AfterDawn: Tech news

LinkedIn: Browser plugin does not hack our service

Written by James Delahunty @ 01 Apr 2014 6:03 User comments (1)

LinkedIn: Browser plugin does not hack our service LinkedIn has responded to reports about a browser plug-in that claimed to be able to hack e-mail addresses of any users.
The Sell Hack browser plug-in can be installed in Chrome, Safari or Firefox, and it adds a "Hack In" button to every LinkedIn profile that you visit. It claims that with just a click of this button, it can dump the e-mail address information associated with the profile.

Early reports suggested that the tool somehow compromises LinkedIn's system to dump the e-mail addresses. However, at closer look, the plug-in clearly does not work for every profile that you try, whereas it appears to work for profiles of well known individuals.

That led quickly to more skeptical-types assuming that the plug-in is using some other means to find information available elsewhere about a particular user.

According to LinkedIn's senior manager of corporate communications, Krista Canfield, no LinkedIn data has been compromised by the plug-in, and the e-mail addresses that are revealed are not done so through any breach, bug or vulnerability with the site.



LinkedIn warns users on the risks of the plug-in

On Monday, Canfield confirmed that the service had sent a cease and desist letter to address "several violations," and she warned against users installing the plugin.

"We advise LinkedIn members to protect themselves and to use caution before downloading any third-party extension or app," Canfield told Yahoo Tech, reports Alyssa Bereznak. "Often times, as with the SellHack case, extensions can upload your private LinkedIn information without your explicit consent."

That seems like reasonable advice for more than just this particular plug-in.

Sell Hack defends itself

The individuals behind Sell Hack describe themselves as "dads from the midwest", and object to being described as sneaky, nefarious, no good, or not "legitimate". They confirmed the cease and desist letter sent from LinkedIn, and that Sell Hack no longer works with LinkedIn.

"We only processed publicly visible data from LinkedIn based on your profile permissions...all of which has been deleted."

At the same time, it has been a mixed bag for them as they have had more signups today than the first 60 days of availability combined, and that they are working on a better product that complies with LinkedIn's terms of service.


Sources & Recommended Material:
Original report from Yahoo Tech: https://www.yahoo.com/tech/...
Response from Sell Hack: http://blog.sellhack.com/
Analysis by security analyst Graham Cluley: http://grahamcluley.com/2014/04/sellhack-linkedin/

Tags: LinkedIn
Previous Next  

1 user comment

12.4.2014 21:15

I HATE Linkedin!

It benefits recruiters only. They build a massive list of prospective job hunters off this crappy site.

I wish Linkedin died forever and was shutdown. I promise nobody would miss it!

Comments have been disabled for this article.

Latest news

Sony suspends memory card sales because memory chips are simply not available Sony suspends memory card sales because memory chips are simply not available (28 Mar 2026 6:49)
Sony has announced that it is temporarily suspending the sale of memory cards used in mobile phones and digital cameras, among other things. The company states that the reason is problems with the availability of memory chips.
Austria plans to ban social media for under 14 year olds Austria plans to ban social media for under 14 year olds (28 Mar 2026 6:17)
Austria is planning to ban social media for children under 14. The reform aims to protect children from harmful effects and addictions, but at the same time, it is problematic from a privacy perspective.
TP-Link urges users to update their routers - several vulnerabilities patched TP-Link urges users to update their routers - several vulnerabilities patched (26 Mar 2026 1:56)
Serious security vulnerabilities have been discovered in several TP-Link router models, for which patches were released at the end of March 2026. The company urges users to update their router software immediately.
Google: The feared Q-Day is now expected to happen in 2029 Google: The feared Q-Day is now expected to happen in 2029 (25 Mar 2026 4:32)
Google has advanced its estimate of when current forms of encryption will become insecure. The moment is called Q-Day, or Quantum Day, when the computational power of quantum computers will be sufficient to break currently used encryptions.
OpenAI shuts down its AI video service Sora OpenAI shuts down its AI video service Sora (24 Mar 2026 6:28)
OpenAI has decided to shut down Sora, its AI video creator, just months after its release. The decision is due to issues such as copyright problems and the deepfake phenomenon.

News archive