Live data from Hacker News

LinkedIn is scanning browser extensions

404privacy.com

81–90 of 226 posts

Re: LinkedIn is scanning browser extensions

#81
post #29

Can someone here please create a LinkedIn replacement for developers that 1. Doesn't have the spam 2. That doesn't look like it's from 2008 3. That only developers / engineers / tech folks can join 4. Doesn't try to log into your email to steal your contact list 5. That doesn't track you or your extensions / browser fingerprint 6. That doesn't have a bunch of fake "linkedinmaxxing" garbage content 7. that doesn't hav…

Except for #2 I think you're looking for Hacker News.

Re: LinkedIn is scanning browser extensions

#82
post #29

Can someone here please create a LinkedIn replacement for developers that 1. Doesn't have the spam 2. That doesn't look like it's from 2008 3. That only developers / engineers / tech folks can join 4. Doesn't try to log into your email to steal your contact list 5. That doesn't track you or your extensions / browser fingerprint 6. That doesn't have a bunch of fake "linkedinmaxxing" garbage content 7. that doesn't hav…

How much would you pay for this?

Re: LinkedIn is scanning browser extensions

#83
post #40

Earlier quoted context omitted.

It isn’t exactly. They created a list of known extensions by their id and a file which is known to exist in that extension. The site iterates over each pair and tries to load that file, if it doesn’t error it knows the extension is installed. It’s a clever and difficult manual process, but it does bypass the security trying to prevent this kind of thing. I read that their reasoning is it exists to block users that us…

So the follow up question, is why is a random website, allowed to try and load arbitrary files?

This is how I interpreted the original question and indeed it makes no sense, JavaScript from a website should not be allowed to interact with extensions like this.

Re: LinkedIn is scanning browser extensions

#84
post #73
post #62

Earlier quoted context omitted.

If you want it to happen, we should talk requirements - what would you want from a LinkedIn NextGen? - A professional profile page - Contacts - Introductions/referrals - Ask my (sub-)network? Anything else?

A way for you to make money that isn’t ads / harvesting my data. Exportable format so I can leave if needed.

It's tough to generate revenue that isn't through ads.

That said, if the users could organize into special interest groups and create a walled-garden with default no ads, and then gate-keep advertisers to a permitted white-list.

I dunno, I'm just spit-ballin

Re: LinkedIn is scanning browser extensions

#85
This is re-posted article from the author's Substack that does a pretty bad job of explaining the situation. The second link in the article is supposed to take you to a "GitHub repository tracking the extension list" but it goes to a GitHub page for a plugin that hasn't been updated in 9 years.

It has a lot of hallmarks of LLM writings ("It's not this, it's that" and feeling like a lot of empty words rehydrated from an outline) while missing the real updates in the story like the German affidavit filed by a LinkedIn engineer who worked on these tools.

A key piece of information that this article omits is that the list of extensions being scanned for doesn't include anything you'd recognize or anything you'd even think to install. It's full of data extraction tools, scrapers, AI spam and recruiting tools (remember all those automated spammy LinkedIn messages you got?), and plugins masquerading as simple things that have been pulled from the extension store for violations.

A lot of articles have been trying hard to distract from this fact by highlighting that the list of extension includes things like a plugin designed to simplify web pages for neurodivergent users or an "anti-Zionist political tagger" to imply that they're trying to do fingerprinting based on those attributes, but they neglect to mention that those plugins were pulled from the extension store most likely because they were data exfiltrators dressed up as simple plugins to get people to install them.

An updated list is available here: https://browsergate.eu/extensions/

But read that site carefully and actually try to click the links. In this section they're trying to direct your attention away from all of the AI spam and data extraction tools with this section:

> The scan doesn’t just look for LinkedIn-related tools. It identifies whether you use an Islamic content filter (PordaAI — “Blur Haram objects, real-time AI for Islamic values”), whether you’ve installed an anti-Zionist political tagger (Anti-Zionist Tag), or a tool designed for neurodivergent users (simplify).

But click the links. They've all been pulled from the store. Extensions like that are often bait to get people to install scrapers that will use your computer and LinkedIn login to extract data and send it back to their servers.

So regardless of where you stand on probing for the presence of these scammy extensions, you should at least understand the facts rather than the story that companies like this are trying to sell you to drive traffic to their product.

I suggest cutting through the ragebait journalism and reading more directly from a recent source, like this affidavit filed in Germany by a LinkedIn engineer familiar with the project: https://browsergate.eu/downloads/Lakam-affidavit-redacted.pd...

Re: LinkedIn is scanning browser extensions

#86
post #75

Earlier quoted context omitted.

Huh, kind of. That's not the actual quote. Note I haven't followed the chain further back than this: https://browsergate.eu/the-evidence-pack/ LinkedIn’s systems “may have taken action against LinkedIn users that happen to have [XXXXXX] installed.” Edit: nice! I just notice indent-formatted text is now wrapping on mobile browsers. (Or at least ffm.) I wonder how long that's been fixed...

Saying 'I may have taken a shower' instead of 'I took a shower' makes my wife use her disapproving look.

True - also when you put something in quotes I think it should be a quote.

Re: LinkedIn is scanning browser extensions

#87
post #29

Can someone here please create a LinkedIn replacement for developers that 1. Doesn't have the spam 2. That doesn't look like it's from 2008 3. That only developers / engineers / tech folks can join 4. Doesn't try to log into your email to steal your contact list 5. That doesn't track you or your extensions / browser fingerprint 6. That doesn't have a bunch of fake "linkedinmaxxing" garbage content 7. that doesn't hav…

what exactly do you want this for? I think HN satisfies all of these (#2 - HN has a mid 90's aesthetic)

Re: LinkedIn is scanning browser extensions

#88
post #29

Can someone here please create a LinkedIn replacement for developers that 1. Doesn't have the spam 2. That doesn't look like it's from 2008 3. That only developers / engineers / tech folks can join 4. Doesn't try to log into your email to steal your contact list 5. That doesn't track you or your extensions / browser fingerprint 6. That doesn't have a bunch of fake "linkedinmaxxing" garbage content 7. that doesn't hav…

IRC has existed for decades.

I met some of my girlfriends through irc :)

Re: LinkedIn is scanning browser extensions

#89
post #50

Earlier quoted context omitted.

Be the change you want to see mate.

It's odd, yeah? We have the ability to vibe these things over a weekend, yet getting to the critical mass/tipping point of adoption is something else. Whatever happened to: if you build it, they will come?

It only took a weekend to build a social network preAI

Re: LinkedIn is scanning browser extensions

#90
post #29

Can someone here please create a LinkedIn replacement for developers that 1. Doesn't have the spam 2. That doesn't look like it's from 2008 3. That only developers / engineers / tech folks can join 4. Doesn't try to log into your email to steal your contact list 5. That doesn't track you or your extensions / browser fingerprint 6. That doesn't have a bunch of fake "linkedinmaxxing" garbage content 7. that doesn't hav…

Except for #2 I think you're looking for Hacker News.

didn't see your comment when I said basically the same thing. #2 is good though, bc HN has a pre-2008 look
Post reply on HN