LinkedIn is spying on you, and you agreed to nothing
Get the full intelligence
Search transcripts, export clips, track mentions, and explore all topics from “LinkedIn is spying on you, and you agreed to nothing” inside PodZeus.
In this episode of Smashing Security, hosts Graham Cluley and Dave Bittner dive into a controversial revelation about LinkedIn's hidden data collection practices. A German privacy group, Fairlinked, published the 'BrowserGate Report,' exposing that LinkedIn injects a 2.7MB JavaScript snippet into Chrome-based browsers on every visit, silently fingerprinting users by harvesting CPU details, screen resolution, battery status, language settings, and over 6,000 browser extensions—including those related to religion, politics, ADHD, and dyslexia. This data is tied to users' real identities, raising serious privacy concerns under GDPR, despite LinkedIn denying malicious intent and claiming the scanning is only to detect data-scraping extensions. The hosts critique LinkedIn’s lack of transparency and explore workarounds like switching to Firefox, Brave, or Safari. The episode also covers a chilling real-world case of 'wrench attacks' in California, where crypto holders were physically assaulted by fake delivery drivers to extract cryptocurrency passwords, highlighting how physical threats can bypass even the strongest digital security. The hosts reflect on the irony of tech-driven protection being undermined by old-school coercion. The episode closes with a lighter 'Pick of the Week' segment: Graham celebrates the rediscovery of two lost 1965 Doctor Who episodes, while Dave shares his nostalgia for vintage robotic chess computers, particularly a modern robotic arm version reviewed on the Techmoan YouTube channel. Both segments underscore the enduring appeal of retro tech and cultural preservation. The hosts emphasize the importance of privacy, digital hygiene, and community support, urging listeners to subscribe, review, and join Smashing Security Plus for ad-free access and early episodes.
LinkedIn silently collects detailed device and browser fingerprint data from Chrome-based users on every click, even when not logged in.
This data includes sensitive info like language, time zone, screen resolution, battery status, and over 6,000 installed extensions—some tied to religion, neurodiversity, or politics.
The practice is not disclosed in LinkedIn’s privacy policy and raises serious GDPR compliance concerns.
Users on Chrome or Edge are vulnerable; switching to Firefox, Brave, or Safari offers protection.
LinkedIn claims the scanning detects data-scraping extensions, but critics argue the scale and scope go far beyond that.
…and 5 more takeaways available in PodZeus
Welcome & Sponsor Intro: ESET
The hosts kick off the episode with banter about podcasting fatigue and introduce ESET as a sponsor, highlighting their 30-year legacy in cybersecurity research, AI-powered threat intelligence, and global telemetry.
LinkedIn’s Hidden Fingerprinting: The BrowserGate Report
“It's not just about scraping data. It's about building a detailed, real-name-linked fingerprint of you every time you click on LinkedIn.”
LinkedIn’s Defense & Privacy Implications
“If you're tracking prayer times and ADHD tools, you're not just protecting your platform—you're building a dossier on users' private lives.”
Wrench Attacks: When Physical Violence Beats Encryption
“His laptop's encrypted. Drug him and hit him with his $5 wrench until he tells us the password. That’s what actually happens.”
Cultural Nostalgia & Pick of the Week
Graham celebrates the rediscovery of two lost Doctor Who episodes from 1965, while Dave shares his love for vintage robotic chess computers, particularly a modern robotic arm version that moves pieces with mechanical precision.
“His laptop's encrypted. Drug him and hit him with his $5 wrench until he tells us the password. That’s what actually happens.”
“If you're tracking prayer times and ADHD tools, you're not just protecting your platform—you're building a dossier on users' private lives.”
“It's not just about scraping data. It's about building a detailed, real-name-linked fingerprint of you every time you click on LinkedIn.”
Hosts
Guest
organization
graham cluley
person
dave bittner
person
chrome
product
fairlinked
organization
doctor who
media
eset
organization
vanta
organization
mita
organization
firefox
product
This man hid $400 million in a fishing rod. Then it vanished
Smashing Security • 45m • 4/1/2026
This AI company leaked its own code. It's also built something terrifying
Smashing Security • 50m • 4/15/2026
Rockstar got hacked. The data was junk. The secrets it revealed were not
Smashing Security • 51m • 4/22/2026
This developer wanted to cheat at Roblox. It cost millions
Smashing Security • 1h 4m • 4/29/2026
Meta sees everything, Copy Fail, and a deepfake gets hired
Smashing Security • 1h 2m • 5/6/2026
Get the full intelligence
Search transcripts, export clips, track mentions, and explore all topics from “LinkedIn is spying on you, and you agreed to nothing” inside PodZeus.
Start discovering podcast insights today
Start with a 7-day trial and explore a growing catalog of popular podcasts. No credit card required.
No credit card required • 7-day trial • Cancel anytime
