What t…

I integrate these kinds of systems in order to prevent criminals from being able to use our ecommerce platform to utilize stolen credit cards. That involves integrating with tracking providers to best recognize whether a purchase is being made by a bot or not, whether it matches "Normal" signals for that kind of order, and importantly, whether the credit card is being used by the normal tracking identity that uses it…

What I'm wondering is if this requires sending the full list of extensions straight to a server (as opposed to a more privacy-protecting approach like generating some type of hash clientside)?

Based on their privacy policy, it looks like Sift (major anti-fraud vendor) collects only "number of plugins" and "plugins hash". No one can accuse them of collecting the plugins for some dual-use purpose beyond fingerprinting, but LinkedIn has opened themselves up to this based on the specific implementation details described.

Re: LinkedIn is searching your browser extensions

#557
post #145
post #119

Earlier quoted context omitted.

but the language of "your computer" implies files on your computer, as it would be what people commonly call it. Merely just the extension is not enough. If it has the ability to scan your bookmarks, or visited site history, that would lend more credence to using the term "computer". The title ought to have said "linkedIn illegally scans your browser", and that would make clear what is being done without being sensat…

Extensions are files installed on your computer, though?

So are fonts. But running Window.queryLocalFonts() is not equivalent to “illegally searching your computer”.

I’m not defending the act of scanning for these extensions, and I’m of the opinion that such an API shouldn’t even exist, but just pointing out that there are perfectly legitimate APIs that reveal information that could be framed as “files installed on your computer” that are clearly not “searching your computer” like the title implies.

Re: LinkedIn is searching your browser extensions

#559
Yep, LinkedIn is cancer.

2020 - LinkedIn Sued For Spying on Clipboard Data After iOS 14 Exposes Its App:

https://wccftech.com/linkedin-sued-for-spying-on-clipboard-d...

2013 - LinkedIn MITM attacks your iPhone to read your mail:

https://www.troyhunt.com/disassembling-privacy-implications-...

2012/2016 - Data breach of 164.6 million accounts:

https://haveibeenpwned.com/breach/LinkedIn

According to haveibeenpwned.com, my email & password were leaked in both the 'May 2012' and 'April 2021' LinkedIn incidents.

Re: LinkedIn is searching your browser extensions

#560

Earlier quoted context omitted.

Every browser should have ad blocking technology included and enabled by default. I do not understand why Apple in particular has not pushed this with Safari, as they like to portray that they care about privacy. I get why Chrome doesn't, and that's why you should not use it. But Netscape? Edge? What is stopping them? Browsing the web without an ad blocker is a miserable experience. Users who have never tried or don'…

At least with Chrome i can use ublock - not so with safari. The best browser is ofc Firefox but everyone seems to have forgotten that bc of bad publicity or whatever

The best browser is either Waterfox or Librewolf since they're Firefox-based but don't steal your data or claim copyright on it.
Post reply on HN