Live data from Hacker News

How LinkedIn detects browser extensions

github.com

71–80 of 113 posts

Re: How LinkedIn detects browser extensions

#71
post #28

[deleted]

I'm failing to see how these extensions "circumvent the privacy of our members", but normal use of the website doesn't. Either you're safeguarding the information properly, or you aren't. I am fine with huge GDPR fines to teach companies that data is a liability as well as an asset, and needs to be protected appropriately (which this measure doesn't seem to do, since it is trivial to bypass). I'm not so sure I'm OK w…

> I'm failing to see how these extensions "circumvent the privacy of our members", but normal use of the website doesn't.

Of course the website does. But the website does it to provide revenue for the website, whereas the extensions probably do it to avoid generating revenue for the website.

LinkedIn is infamous for its dark patterns. They probably do this to protect their revenue model. That in this case it involves protecting the privacy of their users, makes for nice PR.

Though for that matter, their users (which include me) have at least chosen to share their information with LinkedIn. LinkedIn may scam them into sharing more data than they want (which also happened to me), which is absolutely questionable, but at least the users have chosen to do something with LinkedIn, and haven't chosen to do something with the scrapers.

To use rape as an analogy: it's the difference between a guy you wanted to have safe sex with puncturing the condom, and a stranger jumping from the bushes to pull you from your bike. Both are rape, but in very different ways.

Was I trying to defend LinkedIn here? I guess it's different shades of very dark grey.

Re: How LinkedIn detects browser extensions

#72
The written tone used in the repo comes of as too drastic, specially as it only reports the collection of analytics on how LinkedIn users use the website.

Is the detection result reported back to LinkedIn?

In their [Privacy Policy](https://www.linkedin.com/legal/privacy-policy#your_device_an...) they do mention they collect information on "web browser and add-ons".

This reminds me of similar approaches used in other environments. For example in the game industry, anti-cheat techniques of detecting the running software in mobile devices to flag users. How do you think this differs?

Re: How LinkedIn detects browser extensions

#75
post #28

[deleted]

I'm failing to see how these extensions "circumvent the privacy of our members", but normal use of the website doesn't. Either you're safeguarding the information properly, or you aren't. I am fine with huge GDPR fines to teach companies that data is a liability as well as an asset, and needs to be protected appropriately (which this measure doesn't seem to do, since it is trivial to bypass). I'm not so sure I'm OK w…

If LinkedIn has a 'delete profile' button that works, and extensions let recruiters scrape profiles and thus keep records on deleted users, who do you think is in the wrong?

Re: How LinkedIn detects browser extensions

#76

Earlier quoted context omitted.

I'm failing to see how these extensions "circumvent the privacy of our members", but normal use of the website doesn't. Either you're safeguarding the information properly, or you aren't. I am fine with huge GDPR fines to teach companies that data is a liability as well as an asset, and needs to be protected appropriately (which this measure doesn't seem to do, since it is trivial to bypass). I'm not so sure I'm OK w…

If LinkedIn has a 'delete profile' button that works, and extensions let recruiters scrape profiles and thus keep records on deleted users, who do you think is in the wrong?

Still the recruiter can just "Save the page..."

Re: How LinkedIn detects browser extensions

#78

For anyone who is asking what/who LinkedIn are protecting with this, it's not the users with the extensions installed, it's to protect the other users on the sites. I poked through some of the listed extensions and most are basically bots that you can turn on that will crawl through LinkedIn pages very quickly and either collect info (like email addresses) or send out messages to other LinkedIn users. I found this vi…

In 2015 I wrote and publish and Chrome Extension for LinkedIn that calculated the age of a person and put that age next to the name in their LinkedIn profiles. It quickly went viral and showed up in several places including Product Hunt. Someone from BuzzFeed reached out to me asking questions about it and then later that day wrote an article claiming that LinkedIn had asked me to take it down (until that point they…

>> In the end, that's their most valuable asset (users' data)

Some might say it's their only valuable asset...

Re: How LinkedIn detects browser extensions

#79
post #71

Earlier quoted context omitted.

I'm failing to see how these extensions "circumvent the privacy of our members", but normal use of the website doesn't. Either you're safeguarding the information properly, or you aren't. I am fine with huge GDPR fines to teach companies that data is a liability as well as an asset, and needs to be protected appropriately (which this measure doesn't seem to do, since it is trivial to bypass). I'm not so sure I'm OK w…

> I'm failing to see how these extensions "circumvent the privacy of our members", but normal use of the website doesn't. Of course the website does. But the website does it to provide revenue for the website, whereas the extensions probably do it to avoid generating revenue for the website. LinkedIn is infamous for its dark patterns. They probably do this to protect their revenue model. That in this case it involves…

Exactly it's not to protect their users, to protect their money. They have way too many dark patterns for me to believe they have any good intentions.

Re: How LinkedIn detects browser extensions

#80
post #41

Earlier quoted context omitted.

But how is this data accessible to the extension? I ‘m not an expert, but it seems that this data has to publicly available for an extension to find and parse it. Extensions don’t have magic Auth rights or credentials.

Extensions have the same auth rights as your logged-in account (the ability to see people who are out of network, for example). It’s against LinkedIn’s ToS to scrape data.

This should go both ways. It is against my ToS for LinkedIn to scrape which extensions I have installed.
Post reply on HN