Claims of LinkedIn browser 'spying' clash with security research findings

April 14, 20262 min read1 sources
Share:
Claims of LinkedIn browser 'spying' clash with security research findings

Sensational allegations that LinkedIn’s browser extension was conducting “corporate espionage” for Microsoft have been largely refuted by independent cybersecurity researchers. The claims, which gained traction in late 2023, posited that the extension was covertly exfiltrating sensitive data from every website a user visited.

Technical analysis of the extension’s behavior, however, paints a different picture. Researchers, including prominent privacy analyst Zach Edwards, confirmed that tools like LinkedIn Sales Navigator and Recruiter do examine the HTML content of web pages. They are designed to detect keywords, such as company names, job titles, and email addresses, to identify potential professional contacts or sales leads.

When the extension identifies a relevant entity, it makes an API call to LinkedIn’s servers. This call typically includes the detected keyword and limited contextual data, but not the full content of the webpage. This process enables the extension’s core features, such as displaying a company’s LinkedIn profile or suggesting relevant contacts directly on the page being viewed.

The consensus among security experts is that this activity does not constitute malicious spying. While the data collection is extensive and raises valid privacy questions, its function appears to align with the extension’s stated purpose of integrating LinkedIn’s professional networking tools into a user’s browsing experience. This functionality is generally covered by the terms of service that users agree to upon installation.

The incident, dubbed “BrowserGate” by some, highlights a persistent tension between software functionality and user privacy. It serves as a critical reminder for users to carefully review the permissions granted to browser extensions and for developers to provide greater transparency about their data handling practices.

Share:

// SOURCES

// RELATED

Audit: Big Tech often ignores California privacy law opt-out requests

An audit by the Privacy Rights Clearinghouse found that Google, Meta, and Microsoft fail to honor consumer 'Do Not Sell or Share' requests about half

6 min readApr 16

The battle over FISA's Section 702: A temporary truce in the war between national security and American privacy

A contentious U.S. surveillance law, Section 702 of FISA, was renewed for two years, continuing the debate over national security versus American priv

6 min readApr 16

Big tech fails to opt-out users requesting not to be tracked much of the time, new research says

A new audit from privacy organization webXray reveals 194 online ad services are ignoring the legally binding Global Privacy Control opt-out signal.

6 min readApr 15

Majority of Australian youth still use social media despite school ban, researchers find

New research reveals that a statewide social media ban in NSW schools is largely ineffective, with two-thirds of students easily bypassing restriction

6 min readApr 14