They Didn't Hack Your Browser. They Inventoried It.
Every time you open LinkedIn in Chrome, a script fires thousands of silent requests at your browser asking one question over and over: is this extension installed? It checks a hardcoded list of 6,222 of them, walks your DOM for the ones it missed, builds a 48 feature fingerprint of your machine, encrypts the lot, and staples it to every API call for the rest of your session. BleepingComputer confirmed the scan. Two class actions over it were thrown out of federal court in September on standing, not because anyone ruled the scan legal. Here is the angle I do not think anyone else covering this can write: I have run this exact scan for a living. It is a software inventory, the same one I have pushed across hundreds of thousands of corporate endpoints for nearly 30 years. The only difference is that somebody signed for mine.
Read More