Live data from Hacker News

LinkedIn is searching your browser extensions

browsergate.eu

601–610 of 836 posts

Re: LinkedIn is searching your browser extensions

#601
post #468

Earlier quoted context omitted.

Firefox FTW. I was relieved to find this was a Chrome-only problem.

Turns out Firefox has a similar issue, despite mitigations :( https://bugzilla.mozilla.org/show_bug.cgi?id=1372288

This only happens if the extension puts their `moz-extension://` links into the DOM. It's different to chrome case where extensions can be detected regardless of being activated on that site or not.

Re: LinkedIn is searching your browser extensions

#602

Earlier quoted context omitted.

coveryoutracks always tells me I'm unique Which is concerning. Until you realise I do the same thing a few days later and I'm still unique.

It tells you that you have a unique fingerprint. It is not telling you that the test site has never seen you before, because the eff isn't storing your fingerprint for later analysis and tracking It could actually tell you about which real tracking vendors are showing you as "Seen and tracked" so it's pretty annoying they don't do that. If that site shows you as having a unique fingerprint, I guarantee you are being…

It must store the fingerprints to determine if I'm unique, otherwise everyone would be unique.

If it doesn't store the fingerprints then how does it tell the difference between

5 identical looking browsers connecting from 5 different IPs

1 browser connecting 5 times from 5 different IPs

Re: LinkedIn is searching your browser extensions

#603
post #14

The headline seems pretty misleading. Here’s what seems to actually be going on: > Every time you open LinkedIn in a Chrome-based browser, LinkedIn’s JavaScript executes a silent scan of your installed browser extensions. The scan probes for thousands of specific extensions by ID, collects the results, encrypts them, and transmits them to LinkedIn’s servers. This does seem invasive. It also seems like what I’d expect…

Your expectations do not matter here frankly. This reads like CFAA to me, unauthorized access.

Re: LinkedIn is searching your browser extensions

#604
post #80

Earlier quoted context omitted.

This, to me, seems like the more salient point. A headline like “Major browsers allow websites to see your installed extensions” seems more appropriate here. We’ve known for a long time that advertisers/“security” vendors use as many detectable characteristics as possible to constrict unique fingerprints. This seems like a major enabler of even more invasive fingerprinting and that seems like the bigger issue here.

Well it would be more appropriate headline if it would be about broken browser behavior. But this is about major corporation sneakily abusing this to ilegally extract specific sensitive data which they are abusing.

What law is it breaking?

If a company leaks my sensitive data, I get some nice junkmail offering me some period of time of credit monitoring or whatever so what are browsers doing to prevent this?

The issue should never be 'We want entities to have this data but only use it in some constrained and arbitrary manner that we can't even agree about it's definition.' instead 'This data shouldn't be made available to X'

Re: LinkedIn is searching your browser extensions

#606

Earlier quoted context omitted.

I integrate these kinds of systems in order to prevent criminals from being able to use our ecommerce platform to utilize stolen credit cards. That involves integrating with tracking providers to best recognize whether a purchase is being made by a bot or not, whether it matches "Normal" signals for that kind of order, and importantly, whether the credit card is being used by the normal tracking identity that uses it…

> Even the GDPR gives us enormous leeway to do literally this, but it requires participating in tracking networks that have what amounts to a total knowledge of purchases and browsing you do on the internet. That's the only way they work at all. That data sounds like it would be very valuable. But I think if I sell widgets and a prospective customer browsers my site, telling my competitors (via a data broker) that cu…

They get demographic data on their customers and can use that for marketing and setting prices.

Re: LinkedIn is searching your browser extensions

#608

Earlier quoted context omitted.

> How is probing your browser for installed extensions not "scanning your computer"? I think most people would interpret “scanning your computer” as breaking out of the confines the browser and gathering information from the computer itself. If this was happening, the magnitude of the scandal would be hard to overstate. But this is not happening. What actually is happening is still a problem. But the hyperbole underm…

> What the article describes sounds like what many devs would land on given the browser APIs available. > To reiterate, at no point am I saying this is good or acceptable. I think there’s a massive privacy problem in the tech industry that needs to be addressed. These two sentences highlight the underlying problem: Developers without an ethical backbone, or who are powerless to push back on unethical projects. What t…

One works for money. And money is important. Ethics isn’t going pay mortgage, send kids to university and all that other stuff. I’m not going to do things that are obviously illegal. But if I get a requirement that needs to be met and then the company legal team is responsible for the outcome.

In short, you are not going to solve this problem blaming developer ethics. You need regulation. To get the right regulation we need to get rid of PACs and lobbying.

Re: LinkedIn is searching your browser extensions

#609
post #14

The headline seems pretty misleading. Here’s what seems to actually be going on: > Every time you open LinkedIn in a Chrome-based browser, LinkedIn’s JavaScript executes a silent scan of your installed browser extensions. The scan probes for thousands of specific extensions by ID, collects the results, encrypts them, and transmits them to LinkedIn’s servers. This does seem invasive. It also seems like what I’d expect…

How does this scan happen. AFAIK there is no API for a webpage to scan for extensions. The most a page could do is try to figure out indirectly if an extension exists if that extension leaks info into the page.

Re: LinkedIn is searching your browser extensions

#610

Earlier quoted context omitted.

> What the article describes sounds like what many devs would land on given the browser APIs available. > To reiterate, at no point am I saying this is good or acceptable. I think there’s a massive privacy problem in the tech industry that needs to be addressed. These two sentences highlight the underlying problem: Developers without an ethical backbone, or who are powerless to push back on unethical projects. What t…

> These two sentences highlight the underlying problem: Developers without an ethical backbone, or who are powerless to push back on unethical projects. One reason your boss is eager to replace everyone with language models, they won’t have any “ethical backbone” :’)

Many developers overestimate their agency without extremely high labor demand. We got a say because replacing us was painful, not because of our ethics and wisdom. Without that leverage, developers are cogs just like every other part of the machine.
Post reply on HN