6 ms·
Skimming the list, looks like most extensions are for scraping or automating LinkedIn usage. Not surprising as there's money to be made with LinkedIn data. Scra
by rdoherty 8mo ago
Skimming the list, looks like most extensions are for scraping or automating LinkedIn usage. Not surprising as there's money to be made with LinkedIn data. Scraping was a problem when I worked there, the abuse teams built some reasonably sophisticated detection & prevention, and it was a constant battle.
- bryanrasmussen 8mo agofrom the code doesn't look like they do anything if they have a match, they just save all the results to a csv for fingerprinting?
- cxr 8mo ago"The code" here you're referring to (fetch_extension_names.js[1]) isn't and doesn't claim to be LinkedIn's fingerprinting code. It's a scraper that the researcher behind this repo wrote themselves in order to create the CSV of the data that they're publishing here. LinkedIn's fingerprinting code, as the README explains, is found in fingerprint.js[2], which embeds a big JSON literal with the IDs of the extensions it probes for. (Sickeningly enough, this data starts about two-thirds of the way through the file* and isn't the culprit behind the bulk of its 2.15 MB size…) * On line 34394; the one starting: const r = [{ id: "aacbpggdjcblgnmgjgpkpddliddineni", file: "sidebar.html" 1. <https://github.com/mdp/linkedin-extension-fingerprinting/blob/main/fetch_extension_names.js https://github.com/mdp/linkedin-extension-fingerprinting/blo...> 2. <https://github.com/mdp/linkedin-extension-fingerprinting/blob/main/fingerprint.js https://github.com/mdp/linkedin-extension-fingerprinting/blo...>
- bryanrasmussen 8mo agothanks, my fault for not reading the read me and just doing a quick read of the code.
- hsbauauvhabzb 8mo agoWont someone think of poor little LinkedIn, a subsidiary of one of the largest data brokers in the world?
- charcircuit 8mo agoWhy frame what you are trying to say like that? Businesses of all sizes deserve the ability to protect their businesses from abuse.
- ronsor 8mo agoI think they framed it this way because they don't consider scraping abuse (to be fair, neither do I, as long as it doesn't overload the site). Botting accounts for spam is clear abuse, however, so that's fair game.
- hsbauauvhabzb 8mo agoNo, I consider all data collection and scraping egregious. From that perspective, LinkedIn is hypocritical when Microsoft discloses every filesystem search I do locally to bing.
- dylan604 8mo agoAre you not scraping a site with your eyeballs when you view a site?
- hsbauauvhabzb 8mo agoBy that logic I can charge you for looking at me.
- direwolf20 8mo agoI agree. Maybe that logic (which is your logic) isn't very good.
- cxr 8mo agoIn order to create the data source that LinkedIn's extension-fingerprinting relies on to work, someone (at LinkedIn*?) almost certainly violated the Chrome Web Store TOS—by (perversely*) scraping it. * if LinkedIn didn't get it from an existing data source
- bastawhiz 8mo ago3000 extensions is few enough that a small team could download each extension manually over a few months. You don't need to scrape at all.
- cxr 8mo agoIn the first place, no one said they needed to, only that they probably did. Secondly, it's not "3000 extensions". They didn't somehow magically divine that the 2953 (+/-47) extensions we see here were the ones that they needed to download in order to be able to exploit the content-accessible resources described in their extension manifest. They looked at a much larger set, and it got filtered down to these 2953 that satisfied the necessary criteria.
- bastawhiz 8mo agoLol no, did you even read the list? You could pay someone to just search "LinkedIn" and "talent" and "recruiting" on the chrome web store and download each extension. It's probably harder to automate this than it is to do it manually. This is something you could develop in an afternoon and pay a small team of people to do for pennies on the dollar. Even ten thousand extensions is nothing. Spread that over years and this is trivial.
- deleted 8mo ago[deleted]
- cxr 8mo agoFor someone choosing to be so obnoxiously condescending, you are excruciatingly stupid.
- winddude 8mo agoa problem for linkedin != "a problem". The real problem for people is the back room data brokering linkedin and others do.
- dumbo23 8mo ago[dead]
- RHSman2 8mo agoI had the pleasure of scraping LinkedIn for a client. Great fun.
- tlogan 8mo agoBy looking the list it seems like it is not really “sophisticated”. It is just list based on names (if there is a “email” in the name). Majority of extensions do not even ask for permissions to access linkedin.com.