11 ms·
The headline seems pretty misleading. Here’s what seems to actually be going on: > Every time you open LinkedIn in a Chrome-based browser, LinkedIn’s JavaScrip
by haswell 6mo ago
The headline seems pretty misleading. Here’s what seems to actually be going on:
> Every time you open LinkedIn in a Chrome-based browser, LinkedIn’s JavaScript executes a silent scan of your installed browser extensions. The scan probes for thousands of specific extensions by ID, collects the results, encrypts them, and transmits them to LinkedIn’s servers.
This does seem invasive. It also seems like what I’d expect to find in modern browser fingerprinting code. I’m not deeply familiar with what APIs are available for detecting extensions, but the fact that it scans for specific extensions sounds more like a product of an API limitation (i.e. no available getAllExtensions() or somesuch) vs. something inherently sinister (e.g. “they’re checking to see if you’re a Muslim”).
I’m certainly not endorsing it, do think it’s pretty problematic, and I’m glad it’s getting some visibility. But I do take some issue with the alarmist framing of what’s going on.
I’ve come to mostly expect this behavior from most websites that run advertising code and this is why I run ad blockers.
- replwoacause 6mo agoI disagree, I think we should push back hard on behavior like this. What business is it of LinkedIn's what browser extensions I have installed? I think the framing for this is appropriate.
- haswell 6mo agoTo broaden my point, I think we’d find that many websites we use are doing this. My point isn’t that this is acceptable or that we shouldn’t push back against it. We should. My point is that this doesn’t sound particularly surprising or unique to LinkedIn, and that the framing of the article seems a bit misleading as a result.
- devy 6mo ago> To broaden my point, I think we’d find that many websites we use are doing this. Your point of "I think we’d find that many websites we use are doing this" doesn't make LinkedIn's behavior ok! By your logic, if our privacy rights are invaded which is illegal in most jurisdiction, and then it become ok because many companies do illegal things??
- haswell 6mo agoAbsolutely not. At no point am I saying this is ok. I’m saying that the framing of the article makes this sound like LinkedIn is the Big Bad when the reality is far worse - they’re just one in a sea of entities doing this kind of thing. If anything, the article undersells the scale of the issue.
- coldpie 6mo agoYou really need to work on your reading comprehension, dude.
- deleted 6mo ago[deleted]
- autoexec 6mo agoI've love it if LinkedIn got successfully sued for millions and it resulted in similar lawsuits against every other website that did this sort of thing.
- kps 6mo agoWhy is it possible for a web site to determine what browser extensions I have installed? If there are legitimate uses, why isn't this gated behind a permission prompt, like things like location and camera?
- haswell 6mo agoThis, to me, seems like the more salient point. A headline like “Major browsers allow websites to see your installed extensions” seems more appropriate here. We’ve known for a long time that advertisers/“security” vendors use as many detectable characteristics as possible to constrict unique fingerprints. This seems like a major enabler of even more invasive fingerprinting and that seems like the bigger issue here.
- acheron 6mo agoThis is a Chrome thing. It’s a safe bet that if you use Google products you don’t care about privacy anyway. “Google product collects info about you: news at 11.”
- taneq 6mo agoGoogle cares deeply about privacy. Google defines privacy as them not giving your private data that they have collected to anyone else unless you ask them to.
- dmoose 6mo agoGoogle cares deeply about privacy. Google defines privacy as them not giving your private data that they have collected to anyone who hasn't paid them for it or can compel them to give it up.
- seanw444 6mo agoThere's a fourth amendment case on the Supreme Court docket (Chatrie v. U.S.) about Google searching a massive amount of user data to find people in a location at a specific time, at police request. The case is about whether the police's warrant warranted such a wide scope of search (if general warrants are allowed). Point being: Google will 100% give your info to the police, regardless of whether the police have the legal right to it or not, and regardless of whether you actually committed a crime or not. Bonus points: the federal court that ruled on the case said that it likely violated the fourth amendment, but they allowed the police to admit the evidence anyway because of the "good faith" clause, which is a new one for me. Time to add it to the list of horribly abusable exceptions (qualified immunity, civil asset forfeiture, and eminent domain coming to mind).
- casey2 6mo ago[flagged]
- Aurornis 6mo ago> What business is it of LinkedIn's what browser extensions I have installed? The list of extensions they scan for has been extracted from the code. It was all extensions related to spamming and scraping LinkedIn last time this was posted: Extensions to scrape your LinkedIn session and extract contact info for lead lists, extensions to generate AI message spam. That seems like fair game for their business.
- tartoran 6mo agoAnd instead LinkedIn is scraping all users computers?
- Aurornis 6mo agoThis doesn’t fit the description of scraping by any normal definition. It’s a classic feature probe structure, where the features happen to be scraping extensions. I think it’s kind of funny that HN has gone so reactionary at tech companies that the comments here have become twisted against the anti-spam measures instituted on a website that will never trigger on any of their PCs, because HN users aren’t installing LinkedIn scrape and spam extensions.
- ImPostingOnHN 6mo agoHackerNews users used to be the type that would do the scraping, so they could Hack the data into whatever format or integration they desired. It's unfortunate to see folks here who don't support that – interoperability is at the heart of the Hacker Ethic. LinkedIn (along with any other big tech companies locking down and crippling their APIs) is wrong to even try to block it. Is it an issue of the resources scrapers consume? No: Even ordinary users trying to get API access on a registered persistent account linked to their name are stymied in accessing their own data. LinkedIn simply doesn't want you to access your own data via API, or in any manner that isn't blessed by them. That ain't right.
- warkdarrior 6mo ago
- jacquesm 6mo ago> I think we should push back hard on behavior like this. Indeed, so I gather all of you have canceled your LI account over this? I never made one in the first place because it was pretty clear to me that this company - even before the acquisition - had nothing good in mind.
- MikeNotThePope 6mo agoIf I had to guess, LinkedIn would be primarily searching for extensions that violate their terms of service (e.g. something that could be used to scrape data). They put a lot of effort into circumventing automated data collection. I could be wrong.
- phendrenad2 6mo agoSo why not say that LinkedIn is murdering people? I mean, if all you care about is raising awareness with maximal clickbait...
- mentalgear 6mo ago> The scan probes for thousands of specific extensions by ID, collects the results, encrypts them, and transmits them And probably also vibe-coded therefore 2 tabs of LinkedIn take up 1GB of RAM (was on the front page a few days back).
- al_borland 6mo ago> I’ve come to mostly expect this behavior from most websites that run advertising code and this is why I run ad blockers. Expecting and accepting this kind of thing is why everyone feels the need to run an ad-blocker. An ad-blocker also isn’t full protection. It’s a cat and mouse game. Novel ideas on how to extract information about you, and influence behavior, will never be handled by ad-blockers until it becomes known. And even then, it’s a question of if it’s worth the dev time for the maker of the ad-blocker you happen to be using and if that filter list gets enabled… and how much of the web enabling it breaks.
- haswell 6mo agoTo be clear, expecting != accepting. The point was more that the headline frames this as some major revelation about LinkedIn, while the reality is that we’re getting probed and profiled by far more sites than most people realize.
- armchairhacker 6mo agoRegulation is also a cat-and-mouse game. Life is a cat-and-mouse game.
- nanocat 6mo ago[flagged]
- echelon 6mo agoLinkedIn's whole business model is gatekeeping their database. They're scanning your extensions to make sure you aren't using third party tools to scrape LinkedIn. It's stupid, but they're trying to stop people from making money on LinkedIn when they feel like they're the only ones that should be able to do that.
- gausswho 6mo agoHas anyone published useful parts of their database? It'd be kinda nice to use a rolodex that wasn't slimed with the rest of LI's taint.
- VladVladikoff 6mo agoIt is likely in response to scraping. Linked in is heavily scraped by scammers who do the BEC scams. So linked in is trying to find ways to link together banned accounts, to handle their ban evasion. I run a site which attracts a lot of unsavoury people who need to be banned from our services, and tracking them to reban them when they come back is a big part of what makes our product better than others in the industry. I do not care at all about actually tracking good users, and I am not reselling this data, or anything malicious, it's entire purpose is literally to make the website more enjoyable for the good users.
- dweinus 6mo agoUnderstandable, and yet none of that makes it ok.
- jacquesm 6mo ago> it's entire purpose is literally to make the website more enjoyable for the good users. There are people who actually enjoy using LinkedIn?
- colechristensen 6mo ago>Linked in is heavily scraped by scammers who do the BEC scams. It's also heavily scraped by businesses for lead generation for sales and recruiting. Either before their API became available or to not pay them or to get around the restrictions of their API.
- fp64 6mo ago[dead]
- andersonpico 6mo agoHow is probing your browser for installed extensions not "scanning your computer"? Calling the title misleading because they didn't breach the browser sandbox is wrong when this is clearly a scenario most people didn't think was possible. Chrome added extensionId randomization with the change to V3, so it's clearly not an intended scenario. > vs. something inherently sinister (e.g. “they’re checking to see if you’re a Muslim”) They chose to put that particular extension in their target list, how is it not sinister? If the list had only extensions to affect LinkedIn page directly (a good chunk seem to be LinkedIn productivity tools) they would have some plausible deniability, but that's not the case. You're just "nothing ever happens"ing this.
- afandian 6mo agoWhen "the browser is the OS", scanning that is a pretty big chunk of "your computer".
- chii 6mo agobut the language of "your computer" implies files on your computer, as it would be what people commonly call it. Merely just the extension is not enough. If it has the ability to scan your bookmarks, or visited site history, that would lend more credence to using the term "computer". The title ought to have said "linkedIn illegally scans your browser", and that would make clear what is being done without being sensationalist.
- blenderob 6mo ago> but the language of "your computer" implies files on your computer, as it would be what people commonly call it. Merely just the extension is not enough. But the language of "your computer" also implies software on your computer including but not limited to Chrome extensions.
- ImPostingOnHN 6mo agoIt implies more than just the browser, which is likely why it was used for the post title. If it is exclusively limited to the browser, then "scans your browser" is more correct, and doesn't mislead the reader into thinking something is happening which isn't commonplace on the internet.
- neya 6mo ago> I’ve come to mostly expect this behavior from most websites that run advertising code and this is why I run ad blockers. We should not normalise nor accept this behaviour in the first place.
- nkrisc 6mo ago> i.e. no available getAllExtensions() or somesuch) vs. something inherently sinister (e.g. “they’re checking to see if you’re a Muslim” But I bet they could reliably guess your religious affiliation based on the presence of some specific browser extensions.
- caminante 6mo agoThey already have so much telemetry from your phone, IP, etc. God forbid they make an educated guess based on your actual LinkedIn connections, name, interests, etc.
- giancarlostoro 6mo ago> It also seems like what I’d expect to find in modern browser fingerprinting code. Time to figure out if I can make FireFox pretend to be Chrome, and return random browser extensions every time I visit any website to screw up browser fingerprinting...
- MisterTea 6mo ago> The scan probes for thousands of specific extensions by ID, collects the results, encrypts them, and transmits them to LinkedIn’s servers. Why is this even possible in the first place? It's nobodies business what extensions I have installed.
- Aurornis 6mo agoThis has been covered several times including reverse engineering of the code. The list of extensions they check for doesn’t include common extensions like ad blockers. It’s exclusively full of LinkedIn spamming and scraping type of extensions. They also logically don’t need to fingerprint these users because those people are literally logging in to an account with their credentials. By all appearances they’re just trying to detect people who are using spam automation and scraping extensions, which honestly I’m not too upset about. If you never install a LinkedIn scraper or post generator extension you wouldn’t hit any of the extensions in the list they check for, last time I looked.
- honzaik 6mo agoit apparently scans for something like "PQC Checker", an extension for checking if TLS connection is PQC-enabled? how is that a spam extension (and thats just a random one i saw)
- Aurornis 6mo agoProbably compromised extensions or misleading extensions. It’s common for malware extensions to disguise themselves as something simple and useful to try to trick a large audience into installing them. That’s why the list includes things like an “Islamic content filter” and “anti-Zionist tagger” as well as “neurodivergent” tools. They look for trending topics and repackage the scraper with a new name. Most people only install extensions but never remove them if they don’t work.
- honzaik 6mo agowell if they have evidence why they dont report it? why are these extensions on the store? im sure linkedin has enough motion to report it directly to google also, having a PQC enabled extension doesnt seem like a good "large user base capture" tactic. the source code is as usual obfuscated react but that doesnt mean its malicious... EDIT: i debuged the extension quickly and it doesnt seem to do anything malicious. it only sends https://pqc-extension.vercel.app/?hostname=[domain] https://pqc-extension.vercel.app/?hostname=[domain] request to this backend to which it has permissions. it doesnt seem to exfiltrate anything else. it might get triggered later but it has very limited permissions anyway so it doesnt seem to be a malicious extension. (but im no expert)
- pqtyw 6mo ago> no available getAllExtensions() Well great there is no avalable 'getAllFiles()' or such either because they'd be scanning your files for "fingerprinting" as well. > alarmist framing Well they literally searching your computer for applications/extensions that you have installed? (and to an extent you can infer what are some of the desktop applications you have based on that too)
- jredwards 6mo agoI've been avoiding Chrome-based browsers for many years now but have only recently become aware of how catastrophically low the Firefox market share is. I'm kind of shocked that more people aren't choosing to avoid Chrome.
- inetknght 6mo ago> the fact that it scans for specific extensions sounds more like a product of an API limitation (i.e. no available getAllExtensions() or somesuch) vs. something inherently sinister (e.g. “they’re checking to see if you’re a Muslim”). Your computer is your private domain. Your house is your private domain. You don't make a "getAllKeysOnPorch()" API, and certainly don't make "getAllBankAccounts()" API. And if you do, you certainly don't make it available to anyone who asks. It absolutely is sinister.
- j45 6mo agoI wonder if this is part of the reason why LinkedIn tabs seem to use so much ram, and sometimes run away CPU processes.
- lastofthemojito 6mo ago> this is why I run ad blockers. It's pretty wild that we live in a world where the actual FBI has recommended we use ad blockers to protect ourselves, and if everyone actually listened, much of the Internet (and economy) as we know it would disappear. The FBI is like "you should protect yourself from the way that the third largest company in the world does business", and the average person's response is "nah, that would take at least a couple of minutes of my time, I'll just go ahead and continue to suffer with invasive ads and make sure $GOOG keeps going up".
- j45 6mo agoAd blockers focus on ads, not fingerprinting.
- mewmewblobcat 6mo agoDepends on what lists you use. If you use uBlock Origin, and enable most of the lists, it'll target both.
- j45 6mo agoGo try it with fingerprint.com. Even post-sanitization, pi-hole, you name it, it will be surprising.
- streetfighter64 6mo agofingerprint.com seems to be some fingerprinting vendor, they don't even offer a demo without logging in. https://coveryourtracks.eff.org https://coveryourtracks.eff.org is EFFs demo site is non-profit and doesn't require login
- iso1631 6mo agocoveryoutracks always tells me I'm unique Which is concerning. Until you realise I do the same thing a few days later and I'm still unique.
- j45 6mo agoThere is clear rules around what you can and can't do to fingerprint users. if it's being done overtly, covertly, obscurely, indirectly, all for the same result through direct or indirect or correlated metadata it ends up with the same outcome. My understanding is the rules and laws are to prevent the outcome, by any means, if it's happening.
- j45 6mo ago> "they're checking to see if you're a Muslim" This could be easily inferred from the depth, breadth, and interconnectedness of data in the website. By downplaying it, it's allowing it to exist and do the very thing. The issue here is this stuff is working likely despite ad blockers. Fingerprinting technology can do a lot more than just what can be learned from ads. From the site: "The scan doesn’t just look for LinkedIn-related tools. It identifies whether you use an Islamic content filter (PordaAI — “Blur Haram objects, real-time AI for Islamic values”), whether you’ve installed an anti-Zionist political tagger (Anti-Zionist Tag), or a tool designed for neurodivergent users (simplify). Under GDPR Article 9, processing data that reveals religious beliefs, political opinions, or health conditions requires explicit consent. LinkedIn obtains none." https://browsergate.eu/extensions/ https://browsergate.eu/extensions/
- RankingMember 6mo ago> this is why I run ad blockers. What's been really obnoxious lately is the number of sites I try to do things on that are straight up broken without turning off my ad-blocker.
- catlifeonmars 6mo ago> I’m certainly not endorsing it, do think it’s pretty problematic, and I’m glad it’s getting some visibility. But I do take some issue with the alarmist framing of what’s going on. Speaking has someone who shares the same lack of surprise, perhaps some alarm is warranted. Just because it’s ubiquitous doesn’t mean it’s ok. This feels very much frog in boiling water for me. Why do you think the alarmist framing is unwarranted?
- haswell 6mo agoI do think a degree of alarm is appropriate. But it’s critical to sound the correct alarm. To me, it seems like the authors pulled the fire alarm for a single building when in reality there’s a tornado bearing down. And by doing so, everyone is scrambling about a fire instead of the response a tornado siren would cause. They’re both dangerous and worthy of an immediate reaction, but the confusion and misdirection this causes seems deeply problematic. When people realize the fire wasn’t real, they start to question the validity of the alarm. The tornado is still out there. I realize this analogy is a bit stretched. As someone who has spent quite a lot of time steeped in security/privacy research, the stuff described in the article has been happening pervasively across the industry. People absolutely should be alarmed. Many of us have been alarmed for quite some time. Raising the alarm by saying “LinkedIn is searching your computer” isn’t it.
- mr-wendel 6mo agoI think this is a great analogy. I read quite a bit of the site and it's wildly blown out of proportion and severely lacking in context. How many phone apps do you think are trying to detect what else is installed on your phone? I was part of an acquisition of a company with a very large mobile user base and our new parent was shocked we weren't trying to passively collect device information like this. They for sure were. And on the flip side, as others have done well to point out, there are a LOT of legitimate reasons to fingerprint users for anti-fraud/abuse and I am 100% convinced that we're all better off for this. Maybe thats all this story is about, maybe not, but this article leaves out an incredible amount of complexity.
- wat10000 6mo agoYour post sounds like "it sounds bad, but it's no different from what others do, so it's not that bad." I would put it more like: it sounds bad, and it's no different from what others do, so they're all that bad. The fact that they're working around an API limitation doesn't make this better, it just proves that they're up to no good. The whole reason there isn't an API for this is to prevent exactly this sort of enumeration. It's clear that companies will do as much bad stuff as they can to make money. The fact that you can do this to work around extension enumeration limits should be treated as a security bug in Chrome, and fixed. And, while it doesn't really make a difference, LinkedIn should be considered to be exploiting a security vulnerability with this code.
- tpoacher 6mo agoI get the point you're making, but to be clear, "they’re checking to see if you’re a Muslim" vs "they’re checking to see if your fingerprint matches that of known Muslims in our ever-expanding database" are not too far off.
- Betelbuddy 6mo agoThe next step for a forensic investigator, is to found out how many of those extensions, are actually from a partner or fully owned subsidiary from LinkedIn... When you see a cockroach...
- lxgr 6mo ago> The scan probes for thousands of specific extensions by ID, collects the results Why exactly does Chrome even allow this in the first place!? This is the most surprising takeaway for me here, given browser vendors' focus on hardening against fingerprinting.
- spopejoy 6mo agoFirefox FTW. I was relieved to find this was a Chrome-only problem.
- deleted 6mo ago[deleted]
- lxgr 6mo agoTurns out Firefox has a similar issue, despite mitigations :( https://bugzilla.mozilla.org/show_bug.cgi?id=1372288 https://bugzilla.mozilla.org/show_bug.cgi?id=1372288
- eipi10_hn 6mo agoThis only happens if the extension puts their `moz-extension://` links into the DOM. It's different to chrome case where extensions can be detected regardless of being activated on that site or not.
- lxgr 6mo agoAs I understand it, an extension could also leak its links via its own backend, e.g. to advertisers, who could then detect it even though no user-observable DOM modification is happening. Much better than static global IDs, but still not ideal.
- eipi10_hn 6mo agoYeah, anything happening in backend depends totally on the extensions. Unless I need something, I rarely use extensions that are closed-source or open-source but has some sending data in their features.
- chromacity 6mo ago> I’m not deeply familiar with what APIs are available for detecting extensions, but the fact that it scans for specific extensions sounds more like a product of an API limitation (i.e. no available getAllExtensions() or somesuch) vs. something inherently sinister This seems like a really weird argument to make. The fact that the platform doesn't provide a privacy-violating API is not an extenuating circumstance. LinkedIn needed to work around this limitation, so they knew they're doing something sketchy. For the record, I don't think they're being evil here, but the explanation is different: they're don't seem to be trying to fingerprint users as much as they're trying to detect specific "evil" extensions that do things LinkedIn doesn't want them to do on linkedin.com. I guess that's their prerogative (and it's the prerogative of browsers to take that away).
- davedx 6mo agoWhat are the religious-related extensions described in the article doing that's "evil"?
- chromacity 6mo agoJudging from the fact that 99% of the list seem like data-mining scam apps or spam tools, I suspect that's the answer in these cases too. If LinkedIn really wanted to profile your religious beliefs, they would presumably go after the most popular religion-related extensions, not some "real-time AI for Islamic values" thing with 6k users.
- urig 6mo agoThe tracking described is extremely invasive. You say you are not endorsing it but you are certainly normalizing it. This is unacceptable. The people behind this URL are trying to hold Microsoft accountable. The power to them.
- fasterik 6mo ago>this is why I run ad blockers. It's important to note that this isn't fixed by ad blockers. To avoid this kind of fingerprinting, you need to disable JavaScript or use a browser like Firefox which randomizes extension UUIDs.
- spopejoy 6mo agoYes, but FF also prevents the extension scanning. It's scandalous that Chrome allows this!
- mcv 6mo agoWhy is JavaScript running in a page even allowed to know what extensions I have? Is this also what sites use to see I've got an ad blocker? Just run everything in a safe environment that it can't look out of.
- cwmma 6mo agoThe page isn't allowed to know what extensions you have, instead LinkedIn is looking for various evidence that extensions are installed, like if an extension was to create a specific html element, LinkedIn could look for evidence of that element being there. Since the extensions are running on the same page as LinkedIn (some of them are explicitly modifying the LinkedIn the website) it's impossible to sandbox them so that linked in can't see evidence of them. And yes this is how a site knows you have an ad blocker is installed.
- eipi10_hn 6mo agoPage can know what your chrome extensions are, even when your extensions don't interact with the site, by fetching `web_accessible_resources`: https://browserleaks.com/chrome#web-accessible-resources-detection https://browserleaks.com/chrome#web-accessible-resources-det... . uBO mitigates this partly by generating internal secret tokens for each request: https://github.com/gorhill/uBlock/tree/master/src/web_accessible_resources#readme https://github.com/gorhill/uBlock/tree/master/src/web_access... . However, there are other proof of concept of another attack vector to bypass this by using timing difference when fetching those resources. I help maintaining uBO's lists and I've seen one real world case doing this. It's a trash shortener site, and they use the `web_accessible_resources` method as one of their anti-adblock methods. Since it's a trash site, I didn't care much later.
- dfxm12 6mo agoBut I do take some issue with the alarmist framing of what’s going on. I’ve come to mostly expect this behavior from most websites that run advertising code We should be alarmed that websites we go to are fingerprinting us and tracking our behavior. This is problematic, full stop. The fact that most websites are doing this doesn't change that.
- chistev 6mo agoBut what would be the benefit of them doing that?
- storus 6mo agoWhich browsers in which mode (normal/private) are affected?
- nailer 6mo ago> The headline seems pretty misleading. Yes. I was expecting LinkedIn was connecting to extensions that are using their exhanced privileges to scan your computer, per the "LinkedIn Is Illegally Searching Your Computer" headline. Instead, LinkedIn is scanning for extensions.
- FloorEgg 6mo agoI wonder if their motivation for doing this is to detect the LinkedIn automation tools that power all the spam messaging and connection requests?
- thfuran 6mo ago>vs. something inherently sinister This is inherently sinister.
- cachius 6mo ago> expect to find in modern browser fingerprinting No. Don't need extensions for that. See how Cloudflare Turnstile does it, recently popped up at https://news.ycombinator.com/item?id=47566865 https://news.ycombinator.com/item?id=47566865 cause ChatGPT uses it now: Layer 1: Browser Fingerprint WebGL (8 properties): UNMASKED_VENDOR_WEBGL, UNMASKED_RENDERER_WEBGL, WEBGL_debug_renderer_info, getExtension, getParameter, getContext, canvas, webgl Screen (8): colorDepth, pixelDepth, width, height, availWidth, availHeight, availLeft, availTop Hardware (5): hardwareConcurrency, deviceMemory, maxTouchPoints, platform, vendor Font measurement (4): fontFamily, fontSize, getBoundingClientRect, innerText. Creates a hidden div, sets a font, measures rendered text dimensions, removes the element. DOM probing (8): createElement, appendChild, removeChild, div, style, position, visibility, ariaHidden Storage (5): storage, quota, estimate, setItem, usage. Also writes the fingerprint to localStorage under key 6f376b6560133c2c for persistence across page loads. Scanning for 6000 extensions is anti-competitive, surveillant and immoral.
- gabbagool 6mo agoJust because someone lets the electrician (LinkedIn) into their home (browser) doesn't mean they can do whatever the hell they want that isn't expressly prohibited. If the electrician wants to rifle through my desk drawers, they should ask for permission, and I will politely tell them to leave.
- longislandguido 6mo agoIf your electrician was known to be hostile like the Internet, then you'd put locks on your drawers. The browser security model right now is more like those completely ineffective "gun free zone" signs cities tack up in public parks.
- whimsicalism 6mo agothis is obviously not fingerprinting code to anyone with a brain, it's about scraping
- xXSLAYERXx 6mo agoI worked for a company that sold b2b contact data and they had (maybe still have) a linkedIn extension. It basically enriched the linkedIn profile. I wonder if linkedIn is trying to block these, or heavily target, in some way, these types of users to push folks towards their sales navigator.
- Bender 6mo agoJavascript can query chrome extensions [1] and much more [2]. [1] - https://browserleaks.com/chrome https://browserleaks.com/chrome [2] - https://browserleaks.com/javascript https://browserleaks.com/javascript
- francoi8 6mo agoThis blows my mind. What good reason is there for giving javascript such permissions by default? This should at the minimum trigger an explicit permission request from the user.
- Bender 6mo agoMy guess would be that the internet is run by developers. Apps will want this data so javascript provides it to make decisions about window sizing and user agent capabilities. Authorization would probably only occur if javascript was gated by non developers just as SSDP open and forwards ports on routers without user intervention or knowledge rather than an API that prompt the user. Just a guess.
- Bender 6mo agoMore [1] [1] - https://www.whatsmyip.org/more-info-about-you/ https://www.whatsmyip.org/more-info-about-you/
- deleted 6mo ago[deleted]
- dcchuck 6mo agoI agree. The first paragraph on the page implies the javascript can natively search your machine (vs. via Browser Extensions)
- vaginaphobic 6mo ago[dead]
- stronglikedan 6mo ago> sounds more like a product of an API limitation (i.e. no available getAllExtensions() or somesuch) vs. something inherently sinister (e.g. “they’re checking to see if you’re a Muslim”) Then why search for PordaAI or Deen Shield? Or more specifically, since getAllExtensions() would return them, why would they be on the "scan list", instead of just ignored?
- secondcoming 6mo agoMy biggest gripe is why these JS APIs even exist in the first place
- jollymonATX 6mo agoYour expectations do not matter here frankly. This reads like CFAA to me, unauthorized access.
- socalgal2 6mo agoHow does this scan happen. AFAIK there is no API for a webpage to scan for extensions. The most a page could do is try to figure out indirectly if an extension exists if that extension leaks info into the page.
- drnick1 6mo agoThe bigger problem I see here is browser security and Javascript as a whole. Browsers should not be allowed to extract and send such vast amounts of information in the first place, especially without the user's consent. At most, they should return a few broad things such as browser type (major version), language perhaps, and device type (mobile/desktop). That's it. Other things, such as exact resolutions, time zones, and other hardware identifiers make it trivially easy to track users across the Internet. Now that it's too late to revise Web standards, browsers should default to return spoofed values for all the rest.
- Griffinsauce 6mo ago> But I do take some issue with the alarmist framing of what's going on. On the contrary, your framing is quite defeatist IMO. The fact that stores get robbed frequently does not mean we should just normalize that and accept it as a fact of life.
- austin-cheney 6mo ago> I’m not deeply familiar with what APIs are available for detecting extension Here is what the article says: Method 1 async function c() { const e = [], t = r.map(({id: t, file: n}) => { return fetch(`chrome-extension://${t}/${n}`) }); (await Promise.allSettled(t)).forEach((t, n) => { if ("fulfilled" === t.status && void 0 !== t.value) { const t = r[n]; t && e.push(t.id); } }); return e; } Method 2 async function(e) { const t = []; for (const {id: n, file: i} of r) { try { await fetch(`chrome-extension://${n}/${i}`) && t.push(n); } catch(e) {} e > 0 && await new Promise(t => setTimeout(t, e)); } return t; } The API is making an HTTP request to chrome-extension://${store_id}/${file_name} There is then a second stage where they walk the DOM looking for text signatures and element attributes indicative of the store_id values It looks like the user has the freedom to manage this by launching chrome with this flag: --disable-extensions It also seems there is an extension for extension management to deny extension availability by web site: https://superuser.com/questions/1546186/enable-disable-chrome-extensions-per-site-via-white-or-blacklist https://superuser.com/questions/1546186/enable-disable-chrom...
- darepublic 6mo agolinked in is scummy but yes I was puzzled by how linked in could scan your comouter from the browser. when i saw they meant extensions I thought aha.
- btown 6mo agoFor what it's worth - and I'm not saying that LinkedIn is doing this for the right reasons - I can imagine a frontend QA team wanting to do this to understand how prominent certain extensions are for users of various parts of their product, correlating those extensions against frontend bug reports, and using that to guide QA procedures with real-world extension sets. When you're literally the company that invented Kafka for your clickstreams, "everything looks like a nail." (More likely, though, this is an anti-scraping initiative, since headless browsers are unlikely to randomize their use of extensions, and they can use this to identify potential scrapers.)
- cogman10 6mo ago> It also seems like what I’d expect to find in modern browser fingerprinting code. Exactly what I think it is. It's all for tracking and ultimately for advertisement. Linkedin can get exactly who you are and then they share that data with ad companies to better target you. Really gross behavior.
- gettingoverit 6mo agoWell, that's precisely what is sinister here. Those profiling tools don't really care which features are going to be used for predictions. It's just machine learning, and it's indiscriminate. So if you have an extension that correlates with you being Muslim, it will be used for whatever ML predictions they give to other companies, and the worst case will be another "oh we didn't do this intentionally". Of course, that's not the first time this ever happened in human history, so even if it's not "something inherently sinister", it's just "criminal negligence".
- fragmede 6mo agoTo flip it around, if one of those chrome extensions saved parts of the contents of the page it was on into a database, and I had the chrome extension navigate around on LinkedIn for me, collecting information, LinkedIn would sue me for CFAA violations because I'm scraping them for email addresses and phone numbers. This is not theoretical either, as LinkedIn has sued people in the past for scraping.
- downrightmike 6mo agoAndroid had a similar feature, but google removed it because it was invasive and being misused to target people.
- brainzap 6mo agoextensions create so many bug reports, I would do the same
- RIMR 6mo agoI'm confused, you call this "misleading" then quote the claim, but say it's "what [you'd] expect to find in modern browser fingerprinting code". So what is it? Misleading, or exactly what you expected to find? It cannot be both. It sounds more like you object to the negative framing of Microsoft hoovering up as much data as possible for profit, even though this is objectively a crime in the jurisdictions they are being sued in.
- 1vuio0pswjnm7 6mo ago"The headline seems pretty misleading." How? What exactly would a reader be "mislead" to believe The part about "inherently sinister" seems to be a thought from the mind of an HN commenter not the authors of the submitted web page. The later only describe LinkedIn's actions as illegal, not "sinister". The laws cited by the authors do not appear to consider any "state of mind", e.g., "sinister", or intent as relevant "But I do take some issue with the alarmist framing of what's going on." AFAICT, the submitted web page does not suggest that anything LinkedIn does is "dangerous", i.e., cause for "alarm". What it suggests is that LinkedIn's actions _violate European privacy laws_. The authors claim LinkedIn's actions present an opportunity to enforce these laws, i.e., "take action" https://browsergate.eu/why-its-illegal/ https://browsergate.eu/why-its-illegal/ https://browsergate.eu/take-action/ https://browsergate.eu/take-action/
- 1vuio0pswjnm7 6mo ago*misled
- account42 6mo ago> This does seem invasive. It also seems like what I’d expect to find in modern browser fingerprinting code. I’m not deeply familiar with what APIs are available for detecting extensions, but the fact that it scans for specific extensions sounds more like a product of an API limitation (i.e. no available getAllExtensions() or somesuch) vs. something inherently sinister (e.g. “they’re checking to see if you’re a Muslim”). Working around deliberate API designs that are designed to make it harder to get a list of all installed extensions is inherently sinister. It's very clearly malicious. We absolutely should not accept that kind of behavior from anyone and definitely not from the corporations large enough that we can't realistically avoid depending upon them.