281

Microsoft is running one of the largest corporate espionage operations in modern history.

Every time any of LinkedIn’s one billion users visits linkedin.com, hidden code searches their computer for installed software, collects the results, and transmits them to LinkedIn’s servers and to third-party companies including an American-Israeli cybersecurity firm.

The user is never asked. Never told. LinkedIn’s privacy policy does not mention it.

Because LinkedIn knows each user’s real name, employer, and job title, it is not searching anonymous visitors. It is searching identified people at identified companies. Millions of companies. Every day. All over the world.

you are viewing a single comment's thread
view the rest of the comments
[-] inlandempire@jlai.lu 41 points 1 month ago

it does NOT scan applications on your computer

technically browser extensions are considered applications under EU's GDPR

It DOES scan which browser extensions you have running (if they affect page loading).

as per their report:

Why two detection methods

Method Technique What it catches
AED fetch() against known resource paths Extensions that are merely installed, even if they inject nothing into the current page
Spectroscopy Full DOM tree walk Extensions that actively modify the page, even if they are not in LinkedIn’s hardcoded list
[-] Alberat@lemmy.world 18 points 1 month ago

it's misleading to say its searching your computer tho...? this invokes the thought of LinkedIn getting to rifle through your files like it has access to ~/Documents/ or smth.

but yeah tracking you over the internet is similarly bad

[-] stroz@infosec.pub 10 points 1 month ago

it's misleading to say its searching your computer tho...?

Wait, your browser extensions aren't on your computer?

[-] Armok_the_bunny@lemmy.world 12 points 1 month ago

It's misleading because saying "search the computer" implies a breadth of scan that isn't present. That's like saying a website "searches the computer" to grab cookies generated by that site; technically true but worded to be misleading.

To be clear this is bad, but it's important to be clear when explaining why it is bad to avoid creating resentment when the person you are explaining it to looks deeper into it themself and finds that it's not as bad as your explanation was implying.

[-] partofthevoice@lemmy.zip 1 points 1 month ago* (last edited 1 month ago)

I believe the point they’re trying to make is that they have access to APIs which describe particular software on your PC. You can argue based on the fact that, yes, the software is persisted on your filesystem. However, the API they access brokers [meta]data about the software. It’s not a filesystem API. If I add arbitrary files to an extension directory under my browsers path for extension persistence, they probably cannot see those arbitrary files unless the extension is built to allow it.

There is a big difference between having direct and broad read access to the filesystem, versus the much smaller volume of data they can infer about your filesystem using APIs for browser extension data.

[-] FooBarrington@lemmy.world 2 points 1 month ago

There isn't an API for browser extension data. They are searching for the existence of thousands of specific addresses to perform the search.

[-] GreenShimada@lemmy.world 1 points 1 month ago

While browser extensions are considered apps under the GDPR, the headline is intentionally misleading. LinkedIn isn't "Illegally Searching your Computer." It's asking the browser for all the info it's maximally able to give up. We do need to define browser extensions in a way that doesn't use fear as clickbait to make it sound like LinkedIn has greater access to a device than it really has.

And thanks for the correction on AED, I had seen another analysis a couple weeks back and I didn't recall correctly what was being collected.

this post was submitted on 30 Apr 2026
281 points (100.0% liked)

World News

56312 readers
1617 users here now

A community for discussing events around the World

Rules:

Similarly, if you see posts along these lines, do not engage. Report them, block them, and live a happier life than they do. We see too many slapfights that boil down to "Mom! He's bugging me!" and "I'm not touching you!" Going forward, slapfights will result in removed comments and temp bans to cool off.

We ask that the users report any comment or post that violate the rules, to use critical thinking when reading, posting or commenting. Users that post off-topic spam, advocate violence, have multiple comments or posts removed, weaponize reports or violate the code of conduct will be banned.

All posts and comments will be reviewed on a case-by-case basis. This means that some content that violates the rules may be allowed, while other content that does not violate the rules may be removed. The moderators retain the right to remove any content and ban users.


Lemmy World Partners

News !news@lemmy.world

Politics !politics@lemmy.world

World Politics !globalpolitics@lemmy.world


Recommendations

For Firefox users, there is media bias / propaganda / fact check plugin.

https://addons.mozilla.org/en-US/firefox/addon/media-bias-fact-check/

founded 3 years ago
MODERATORS