45
you are viewing a single comment's thread
view the rest of the comments
[-] mlfh@lemmy.sdf.org 24 points 1 month ago

Since this is being posted fucking everywhere with the same sensational headline that makes it look like linkedin is jumping out of the browser to scan your actual filesystems, here's an exerpt from the site linked:

The Attack: How it works
Every time you open LinkedIn in a Chrome-based browser, LinkedIn’s JavaScript executes a silent scan of your installed browser extensions. The scan probes for thousands of specific extensions by ID, collects the results, encrypts them, and transmits them to LinkedIn’s servers. The entire process happens in the background. There is no consent dialog, no notification, no mention of it in LinkedIn’s privacy policy.

It's enumerating the browser extensions you have installed.

[-] LodeMike@lemmy.today 12 points 1 month ago

Why does Chrome give websites this ability?

[-] ActualGrapesTasteGreen@piefed.zip 9 points 1 month ago* (last edited 1 month ago)

This should be top comment in every post of this article. It doesn't make what they're doing ok, but it's less sensational.

Honestly I'm surprised any browsers let arbitrary websites list installed extensions.

[-] OwOarchist@pawb.social 5 points 1 month ago

Still could be quite damaging to your privacy, especially since LinkedIn usually also knows your real name and your employer, so they can easily match this list of extensions up with a precisely identified person.

this post was submitted on 02 Apr 2026
45 points (89.5% liked)

Hacker News

4838 readers
494 users here now

Posts from the RSS Feed of HackerNews.

The feed sometimes contains ads and posts that have been removed by the mod team at HN.

Source of the RSS Bot

founded 2 years ago
MODERATORS