Security Now (Audio) · TWiT

The FCC Bans New Consumer Routers - LinkedIn's JavaScript Bombshell

April 8, 2026·2 hr 52 min·5 clips
LinkedIn secretly scans your computer for 6,000 browser extensions and 48 hardware details every time you visit.
Episode 1073 was recorded Tuesday, April 7, 2026. The cold open points to Steve Gibson on LinkedIn's privacy-invasive JavaScript, the FCC router ban, and the show's familiar security-and-privacy rhythm. The banter is almost part of the machinery by now. Steve and Leo joke about Tuesdays, 168 hours, and the little scheduling rituals that make the show feel lived-in before the technical material starts. Then LinkedIn becomes the story. Steve walks from the old web tracking pixel, a tiny remote image, to something much bigger and harder to wave away. As he describes Bleeping Computer's reporting, LinkedIn serves a 2.7 megabyte chunk of unsolicited JavaScript to visitors of linkedin.com. The code is described as checking visitors' file systems for files tied to browser extensions. Its target list has reached 6,236 web browser extensions, a number Steve treats as both oddly specific and clearly growing. The consumer objection is simple: those extensions are arguably none of LinkedIn's business. Steve stays close to the mechanism. Short of using a non-Chromium browser such as Firefox, the excerpt says users do not get a visible setting that stops the scanning. Firefox is not a magic door out, either. The quoted analysis says it may limit fingerprinting capabilities without necessarily ending them, which lands like a browser recommendation with a warning label still attached. The legal question stays open. The Next Web is cited on the possibility that this may be illegal in the EU, where privacy regulation is described as strong and getting stronger. Disclosure is the sour part of the story. The excerpt says LinkedIn's privacy policy does not explain how this data collection practice relates to Microsoft's broader AI ambitions. There is no opt-out because the practice is not disclosed in the first place. Steve's blunt read is that, legal or not, it has gone out of bounds through a lack of adult supervision. The episode's signal is patient irritation: ordinary tracking has turned into opaque browser inspection at industrial scale.

As heard by us

A pointed Security Now warning about LinkedIn's JavaScript tracking and the browser controls users still lack.

LinkedIn's browser-side data collection gives this Security Now episode its sharpest edge. Steve Gibson and Leo Laporte move from the old tracking pixel to a 2.7 MB JavaScript payload that, according to the discussion, checks visitors' local browser-extension traces across more…

Read the full review in PlayNext →

Why you'd press play

LinkedIn is silently scanning your browser for over 6,000 installed extensions -- and you cannot opt out.

Read the full recommendation in PlayNext →
Listen to the show on