How LinkedIn exfiltrates extension data from the browser
prophitt.me
prophitt.me
The whole thing is weirdly deceptive.
With all that said, I also think people have a right to use the extensions they want to scrape or block content on sites they visit, so catch 22 I guess.
It's worth thinking of this from both angles before getting angry at LinkedIn, or the author of this post :)
"Is that plugin installed" is also a terrible "protection" against scraping.
Looking for access patterns that are typical for automated usage are a much better answer - and not publicly showing email addresses to everyone, of course.
Do you also think people have a right to record movies they watch in the theater?
I think people are free to run whatever extensions they want in their browser. I think companies are also free to tell people they aren't welcome if they're going to use that extension.
Why should a company like linkedin be FORCED to serve anyone? It's not a public service, they aren't a government entity, you have no right to their service.
The difference in this analogy is that films are fully the IP of the production company but LI sells data that they don't explicitly own.
What are you talking about? Anything you post on LinkedIn is their property. You can't legally access anything on their site without agreeing to their policy. Did you not read the agreement when you signed up for the site?
https://www.linkedin.com/legal/user-agreement#rights
> As between you and LinkedIn, you own the content and information that you submit or post to the Services, and you are only granting LinkedIn and our affiliates the following non-exclusive license:
>You own all of the content, feedback, and personal information you provide to us, but you also grant us a non-exclusive license to it.
You can call it what you want, they have rights to use anything you post on their site as they see fit.
My point stands. They are selling your content without your explicit permission, and against their own terms of service unless you argue that people would agree to their data being sold to recruiters.
That's fine and they're able to do so. But don't say it's also ethical for them to aggressively prevent other services from doing that without paying them.
I can just keep quoting it or you can just admit you're wrong:
>We will get your consent if we want to give others the right to publish your content beyond the Services. However, if you choose to share your post as "public", we will enable a feature that allows other Members to embed that public post onto third-party services, and we enable search engines to make that public content findable though their services.
>You and LinkedIn agree that we may access, store, process and use any information and personal data that you provide in accordance with the terms of the Privacy Policy and your choices (including settings).
Literally says right there that they're only getting your permission if they share your content outside of "Services" - meaning outside of the Linkedin Platform. Those recruiters are using the service.
>Services
>This Contract applies to LinkedIn.com, LinkedIn-branded apps, Slideshare, LinkedIn Learning and other LinkedIn-related sites, apps, communications and other services that state that they are offered under this Contract (“Services”), including the offsite collection of data for those Services, such as our ads and the “Apply with LinkedIn” and “Share with LinkedIn” plugins. Registered users of our Services are “Members” and unregistered users are “Visitors”. This Contract applies to both Members and Visitors.
Nope, but I'd sure be upset if I caught movie theater employees surreptitiously reaching into my pockets to check for cameras.
https://torrentfreak.com/movie-spy-cameras-attack-the-dying-...
They also apparently use the data to gauge emotional response to movie scenes!
https://www.theverge.com/2017/8/15/16148250/microsoft-linked...
AFAIK the current state of things is that LinkedIn is welcome to try and stop people from scraping the site, but it can't criminally charge them or try to legally block them from the service. Roughly the same situation as adblockers -- you can detect them and stick banners all over the place, but you can't outright bar someone from running uBlock Origin on your domain.
Please note that I am not a lawyer.
Or a particular browser. Or a specific operating system. Or the wrong brand of device.
You can probably see where I'm going with that, but in case it's not perfectly clear, I'm trying to say that a company might want to dictate a lot more than just what extension you're using in a browser. Not everyone is going to agree that they are right to do that.
Bear in mind that there's more to consider here than the legality of what they're doing. The openness of the Internet, the interoperability of different operating systems and devices over a particular somewhat-standardized protocol -- these aspects aren't regulated by a law, but they're still important. I'm one of those people who remember the Browser Wars and I don't remember them fondly.
Of course, it's not just about technical aspects, either. There's the whole grey area of whether it's okay for LinkedIn to metaphorically rifle through our proverbial pockets, looking for stuff they don't like and don't want to admit on their virtual premises.
So no, I wouldn't agree that things are as clear cut as you present them.
Of course where to draw the lines is important and up for debate
They are not free to snoop into information that isn't standard or reasonable. But if they aren't running spyware on my computer[2], they can decide whatever they want with the information my browser send to them.
[1] Do they? I'm not sure wether Linked-in has a monopoly as middleman in job searchers.
[2] How does invasive Javascript stands here? I'm inclined to consider that it's my browser's job to protect me, not theirs. But if they do some very unreasonable things, the blame is on them again.
> Why should a company like linkedin be FORCED to serve anyone?
Companies are routinely forced to serve people per the ADA and CRA. There are various rationales for them; I favor them because they cause a degree of integration that helps to disrupt identity politics.
I think, beyond that, if a company has clearly advertised terms of service and sticks to them (it should be possible to sue a company for violating its stated policies) then they should be able to reject customers if they want. Especially, it's often a reasonable engineering/business tradeoff to not support a customer over delivering a buggy product.
Where is the line?
Also, companies are forced to serve people all the time. That was a large part of the fight for civil rights. At some level we do have a right to the service of a private company.
Sure, but that doesn't make it not wrong. Companies are made of people. Forcing people to do something against their will is aggression; if they haven't started it then it's morally wrong.
But I doubt that's why they're doing this.
Sounds like American workplace culture in a nutshell to me. If so, LinkedIn is actually doing it right.
The only utility I get out of it is that I can put up my resume and get recruiters to contact me. Which more than makes up for everything else since it has led to job offers
2 out of my last 4. There's a huge amount of spam. Mostly from big Indian firms looking for cheap labor to staff out a contract. But if you filter that out most of the other messages are legit that have a realistic potential of a job offer.
“Congratulations on hiding your misery for 10 years!!!”
The number of people willing to do that on LinkedIn is a bit shocking....
Those extensions would break the site far less frequently if linkedin would stop trying to break them. And, our users definitely knew when it was us breaking linkedin.
I'm not sure it's as much a catch 22 as it is a self inflicted wound.
It gets complicated when you start thinking of things like blocking other accounts from viewing your profile, or adjusting visibility settings. Arguably LinkedIn has a duty to protect the integrity of their privacy controls, which would entail implementing anti-scraping measures.
... under specific terms of use that scraping technically violates.
I can think of a number of crimes where this statement is also true, so I'm not so certain it serves as an adequate defense.
It's one thing to have police stationed at a bus stop, waiting for a suspect to emerge. It's another to network facial recognition cameras across a city or country and log the motions of the entire population.
It's one thing to greet people in a grocery store and offer coupons for your product. It's another to (as discussed a couple days ago) install Bluetooth beacons in a variety of stores, install trojan packages in popular phone apps, and track people moving through stores.
It's one thing to browse LinkedIn for a person's profile, read the bio of an interesting candidate, and email them. It's another to slurp up 2000 candidates and send an email to all of them.
It's data you or someone else you know made public. Guilty by association?
13 MB of JS/css/html: https://imgur.com/a/oehQQzJ
At one point it had become so bad that we had purge the excess whitespace from the HTML at the traffic layer with middleware. It actually had megabytes of whitespace.
Not to mention the server side rendering mess.
However when it comes to the subject matter of this thread, I don't think this is as sketchy as the OP makes it sound to be. This is LinkedIn's anti-scraping team at work, and nothing nefarious is going on.
Are you a primary source or do you have a source to cite?
This would be the application security team's work. They have a pretty extensive anti-scraping initiative and I know for a fact that these are used to determine if the account is scraping or not.
Someone on a different comment mentioned the "email-hunter" extension. That's exactly the kind of extension they are targeting. I remember many requests sent to support, asking why their account is terminated, and the response was usually "oh you used email-hunter" etc.
What? Can you expand on this? It sounds like a server rendering issue which has nothing to do with the framework itself.
I don't have any examples from the past because I no longer work there but when this middleware was turned off for a few days by ommission, homepage would become 2/3 whitespace. DOM would render correctly of course and the user wouldn't notice anything is wrong however if they were to "View Source", they'd realize they just downloaded a bunch of whitespace.
Imagine having 5 kilobytes of "\n" after each HTML element kind of thing.
When it comes to the middleware, it is just parsing and minifying the HTML source, in the form of an Apache Traffic Server plugin/middleware.
244 Requests of the 552 requests (12.2MB of 26.3MB) required to show my feed are in JS and CSS.
[1] https://www.quora.com/Does-LinkedIn-access-your-email-or-con...
I deleted LinkedIn as soon as it started seeming creepy, since I didn't need to hear from recruiters, at the time.
I'm currently resisting LinkedIn, and trying to skim angel.co, which doesn't seem too creepy. (Though many of the hiring startup blurbs on there are creepy, like "What Up is disrupting at the intersection of blockchain and marketing insights from intimate medical devices!".)
1. Support requests because site is broken, but it turns out you are using an extension that breaks the site.
2. Extensions are exfiltrating data to the extension owners, against LinkedIn's TOS, and they are trying to protect their users, or rather, they don't want competition :)
OK, that was two.
They aren't blinding probing for any and all extensions, only a specific set, which shows restraint and implies to me they are having a sort of arms race with extensions that scrape contact info.
A cursory google-search for something like "linkedin browser plugin" yields tons of these types of products.
I agree that the goal here is likely to combat scraping, but I don't think we can use this behavior to draw that conclusion. From the article:
"I recommend not using web accessible resources. Out of all extensions LinkedIn finds, a majority of them are due to web accessible resources."
There's no trivial way to get a list of all the user's extensions, so they needed a side channel that they could use to detect them on a case-by-case basis. The only extensions that they can detect are ones that feature this side-channel. Even if Linkedin did want to know all your extensions (which, again, I think is less plausible than an arms race) we would see this same sort of behavior due to the limitations imposed by the browser.
https://arstechnica.com/tech-policy/2017/08/court-rejects-li...
My take is that some motivation comes from LinkedIn seeing which Sales Engagement company they want to buy in order to replace Sales Navigator. Therefore by extension they are probably seeing what extensions people are using most commonly with LinkedIn in order to either beat or buy them.
Linkedin can skew results and obfuscate data to users who are heavily digging for lead data. Remember, Linkedin's main value proposition is that it has a wealth of user-submitted data, and if it loses that it loses some of it's value.
LinkedIn doesn't have a great track record, but in this case they might just be trying to prevent abuse.
(LinkedIn disabled this option about a year ago; now it’s only accessible via extensions.)
Maybe this: https://www.securitee.org/files/xhound-oakland17.pdf
In the meantime, we should build and use simpler web browsers, without extension support for one. I've found surf[0] to be the most usable of all WebKit wrappers. Without much C experience, I've managed to use my own fork[1] for a few months now, which wasn't much work thanks to the lean sub-3KLOC codebase of very readable C code and helpful comments.
I imagine that an experienced group of C programmers could take surf as base and easily build a secure and user-friendly web browser with most of the features of the big boys. WebKit is still a concern, but with some work it too could be abstracted away and made easily replaceable.
For LinkedIn specifically, I use a separate cookie file, and with the surf process isolation it gives me a degree of sandboxing similar to Chrome. A modern browser should be built on sandboxing principles for web content, and expose this functionality for each site by default.
Our privacy team took one look at the code and said to stay 100 feet from it.
Slightly tangential but does anyone know if this is what Chrome does? It has a software reporter tool. Also Windows seems to do this too :/ though I'm not 100% sure.
Explaining why I don't have either is a burden I live with in my professional life, but the degree to which even other technical professionals don't sympathize with not having accounts on LinkedIn is pretty amazing.
I guess I'm relegated to a bit of sub-culture-ness. I'm self-employed, so I'm okay with that, but I guess others might find it challenging.
That's worked so far.
Nah. Perhaps I have a more strict work/not-work separation than many, but I am 9-5:30 plain-ol'-employed here, and from what I have seen of LinkedIn I am absolutely not challenged by this. I care about doing a job well, but watching a bunch of people advertising themselves to future employers by pretending to give far more a shit about The Haps in their industry than they actually do is, while almost charming, not something I would care to spend more than about two minutes every two years doing.
Seems like something that shouldn’t be accessible by a website.
- users associating spam received to their use of LinkedIn
- undermining the value of LinkedIn paid services
I'm more upset at browser vendors for creating such an obvious security/privacy hole than at LinkedIn for using it. And now Chrome will use this as subterfuge for nerfing adblock. This is why we can't have nice things.
As the author points out, there are mechanisms for showing extension UIs that don't rely on DOM manipulation.
(FYI: Perma.cc, an anti-link-rot service run by Harvard Law School, is free for up to 10 links per month. The project is run by my department, but I'm not on the Perma team.)
I wonder if there will be a successor to LinkedIn in the near future?
LI is awful.
To be honest I should probably delete my account, but I actively enjoy ignoring it..
But one day I may have to.
Can the URL be blocked in uBlock Origin so that the uploading of the collected data will not take place?
Not true. You definitely figured out how to market your scraper by lying. Nice job!