Live data from Hacker News

LinkedIn is searching your browser extensions

browsergate.eu

751–760 of 836 posts

Re: LinkedIn is searching your browser extensions

#751
post #663

Earlier quoted context omitted.

> There's no viable "grassroots" solution to the problem Does something like running the duckduckgo extension not help?

I'm hoping the Ladybird project's new Web browser (alpha release expected in August) will solve some issues resulting from big tech controlling most browers.

Yes, that might be good. I use Firefox with the dog plugin, and Proton login aliases, and hope for the best.

Re: LinkedIn is searching your browser extensions

#752
post #618

Earlier quoted context omitted.

It was their terms of service change at the start of 2025. It caused quite a shitstorm.

So essentially a bunch of noise that didnt really mean anything concrete?

Mozilla backed down due to the backlash. It still means Mozilla is untrustworthy.

Re: LinkedIn is searching your browser extensions

#753

Earlier quoted context omitted.

> 1. Do a request to `chrome-extension:// / `. It's unclear to me why this is allowed. Big +1 to that. The charitable interpretation is that this behavior is simply an oversight by Google, a pretty massive one at that, which they have been slow to correct. The less-charitable interpretation is that it has served Google's interests to maintain this (mis)feature of its browser. Likely, Google or its partners use simila…

> This would be in the same vein as Google Chrome replacing ManifestV2 with ManifestV3, ostensibly for performance- and security-related purposes, when it just so happens that ManifestV3 limits the ability to block ads in Chrome… the major source of revenue for Google. uBlock Origin Lite (compatible w/ ManifestV3) works quite well for me, I do not see any ads wherever I browse.

The mv3 problem was never about "does it work now". It was about "can it keep up". Ad blocking is a cat and mouse game, and the mouse is kneecapped now. You're being slow boiled.

Re: LinkedIn is searching your browser extensions

#754

Earlier quoted context omitted.

So these extensions allow linkedin to do this though, it's literally them saying "yes, this site can ping this resource" - called "web_accessible_resources". This is fair from Linkedin IMO as I've seen loads of different extensions actually scraping the linkedin session tokens or content on linkedin.

It's not the extension developer who should decide this, but the browser user.

On what would the browser user base their decision?

If an extension injects an icon into the DOM of the page, then the resulting `img` tag needs to put something in its `src`.

The extension author may choose to use the `data:` scheme, but that's a development-time decision.

Re: LinkedIn is searching your browser extensions

#756
post #60

I can’t take an article seriously that starts: > Every time any of LinkedIn’s one billion users visits linkedin.com, hidden code searches their computer for installed software and then proceeds not to explain how it’s doing that to me, a Safari user. Because, spoiler: it isn’t. Or, it might try to search, and fail, and nothing will be collected.

Yeah, that won’t work for Firefox users as well (extension IDs are randomized on install).

But people do use Chrome, and this trick works there.

Re: LinkedIn is searching your browser extensions

#758

Earlier quoted context omitted.

I integrate these kinds of systems in order to prevent criminals from being able to use our ecommerce platform to utilize stolen credit cards. That involves integrating with tracking providers to best recognize whether a purchase is being made by a bot or not, whether it matches "Normal" signals for that kind of order, and importantly, whether the credit card is being used by the normal tracking identity that uses it…

> Even the GDPR gives us enormous leeway to do literally this, but it requires participating in tracking networks that have what amounts to a total knowledge of purchases and browsing you do on the internet. That's the only way they work at all. That data sounds like it would be very valuable. But I think if I sell widgets and a prospective customer browsers my site, telling my competitors (via a data broker) that cu…

I suspect a lot of retailers simply aren’t aware that that data is being collected and sold off to their competitors (or to ad networks so their competitors can poach their audience)

Re: LinkedIn is searching your browser extensions

#759
post #667

Earlier quoted context omitted.

> Yes, but I also think that most people would interpret "Getting a full list of all the Chrome extensions you have installed" as a meaningful escape/violation of the browser's privacy sandbox. I don't think so, because most people understand that extensions necessarily work inside of the sandbox . Accessing your filesystem is a meaningful escape. Accessing extensions means they have identification mechanisms unfortu…

Y'all are letting "most people" carry an awful lot of water for this scummy behavior here. In my experience, most people - even most tech people - are unaware of just how much information a bit of script on a website can snag without triggering so much as a mild warning in the browser UI. And tend toward shock and horror on those occasions where they encounter evidence of reality. The widespread "Facebook is listenin…

> The widespread "Facebook is listening to me" belief is my favorite proxy for this ... Because, it sorta is - just... Not in the way folks think. Don't need ears if you see everything!

Getting folks to install “like” and “share” widgets all over their websites was a genius move.

Re: LinkedIn is searching your browser extensions

#760

The claims made on the website linked here are plain wrong. The person behind them is subject to an account restriction for scraping and other violations of LinkedIn’s Terms of Service. To protect the privacy of our members, their data, and to ensure site stability, we do look for extensions that scrape data without members’ consent or otherwise violate LinkedIn’s Terms of Service. Here’s why: some extensions have st…

All illegal or unethical means can be explained, but not justified, by their ends. I'm quite sure having unfettered insight into the browser environments of your users makes enforcing your Terms of Service much easier, but held against the (even minute) risk of exposing one of users' political, religious or sexual preferences, any of which might carry with it massive risk of bodily injury or death in many parts of th…

Why is scraping even an issue? If people don't want others to find this info, just don't put it out there in the public?
Post reply on HN