7 ms·
How LinkedIn detects browser extensions
- mirimir 8y agoOK, but why does LinkedIn scan extensions?
- tgtweak 8y agoAnd, do they need to do it or are they just data mining?
- t0astbread 8y agoIf they don't need it, isn't it illegal to collect that data under the GDPR?
- TeMPOraL 8y agoI don't see the repo actually saying they're collecting this data, i.e. sending it back to their servers. It may just be a "reverse adblocker" - a list of signatures of extensions that the website's JS will try to interfere with on the user end.
- ve55 8y agoWho is going to stop them? I'm sure the data is worth >0 to them (or someone)
- shannongreen 8y agoThey want to block tools that offer functionality similar to their paid offerings.
- cwilkes 8y agoTo fingerprint you via what you cremations you have installed to track your browsing habits.
- tracker1 8y agoMore metadata to shape information... do you have ublock, authy, lastpass, bitmoji, etc. Could be anything from metrics, to useful interactions. Got the dropbox extension, show an option to upload your resume from dropbox directly. etc. Blocking ads, show integrated ads through a secondary channel.
- tracker1 8y agoI really don't understand the downvotes.
- mirimir 8y agoLinkedIn's reputation isn't so great. Primarily because they harvest user mailboxes, and spam endlessly about Mirimir (for example) inviting recipients to join their associate at LinkedIn. And it's not just annoying. Sometimes it hurts people's careers.
- tracker1 8y agoOh, LinkedIn's reputation is deplorable... what they did to bypass security on iOS (and I think Android too) are particularly interesting (mail proxy). I'm not saying that metadata collection is good, or that there aren't nefarious reasons... I stated that was one reason, and it could be to offer features. I only created a linkedin account to stop all the email invites... and even then, refuse to install their app (links pervasive in mobile web) and only accept connections to those I've met personally, and very few recruiters.
- mirimir 8y agoFair enough. But some people just downvote anything even neutral about something that they hate. That's a funny story. But I have a funnier one. Not long ago, maybe the last time LinkedIn came up on HN, I created a test LinkedIn account as Mirimir. Or at least, I attempted to. Given that I use VPNs, I got a cellphone text authentication prompt. But Mirimir doesn't have a cellphone, so I blew it off. And here's the funny part. A few days later, Mirimir received email from LinkedIn, inviting him to join Mirimir's network on LinkedIn!
- gkoberger 8y agoTo flag accounts that are scraping data or "revealing" email addresses. Negative view: they're blocking people from circumventing their paid features Positive view: they're protecting their other users from getting spammed
- vidarh 8y agoA lot of these are used as CRM type applications where people would love it if LinkedIn just charged for access to a more comprehensive API instead. LinkedIns messaging UI sucks, and ironically one of the reasons to want to use CRMs like Nimble to interact with your LinkedIn connections is to be able to better track communication with them so you don't spam. But of course people will use it to spam too. If LinkedIn offered API access to messaging in a way that let CRMs work with them instead of feel forced to circumvent them I think most who want to use it legitimately would be perfectly happy to have LinkedIn impose various usage limits and peotections even if paid. They should see this as revenue potential: there are lots of potential to get companies with legitimate reasons for more integration than the current API to upsell their customers on paid LinkedIn features if they are able to offer it in an approved way, and I bet many would be happy to let LinkedIn monitor how it's used. If they try to block access instead, they'll find more and more companies keep offering the same, but manually.
- darkpuma 8y agoThey have zero scruples. This is a company infamous for spamming people.
- manigandham 8y agoLinkedIn contains lots of personal data, a large part of which is only available to users who are signed in and/or paid members. They want to protect this information from potential exfiltration by these extensions and their backing companies.
- rathish_g 8y agoLooks like they are trying to block spiders and protect its users
- peteretep 8y agoNo, they're trying to protect their LinkedIn Recruiter license revenue.
- gkoberger 8y agoThe repo says "A look at how LinkedIn spies on its users" I'm not convinced this is LinkedIn spying on users... rather, it's them protecting its users from the spammy people using these extensions. There's not a single extensions on that list that doesn't result in someone getting an unsolicited email.
- kodablah 8y agoCan you link to where they say that? I would figure someone doing something so helpful for users would at least document it. There's no reason to be surreptitious when doing such a favor. One wonders if they'll start offering a LinkedIn AntiVirus download with such an altruistic approach towards protecting users from what they have installed.
- gkoberger 8y agoI think you're misunderstanding. LinkedIn isn't protecting the people with the extensions installed; they're protecting users FROM the people with the extensions.
- kodablah 8y agoAh, as an anti-scraper/anti-bot method, every user has all these local network requests made? Maybe it's the true reason, maybe not. Transparency is key here to assume anything more than the worst. Of course any of the rest of us with a modicum of smarts would just side load a custom extension via CLI args (or we'd just browser automate, headless if not detected). Even given the most generous justification, it reeks of careless decision makers playing whack-a-mole (likely fruitlessly) with the users in the crossfire.
- Buge 8y agoI think it's a cat and mouse game. The more that Linkedin publishes about their anti-spam techniques, the more information spammers have to try to evade those anti-spam techniques.
- meitham 8y agoIs this issue unique to Chrome? Does it happen with Firefox?
- mweibel 8y agoI do have the same localStorage item in my Firefox. The shown way of decoding the content works too.
- aswan 8y agoThe technique of attemping to load web accessible resources does not work in Firefox. For starters, Firefox uses moz-extension: instead of chrome-extension:, that's obviously trivial to adapt to, but Chrome then uses the extension's global identifier in those URLs, while Firefox uses a locally generated identifier, specifically to avoid this sort of fingerprinting.
- pacifika 8y agoEven if the intent by LinkedIn is legit this will soon get used by data tracking scripts to further de-anonymise people
- deleted 8y ago[deleted]
- robin_reala 8y agoCould you explain what holes these extensions are using to extract the hidden personal data? Or is it that the personal data is already in plain view and these extensions are just collating it?
- nikbackm 8y agoProbably the latter. Otherwise LinkedIn would just fix the holes and not bother blocking extensions.
- deleted 8y ago[deleted]
- cooc 8y agoDo you know if the user is blocked on LinkedIn, if the system detects one of the extension?
- peteretep 8y ago> but I do know the intention is unequivocally to protect the PII of our members The first item from the block list is "Daxtra", who make a very widely used ATS. Please could you explain the difference from Microsoft's GDPR perspective from when a recruiter accesses this information via a normal browser and manually enters the data into Daxtra vs when someone with the Daxtra plugin accesses it, and uses that to pull the data over?
- guitarbill 8y agoI'm failing to see how these extensions "circumvent the privacy of our members", but normal use of the website doesn't. Either you're safeguarding the information properly, or you aren't. I am fine with huge GDPR fines to teach companies that data is a liability as well as an asset, and needs to be protected appropriately (which this measure doesn't seem to do, since it is trivial to bypass). I'm not so sure I'm OK with you probing my browser to detect ToS violations/scraping, but not transparently mentioning it makes it worse.
- tnolet 8y agoI don’t get it. How can a browser extension mine data that otherwise is inaccessible? This should be covered by basic RBAC. Or are they just convenient scrapers, saving time but otherwise not accessing privileged information. If so, the LinkedIn story about “protecting our users” seems a bit shaky.
- superfrank 8y agoThe extensions are basically bots to collect info for the user with the extension installed, not steal info from that user. Most are either scraping email, names, and job titles as quickly as a bot can, or mass sending out messages to users based on some criteria. Here's a video for one of the extensions https://www.youtube.com/watch?v=2XvtuZjblCc https://www.youtube.com/watch?v=2XvtuZjblCc (Warning: loud music)
- peteretep 8y ago> The extensions are basically bots No, most appear to be plugins for ATS/CRMs, which allow recruiters -- having found a lead on LinkedIn -- to then add them to their CRM. This is profoundly differently.
- ed_blackburn 8y agoTalking of LinkedIn. Any suggestions of how I can bulk-remove contacts? I was wondering if there’s a Chrome Extension? I’m assuming all I’m missing is the motivation to script it?
- tanilama 8y ago> LinkedIn violates their own users' privacy in an effort to detect the usage of browser extensions. At the time of writing this, LinkedIn is scanning visitors for 38 different browser extensions. No it is defending against malicious actors from abusing its API.
- enriquto 8y ago> No it is defending against malicious actors from abusing its API. I do not really understand the concept of "abusing an API". If an API is amenable to a "bad" use, it seems entirely to be the fault of the API designers, not of its users. The designers built an API that enabled an usage that they did not want. That is their fault, how could it be otherwise?
- tanilama 8y agoThat is exactly what LinkedIn is doing, they are preventing bad actors from calling their API essentially blacklist them. They cant be blacklisted via IP since they are scattered across the internet, so they are banning them productively. Simple and easy.
- newsbinator 8y agoWhy not simply rate-limit everyone reasonably?
- peter_retief 8y agoI am really in two minds about Linkedin, I cancelled my account years ago after getting spammed by recruiters, this could be an attempt to clean up but looking quite sinister in the attempt
- kerouanton 8y agoLinkedin has been an issue for years for me, because they simply disclosed your email to anyone connected. This enables some people and/or corporations to scrap profiles and build spam email databases. After being annoyed about this, I started to change my linkedin dedicated email address frequently, 4-5 times a year. The conclusion was obvious: less than a few days after the change, I began receiving spam and proposals on this new dedicated email address, thus confirming the email scraping problem. Yesterday I went back to Linkedin to reconfigure a new email address, and found that the account settings now incorporate a setting to hide your email address to anyone (inactive by default...). I've enabled it and changed again to a new dedicated email address, to see if it is true. I hope this time Linkedin did things right.
- peter_retief 8y agoMaybe I should try again, I am not looking to hire or be hired so not really sure if there is a point anymore
- 345tw4erfd 8y agoCalling this "nefarious-linkedin" when it's obvious that LinkedIn is trying to protect itself from unauthorized data collection shows that the developer is either seeking for attention or didn't really look into the purpose of those extensions (https://github.com/dandrews/nefarious-linkedin/pull/1 https://github.com/dandrews/nefarious-linkedin/pull/1)
- tnolet 8y agoBut how is this data accessible to the extension? I ‘m not an expert, but it seems that this data has to publicly available for an extension to find and parse it. Extensions don’t have magic Auth rights or credentials.
- tylerhou 8y agoExtensions have the same auth rights as your logged-in account (the ability to see people who are out of network, for example). It’s against LinkedIn’s ToS to scrape data.
- feanaro 8y agoThis should go both ways. It is against my ToS for LinkedIn to scrape which extensions I have installed.
- newsbinator 8y agoI'm on the anti-LinkedIn side of this scraping debate. But that said, LinkedIn never agreed to your ToS.
- feanaro 8y agoTrue, and I accept this is a potentially good legal refutation of this kind of argument. However, I do consider ToS-es untenable and unjust because of this power asymmetry. If my computing node is interacting with your computing node, we should either both be able to put restrictions on the use of obtainable information or neither.
- xg15 8y ago> Furthermore, there's no good reason to use web accessible resources in an extension! You can always find a solution to your problem that does not require them. How would I e.g inject an extension-provided image into a web page without using web accessible resources? The only ways I can think of would be copying the image to a blob or drawing it on a canvas - both seem significantly more complex than just injecting an IMG tag and would still be detectable as side effects.
- leni536 8y agoI'm not familiar with writing browser extensions, but data URI comes to mind.
- xg15 8y agoAh, right, I forgot those. That's true of course. I think you could still use them for side-effect detection (watch for images/scripts/etc with a known data uri suddenly appearing in your DOM) - but at least you couldn't actively query it without the extension doing anything.
- Brosper 8y agoWhy this is dangerous?
- maaaats 8y agoHow is a webpage able to query the local file system? That sounds pretty bad.
- kiallmacinnes 8y agoIt doesn't, it queries the local assets of installed extensions. Chrome (and I guess other browsers?) provide a way to do this, so the HTML etc injected by an extension can reference assets shipped with the extension.
- akerro 8y agoYou can query static asset of extension by it's path chrome://extensionid/asset.css
- superfrank 8y agoFor anyone who is asking what/who LinkedIn are protecting with this, it's not the users with the extensions installed, it's to protect the other users on the sites. I poked through some of the listed extensions and most are basically bots that you can turn on that will crawl through LinkedIn pages very quickly and either collect info (like email addresses) or send out messages to other LinkedIn users. I found this video for one of the extensions that is a good example of what I'm talking about https://www.youtube.com/watch?v=2XvtuZjblCc https://www.youtube.com/watch?v=2XvtuZjblCc (Warning: Loud music)
- whoisjuan 8y agoIn 2015 I wrote and publish and Chrome Extension for LinkedIn that calculated the age of a person and put that age next to the name in their LinkedIn profiles. It quickly went viral and showed up in several places including Product Hunt. Someone from BuzzFeed reached out to me asking questions about it and then later that day wrote an article claiming that LinkedIn had asked me to take it down (until that point they hadn't). That night I received a cease and desist letter, so I took it down. There were many valid reasons to ask for my extension to be removed, but I never got the impression that they were doing it to protect the users whose age was being augmented or at least it didn't feel that was their angle. It felt more like "this data is ours, so back-off". Just to be clear, I'm not saying that they were rude in their communications or anything like that. But the C&D letter focused a lot on the techniques and uses of my extension and not so much on the "this violates user's privacy" or "this is not representing accurate data". I just think that in general LinkedIn doesn't like people poking around and trying to scrape data in any way. In the end, that's their most valuable asset (users' data). For anyone curious, I still have the website: http://www.whoisjuan.me/age-insight-linkedin/ http://www.whoisjuan.me/age-insight-linkedin/
- kiallmacinnes 8y agoC&D letters are written by lawyers. They don't appeal to your empathy over the PII of other users, they state facts and appeal to the legal standing LinkedIn (or $company...) has over the data being used. That said, I have no idea of the reasons LinkedIn sent you a C&D. It could well be any of the proposed options, or something else entirely. I'm just highlighting that the language in a C&D will rarely give any indication of intent, at least not "well written" ones anyway.
- dawnerd 8y agoIgnoring everything else, it seems a bit weird a page can make requests to an extension's assets without originating from that extension.
- kiallmacinnes 8y agoI guess this comes down to extensions that inject code / modify the page. Extensions can choose if their assets are public or private, and if they reference the asset from injected code - it needs to be public. It sounds like a better solution might be to track the injected / modified code, and only allow it to read the assets. But I'll bet there is some tradeoff i've no clue about preventing that from happening.
- tinus_hn 8y agoImagine an extension modifying a page and adding an image. How would it allow the image to load if that wasn’t possible?
- deleted 8y ago[deleted]
- dividuum 8y agoI would have hoped for some shared secret approach where the extension can generate one-time use urls for their bundled resources on demand and use those instead of easily predictable urls. It seems that extensions like ad blockers that are explicitly targeted by such detection methods have ways for work around that (see https://github.com/gorhill/uBlock/blob/master/src/web_accessible_resources/README.txt https://github.com/gorhill/uBlock/blob/master/src/web_access...). I honestly would have expected for that to be the enforced default behavior.
- dawnerd 8y agoI was thinking if an image is injected, it'd be injected by a script loaded from the plugin thus trusted.
- 8y ago
- valugi 8y agoGetting intel from their users is just their core business, think it as CV enhancement. I see there a gay2sms extension, that is a pretty sensitive information I would say.
- deleted 8y ago[deleted]
- pheres 8y agoThe written tone used in the repo comes of as too drastic, specially as it only reports the collection of analytics on how LinkedIn users use the website. Is the detection result reported back to LinkedIn? In their [Privacy Policy](https://www.linkedin.com/legal/privacy-policy#your_device_and_location https://www.linkedin.com/legal/privacy-policy#your_device_an...) they do mention they collect information on "web browser and add-ons". This reminds me of similar approaches used in other environments. For example in the game industry, anti-cheat techniques of detecting the running software in mobile devices to flag users. How do you think this differs?
- ttty 8y agoDo they detect the extension... What they do after that? Hide the email?
- userbinator 8y agoChanging the name of the extension resources and any extra elements they add to the page would be enough to stop this. (It reminds me of another "trick" pages like to use: randomising the element IDs. Easily defeated by searching for other properties of the desired element.) Just like DRM, it's a stupid cat-and-mouse game, and the mice will always win...
- patrickwiseman 8y agoOne aspect is that LinkedIn is protective of plugins that incidentally cover up their own ads. Notably several entries on this list once had such grievances filed against them.
- Linkedout 8y agoI admit one of the extensions from the list is mine. But is not as malicious or spammy as some like to picture it. Most of them are complements, addons to help the user with their CRM. I don´t know of any intended to steal data ( i believe they will use scrapers or other ways instead of asking users to pay for an extension) There are well know CRMs like Hubspot or SOHO that aim to sync data. Yes, some others are used to send messages to connections.. just as unsolicited as Inmails, the linkedin paid version( but at least is to connections). They also block extensions that block their ads and extensions like help users to filter out "sponsored " content ( we did that) Regarding GDPR , even LInkedin says Is not actually their data but the users are data controllers ( owners) https://legal.linkedin.com/dpa https://legal.linkedin.com/dpa . Obviously, this is not Ok with LinkedIn because they are a walled garden and not an open platform. The points is they do not let the user decide, customize or adapt their experience to suit their needs. Any feature that is not in their revenues agenda, gets killed even if thousands of users cry for it ( happens regularly ) and they do not let anyone else offer it. Nobody likes spam , but is up the user no to do it - is like if your gmail will not let you send an email to more than one person at a time or be conneted to any other app ( yes, I know there are limits in gmail ). Notice that is not the legal way that Linkedin takes to stop these services because in reality, they are a monopoly ( and as pointed earlier Courts has ruled against Linkedin). Neither they use a educational or marketing path telling the users why is better FOR THEM not to use those extensions. No, they use FUD ( fear, uncertainty & doubt) to scare users and cancel the Linkedin of the people who create this "competition" ..it happened to me, to the people of hunter.io, findthatlead and many others. Mafia style. This is not a moral justification from me, it is a business decision to offer extensions to give capabilities that people want.