7 ms·
Skimming the list, looks like most extensions are for scraping or automating LinkedIn usage. Not surprising as there's money to be made with LinkedIn data. Scra
by rdoherty 8mo ago
Skimming the list, looks like most extensions are for scraping or automating LinkedIn usage. Not surprising as there's money to be made with LinkedIn data. Scraping was a problem when I worked there, the abuse teams built some reasonably sophisticated detection & prevention, and it was a constant battle.
- hsbauauvhabzb 8mo agoWont someone think of poor little LinkedIn, a subsidiary of one of the largest data brokers in the world?
- charcircuit 8mo agoWhy frame what you are trying to say like that? Businesses of all sizes deserve the ability to protect their businesses from abuse.
- ronsor 8mo agoI think they framed it this way because they don't consider scraping abuse (to be fair, neither do I, as long as it doesn't overload the site). Botting accounts for spam is clear abuse, however, so that's fair game.
- hsbauauvhabzb 8mo agoNo, I consider all data collection and scraping egregious. From that perspective, LinkedIn is hypocritical when Microsoft discloses every filesystem search I do locally to bing.
- dylan604 8mo agoAre you not scraping a site with your eyeballs when you view a site?
- hsbauauvhabzb 8mo agoBy that logic I can charge you for looking at me.
- direwolf20 8mo agoI agree. Maybe that logic (which is your logic) isn't very good.
- hsbauauvhabzb 8mo agoYou’re just making yourself look dumb by drawing invalid comparisons and an inaccurate understanding of my logic.
- schmidtleonard 8mo agoThe big social media businesses deserve a Teddy Roosevelt character swooping in and busting their trusts, forcing them to play ball with others even if it destroys their moats. Boo hoo! Good riddance. World's tiniest violin. This is a popular position across the aisle. Here's hoping the next guy can't be bought, or at least asks for more than a $400M tacky gold ballroom!
- sellmesoap 8mo agoWe enjoy the fruits of an LLM or two from time to time, derived from hoards of ill gotten data. Linkedin has the resourses to attempt to block scraping, but even at the resource scale of LI I doubt the effort is effective.
- charcircuit 8mo agoI am not denying that scraping is useful. If it wasn't people wouldn't do it. But if the site rules say you aren't allowed to scrape, then I don't think people should be hostile towards the people enforcing the rules.
- ronsor 8mo agoWell, they can try to enforce the rules; that's perfectly fair. At the same time, there are many methods of "trying" which I would not consider valid or acceptable ones. "Enforcing the rules" does not give a carte blanche right to snoop and do "whatever's necessary." Sony tried that with their CD rootkits and got multiple lawsuits.
- jmward01 8mo agoDo they respect my data? Why do they get to track me across sites when I clearly don't want them to but someone can't scrape their data when they don't want them to. Why should big companies get the pass but individuals not? They clearly consider internet traffic fair game and are invasive and abusive about it so it is not only fair to be invasive and abusive back, it is self defense at this point.
- hsbauauvhabzb 8mo agoThey don’t need to track your web browser when they’re owned by Microsoft, because they track every action at a lower level.
- missingdays 8mo agoWhat lower level? Microsoft owns internet?
- zelphirkalt 8mo agoThe operating system. For example see the Windows 11 screenshot debacle/scandal.
- Dylan16807 8mo agoAre you talking about Recall, which got such huge negative press they delayed it a year and added a clear opt-in? And never sent anything off the device itself? If anyone has evidence of constant tracking and reporting then please share it.
- zelphirkalt 7mo agoWell, I won't touch Windows 11 with a ten feet pole and I don't know if what I am referring to is called "Recall". Not that much into the MS terminology. I also read about Windows 11 having all kinds of shenanigans to suddenly upload data into onedrive. Wouldn't be surprised, if that also included screenshots, or could "accidentally" lead to that happening. Screenshotting every few seconds is unacceptable even if it stays on the device per se. Once data exists, it has potential to leak, and we have not even started considering malware infection yet. Huge risk to people's privacy and safety online. We can stop pretending all it alright at some point, can't we? We don't need more enshittification. Windows 11 is already a disaster, that no one wants. It already starts with its idiotic HW requirements, trying to make perfectly fine HW obsolete. $$$
- nitwit005 8mo agoI'm sure there are issues with fake accounts for scraping, but the core issue is that LinkedIn considers the data valuable. LinkedIn wants to be able to sell the data, or access to it at least, and the scrapers undermine that. They could stop all the scraping by providing a downloadable data bundle like Wikipedia.
- compiler-guy 8mo agoLLMs scrape Wikipedia all the time, or at least attempt to. The data bundle doesn't help that at all.
- nitwit005 8mo agoThat's true, the normal scraping would still happen, but it would eliminate this side business of trying to re-sell LinkedIn's data.
- sidrag22 8mo agothinking more about, I don't think its a terrible thing that they prevent scraping. Their listings are already suffering from being flooded with garbage applications and having to sift through tons of noise. allowing scraping would just amplify that and make the platform almost entirely worthless. I "scrape" linkedin in a roundabout way for personal use, and really what Ive found is that i should just maybee not bother at all. I can't get through the noise even when im applying at places that heavily match my skillset, and just get automated rejection emails.
- b112 8mo agoYes, until it becomes abusive and malignly affects innocents.
- RockRobotRock 8mo agoWhen they scrape, it’s innovation. When you scrape, it’s a felony.
- cyanydeez 8mo agothe abuse>using the information they publish to the public
- qotgalaxy 8mo ago[dead]
- mistrial9 8mo agothis exchange -- obvious critical / perhaps insurrection speech versus a stable voice of business economics -- should be within the purview of an orderly and predictable legal environment. BUT things moved quickly in the phone battles. Some people say that the legal system has never caught up to the data brokering, and in fact the surveillance state grew by leaps and bounds. So, reasonable people may disagree. This is a fine place to mention it .. what if individual profiles built at LinkedIn are being combined with illegitimate and even directly illegal surveillance data and sold daily? Everyone stand up and salute when LinkedIn walks in the room? there has to be legal and direct ways to deal with change, and enforcement to complete an orderly and predictable economic marketplace.
- duskdozer 7mo ago>BUT things moved quickly in the phone battles. Some people say that the legal system has never caught up to the data brokering, and in fact the surveillance state grew by leaps and bounds. Partially by discrepancy in how responsive you can be or comprehensive you must be to win the next round of cat-and-mouse, and partially because a private/corporate surveillance apparatus is useful to a government that might otherwise be hampered by constitutional bounds.
- direwolf20 8mo agoWhat is abuse? Is it anything that reduces my profit margin? Or is it anything that makes the world a worse place? The Flock CEO called Deflock terrorism, is he right?
- xp84 8mo agoI mean, regardless of who they are or even if you don’t like what LinkedIn does themselves with the data people have given them, the random third parties with the extensions don’t additionally deserve to just grab all that data too, do they?
- sieabahlpark 8mo ago[dead]
- mathfailure 8mo agoSurely they do! The data is in the public internets, aren't they?
- ronsor 8mo agoThey'd put Widevine or PlayReady DRM on the website if they could, I'm sure.
- bigfishrunning 8mo agowhy can't they?
- direwolf20 8mo agobecause they're only for video files?
- josephg 8mo agoEh. I worked at a company which made an extension which scraped LinkedIn. We provided a service to recruiters, who would start a hiring process by putting candidates into our system. The recruiters all had LinkedIn paid accounts, and could access all of this data on the web. We made a browser extension so they wouldn’t need to do any manual data entry. Recruiters loved the extension because it saved them time. I think it was a legitimate use. We were making LinkedIn more useful to some of their actual customers (recruiters) by adding a somewhat cursed api integration via a chrome extension. Forcing recruiters to copy and paste did’t help anyone. Our extension only grabbed content on the page the recruiter had open. It was purely read only and scoped by the user.
- bryanrasmussen 8mo agofrom the code doesn't look like they do anything if they have a match, they just save all the results to a csv for fingerprinting?
- cxr 8mo ago"The code" here you're referring to (fetch_extension_names.js[1]) isn't and doesn't claim to be LinkedIn's fingerprinting code. It's a scraper that the researcher behind this repo wrote themselves in order to create the CSV of the data that they're publishing here. LinkedIn's fingerprinting code, as the README explains, is found in fingerprint.js[2], which embeds a big JSON literal with the IDs of the extensions it probes for. (Sickeningly enough, this data starts about two-thirds of the way through the file* and isn't the culprit behind the bulk of its 2.15 MB size…) * On line 34394; the one starting: const r = [{ id: "aacbpggdjcblgnmgjgpkpddliddineni", file: "sidebar.html" 1. <https://github.com/mdp/linkedin-extension-fingerprinting/blob/main/fetch_extension_names.js https://github.com/mdp/linkedin-extension-fingerprinting/blo...> 2. <https://github.com/mdp/linkedin-extension-fingerprinting/blob/main/fingerprint.js https://github.com/mdp/linkedin-extension-fingerprinting/blo...>
- bryanrasmussen 8mo agothanks, my fault for not reading the read me and just doing a quick read of the code.
- cxr 8mo agoIn order to create the data source that LinkedIn's extension-fingerprinting relies on to work, someone (at LinkedIn*?) almost certainly violated the Chrome Web Store TOS—by (perversely*) scraping it. * if LinkedIn didn't get it from an existing data source
- direwolf20 8mo agoProgrammers don't appreciate the fact that you can just violate terms of service. You can just do it. It's okay. The police won't come after you. Usually.
- mosselman 8mo agoIndeed. I read a lot of comments like these one you are responding on HN. It seems like there is a type of person who thinks that writing down what their rules are has some magical power. “This isn’t what it was intended for”. Who cares? A long long time ago in a galaxy far far away I would encounter warnings on pirating websites saying “If you are an FBI agent you are not allowed to continue on this site”. Imagine their utter disbelief and shock if they were to be arrested by an FBI agent that clicked past the warning anyway. I agree is must be programmers as a type that like rules a lot and, they think, what a perfect world it could be if people would follow them.
- deleted 7mo ago[deleted]
- cxr 7mo agoI'd ask who you think you have me confused for or where you got that quote from, but I know how little it matters insofar as getting you to recognize whatever delusion led to your comment.
- mosselman 7mo agoI am sorry, I wasn't reacting to you I was reacting to the commenter who said: "Programmers don't appreciate the fact that you can just violate terms of service."
- winddude 8mo agoa problem for linkedin != "a problem". The real problem for people is the back room data brokering linkedin and others do.
- dumbo23 8mo ago[dead]
- RHSman2 8mo agoI had the pleasure of scraping LinkedIn for a client. Great fun.
- tlogan 8mo agoBy looking the list it seems like it is not really “sophisticated”. It is just list based on names (if there is a “email” in the name). Majority of extensions do not even ask for permissions to access linkedin.com.