5 ms·
Embed Linkedin profile page to see who visited your website
- ceejayoz 11y agoLinkedIn sets X-Frame-Options: sameorigin on requests, so this is likely to only work on old browsers (IE7 and lower, basically).
- bkm 11y agoYou could load it as an image, as cross-origin policies are not enforced for images. Not sure if their tracker is server-side or requires loading JS.
- diggan 11y agoAlso, you should be able to have a proxy on your own domain, changing nothing but the `X-Frame-Options` header.
- dangrossman 11y agoIt's cookies in each user's browser that tell LinkedIn who's viewing a profile. They wouldn't be transmitted to your proxy, so this wouldn't work.
- diggan 11y agoOh, that's true. Good point that I didn't think about at all. Just have done this myself in simple cases where cookies aren't involved.
- aidos 11y agoI've looked at the code - there definitely is some tracking done via XHR requests after the page load. This includes CSRF tokens so you can't hit those tracking links directly. Having said that, we still can't know whether or not the profile view information is harvested from the server-side logging of the main page view or not without testing it.
- annnnd 11y agoTo play the devil's advocate: if LinkedIn are smart they should offer this functionality (for premium users, of course). This is really useful info for businesses.
- dangrossman 11y agoPeople don't want every website they visit to automatically know their real identity. This would chase people off their platform.
- jan_g 11y agoLinkedIn also has an option 'Select what others see when you've viewed their profile' in account privacy settings which one can set to 'Anonymous'.
- annnnd 11y agoI think you overestimate how much ordinary people care / know about their online privacy. I think almost nobody would leave. That said, I myself wouldn't be too happy about it, but I would try to find some other solution instead of leaving LinkedIn.
- manigandham 11y agoNot sure why you're downvoted - because they already do this for businesses, just not private users. There's no money in it outside of selling data to businesses but LinkedIn, Facebook and tons of other major internet properties all share login data specifically to identify users across the web. (I work in digital advertising)
- username223 11y agoWhat kind of data for each profile? Sites? URLs? What types of "selectors" are available, e.g. "profile number X" or various demographics? And roughly what does it cost?
- 11y ago
- barkbark 11y agoFor what it's worth, this technique used to work by loading profiles as a 1x1 pixel image. That technique may still be effective.
- ishener 11y agobut the request has already been sent. Yes, the browsers will respect this header and not display the page and not run javascript, BUT what if the user tracking is done on the server in the first request? In that case, this technique might work...
- deleted 11y ago[deleted]
- orf 11y agoI assume they make a preflight HEAD request the same as CORS, in which case they would have to be very sloppy to make that count towards the stats.
- realityking 11y agoNope. There's no preflight for X-Frame-Options, as it was designed as a click jacking prevention.
- joshuahutt 11y agoI just tried it with Chrome. It works -- the view showed up, even though Chrome refused to load the page in the frame.
- Tinyyy 11y agoThat's one more reason to use extensions like Ublock and Ghostery.
- vlunkr 11y agoAnd one more reason to avoid linked in! If this actually works.
- lucb1e 11y agoNeat one! Not sure it will work too great for a hacker audience -- all sorts of content blockers, and they probably aren't logged into Linkedin 24/7 anyway -- but I really like the idea. The only issue I have with this is that it tracks people on yet another part of the Internet. Same reason as why I don't have Google Analytics or Youtube embedded videos or embedded Google Maps on my website (let alone Google Ads).
- monochromatic 11y agoCreepy. I hope LinkedIn breaks this soon.
- julien 11y agoThis is terri(fic|ble).
- noer 11y agoI read about this over a year ago (I think it may have been on HN, though the article was different). It seemed like it might be a security flaw and that it would get resolved, but I guess not.
- codingdave 11y agoI know my browsing habits/history is not private, and I know I am being tracked, even though I use plugins to minimize that. But having a marketing person send me a personalized email slapping me in the face with that tracking by explicitly telling me that they know what web page I visited on their site... that would be a pretty big turn off for me.
- dizzyviolet 11y agoExactly. The moment I get a cold contact like this, I'll put your business on the "Never use them for any reason" list. After I send them an email explaining why.
- hbbio 11y agoCan someone kill this news immediately, please? We fear for our current business model.
- rubidium 11y agoYou need a new business model.
- squiggy22 11y agoWhat size is the request / overhead?
- userbinator 11y agoThe size of a LinkedIn profile page: <iframe src="LINK TO YOUR LINKEDIN PROFILE" height="1" width="1" frameBorder="0"></iframe>
- ejcx 11y agoYou might not need a whole iframe. Why not just an img tag like a regular cross site request forgery over GET. If the WHO isn't logged with any js Magic it will work all the same.
- uptown 11y agoI've been thinking about creating a separate Chrome login for use on any browsing on social sites (FB, Twitter, LinkedIn) - maybe even a unique login for each. Would that be an effective way to isolate this type of thing?
- pavel_lishin 11y agoWhy not a create a new Chrome profile that's not signed into Google, and use its Incognito mode?
- uptown 11y agoThat's what I meant by Chrome login - a separate Chrome user profile, and wouldn't incognito mode require that I authenticate each time I visit these sites since any authentication cookies would be disposed of at the end of a session?
- r3bl 11y agoYou could just combine two separate browsers and use one for Facebook, Twitter, LinkedIn, Google and whatever else you wish for and use the second one while being logged out of social networks.
- yati 11y agoI have a LinkedIn profile that I've not updated for a long time. Have programmers here found it to be of any value, apart from being in the know of what your friends/colleagues are up to in their careers?
- krschultz 11y agoBeing able to contact former co-workers is invaluable. I moved out of New York in 2009 and moved back in 2012. In between the startup I had worked at basically gone out of business and everyone had new jobs. I didn't have anyone's email address or phone number or even Facebook connection, but I was connected on LinkedIn. I was able to reach out, find out what companies were hiring, get some interviews, etc. It massively helped in my move back and I'm in a far better place because of it. All the recruiters, resumes, cover letters, and interview prep pale in comparison to just having a bunch of people that want to work with you again. Ultimately whether you use LinkedIn or Facebook or a paper rolodex of phone numbers, the key thing is that you need that collection of weak connections. These are not my 20 friends, these are the 150 people that have been in a company with me and know my reputation but probably don't know much more than that. I find LinkedIn is a good tool for that. Sure there are some negatives, but I haven't found anything better. I don't necessarily want to be Facebook friends with all of the people I currently or previously worked with, and there is no way to keep an up to date contact list by yourself.
- yati 11y ago> Being able to contact former co-workers is invaluable. Agreed. Maybe I never felt the need of using LinkedIn for this because I'm already well connected with most of my former colleagues via other channels, since before this, I was at a pretty small startup. My friends with management jobs love LinkedIn as a job finding tool, and some even claim that being connected to influential people in the industry on LinkedIn helps them stand out somehow, but most of my programmer friends do not like the type of recruiters on LinkedIn. In my personal job searches, I almost never needed anything other than a CV, a cover letter and Github/StackExchange accounts (as opposed to "connections" with famous people).
- SmellyGeekBoy 11y ago
- userbinator 11y agoThe essence of this hack is "turn LinkedIn into a tracking pixel." I suppose it's possible to do it with some other social-network-type sites too.
- jedberg 11y agoThis is why I hate the term "growth hacking". It encourages this kind of behavior. I'd be curious to know if anyone on HN thinks that this is morally and ethically ok? What happened to the good old days when "growth hacking" was building a good product that people want to share with each other and then making it easy for them to share?
- alanorourke 11y agoLike all marketing it can be used for good or ill. It is something that we approached internally very carefully.
- lawstudent2 11y ago> I'd be curious to know if anyone on HN thinks that this is morally and ethically ok? 1. Yes. Absolutely. What could be morally unacceptable about this? 2. I very strongly believe in business ethics. And consumer protection, and worker protection. I don't think that this, in general, rises to the level of even being an issue with regard to consumer protection or worker protection. I don't know what about this would be unethical. 3. If you are going to say "user tracking" then I am just at a loss. This is categorically no different than any of the many dozens of user tracking services already in use. Except that, unlike many of those services who are very, very explicitly shady and fly-by-night, LinkedIn is, overall, an ethical player. When I visit NYTimes.com, my ghostery registers: * Chartbeat * Doubleclick * Dynamic Yield * Facebook Connect * Facebook Custom Audience * Google Analytics * Moat * Netratings Site Census * New Relic * Optimizely * ScoreCard Research * WebTrends As long as this guy has an appropriately written privacy policy, I see absolutely nothing legally wrong with this, either. Morally - I just don't even know where to begin on how facile a complaint I consider that to be.
- hyperpape 11y agoIt is a third party exploiting LinkedIn's tracking to monitor and expose identifiable information about who is visiting their website that LinkedIn probably didn't intend to be public. Obviously, there are lots of trackers out there. But the fact that those trackers exist, and we're sorta, kinda, maybe ok with it, or at least resigned to it--that doesn't imply that we're ok with any third party using leaks of that information to track us. Probably the reasonable thing to do is say "if we're ok with X tracking us, we're ok with everyone tracking us, because the information will leak." But that's not the same as saying it's ok for everyone to try and make it leak. It wouldn't at all surprise me if it's against LinkedIn's TOS, and the author admits as much. What about this is not unethical?
- dorfsmay 11y agoI wonder what impact it has on page rank? I remember playing with 1x1 pixel links a few years back and finding my page completely disappear from Google.
- santialbo 11y agoThat's actually a sneaky way of following up with people who visited your carrers page. Check their linkedin and if they are a nice candidate send them a message through linkedin.
- bigredtech 11y agoWhile doing this for your own profile could be useful for you and some metrics you may want, someone else could be a bit more nefarious. On a high profile/traffic blog, web app, or site - could just include some targeted, random, or interesting LinkedIn profiles, and then all of these people would be bombarded with misinformation about who's viewed their page. Want to confuse sales team at XYZ Startup Corp., sure have all of their profile links in hidden IFrames too...
- userbinator 11y agoIf all you need to get onto the list is a request to the profile page URL, even a simple image link in a forum signature/profile image/etc. might be enough...
- samstave 11y agoHmm so you could then see everyone who loaded that page/comment? This has probably already been an exploit used by some people..
- buro9 11y agoThis is also why you should segregate your browsing to different browsers and different browsing modes. I personally now use two browsers for different reasons: * Chrome = Gmail, Drive, Docs, Search that I wanted tracked (work related usually) * Chrome Incognito = Social media (Twitter, Instagram) and sites I stay on most of the time (HN) * Firefox Private Browsing = Search that I do not want tracked (shopping research usually), shopping, news sites, media sites, LinkedIn One can also view these in terms of cookie/data retention periods: * Chrome = +1 week * Chrome Incognito = 1 day maximum * Firefox Private Browsing = Session (created and destroyed for a specific purpose, short-lived) And yes, it's not convenient as if I get an email with a link in it I will copy the link into the appropriate browser and then browse to it. But then the upside is that I don't get tracked relentless by tracking stuff that expects cookies. Oh, and I'm aware of IP tracking too. I tend to use PIA VPN for this reason and do not autoconnect to the closest place, but instead semi-randomly pick somewhere in Europe to surface from each day.
- jadyoyster 11y agoSomething which might be useful if you want to do this: you can use Firefox with multiple profiles, by starting it with the '-P <profile-name>' option.
- oxplot 11y agoChrome also has multiple profile feature.
- hu_me 11y agogoogle chrome has a multiple user option with quick switching, i have multiple profiles with different settings / extensions suited to mode. saves the time to login to accounts [unless thats the whole point for you].
- joshbaptiste 11y agoLove this, and this is similar to how I surf, Chrome + umatrix = Legit news and Google sites Opera = Facebook, Instagram Firefox + FoxyProxy + Ghostery + noscript = Shady places
- BillFranklin 11y agoInteresting, I just tested this. It doesn't work as an image or an iframe on Chrome. iFrame wont work on modern browsers: Refused to display 'my linkedin url' in a frame because it set 'X-Frame-Options' to 'sameorigin'. Image also probably did not work, though Linkedin might delay reporting profile visits, any ideas?
- bigtunacan 11y agoThis is interesting; I was wondering though are you really using the Chrome Scraper extension to get this data? Is there some way to run that on a schedule, or are you manually scraping periodically?
- mgalka 11y agoI think there are some ethical issues with this, but the idea is brilliant.
- _xander 11y agoCataclysmic outcome: linkedin is embedded on a porn site/page and starts feeding the names and professional profiles of visitors to the owner. These people are then contacted and blackmailed based on socio-economic status (e.g. targeting rich married individuals). This linkedin feature has always been a pure money grabbing ploy with no merit other than the premium revenues generated from exploiting the emotional vulnerability of people and #growthinghacking needs of recruiters.
- lotsofcows 11y agoI love it when people use meaningless phrases like "reach out to you". It makes spam filtering so easy!