Live data from Hacker News

LinkedIn is searching your browser extensions

browsergate.eu

801–810 of 836 posts

Re: LinkedIn is searching your browser extensions

#801
post #14

The headline seems pretty misleading. Here’s what seems to actually be going on: > Every time you open LinkedIn in a Chrome-based browser, LinkedIn’s JavaScript executes a silent scan of your installed browser extensions. The scan probes for thousands of specific extensions by ID, collects the results, encrypts them, and transmits them to LinkedIn’s servers. This does seem invasive. It also seems like what I’d expect…

"The headline seems pretty misleading."

How? What exactly would a reader be "mislead" to believe

The part about "inherently sinister" seems to be a thought from the mind of an HN commenter not the authors of the submitted web page. The later only describe LinkedIn's actions as illegal, not "sinister". The laws cited by the authors do not appear to consider any "state of mind", e.g., "sinister", or intent as relevant

"But I do take some issue with the alarmist framing of what's going on."

AFAICT, the submitted web page does not suggest that anything LinkedIn does is "dangerous", i.e., cause for "alarm". What it suggests is that LinkedIn's actions _violate European privacy laws_. The authors claim LinkedIn's actions present an opportunity to enforce these laws, i.e., "take action"

https://browsergate.eu/why-its-illegal/

https://browsergate.eu/take-action/

Re: LinkedIn is searching your browser extensions

#802

Earlier quoted context omitted.

It’s the fake drama. Punchy sentences. Contrast . And then? A banal payoff.

Human journalists and marketing copy writers have been writing like this for at least 50 years, if not considerably longer. I am exhausted by so many people calling writing out as AI without sufficient proof other than writing style. Some things are more obvious, sure... maybe I'm just too stupid to see a lot of the rest of it? But so much of what gets called out seems incredibly familiar to me compared with traditio…

I think one factor is the lack of variation. Sure, a copywriter might use those techniques as a hook, but there’s far more content using them paragraph after paragraph after paragraph than I’ve ever seen before.

You might also reframe how you read those comments. Perhaps when people are labeling a piece as “written by AI,” they’re just conveying that they perceive it to use the same “voice” that LLMs use, and judge that voice negatively. Sometimes people say things non-literally and don’t need proof.

Re: LinkedIn is searching your browser extensions

#803

I don't have a linkedin acct. So imagine my shock when I "googled" myself and found a linkedin profile connecting my name to a company I presently have a consulting arrangement with (1099 not W2). I went ballistic and fired off an email to the consulting firm to take down the profile immediately or face legal action (a bluff). Couple days later, the company forwarded an email they received from linkedin confirming th…

Are you sure they took it down completely, not just removed from public eyes? Majority of LinkedIn income is from businesses, they might still sell it in some form (e.g. stats/aggregates).

Re: LinkedIn is searching your browser extensions

#804

Earlier quoted context omitted.

Regulation does not necessarily need to be about deciding what's right and what's wrong. It's about making life better for people. That's supposed to be why we have government. If they are not improving people's lives, why do we even have them? Too many people see the government doing nothing to improve their lives and think there's totally nothing wrong with that.

I fail to see how some of the octogenarians in DC, who are making a kiling for decades in trading on market moves that they initiate/regulate themselves, are making life better for your family, or mine.

Because at least half the country thinks that government can't/shouldn't help them, and reliably votes for people who can't/won't make their lives better. We get the government we vote for, and too many people think the government's job is to grief people.

Re: LinkedIn is searching your browser extensions

#805

Earlier quoted context omitted.

I rather suspect the information was siphoned to linkedin from the payroll company the consulting firm was using. While there are a zillion small consulting firms, there are a small number of firms which process their payroll (whether to employees or independent contractors like myself). I have no evidence to back this up but after thinking it through, it made more sense than every little mom/pop/medium size niche co…

Interesting. That's a possibility... but how much information did the LinkedIn account have? Did it have your full job title? I'm not sure how much information is shared with payroll providers. Again, there's no real reporting on the internet of LinkedIn creating profiles for people without their consent. If you have any documentation and details, this is the kind of thing worth posting here in full detail and/or con…

It reminds me of that thing I had heard of people doing on Facebook years ago. Someone wouldn't have a Facebook account "yet", so one of their friends/family/whomever would create one on their behalf with an assumption that they were being helpful to the other party. "It's all ready to go once you want to login! I knew your email address, so just do a password reset when you start using it. You're welcome!"

I believe even an episode of South Park covered it.

The difference there being that, with the Facebook relationship status stuff, spouses were feeling societal pressure to show a public declaration and "proof" of their partners existence/mutual status. With something like LinkedIn though...does that same sort of pressure exist? Are Hiring Managers (or whomever) feeling some kind of professional pressure to "prove" how many real life people work with/for their company? Does getting the number of users marked as working for that company above a threshold give them secret, special privileges in some locked-off business area of LinkedIn? Or is it just pure clout chasing? It's very odd. It feels like a violation in some way I can't really articulate. "Compulsory volunteer account-to-ID association"? I don't know what to call that. It's gross.

Re: LinkedIn is searching your browser extensions

#806
post #334

Earlier quoted context omitted.

> Alongside thousands of other extensions. If they were scanning for a dozen things and this was one of them, I’d tend to agree with you. But this sounds more like they enumerated known extension IDs for a large number of extensions because getting all installed extensions isn’t possible. To take a step back further: what you're saying here is that gathering more data makes it less sinister . The gathering not being…

> The gathering not being targeted is not an excuse for gathering the data in the first place. I’m not saying it is. My point is that they appear to be trying to accomplish something like getInstalledExcentions(), which is meaningfully different from a small and targeted list like isInstalled([“Indeed.com”, “DailyBibleVerse”, “ADHD Helper”]). One could be reasonably interpreted as targeting specific kinds of users. W…

> But what one might infer about the intent of one vs. the other is quite different, and I think that matters.

That's where we disagree: intent doesn't matter here, because the intent of the person gathering the data is not the same as those who have access to the data. I don't care if the team tasked with implementing this believed they were saving the world, because once this data is in the hands of a big corporation, in perpetuity, and the thousands of people that entails, and it diffuses across advertisers and governments, be it through leaks, backroom deals, or perfectly above-board operations, it makes no difference how it got there.

The two paragraphs given:

> “Microsoft reduces malicious traffic to their websites by employing an anti-bot/anti-abuse system that builds a browser fingerprint consisting of categories of identifiers, including Browser/OS version, installed fonts, screen resolution, installed extensions, etc. and using that fingerprint to ban known offenders. While this approach is effective, it raises major privacy concerns due to the amount of information collected during the fingerprinting process and the risk that this data could be misused to profile users”.

vs.

> “Microsoft secretly scans every user’s computer software to determine if they’re a Christian or Muslim, have learning disabilities, are looking for jobs, are working for a competitor, etc.”

The latter is the tangible effect of the former. The two aren't mutually exclusive, and considering the former has long gone unaddressed in its most charitable form, it only makes sense to use a particularly egregious example of it taken to its natural conclusion to address in courts and the public consciousness.

Re: LinkedIn is searching your browser extensions

#807
post #462
post #14

The headline seems pretty misleading. Here’s what seems to actually be going on: > Every time you open LinkedIn in a Chrome-based browser, LinkedIn’s JavaScript executes a silent scan of your installed browser extensions. The scan probes for thousands of specific extensions by ID, collects the results, encrypts them, and transmits them to LinkedIn’s servers. This does seem invasive. It also seems like what I’d expect…

Javascript can query chrome extensions [1] and much more [2]. [1] - https://browserleaks.com/chrome [2] - https://browserleaks.com/javascript

More [1]

[1] - https://www.whatsmyip.org/more-info-about-you/

Re: LinkedIn is searching your browser extensions

#808
I am the one who published the findings at browsergate.eu and I think most of the debate here misses the point.

This is not about sandboxed or not. That's not the point.

The point is this is being done on a platform with 1 billion users with REAL NAMES, with REAL JOBS, working for REAL EMPLOYERS.

This is a privacy violation by every meaning of the term. But it is a lot more: It is the largest INDUSTRIAL ESPIONAGE operation I have ever heard of.

Literally every company on the planet (and every institution) have their employees browsers scanned for installed extensions. Some 200 are DIRECT COMPETITORS to Microsoft.

This is not about the behavior or a rando website trying to stop malicious actors.That's simply misses the point. By far.

Re: LinkedIn is searching your browser extensions

#809
post #14

The headline seems pretty misleading. Here’s what seems to actually be going on: > Every time you open LinkedIn in a Chrome-based browser, LinkedIn’s JavaScript executes a silent scan of your installed browser extensions. The scan probes for thousands of specific extensions by ID, collects the results, encrypts them, and transmits them to LinkedIn’s servers. This does seem invasive. It also seems like what I’d expect…

"The headline seems pretty misleading." How? What exactly would a reader be "mislead" to believe The part about "inherently sinister" seems to be a thought from the mind of an HN commenter not the authors of the submitted web page. The later only describe LinkedIn's actions as illegal, not "sinister". The laws cited by the authors do not appear to consider any "state of mind", e.g., "sinister", or intent as relevant…

*misled

Re: LinkedIn is searching your browser extensions

#810

Earlier quoted context omitted.

fair enough on tracking history in the centralized model. I had suspicions there would be hidden costs that might make it too expensive. i dont think the data storage would be as much of a problem as the cost to write it to storage. I wasn't fully envisioning credits only being transacted once before cashout either. I was thinking more along the lines of being able to create something that goes viral, a lot of people…

Even with user to user credits it would take a lot for the number of transactions to go above 2. That would mean more than half the money is going to viral payouts. And was this assuming you'd only take a cut on the cash going in and out? Because even a 0.1% cut of the transactions would mean you have $1000 to handle the amount of data I described in the last comment.

>And was this assuming you'd only take a cut on the cash going in and out

I think fee needs to be per transaction, maybe not cash flowed per transaction but accrued per transaction.

Say we both self-host a website for our favorite daily game, and I use yours about as much as you use mine. We would transfer roughly the same amount of credits back and forth to each other ad-infinitum. but the credit service provider is accumulating only expenses with each transaction.

Say someone make a lot of bot accounts to simulate user traffic, and it sends each of them credits to use to visit their own site. the host collects the credits from the bots and transfers them back to the bots to keep them running.

Post reply on HN