9 ms·
LinkedIn is scanning browser extensions
- un-nf 5mo ago[flagged]
- kyleee 5mo agoAnd certainly fingerprint you right?
- WJW 5mo agoI guess that's what they're hoping for. With my admittedly biased opinion of the average linkedin user, about 99% will have the default set of extensions installed and so will not be very useful. Those users might have other identifiers of course, so who knows.
- jwpapi 5mo agoI’m pretty sure it’s not 99% you would wonder how many differences there are along with user-agent resolution and ip range... I think 99% are identifiable
- flomo 5mo agoIdeally about 99% of LinkedIn users are using their professional name, occupation, and location.
- RobRivera 5mo agoOh man time to see if there is a chrome Bonzai Buddy extension
- flomo 5mo agoProbably mostly for abuse prevention. Lots of extensions like this one: https://addons.mozilla.org/en-US/firefox/addon/linkedin-data-scrapper/ https://addons.mozilla.org/en-US/firefox/addon/linkedin-data...
- hirako2000 5mo agoThe "abuse" is that one doesn't have to copy paste for hours.
- Lerc 5mo agoCan you confirm that the title is correct and that it encrypts rather than hashes? Both are concerns, but sending interpretable data is a more serious concern. I scanned through the article and did not see an example of the header it added.
- stingraycharles 5mo agoIt says RSA public key encryption in the article, so I’m going to assume that it’s not a typo.
- phantomathkg 5mo agocan, but how? Have you verify all 6278 and what they do?
- tomhow 5mo agoThis is a good example of why post summaries are considered off-topic on HN. If it becomes the top comment (which it often does if people agree with it or are riled up by it) they'll reply to the summary rather than posting their replies as root comments to the main thread, creating a split between replies to the top comment and root replies. Also, please don't use a title for the HN submission that's different from the title of the original post. The guidelines are specific about this.
- mkw5053 5mo agoInteresting, so would Safari prevent this? I tried moving to Safari and honestly loved everything except I use my google accounts now for authenticating with to many services and that was a pain compared to chrome.
- skeaker 5mo agoI would imagine using any non-Chromium browser would cause it to fail to find any Chrome extensions, yes.
- mkw5053 5mo agoSure, but Safari may or may not leak Safari extension signals in a similar fashion. I haven't actually investigated.
- testfrequency 5mo agoWell if you’re a logged in to Google don’t you just SSO everywhere?
- mkw5053 5mo agoI honestly kind of forget the exact annoyances because it has been some time. I want to say I had to reauth every time I wanted to SSO with my google account because it doesn't allow/deletes third party cookies.
- traderj0e 5mo agoYeah it's something like this. I have multiple Google accounts and am somehow always logged into the wrong one.
- NoahZuniga 5mo agoEven better! Moving to firefox fixes this. Chrome for some reason (still!) gives extensions static ids. Firefox has the id change per firefox instance.
- 5mo ago
- guluarte 5mo agoI did that and got logged out of LinkedIn.
- nokya 5mo ago"What is not a question is that a criminal investigation is now open." Good. These companies deserve each and every stone thrown at them, and much more.
- fuzzfactor 5mo agoWhat's really needed is to find out whose idea this was to begin with. Some truly straight-shooters should be pointing the finger very accurately to where all this is coming from. Anybody who has a team committed to non-below-average websites should be able to screen applicants against a roster of known enshittifiers. It may be too late to nip it in the bud, but there's no reason to allow these individuals to continue unabated, much less keep growing so annoyingly. What's wrong with some people anyway?
- un-nf 5mo agoThis is unfortunately common practice on the internet. Browser fingerprinting is the new norm. LinkedIn just didn't disclose it in their privacy policy. They do mention canvas fingerprinting and collecting other signals, but not specifically this extension enumeration stuff. But fingerprinting is used to track people even without cookies. Take a look at this for some further reading: https://404privacy.com/blog/browser-fingerprinting-is-the-ad-industrys-response-to-your-privacy-settings/ https://404privacy.com/blog/browser-fingerprinting-is-the-ad...
- ChrisArchitect 5mo ago[dupe] Discussion: https://news.ycombinator.com/item?id=47613981 https://news.ycombinator.com/item?id=47613981
- Cider9986 5mo ago28 days ago, 1897 points, 812 comments
- traderj0e 5mo agoIt's a different primary source though
- gnabgib 5mo agoThis is the same source - 404 story lists browsergate.eu (linked by Chris) as the original source
- un-nf 5mo agoYeah, the source I used is browsergate.eu. I do a lot of developing in the dev tools (browser fingerprinting protection tool on the same site) and so I was looking at the dev tools for linked in and saw the extension enumeration a few weeks ago. I didn't realize that's what was going on, but there was a repository from a few years ago that started tracking this. There's a HN link somewhere... nefariouslinkedin I think it was called. Then, I saw the browsergate story drop on mastodon and thought "no way," lo-and-behold, there's a lawsuit in the works for it. I found the audit to be a bit dense and hard to read, this is a response to that. I
- un-nf 5mo agoI did do my own independent audit, though. Sorry, I just checked back today and was not expecting this to get the traction it did.
- traderj0e 5mo agoThat's what I mean, this article has its own audit, it's not a dupe of the other
- rapnie 5mo agoSee also "LinkedIn is searching your browser extensions" (812 comments) https://news.ycombinator.com/item?id=47613981 https://news.ycombinator.com/item?id=47613981
- 3dsnano 5mo agofriends, WHEN you are asked to implement something like this at your job, which will you choose: object (& hold ground, loose job) OR comply (& keep job) as practitioners, where do we hold the line between telemetry and surveillance?
- frogperson 5mo agoI choose not to work at places like linked in, meta, or any place that accepts Saudi or Israeli funding. It makes it a little harder to find a job, but i sleep better at night.
- HerbManic 5mo agoIn years to come you will be so thankful that you took that path. As they say, better to be a poor master than a rich slave.
- vehemenz 5mo agoI wouldn’t lump in Israel in, but good for you.
- bravetraveler 5mo agoI got you covered, boo. I will! For sport. Anyway, for those in this situation, some anecdotes. I've outright refused to do questionable things and kept my job. I've also played incompetent so the sharks look elsewhere. Point being... options exist, don't negotiate [only] with yourself. Would be remiss if I missed the opportunity to quote Louis Rossman: "don't accept the premise of assholes"
- KoftaBob 5mo agoThere have been several spywares developed in Israel and that have been used by them and other governments against civilians, below are just a few examples. Why wouldn't you lump Israel in? https://en.wikipedia.org/wiki/Pegasus_(spyware) https://en.wikipedia.org/wiki/Pegasus_(spyware) https://en.wikipedia.org/wiki/Paragon_Solutions https://en.wikipedia.org/wiki/Paragon_Solutions https://en.wikipedia.org/wiki/Cytrox#Predator https://en.wikipedia.org/wiki/Cytrox#Predator
- maelito 5mo agoWell, I deleted my Linkedin account and life is better now.
- booi 5mo agoThat's big talk coming from someone who currently has a job. getting a job without a linkedin account isn't that straightforward.
- traderj0e 5mo agoI get why people without jobs need a LinkedIn, but I don't get why they post there constantly. Like reposting stuff, writing random thoughts, posting rocket ship emojis, has anyone ever gotten a job that way?
- Eji1700 5mo agoI've heard it makes you more visible on things like search results. Linkdin, of course, is trying to encourage interaction on their site so sounds believable that they'd do that, but i've been lucky enough to not need to care.
- traderj0e 5mo agoThat makes sense. I'm curious if it's proven though. Guess I'm lucky to have a job and credentials, recruiters are contacting me despite 0 public LinkedIn activity.
- Tor3 5mo agoNone of our new hires the last few years had anything to do with Linkedin though. As for myself, I deleted my account around the time when it started to try to look like a Facebook feed.
- maelito 5mo agoI don't have a job. But yes, 80 % of people or more have a job. Please talk about their presence on Linkedin and how they force others to stay.
- deleted 5mo ago[deleted]
- kmeisthax 5mo agoWasn't this specifically some lame-ass attempt to combat some click fraud or something these extensions were doing? And aren't these articles specifically coming from the person doing the fraud (which is why they know about the extension scanning)? To be clear, LinkedIn shouldn't be scanning your browser extensions, but still. The ultimate problem is that browser extensions are a powerful malware vector and there's a huge market of people buying little utilities off of solo developers to enshittify them.
- dnnddidiej 5mo ago> LinkedIn shouldn't be scanning your browser extensions. Correct Yes there are other problems in the world and we can JAQ the messanger too.
- cxr 5mo ago> Wasn't this specifically some lame-ass attempt to combat some click fraud or something these extensions were doing? No. That you believed that was just an unfortunate consequence of HN's kneejerk tendency to upvote middlebrow dismissals to the top comment, which resulted in people rushing to craft apologetics for what is in reality bonafide scumminess on LinkedIn's part, which itself resulted in confabulations like the claim that, "It was all extensions related to spamming and scraping LinkedIn last time this was posted"—which is simply untrue.
- ro_bit 5mo agoWhy is my Chrome telling random websites which extensions I have installed?
- gib444 5mo agoChrome is a browser produced by an advertising company. Its reason for existence is to track you.
- lucb1e 5mo agoNot that I disagree but Google's tracking motivation in making the browser seems irrelevant to why it lets competitors do this fingerprinting
- ranger_danger 5mo ago> Its reason for existence is to track you. Source:
- sethops1 5mo agoCan ask the same question about so many horrible security blunders web browsers have made over the decades.
- 2ndorderthought 5mo agoThey are only blunders if they aren't being used as features by someone
- 5mo ago
- GodelNumbering 5mo agoI saw the following from linkedIn this morning > Update to our terms and data use As of November 3, 2025, we are using some of your Linkedin data to improve the content-generating Al that enhances your experience, unless you opt out in your settings. We also updated our terms. See what's new and how to manage your data. Frankly, it is unacceptable to tell a user "oh we have been using your personal data for 5 months already and will continue to do so unless you explicitly opt out". Are there any transparent alternatives to LinkedIn (not the trust me bro variant)?
- _tgxm 5mo agoI am building corvi.careers, its a job search engine not social network tho
- echelon 5mo agoCan someone here please create a LinkedIn replacement for developers that 1. Doesn't have the spam 2. That doesn't look like it's from 2008 3. That only developers / engineers / tech folks can join 4. Doesn't try to log into your email to steal your contact list 5. That doesn't track you or your extensions / browser fingerprint 6. That doesn't have a bunch of fake "linkedinmaxxing" garbage content 7. that doesn't have marketers and recruiters, etc. 8. ...
- recursivegirth 5mo agoIRC has existed for decades.
- StilesCrisis 5mo agoIs this a hallucination? I can't find this quote anywhere else. > According to browsergate, Milinda Lakkam confirmed this under oath, saying, "LinkedIn took action against users who had specific extensions installed."
- GrinningFool 5mo agoHuh, kind of. That's not the actual quote. Note I haven't followed the chain further back than this: https://browsergate.eu/the-evidence-pack/ https://browsergate.eu/the-evidence-pack/ LinkedIn’s systems “may have taken action against LinkedIn users that happen to have [XXXXXX] installed.” Edit: nice! I just notice indent-formatted text is now wrapping on mobile browsers. (Or at least ffm.) I wonder how long that's been fixed...
- Lerc 5mo agoSaying 'I may have taken a shower' instead of 'I took a shower' makes my wife use her disapproving look.
- GrinningFool 5mo agoTrue - also when you put something in quotes I think it should be a quote.
- deleted 5mo ago[deleted]
- stevenicr 5mo agoand, recently while trying to decipher why computer was at 98% memory and 65% cpu one of the culprits is https://li.protechts.net https://li.protechts.net taking 2GB ram and 8% cpu. DDG searches say this is something for linkedin. - I had two tabs for linkedin open but left behind as I opened other tabs to research. So I had not reopened these tabs in over 9 hours and they are still just humming along sucking down almost 10% of cpu and a couple gigs of ram for what? This is firefox with ublock origin - quick searches saw malwarebytes browser guard considered it (protechts.net) malware for a bit and then took it off the list of things it blocked / warned about. Not sure this is related to the scan mentioned, but it may be related to the overall concerns about data and unknown usage of resources. I'm considering blocking this at the dns hosts level at this point. repost of my comment 28 days ago
- tpurves 5mo agoThanks for flagging this, I was literally seeing the same thing with protechts.net in my activity tab this morning as I was trying to understand why firefox was aggressively draining my battery.
- gedy 5mo agoLinkedIn without the news/post feed would be fine
- ricardonunez 5mo agoThere’s an extension called News Feed Eradicator that does that for you.
- mcintyre1994 5mo agoWonder if it’s on their list of extensions to spy on!
- selcuka 5mo agoWe should be good if the Eradicator extension eradicates the script that scans for extensions.
- em-bee 5mo agoi just don't open the main page with the feed. i practically don't notice it's there. i have the messages view open, and i check notifications. i also don't follow anyone (except my contacts)
- bluedino 5mo agoAnd the useless notifications
- seattle_spring 5mo agoHaving a notification that just shows me an ad for "LinkedIn premium" should be a crime.
- deleted 5mo ago[deleted]
- charcircuit 5mo agoThis is pure speculation. It is a million times more likely that this data is strictly used to combat scraping and fraud.
- mr_toad 5mo agoYou saw speculation, and you raised with speculation and hyperbole!
- dctoedt 5mo agoSeems to do this in Microsoft Edge, too.* * I use Edge bcs of the vertical tabs — Safari's equivalent is a poor substitute. Firefox didn't seem to have vertical tabs last time I checked.
- flenserboy 5mo agoFun to have to spin up a whole VM just to use a particular website!
- 0xAstro 5mo agonow it makes sense with the 1000s of spammy not found requests to chrome extensions i was seeing on linkedin and had claude code debug.
- 0xAstro 5mo agoNow the 1000s of spammy chrome web extension requests when I opened LinkedIn makes sense
- Aurornis 5mo agoThis is re-posted article from the author's Substack that does a pretty bad job of explaining the situation. The second link in the article is supposed to take you to a "GitHub repository tracking the extension list" but it goes to a GitHub page for a plugin that hasn't been updated in 9 years. It has a lot of hallmarks of LLM writings ("It's not this, it's that" and feeling like a lot of empty words rehydrated from an outline) while missing the real updates in the story like the German affidavit filed by a LinkedIn engineer who worked on these tools. A key piece of information that this article omits is that the list of extensions being scanned for doesn't include anything you'd recognize or anything you'd even think to install. It's full of data extraction tools, scrapers, AI spam and recruiting tools (remember all those automated spammy LinkedIn messages you got?), and plugins masquerading as simple things that have been pulled from the extension store for violations. A lot of articles have been trying hard to distract from this fact by highlighting that the list of extension includes things like a plugin designed to simplify web pages for neurodivergent users or an "anti-Zionist political tagger" to imply that they're trying to do fingerprinting based on those attributes, but they neglect to mention that those plugins were pulled from the extension store most likely because they were data exfiltrators dressed up as simple plugins to get people to install them. An updated list is available here: https://browsergate.eu/extensions/ https://browsergate.eu/extensions/ But read that site carefully and actually try to click the links. In this section they're trying to direct your attention away from all of the AI spam and data extraction tools with this section: > The scan doesn’t just look for LinkedIn-related tools. It identifies whether you use an Islamic content filter (PordaAI — “Blur Haram objects, real-time AI for Islamic values”), whether you’ve installed an anti-Zionist political tagger (Anti-Zionist Tag), or a tool designed for neurodivergent users (simplify). But click the links. They've all been pulled from the store. Extensions like that are often bait to get people to install scrapers that will use your computer and LinkedIn login to extract data and send it back to their servers. So regardless of where you stand on probing for the presence of these scammy extensions, you should at least understand the facts rather than the story that companies like this are trying to sell you to drive traffic to their product. I suggest cutting through the ragebait journalism and reading more directly from a recent source, like this affidavit filed in Germany by a LinkedIn engineer familiar with the project: https://browsergate.eu/downloads/Lakam-affidavit-redacted.pdf https://browsergate.eu/downloads/Lakam-affidavit-redacted.pd...
- pino83 5mo ago[flagged]
- Severian 5mo agoWhat's the reason you asked this question? I mean, yeah, you could have stayed silent, and nowadays everyone assumes that pointing out obvious things in a condescending tone is kind of insightful, just because you used enough ellipses. Back then we all knew: vague rhetorical questions aren't arguments. Technically, it's not a big surprise at all that someone would restate "you are the product" like it's a revelation. There is nothing novel at all. And non-technically, yeah, as you said... You tried to weather a paragraph of empty meaning. You know that this comment says absolutely nothing actionable. You've known since word one. Nobody can actually be stupid enough to not instantly see that. It's impossible to not understand it. Your strategy so far was to just scold. Who of you has expected a productive outcome, given this "mediocre" contribution, to say it veeeeeery friendly?
- pino83 5mo agoOn the one hand, this really sounds frustrated, and I know why you are (bcs we both know that I'm right). But beyond that unhappy story, your comment actually made me smile. Linguistically, let's say. And there is no sarcasm at all. It was funny to read!!
- downrightmike 5mo ago"What's the actual problem? I mean, yeah, time passed by... And nowadays everyone assumes that all these services are kind of fine, just because time passed by." no no no no no no no, These sites go on the blacklist.
- pino83 5mo agoEither it was there since day 1, together with Facebook and some others, or your blacklist is a pointless show. What nobody started discussing so far: Every user actively pushed these shady sites. They are/were all active parts of the problem. And usually they somehow knew it. They'll come with lame excuses, as if the issue ever was a technical one, and too difficult to get, but in fact, no, things cannot be more obvious. To everyone who ever got in touch with other human beings. It never was a tech problem. I'm excited when this discussion will start. But we are far away from it yet.
- cynicalsecurity 5mo agoBut how is this supposed to help against scraping? This is ridiculously ineffective against scraping. Just pretend to have a standard set of extensions and you are good to go.
- pyrophane 5mo agoHere's the most relevant section I could find from the original source: "Chrome extensions can expose internal files to web pages through the web_accessible_resources field in their manifest.json. When an extension is installed and has exposed a resource, a fetch() request to chrome-extension://{id}/{file} will succeed. When the extension is not installed, Chrome blocks the request and the promise rejects. LinkedIn tests every extension in the list this way."
- thayne 5mo agoIt seems like it shouldn't let code originating from the site (as opposed to from the extension) to access that.
- fractaled 5mo agoI'm not sure you'd need to directly fetch to determine if they resolve. One could probably inject an img tag and see if it resolves.
- golem14 5mo agoHmm, can one fake-install extensions that randomly return yes/no to those queries ? It's pretty clear which files linkedin (and other sites doing the fingerprinting) is testing, one can observe it as the OP author points out. It should also be interesting to see which other sites test those very same files, has anybody looked yet ?
- theturtle 5mo ago[dead]
- SpyCoder77 5mo ago> Users who had no idea their software was being inventoried, no idea the inventory was being used against them, and no way to know it was happening because none of it appears in LinkedIn's privacy policy. As if users are actually reading the privacy policy...
- lemax 5mo agoThis is fairly standard practice for device fingerprinting. LI is probably using this to protect its platform from scraping etc, and extension lists have sufficient enough entropy to help identify users and form a useful component of a fingerprint.
- ghm2180 5mo agoIts already pretty easy to oneshot an extension aiding scraping and LI can do nothing about it. I've seen people build and install a local chrome extension in a couple of days and have an AI inject itself into devtools and scrape pretty much any website. And that was a few months ago. I don't think there is an easy way to defend against such things anymore. Its a matter of time that defensive programming measures like this become useless.
- varenc 5mo agoOne trick to evade some of LinkedIn's detection: A big part of its detection relies on finding known extension resources at URLs of the form `chrome-extension://{extension_id}/{file}` An extension installed from the Chrome store has the same `extension_id` for every user. But, if you just extract the source for that extension, and then load it yourself, you'll get a NEW extension_id. Same extension with the same functionality, but its extension_id will be completely new so impossible for LinkedIn to query. Granted this won't evade the second type of detection LinkedIn employs, it'll help you evade quite a bit. I often clone extension source code anyway since it mostly protects me from malicious extension updates (by effectively disabling updates).
- cromka 5mo agoCall me crazy but both Google and MS started doing weird things like that since about the dinner at Trump. Did you know that Google Chrome now happily asks you to store your ID/Passport information on top of all the information they offered to store for the last 10 years or so? Why now? Why this crazy "enhanced" feature? (https://blog.google/products-and-platforms/products/chrome/enhanced-autofill/ https://blog.google/products-and-platforms/products/chrome/e...) I am far from conspiracy theorist but, god damn, if you take a few steps back from all the current madness and look at what's happening from a perspective, then YES, they're collecting all that data and it up to specific people and their IDs. I don't even want to guess how deep are Palantir and AI chat in this.
- estimator7292 5mo agoThis is complete and utter conspiracy nonsense. This kind of tracking has been going on for decades
- jameson 5mo agoWhy doest the browser even allow it? Runtime of extensions should be blackbox to a website IMO
- thwarted 5mo ago> Hundreds of job search extensions are in the scan list. LinkedIn knows which of its users are quietly looking for work before they've told their employer. … Extensions tied to political content, religious practice Why are these even extensions to begin with? A legit job finding service can be a website, no extension required. If they are nefarious extensions that fake ad clicks or mine cryptocurrency, that they are job search, or political, or religious in name/nature only serves to get rubes to install them. This entire ecosystem is goofed up.
- ghm2180 5mo agoI use firefox with uBlock Origin's matrix turned on linked in and its cdn is explicitly black listed globally on it. I see links like ~`licdn` or some shit appear with a lot more frequency on webapps in the matrix now a days. I would recommend you all install it and block it actively. Its disgusting.
- claytonn 5mo agoJust as invasive as Akamai bot manager on every other site you visit. Akamai is so jam packed they can likely identify you from the mouse movement data alone. The LinkedIn discourse feels forced, the problem is so much worse than what you're seeing here.
- namar0x0309 5mo agoAside from the gross privacy invasion it specifically looks for Muslim/Islamic related extensions. Having a lot of connections working at Microsoft and Western tech industry, I'm not surprised with the targeting of Muslims.
- itake 5mo agoMuslim/Islamic extremist recruiters used Adobe's Express platform for terrorist / extremist recruitment. No idea if if LinkedIn has the same issue though.
- gusfoo 5mo agoIn fairness, their privacy policy DOES explicitly say that they collect this information. See https://www.linkedin.com/legal/privacy-policy?ref=cms.hondas.net#your-device-and-location https://www.linkedin.com/legal/privacy-policy?ref=cms.hondas... > 1.5 Your Device and Location > We receive data through cookies and similar technologies When you visit or leave our Services (including some plugins and our cookies or similar technology on the sites of others), we receive the URL of both the site you came from and the one you go to and the time of your visit. We also get information about your network and device (e.g., IP address, proxy server, operating system, web browser and add-ons, device identifier and features, cookie IDs and/or ISP, or your mobile carrier). If you use our Services from a mobile device, that device will send us data about your location based on your phone settings. We will ask you to opt-in before we use GPS or other tools to identify your precise location. "including some plugins" being the relevant bit.
- soraminazuki 5mo agoThat's them worming themselves out of legal responsibility and makes them look even worse.
- tim333 5mo agoIt's quite the resource hog too > tracks 6,278 extension I just tried it and in 7 mins it got to 800 errors so that's like 50 minutes to do them all, using ~5% of cpu.
- 1vuio0pswjnm7 5mo ago"Then, I saw the browsergate story drop on mastodon and thought "no way," lo-and-behold, there's a lawsuit in the works for it." - un-nf Farrell v LinkedIn Corporation 4:26-cv-02953-KAW (N.D. Cal. Apr. 6, 2026) https://ia601503.us.archive.org/33/items/gov.uscourts.cand.467271/gov.uscourts.cand.467271.1.0.pdf https://ia601503.us.archive.org/33/items/gov.uscourts.cand.4...
- ifh-hn 5mo agoSo if you must use LinkedIn, the answer then is to use Firefox, and create a locked down profile with ublock origin installed with webrtc disabled in advanced mode and block everything be default. Then navigate to linkedin and only whitelist the minimum scripts needed to run the site.