Microsoft is running one of the largest corporate espionage operations in modern history.
Every time any of LinkedIn’s one billion users visits linkedin.com, hidden code searches their computer for installed software, collects the results, and transmits them to LinkedIn’s servers and to third-party companies including an American-Israeli cybersecurity firm.
The user is never asked. Never told. LinkedIn’s privacy policy does not mention it.
Because LinkedIn knows each user’s real name, employer, and job title, it is not searching anonymous visitors. It is searching identified people at identified companies. Millions of companies. Every day. All over the world. This is illegal and potentially a criminal offense in every jurisdiction we have examined.
How does web code have access to do that? Why would they even need that info? Feels a massive security issue. On an android app, it’d probably need permission. Does web security even exist? Surely it should say “LinkedIn is requesting access to see if you have Adblock Origin on your computer. Allow or deny”. If they request 200 apps, it asks 200 times. Eventually companies stop doing it.
MS is shit, but it feels Google, Apple and Mozilla are partly guilty even allowing this.
Looks like Firefox is not affected. The page says it applies to Chrome-based browsers
Ah, that’s good. Thanks for clarifying.
MS is shit, but it feels Google, Apple and Mozilla are partly guilty even allowing this.
You talk like that isn’t like a cartel
For the first, yes. The other 2 will probably win support by implementing better protections. Apple pretends to be privacy focussed. Mozilla would win over more users with it.
They can’t have a list of all the installed browser extensions but can probe if a specific one is installed. So they probe ALL of them one by one
So effectively can probe for all. Browsers have no need to know what extensions I use. Surely there is a vulnerability because they could exploit outdated vulnerable extensions. This had to end.
You can’t stop it from knowing what extentions you have unless you disable javascript. I’m pretty sure web browsers shouldn’t have access to your local files although this post makes me doubt what I thought I knew.
Basically every website does this now (except lemmy and most of the fediverse sites!), generally the more private browsers e.g. brave and librewolf will protect against this, the biggest danger is storage scanning, webrtc, and device identification
and who knows who else is exploiting our devices to exfiltrate data. when did it become acceptable for companies to act like fucking malware.
I’m pretty sure just about every website associated with a corporation or business does this






