• DrWorm@piefed.blahaj.zone
    link
    fedilink
    English
    arrow-up
    7
    ·
    13 hours ago

    It looks like the attack only works on Chrome (or Chrome based browsers).

    They have 2 methods for figuring out which extensions are used: asking the browser for files related to each of the 6000+ extensions they scan for, and checking the DOM for injected content

    But that doesn’t mean that Firefox couldn’t be targeted in the future.

    A good way to protect yourself is to use uBlock Origin or something similar, which will block the collected data from getting sent to LinkedIn

    • TheSlad@sh.itjust.works
      link
      fedilink
      arrow-up
      4
      ·
      12 hours ago

      Extensions? It just said software above.

      Is it actually scanning for installed software on the system or just chrome extensions?

      • DrWorm@piefed.blahaj.zone
        link
        fedilink
        English
        arrow-up
        4
        ·
        11 hours ago

        Yeah it’s a bit dishonest

        Instead of

        hidden code searches their computer for installed software

        I would say

        hidden code searches their browser for installed extensions