10 ms·
LinkedIn checks for 2953 browser extensions
- lapcat 8mo ago[removed]
- ronsor 8mo agoThis is a security vulnerability and should be patched. Sorry, LinkedIn. (Alternatively extension developers can modify their extensions to block these requests!)
- 0cf8612b2e1e 8mo agoNo kidding. I am shocked this works. Does Firefox have a similar weakness?
- burkaman 8mo agoI don't see any evidence of this happening in Firefox. Either it's more difficult or they just didn't bother, either way I'm happy. Edit: Can't find much documentation on exactly how the anti-fingerprinting works, but this page implies that the browser blocks extension detection: https://support.mozilla.org/en-US/kb/trackers-and-scripts-firefox-blocks-enhanced-track#w_fingerprinters https://support.mozilla.org/en-US/kb/trackers-and-scripts-fi...
- Wicher 8mo agoFrom memory from working with these a couple of years ago: Firefox extension asset URLs are random and long (there's a UUID in there iirc). The extension itself can discover its randomized base so that it can output its asset URLs, but webpage code can't.
- cxr 8mo agoIt doesn't work. The person who posted the comment you're responding to has absolutely no idea what he's talking about. He confabulated the entire explanation based on a single misunderstood block of code that contains the comment «Remove " - Chrome Web Store" suffix if present» in the (local, NodeJS-powered) scraper that the person who's publishing this data themselves used to fetch extension names.
- tech234a 8mo agoNo. Firefox always randomizes the extension ID used for URLs to web accessible resources on each restart [1]. Apparently, manifest v3 extensions on Chromium can now opt into similar behavior [2]. [1]: https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/WebExtensions/Chrome_incompatibilities#miscellaneous_incompatibilities https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/Web... [2]: https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/WebExtensions/manifest.json/web_accessible_resources#manifest_v3_syntax https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/Web...
- tech234a 8mo agoAn additional improvement added in manifest v3 in both Chromium and Firefox is that extensions can choose to expose web accessible resources to only certain websites. Previously, exposing a web accessible resource always made that resource accessible to all websites.
- cxr 8mo agoThat's a different form of defense. The original claim in this thread was that LinkedIn's fingerprinting implementation was making cross-site requests to Chrome Web Store, and that they were reading back the response of those requests. Firefox isn't susceptible to that, because that's not how Firefox and addons.mozilla.org work. Chrome, as it turns out, isn't susceptible to it, either, because that's also not how Chrome and the Chrome Web Store work. (And that's not what LinkedIn's fingerprinting technique does.) (Those randomized IDs for content-accessible resources, however, do explain why the technique that LinkedIn actually uses is is a non-starter for Firefox.)
- toomuchtodo 8mo agoIs there no browser setting to defend against this attack? If not, there should be, versus relying on extension authors to configure or enable such a setting.
- zahlman 8mo agoI imagine that it would require browsers to treat web requests from JS differently from those initiated by the user, specifically pretending the JS-originating requests are by logged-out or "incognito" users (by, I suppose, simply not forwarding any local credentials along, but maybe there's more to it than that). Which would probably wreak havoc with a lot of web apps, at least requiring some kind of same-origin policy. And maybe it messes with OAuth or something. But it does seem at least feasible.
- circuit10 8mo agoAs people have said it’s not making requests to web store, that’s just part of this repository looking for what extensions it’s blocking via nodejs Browsers already have strong protections against that sort of thing, look up the same-origin policy and CORS
- zahlman 8mo agoI see, I was too credulous.
- MrGilbert 8mo agoI'm not sure how you'd patch that. Any request that’s made from the current open tab / window is made on behalf of the user. From my point of view, it's impossible for the browser to know, if the request is legit or not.
- ronsor 8mo agoAn ideal implementation of the same origin policy would make it impossible for a site (through a fetch call or otherwise) to determine whether an extension resource exists/is installed or the site simply lacks permission to access it.
- cobertos 8mo agoWouldn't that mean 2900 requests from fingerprint.js??
- deleted 8mo ago[deleted]
- halapro 8mo agoIf this is true, it's insane that this would work: - why does CWS respond to cross-site requests? - why is chrome sending the credentials (or equivalent) in these requests? - why is the button enabled server-side and not via JS? Google must be confident in knowing the exact and latest state of your installed extensions enough to store it on their servers, I guess
- cxr 8mo agoIt's not true. The person you're responding to has a habit of posting implausible-but-plausibly-plausible nonsense, and it's not how this works at all.
- lapcat 8mo agoI made the mistake of trying to skim the code hastily before I had to leave to run an errand, and yes it turns out I was wrong, but please refrain from the personal comments, and no, I don't have any such "habit."
- cxr 8mo agoWrong again. (PS: The fact that you have now replied—which automatically disables comment deletion—is the only thing that prevented my removing it just now. So great job.)
- lapcat 8mo ago> The fact that you have now replied—which automatically disables comment deletion—is the only thing that prevented my removing it just now. So great job. How was I supposed to know that you intended to delete it? In any case, you may still have time to edit your comment, as I did with my erroneous root-level comment, since I can't delete that either, for the same reason.
- cxr 8mo agoNot interested. You also shouldn't have done that. You broke the thread—exactly what HN's no-deleting-comments-that-have-replies check was created to prevent. Consider this: just stop being reckless.
- usefulposter 8mo agoIsn't it enumerating web_accessible_resources? Below static collectFeatures(e, t) there is a mapping of extension IDs to files in the const r (Minified JS, obviously.) Edit: Confirmed. It's not pinging the Chrome Web Store. https://blog.castle.io/detecting-browser-extensions-for-bot-detection-lessons-from-linkedin-and-castle/ https://blog.castle.io/detecting-browser-extensions-for-bot-...
- jsheard 8mo agoLooks to me like LinkedIn is fetching chrome-extension://{extension id}/{known filename} and seeing if it succeeds, not pinging the web store. Should be patched nonetheless though, that's a pretty obscene fingerprinting vector.
- what 8mo agoHow do you patch it? The extensions themselves (presumably) need to access the same web accessible resources from their content scripts. How do you differentiate between some extension’s content script requesting the resource and LinkedIn requesting it?
- jsheard 8mo agoFirefox already mitigates this by randomizing the extension path: https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/WebExtensions/manifest.json/web_accessible_resources https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/Web... The file is then available using a URL like: moz-extension://<extension-UUID>/images/my-image.png" <extension-UUID> is not your extension's ID. This ID is randomly generated for every browser instance. This prevents websites from fingerprinting a browser by examining the extensions it has installed.
- zahlman 8mo agoDoesn't the browser know which script it's running? Why can't it just deny access to the specified path, except to the extension itself?
- cxr 8mo agoIt does by default, except for the files from the extension that the extension author has explicitly designated as content-accessible. It's explained ("Using web_accessible_resources") at the other end of the link.
- chocolatkey 8mo agoThat’s incorrect, it’s trying to load an asset (hardcoded unique per-extension path) for each extension, there is a huge list of these in the source code: https://raw.githubusercontent.com/mdp/linkedin-extension-fingerprinting/refs/heads/main/fingerprint.js https://raw.githubusercontent.com/mdp/linkedin-extension-fin...
- deleted 8mo ago[deleted]
- minkeymaniac 8mo agoI can confirm.. open up linkedIn.. hit F12 and watch the error count keep going up and up and up Screenshots found here https://x.com/DenisGobo/status/2018334684879438150 https://x.com/DenisGobo/status/2018334684879438150
- iLoveOncall 8mo ago[flagged]
- mongrelion 8mo agoCurious question: why would they check for installed extensions on one's browser?
- deleted 8mo ago[deleted]
- jppope 8mo agomost automations for sales and marketing use browser extensions... linkedIn wants you using their tools not 3rd party
- Nextgrid 8mo agoTheir own tools suck, that’s the issue.
- direwolf20 8mo agoThird–party tools don't bring money to LinkedIn, that's the issue. Rather than try to compete, much easier to force you to use their tools! Reddit did the same thing.
- Nextgrid 8mo agoEasy solution is to sell a plan that explicitly allows third-party tool usage. Then they get the money and the users get the tooling LinkedIn is incapable of building themselves. (except they won't, because they're not after money but engagement, and their built-in tools suck on purpose to maximize wasted time)
- HPsquared 8mo agoAn attempt at fingerprinting, I suppose?
- staticshock 8mo agoFor a social network, more information about their users = better ad targeting. It likely gets plumbed into models to inform user profiles.
- rdoherty 8mo agoSkimming the list, looks like most extensions are for scraping or automating LinkedIn usage. Not surprising as there's money to be made with LinkedIn data. Scraping was a problem when I worked there, the abuse teams built some reasonably sophisticated detection & prevention, and it was a constant battle.
- bryanrasmussen 8mo agofrom the code doesn't look like they do anything if they have a match, they just save all the results to a csv for fingerprinting?
- cxr 8mo ago"The code" here you're referring to (fetch_extension_names.js[1]) isn't and doesn't claim to be LinkedIn's fingerprinting code. It's a scraper that the researcher behind this repo wrote themselves in order to create the CSV of the data that they're publishing here. LinkedIn's fingerprinting code, as the README explains, is found in fingerprint.js[2], which embeds a big JSON literal with the IDs of the extensions it probes for. (Sickeningly enough, this data starts about two-thirds of the way through the file* and isn't the culprit behind the bulk of its 2.15 MB size…) * On line 34394; the one starting: const r = [{ id: "aacbpggdjcblgnmgjgpkpddliddineni", file: "sidebar.html" 1. <https://github.com/mdp/linkedin-extension-fingerprinting/blob/main/fetch_extension_names.js https://github.com/mdp/linkedin-extension-fingerprinting/blo...> 2. <https://github.com/mdp/linkedin-extension-fingerprinting/blob/main/fingerprint.js https://github.com/mdp/linkedin-extension-fingerprinting/blo...>
- bryanrasmussen 8mo agothanks, my fault for not reading the read me and just doing a quick read of the code.
- hsbauauvhabzb 8mo agoWont someone think of poor little LinkedIn, a subsidiary of one of the largest data brokers in the world?
- zahlman 8mo ago> This repository documents every extension LinkedIn checks for and provides tools to identify them. I get that the CSV lists the extensions, and the tools are provided in order to show work (mapping IDs to actual software). But how was it determined that LinkedIn checks for extensions with these IDs? And is this relevant for non-Chrome users?
- usefulposter 8mo agoTechnical writeup from a few weeks ago by a vendor that explains how LinkedIn does it, then boasts that their approach is "quieter, harder to notice, and easier to run at scale": https://blog.castle.io/detecting-browser-extensions-for-bot-detection-lessons-from-linkedin-and-castle/ https://blog.castle.io/detecting-browser-extensions-for-bot-...
- Aurornis 8mo agoI suggest everyone take a look at the list of extensions and their names for some very important context: https://github.com/mdp/linkedin-extension-fingerprinting/blob/main/chrome_extensions_with_names_all.csv https://github.com/mdp/linkedin-extension-fingerprinting/blo... I didn't find popular extensions like uBlock or other ad blockers. The list is full of scammy looking data collection and AI tools, though. Some random names from scrolling through the list: - LinkedGPT: ChatGPT for LinkedIn - Apollo Scraper - Extract & Export Apollo B2B Leads - AI Social Media Assistant - LinkedIn Engagement Assistant - LinkedIn Lead Magnet - LinkedIn Extraction Tool - OutreachSheet - Highperformr AI - Phone Number and Email Finder - AI Agent For Jobs These look like the kind of tools scummy recruiters and sales people use to identify targets for mass spamming. I see several AI auto-application tools in there too.
- NicuCalcea 8mo agoLinkedIn itself provides tools for scummy recruiters to mass spam, so this is just them protecting their business. Also, not all of them are data collection tools. There are ad blockers listed (Hide LinkedIn Ads, SBlock - Super Ad Blocker) and just general extensions (Ground News - Bias Checker, Jigit Studio - Screen Recorder, RealEyes.ai — Detect Deepfakes Across Online Platforms, Airtable Clipper).
- cxr 8mo ago> I suggest everyone take a look at the list of extensions and their names for some very important context[…] I didn't find popular extensions like uBlock Unsurprising outcome since uBlock (specifically: uBlock Origin Lite, the only version available for Chrome on the Chrome Web Store) makes itself undetectable using this method. (All of its content-accessible resources have "use_dynamic_url" set to "true" in its extension manifest.) So its absence in this data is not dispositive of any actual intent by LinkedIn to exclude it—because they couldn't have included it even if they wanted to.
- cbsks 8mo agoLooks like Firefox is immune. This works by looking for web accessible resources that are provided by the extensions. For Chrome, these are are available in a webpage via the URL chrome-extension://[PACKAGE ID]/[PATH] https://developer.chrome.com/docs/extensions/reference/manifest/web-accessible-resources https://developer.chrome.com/docs/extensions/reference/manif... On Firefox, web accessible resources are available at "moz-extension://<extension-UUID>/myfile.png" <extension-UUID> is not your extension's ID. This ID is randomly generated for every browser instance. This prevents websites from fingerprinting a browser by examining the extensions it has installed. https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/WebExtensions/manifest.json/web_accessible_resources https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/Web...
- awesome_dude 8mo agoThis is probably a naive question, but... Doesn't the idea of swapping extension specific IDs to your browser specific extension IDs mean that instead of your browser being identifiable, you become identifiable? I mean, it goes from "Oh they have X, Y , and Z installed" to "Oh, it's jim bob, only he has that unique set of IDs for extensions"
- triceratops 8mo agoIt's not a naive question. This comment says it's not possible to do that: https://news.ycombinator.com/item?id=46905213 https://news.ycombinator.com/item?id=46905213
- awesome_dude 8mo agoOh, it's (re)randomised upon each restart, whew, thanks for the heads up edit: er, I think that that also suggests that I need to restart firefox more often...
- tech234a 8mo agoThe webpage would have to scan the entire UUID space to create this fingerprint, which seems unlikely.
- hasperdi 8mo agoAnother thing... they alter the localStorage & sessionStorage prototype, by wrapping the native ones with a wrapper that prevent keys that not in their whitelist from being set. You can try this by opening devtools and setting localStorage.setItem('hi', 123)
- tech234a 8mo agoSee also: a demo page for the same technique that can enumerate many extensions installed in your browser: https://browserleaks.com/chrome https://browserleaks.com/chrome
- xnx 8mo agoYuck. Disgusting that extension detection is possible.
- shouldnt_be 8mo agoI wrote an article about it a couple of months ago. I also explain why, how and a way to prevent it. https://javascript.plainenglish.io/the-extensions-you-use-are-not-a-secret-especially-to-linkedin-64a8ef3f5b25?gi=62ac8f643b12 https://javascript.plainenglish.io/the-extensions-you-use-ar...
- jmholla 8mo agoTo clarify, you talk about why it's possible, not why LinkedIn is doing it, right? Or did I miss something in your article.
- shouldnt_be 8mo agoFrom the article: > ... it is used to check for abuse (bot use) > If you follow a LinkedIn influencer and they get banned, now you know why.
- DrStartup 8mo agoSetup a quick CDP connection. Have Claude Code attach and inject JS into Page.addScriptToEvaluateOnNewDocument. Loads before the page. Typical early hooks: • fetch wrapper • XMLHttpRequest.prototype.open/send wrapper • WebSocket constructor wrapper • history.pushState/replaceState wrapper • EventTarget.addEventListener wrapper (optional, heavy) • MutationObserver for DOM diffs • Error + unhandledrejection capture
- shj2105 8mo agowhat would this do?
- bluebxrry 8mo agoIt increases the number of jobs at the job factory. You write it into a Chrome extension and name it 2954.
- HumanOstrich 8mo agoThis is irrelevant to the article and discussions here. Weird copypasta bullet points too.
- userbinator 8mo agoLooks like whatever LLM you used is not doing a very good job.
- input_sh 8mo agocut -d',' -f2 chrome_extensions_with_names_all.csv | grep -c "AI" 474 Only 16%!?
- unstatusthequo 8mo agoI’m probably on the list. I made a LinkedIn Redactor that allowed you to add keywords and remove posts from your thread that included such words. It’s the X feature but for LinkedIn. Anyway, got a cease and desist from those lame fucks at LI. So I removed from the chrome store but it’s still available on GitHub.
- avastel 8mo agoI wrote a blog post recently about the technique used by LinkedIn to do extension probing, as well as other ways to do it with less side effects https://blog.castle.io/detecting-browser-extensions-for-bot-detection-lessons-from-linkedin-and-castle/ https://blog.castle.io/detecting-browser-extensions-for-bot-...
- pests 8mo agoNice write up, definitely exactly this.
- direwolf20 8mo agoPatch Firefox so navigator.webdriver is always false, then remote control it. Seems not easily detectable. You could still watch for fast input patterns...
- bastard_op 8mo agoChrome is the new IE6. Google set themselves up to be the next Microsoft and is "ad friendly" in all the creepy ways because that's what Google IS an ad company. All they've contributed to security is diminishing the capability of adblockers and letting malware to do bad things to you as consumers.
- 0xbadcafebee 8mo agoHe who controls the Ads, controls the Internet.
- themafia 8mo ago> Google set themselves up to be the next Microsoft Google became a monopoly. All monopolies do this.
- cyanydeez 8mo agothere's a step before that. Google is a pure capitalist enterprize>pure capitalism goes to monopoly>all monopolies do this.
- braiamp 8mo agoPure unregulated market, that doesn't guarantee free market assumptions does that. Capitalism doesn't need it. Without mechanisms that allow for the free entry/exit of competitors, fair and simultaneous access to information, preventing cartels/price fixing, .... a bunch of assumptions for perfect free market to happen, the market will tend towards monopolies due cumulative advantage (in econ. known as Matthew effect), since small advantages compound into dominance.
- brianpbeau 8mo agoImagine being the nerd that is still using Chrome in the YOL 2026.
- userbinator 8mo agoChrome has become much worse than IE6. Microsoft was not in the business of tracking users and selling ads back then.
- dwedge 8mo agoI wonder if this is why the linkedin feed blocker I installed in Firefox 2 weeks ago stopped working for me within 24 hours
- ta988 8mo agoSo it really is espionage at all levels.
- mrkramer 8mo agoLinkedIn is the worst walled garden of all of them.
- wolvoleo 8mo agoI also really don't understand why their subscription is so extremely expensive for someone who is not a recruiter. It's already a sycophantic cesspool of corporate drones repeating mindless PR. I unfollow everyone who re"tweets" feel-good memes or corporate crap and I have very few people I follow left over :) Critical discussion doesn't exist, if I comment anything that's not 100% celebratory of so-called company successes I get blocked.
- grvdrm 8mo agoClose second: conference apps. They infuriate me. Data harvesting machines in all ways. Incredibly user hostile. Example: making me scroll endlessly through attendee lists. Lack of good filters. Etc. Can’t download attendee lists. I finally lost my patience and wrote a Selenium script to page through an app and extract everything. Worked well after some initial trial and error.
- DOM100 8mo agoconst nameA = getName(a).toLowerCase(); const nameB = getName(b).toLowerCase(); return nameA.localeCompare(nameB); const msg = createDoneMessage(); msg.style.opacity = '1'; console.log("Extensions sorted alphabetically!"); console.table(sortedCards.map(c => ({ name: getName(c), id: c.id || '—'
- deleted 8mo ago[deleted]
- bitbasher 8mo agoLooks like this has been known since 2019. https://www.nymeria.io/blog/linkedins-war-on-email-finder-extensions-like-nymeria https://www.nymeria.io/blog/linkedins-war-on-email-finder-ex...
- insin 8mo agoSo every Chrome extension that wants to avoid being detected this way needs to proxy fetch() on the target site, imagining someone with a bunch of them installed having every legit HTTP request on the target site going through a big stack of proxies
- ramuel 8mo agoWe live in the best timeline.
- bitbasher 8mo agoThe list of extensions being scanned for are pretty clear and obvious. What is really interesting to me are the extensions _not_ being scanned for that should be. The big one that comes to mind is "Contact Out" which is scan-able, but LinkedIn seems to pretend like it doesn't exist? Smells like a deal happened behind the scenes... https://chromewebstore.google.com/detail/email-finder-by-contactou/jjdemeiffadmmjhkbbpglgnlgeafomjo https://chromewebstore.google.com/detail/email-finder-by-con...
- cxr 8mo agoThat extension cannot be fingerprinted by its content-accessible resources. It doesn't declare any in its manifest.
- imvyarqoyzcuem 8mo agointeresting to see why they don't block Claude in chrome or even this: https://chromewebstore.google.com/detail/dassi-ai-coworking-agent/bjcngahpcjeililljmfegmlanlpgibdi https://chromewebstore.google.com/detail/dassi-ai-coworking-...
- ddtaylor 8mo agoDoes anyone know if Brave has any defense against this like Firefox does?
- fHr 8mo agoLinkedin is such a shity wanabe HR adult day care recruiting bs platform, if it would go offline tomorrow and never came back not a single tear would be shed by any Engineer.
- ece 8mo agoCover your tracks from EFF doesn't seem to check extensions? Are there other fingerprint tests to use?
- Banditoz 8mo agoLinkedIn has been employing a lot of strange dark patterns recently: * Overriding scroll speed on Firefox Web. Not sure why. * Opening a profile on mobile web, then pressing back to go to last page, takes me to the LinkedIn homepage everytime. * One of their analytic URLs is a randomly generated path on www.linkedin.com, supposedly to make it harder to block. Regex rules on ublock origin sufficiently stop this. Anyone know why they could be doing this?
- gabeh 8mo agoGiving them the benefit of the doubt here obviously, I know they're in an all out war with the contact database industry. Going from websoup to agents dialing out to rent-a-human services requires different tactics.
- ikr678 8mo agoI always assumed mobile webpage misbehavior was to force you to use the app.
- small_scombrus 8mo agoIt could very much be confirmation bias, but I do feel like most "please use our app" popups appear after a mobile site breaks or refuses to load something
- duskdozer 8mo ago- scroll speed - unsure of ulterior motives, but i've seen this even on some foss things. i think some people just think it looks cool/modern/"responsive"/whatever - back - hijacking it seems fairly common on malicious/dark-pattern sites to try to trap you on them. not sure why because you can just leave and it seems it would obviously piss someone off - analytics paths - not everyone may know about/how to use regex rules for it or may use something else that doesn't support it (the stripped down ublock for chrome? i don't know if it can or not). sites seem to do this with malicious js code as well, presumably to prevent blocking
- rpigab 8mo agoI've been wondering why my scroll speed was off in LinkedIn, inspecting scroll-related css without finding an answer, I thought this was a bug. Anyone know what property does this? I might try to fix it with uBO scripts. I think they want you to feel disoriented. Why do they do all this bs and not fix the bug that happens when you insert Unicode U+202E in your name? I've been having loads of fun with that but it's never been fixed. Anyone tagging me in a comment makes their input right-to-left unless they backspace the tag or insert newline. It also jumbles notification text because your name is concatenated to the notification static text. You can also create an inverted link but it isn't clickable, just like other unicode links which aren't punycode-encoded on LinkedIn but aren't clickable (on the clients I've tried).
- jmyeet 8mo agoI started using Chrome at version 2 I think. It still had the 3D logo. It was such a breath of fresh air and the big innovation was running one process per tab. Firefox existed but the entire browser could (and did) hang. And IE was... well, IE. I did have a relatively early beef with Chrome though, whcih was I couldn't completely opt out of Flash. As in, I didn't even want it installed. This turned out to be an issue because Flash turned out to be one of the earliest vectors for so-called "zombie cookies". Fingerprinting in general has been a longstanding problem and has become more and more advanced. Add to this that Google is, first and foremost, an advertising business and they've become increasingly hostile to ad-bloccking tech for obvious reasons. Basically what I'm getting at is something I couldn't have imagined a decade ago where I think I really have go switch away from Chrome to something that takes privacy and security seriously so that LinkedIn can't do things like this. And I increasingly don't trust Google to do that. I actually have more trust in Apple because they have historically been user-focused eg blocking Meta's third party cookies. But obviously Safari isn't an option because it's not cross-platform. I'm not sure I trust the current state of Mozilla. What's the alternative? Brave? Is Opera still a thing? I honestly don't know. What I really want is a cross-platform browser written in Rust that black-holes ads out of the box. Why Rust? Memory safety. I simply don't trust a large C/C++ code to never have buffer overruns. Memory safety has become too important. I don't want my browser to provide information on what extensions I'm using to a site and that shouldn't be a thing I have to ask for or turn on in any way.
- direwolf20 8mo agoThere's a menagerie of de-mozillaed Firefox forks.
- rudhdb773b 8mo agoMy suggestions: Desktop - Librewolf Android - Ironfox
- deathanatos 8mo agoLinkedIn has also started sending a great deal of spam: A $7.5B chip merger Pinterest prepares layoffs Healthcare premiums surge Autodesk to cut 7% of jobs Ozempic keeps getting cheaper Since the "unsubscribe" link does not lead to a working page, this seems like a trivial violation of even what laughable protections CAN-SPAM alleges to offer. And what's with some of these? Bad mouthing employers is an odd choice for a platform that makes its money from them? Or perhaps now all the revenue is ad derived?
- esprehn 8mo agoReading the fingerprint.js is interesting, it's not just the thousands of extensions. It looks like it's also probing for a long list of webgl extensions, fonts, and other capabilities. There's recaptcha v3 references in there too. Perhaps an overly aggressive attempt to block bots.
- PaulHoule 8mo agoNo wonder it is so slow to load.
- duxup 8mo agoI miss when websites were, by default, there to provide me content ...
- deleted 8mo ago[deleted]
- alunchbox 8mo agowhy would they want this type of check? Like what could it possibly be doing for the end customer or features available?
- a-asad 8mo ago[dead]