Smashing Security podcast #462: LinkedIn is spying on you, and you agreed to nothing

LinkedIn has been secretly scanning your browser for over 6,000 installed extensions – on every single click you make. It can tell if you’re job hunting, what religion you are, and whether you have ADHD. And none of this is mentioned anywhere in their privacy policy.
Meanwhile, California’s crypto millionaires are learning that no amount of encryption can protect you from someone who knocks on your door pretending to deliver a pizza.
All this and more in episode 462 of the “Smashing Security” podcast with cybersecurity expert and keynote speaker Graham Cluley, joined this week by special guest Dave Bittner.
0:00
0:00
Show full transcript
▼
This transcript was generated automatically, probably contains mistakes, and has not been manually verified.
So what should I say?
Uh, let’s say, say, uh, looking forward to this week’s Smashing Security podcast.
With my co-host.
Or my special guest, Dave Bittner.
Stand down, Dave.
Thank you. Sorry. I got ahead of myself. Uh, you know.
Smashing Security, Episode 462: LinkedIn is Spying on You, and You Agreed to Nothing, with Graham Cluley and special guest Dave Bittner. Hello, hello, and welcome to Smashing Security, Episode 462. My name is Graham Cluley.
And I’m Dave Bittner.
Dave Bittner from the CyberWire, back on the podcast again. We can’t get you away from a microphone, can we?
I know, I’m like a terrible rash and difficult to get rid of.
Do you ever feel like, you know, I’ve had enough of this, it’s time to time to hang up my spurs. Well, I suppose they’re not spurs, are they?
Time to hang up my XLR cables.
My XLR cables, yeah.
Not so much that, but I will tell you there are times when I smash my head against the desk and say, I need a vacation. I need a break. I need to get away from the bad news.
Yeah. I mean, I find it tough doing one podcast a week, but you do about 89 a week.
I do. I do. I have to learn how to navigate it so it doesn’t take too hard a toll on you emotionally, but I’m, you know, I’m mostly there, but there are days, Graham, there are days.
Well, we certainly do appreciate you coming on the Smashing Security podcast today. And before we kick off, let’s thank this week’s wonderful sponsors, Meta, ESET, and Vanta. We’ll be hearing more about them later on in the podcast. This week on Smashing Security. We won’t be talking about how hackers working for the Russian government broke into thousands of home routers to steal passwords. You’ll hear no discussion of how tourists traveling to Hong Kong have been warned that it’s now a criminal offense to refuse to hand over to police the passwords for all your personal devices. And we won’t even mention how after authorities cracked down on the use of Telegram, WhatsApp, and VPNs, Russian citizens have switched to using two other apps. For instant message and video call, including in some cases smart cat feeders. So Dave, what are you going to be talking about this week?
I’m talking about some wealthy California crypto holders who are being targeted in wrench attacks.
And I’m going to be shining a light on how LinkedIn is shining a light on its users. All this and much more coming up on this episode of Smashing Security. Well, before we kick off, we’ve just got a moment to thank one of this episode’s sponsors, ESET. Now, there’s no shortage of cybersecurity vendors claiming to be the best, of course, but ESET is one of the few that’s been proven it for 30 years. Research has always been at the core of what ESET does. Their threat intelligence teams are actively tracking APT groups and ransomware affiliates and publishing findings that the security community actually reads and references. That’s not a marketing line. That’s 30 years of doing the work. And here’s what makes it interesting. 3 decades of research means that ESET has built up global telemetry that most vendors simply don’t have access to. They combine that telemetry with AI-native technology and human uh, Maria Varmazis told me about— there’s a Reddit group called LinkedIn Lunatics.
I’ve been there. In fact, I think I’ve been, I’ve been included in on it before.
Okay, well, it’s just, it’s very entertaining, very entertaining.
Yes, I did make an appearance up there and I got a certain amount of abuse about a humble brag. Didn’t involve stepping on an orange, but clearly I’d showed a little bit too much humility or been self-promoting too much. Now, of course, I don’t go on LinkedIn looking for a job. What fool would go on LinkedIn to look for a job? That’s not what it’s there for. You know, it’s not to say though that I don’t love the feeling of a recruiter sliding into my DMs, which they do occasionally, saying, oh, we’ve got the perfect job for you. We can tell that you’re a cybersecurity and AI whatchamacallit. And sometimes they offer me jobs which are entirely inappropriate. I think there was once a touring group that they asked me to join, a chorus line for HMS Pinafore or something going around Bulgaria.
Well, see, that would grab my attention, actually.
You would be tempted by that, wouldn’t you?
Yes, I would. That fish would work on me.
Now, one thing is clear, LinkedIn is a deeply strange corner of the internet. And this week, it got that little bit stranger because a German privacy group— and you always have to worry when a privacy group is German, they’re serious about their privacy. They are called Fairlinked, and they’ve published what they’re calling the Browsergate Report. And you always know you’re in trouble, don’t you, when there’s a gate involved?
Oh, absolutely.
You know, ever since 1972, 2, I think it was.
I often wondered, no, what if there was a scandal involving something like the Brandenburg Gate? Would you then have Brandenburg Gate Gate?
Or perhaps a scandal involving Bill Gates.
Bill Gates Gate. You know, yes. Maybe that’s the defence to prevent there being a scandal about you is to change your surname to Gate beforehand. Anyway, Browsergate reveals that every single time you open LinkedIn in a Chrome-based browser, the LinkedIn platform will quietly inject a little bit of JavaScript into your session. And that little bit of JavaScript, well, I say it’s little, is 2.7 megabytes, David, 2.7 megabytes of JavaScript.
Well, by today’s standards, that’s nothing.
That’s barely anything, is it? And that, that what it does is starts scanning your browser for over 6,000 specific installed extensions. Hmm. So it’s looking for all kinds of information about what you are running on your computer within your browser while you’re on LinkedIn. It also harvests your CPU core count, your available memory, your screen resolution, your battery status, your time zone, your language settings. And this isn’t once per visit to LinkedIn. This is every single click that you make. Hmm. So you click on someone’s profile and it’s going to send a fingerprint, a unique, pretty much unique fingerprint with all these different indicators regarding your computer.
Or if you ignore a connection request from someone you met at a conference a few years ago, again, it will send a fingerprint or If you spend 4 minutes reading a post about 3 things the Navy SEALs taught me about inbox zero, it’s going to— it’s going to send your fingerprint. And none of this, none of this is mentioned anywhere in LinkedIn’s privacy policy, which is absolutely fine.
No, absolutely fine and dandy, isn’t it? It’s brilliant.
No worries. No worries.
No worries at all. So 6,000 extensions is looking nice. I think I’ve got 6,000. And what are these extensions? Well, it turns out they’re like language and grammar extensions. So if you have a tool which helps you translate LinkedIn posts, for instance, hmm, it will pick that up or a grammar extension, something to make you look more eloquent on LinkedIn. If you’re using a tax tool, If you— oh, also extensions designed for people with ADHD or dyslexic users, because there are dyslexic extensions you can put on your browser which change the font to make it easier to read, for instance. There are tools that notify users— oh, this was an odd one— tools that notify users of Islamic prayer times.
Oh, that’s not at all problematic.
Who would be interested in that, I wonder?
No, no. What could possibly— history has told us what could possibly go wrong with tracking people based on their religion.
