To me, this seems like a security flaw in Chromium. Websites should not be able to access any of it (yes, even just the extensions) regardless of what code they're running.
Not great for LinkedIn, but a critical failure of Chromium.
Isn't this what every major social media site does? It's certainly what security and privacy experts have been warning us about for years.
Once can hope LinkedIn pays a heavy price for this, but they've probably done it intentionally knowing the value 100x exceeds the likely penalty. This will probably end up with all of us being offered to join a class action where our settlement is a free month of LinkedIn premium.
What penalty? What illegal thing are they even doing? If the browsers allow this, they should expect it to happen. Prevent it, or expect it. Websites shouldn't be able to "scan" for these extensions in the first place.
At best, they might get a slap on the wrist fine they pay to the FTC or FCC, and admit no fault.
Every time you open LinkedIn in a Chrome-based browser, LinkedIn’s JavaScript executes a silent scan of your installed browser extensions. The scan probes for thousands of specific extensions by ID, collects the results, encrypts them, and transmits them to LinkedIn’s servers. The entire process happens in the background. There is no consent dialog, no notification, no mention of it in LinkedIn’s privacy policy.
So this is a more in depth explanation of what it actually does. In the end it only searches a specific number of extensions from chrome extension store, encrypts it and sends it off to 3rd party.
Installed software! Oh installed software! Where are you! LOL! This guy is using scripts he wrote himself and the combination number #24356357954689 of possible software, desktop GUI and kernel. Okay let's drive our malicious scan!.... Oh sudo password, we need the root password to do anything malicious! Look at this, it even has a welcome screen asking for you to scan as much as it is possible in that image! Darn!
12 Comments
Feyd@programming.dev · 72 pts · 159d
Still wrong, but but not quite as scary as "searches their computer for installed software" which makes it sound like it broke out of browser sandbox
Atelopus-zeteki@fedia.io · 17 pts · 159d
Jokes on them, I never use chrome, and never go to Link'in. I guess they'll never know who I really am, by extension.
null@lemmy.org · 2 pts · 159d
Isn't that what most mainstream sites try to do anyway?
Nollij@sopuli.xyz · 25 pts · 159d
To me, this seems like a security flaw in Chromium. Websites should not be able to access any of it (yes, even just the extensions) regardless of what code they're running.
Not great for LinkedIn, but a critical failure of Chromium.
Dave@lemmy.nz · 6 pts · 159d
Reminds me of how any app in Android can see all the other installed apps. Great for fingerprinting.
French75@slrpnk.net · 14 pts · 159d
Isn't this what every major social media site does? It's certainly what security and privacy experts have been warning us about for years.
Once can hope LinkedIn pays a heavy price for this, but they've probably done it intentionally knowing the value 100x exceeds the likely penalty. This will probably end up with all of us being offered to join a class action where our settlement is a free month of LinkedIn premium.
plz1@lemmy.world · 5 pts · 159d
What penalty? What illegal thing are they even doing? If the browsers allow this, they should expect it to happen. Prevent it, or expect it. Websites shouldn't be able to "scan" for these extensions in the first place.
At best, they might get a slap on the wrist fine they pay to the FTC or FCC, and admit no fault.
HubertManne@piefed.social · 13 pts · 159d
Every time you open LinkedIn in a Chrome-based browser, LinkedIn’s JavaScript executes a silent scan of your installed browser extensions. The scan probes for thousands of specific extensions by ID, collects the results, encrypts them, and transmits them to LinkedIn’s servers. The entire process happens in the background. There is no consent dialog, no notification, no mention of it in LinkedIn’s privacy policy.
Ghostie@lemmy.zip · 8 pts · 159d
StealthLizardDrop@piefed.social · 2 pts · 159d
laughs in linux
solrize@lemmy.ml · 4 pts · 159d
People run Chrome on Linux.
StealthLizardDrop@piefed.social · 2 pts · 159d
So this is a more in depth explanation of what it actually does. In the end it only searches a specific number of extensions from chrome extension store, encrypts it and sends it off to 3rd party.
https://browsergate.eu/how-it-works/
But i also don't use chrome based browser and don't visit LinkedIn. Il live
altphoto@lemmy.today · 0 pts · 159d
Installed software! Oh installed software! Where are you! LOL! This guy is using scripts he wrote himself and the combination number #24356357954689 of possible software, desktop GUI and kernel. Okay let's drive our malicious scan!.... Oh sudo password, we need the root password to do anything malicious! Look at this, it even has a welcome screen asking for you to scan as much as it is possible in that image! Darn!