4 ms·
Why is my Chrome telling random websites which extensions I have installed?
by ro_bit 5mo ago
Why is my Chrome telling random websites which extensions I have installed?
- gib444 5mo agoChrome is a browser produced by an advertising company. Its reason for existence is to track you.
- lucb1e 5mo agoNot that I disagree but Google's tracking motivation in making the browser seems irrelevant to why it lets competitors do this fingerprinting
- ranger_danger 5mo ago> Its reason for existence is to track you. Source:
- sethops1 5mo agoCan ask the same question about so many horrible security blunders web browsers have made over the decades.
- 2ndorderthought 5mo agoThey are only blunders if they aren't being used as features by someone
- hbn 5mo agoIs that information available to websites? I figured they were doing some kind of novel hackery to self-detect extensions based on behaviour that would only happen if X extension was installed. But that would be a lot of work for 6,300 extensions. Unless someone offers that as a service?
- kimos 5mo agoIt isn’t exactly. They created a list of known extensions by their id and a file which is known to exist in that extension. The site iterates over each pair and tries to load that file, if it doesn’t error it knows the extension is installed. It’s a clever and difficult manual process, but it does bypass the security trying to prevent this kind of thing. I read that their reasoning is it exists to block users that use known scraper extensions which bypass their terms of use. But don’t entirely buy that.
- FridgeSeal 5mo agoSo the follow up question, is why is a random website, allowed to try and load arbitrary files?
- stingraycharles 5mo agoThis is how I interpreted the original question and indeed it makes no sense, JavaScript from a website should not be allowed to interact with extensions like this.
- flomo 5mo agoIt's actually the extension injecting itself into the webpage, often to interact with it. (I imagine much of this is just looking for global ExtensionName objects.)
- angoragoats 5mo agoActually, the article is clear about what is happening technically, and it’s both. Chrome does, in fact, allow the page to make requests for resources stored in the extension bundle, and this is one of the two fingerprinting methods that the article describes.
- encom 5mo ago>JavaScript from a website should not be allowed Agreed 100%.
- AndroTux 5mo agoBrave explicitly blocks this
- pnw 5mo agoLast time this was discussed the consensus was Brave does not block it. Brave's fingerprinting protection does not include extensions. https://news.ycombinator.com/item?id=46904361 https://news.ycombinator.com/item?id=46904361
- AndroTux 5mo agoWell, just because LinkedIn still tries to send the requests on Brave doesn't mean the blocking doesn't work. The question is whether any request will give a valid response. That said, I can't find conclusive info on whether this is blocked exactly. Brave does block "plugins" (which is why I assumed this includes this specific kind of fingerprinting), and the getExtension() call (which is probably unrelated), according to this page: https://brave.com/privacy-updates/4-fingerprinting-defenses-2.0/ https://brave.com/privacy-updates/4-fingerprinting-defenses-... But since they don't explicitly mention the chrome-extension URL, you might be right.
- p_stuart82 5mo agobecause Chrome lets sites probe "installed", and LinkedIn turns that into telemetry.
- pyrophane 5mo agoHere's the relevant bit from the original source: "Chrome extensions can expose internal files to web pages through the web_accessible_resources field in their manifest.json. When an extension is installed and has exposed a resource, a fetch() request to chrome-extension://{id}/{file} will succeed. When the extension is not installed, Chrome blocks the request and the promise rejects. LinkedIn tests every extension in the list this way."
- actionfromafar 5mo agoChrome always makes tracking easier. It’s their blind spot, because google.
- estimator7292 5mo agoSo that websites can track and identify you "for improved personalized advertising" in exactly this way. Browser fingerprinting is massively valuable to Google's surveillance/advertising apparatus. This is all working exactly as intended.