跳到主要内容

本页面暂无您所用语言的版本,您正在阅读英文原文。

Blog

LinkedIn reads a profile before the first click: eight paths

You open a page on the network, press nothing, and a report on your visit has already left. It goes to the very site you came to, and a domain blocklist does not catch every request like that. Below are the eight address fragments that give it away, and two requests that expose you only sometimes.

ARMANOS 团队7 min

The counter goes to the same site

Ordinary tracker blocking judges by domain: an outside counter lives on an outside address, and telling it apart is easy. A request to the network's own site looks to that blocking like a plain feed load.

So the platform counts you with its own requests, and they travel mixed in with the useful ones. Only the address fragment separates them, because the domain is the same for all of it. A domain list lets it through together with the feed.

Eight addresses your visit goes to

You will see the eight address fragments below on your own machine, in the request tab of a developer window. Each one means a separate report, and they leave before you press anything at all. They leave in the first seconds after the load.

The last three are bare words: beacon, telemetry and viewedEntity. They turn up in addresses on other sites too, so they mean something only inside the network itself.

What stands in the addressWhat leaves with it
/li/trackA report on what you did on the site
/px/A counter image on the network's own address
/li/ftaA first touch mark: where you arrived from
/csp/ftaThe same touch taken by a second address
/voyager/api/identity/profileViewA view of someone else's page, named outright
beaconA report that leaves even as the tab closes
telemetryThe general stream of readings about you
viewedEntityWhich item actually reached your screen

Two requests expose you only sometimes

Two more requests look ordinary right up until one of the words below appears in the address. With that word an ordinary request turns into a report about you. Without the word it stays a needed part of the work, and must not be touched.

Messaging tells the network that a letter was read and that you are typing a reply right now. Search tells it what you were shown and which of it you looked at.

Request to the networkWhen it becomes a report
/voyager/api/messaging/conversationsThe address picked up seen or typing
/voyager/api/searchThe address picked up track, analytics or impression

Outside counters on the same page

Besides its own reports the page carries outside counters, and those sit on addresses belonging to other companies. Those are exactly what a domain blocklist catches, and it sorts them like this.

Eleven of the addresses do not belong to the network at all: a search engine, a social network, advertising, a crash collector. The rest sit on its own addresses and on the address of its image store.

KindAddresses
Advertising and analytics5
Visit marks6
Insight tag1
Outside counters11

The network's tag sits on other sites

One line in the list is a script that other sites install themselves for the sake of advertising on the network. It is called the Insight tag, and it lives on the address of the image store.

It sits not on the network but on somebody else's site, and it reports your visit back there. So the network knows about shops and blogs where you never signed in to your account. It ties those visits to the account by the same small browser details.

The network counts profile views itself

The network shows the owner of a page who came to look, and an invitation is seen by a living person. So a daily count means more here than in a feed, where nobody sees you by name.

We did have a separate Work / LinkedIn scenario with four daily ceilings, and it has been merged into the Social media scenario: you can no longer pick it, and Social media holds ten ceilings. A ceiling is not a ban but a guide: the Safe pace bar turns amber at four fifths and never tries to stop you.

One bar per profile rather than per action: it counts opened pages, because those are the only thing a browser sees. Viewing somebody's page is an opened page too, and it goes into the day's count.

Action in a dayCeiling
Profile views50
Invitations15
Messages25
Searches30

Ten ceilings of the Social media scenario

The Social media scenario holds ten daily ceilings, and the four in the table above are part of that ten with the same numbers, only Messages is called DMs here. On a profile's first day a fifth of them remains, and the day's figure never drops below one: two account switches become one rather than zero.

The program cannot count these actions for you, so the rows under the bar, in Safe daily ceiling, are numbers without colour, with the «warning at N» threshold on a second line. Only the bar of opened pages is coloured, and the decision on the rest stays yours.

ActionDay oneFull ceiling
Profile views1050
Invitations315
Searches630
Follows840
Likes24120
Comments630
DMs525
Friend requests420
Posts315
Account switches12

Three counter lists on one scenario

The Social media scenario attaches three lists to a profile at once: the general one, this network's own list and the social list. The network's list is the eight address pieces and two query rules discussed above, and it works only on the network's own addresses.

Sixteen of the forty tags the program cuts out of links came from this very network's addresses: trk, trkInfo, lipi, lici, trackingId, refId and the rest. Link cleaning is on in the scenario, and a click from an email lands on the network without the tail.

Other sites do not break from this

The bare word beacon stands in addresses across a great many sites, and almost everywhere it is an ordinary file. Blocked everywhere it did break unrelated pages, which is why these rules are locked to the platform’s own hosts.

So on somebody else's site the same request goes through as usual. It is blocked only on the network's own addresses and on the address of its image store.

How to see this for yourself

Everything named above is visible from a developer window, with nothing to install. Open the request tab, go to the network and press nothing at all.

The first seconds are the interesting part: the reports leave ahead of anything you do. After that, compare what you saw with the eight address fragments in the table above. Later you will not find them among hundreds of requests.

  1. 1

    Open the request tab first

    Before you go to the network, or the earliest requests are gone.

  2. 2

    Filter by an address fragment

    The search line above the list takes a whole fragment of an address.

  3. 3

    Look at the timing

    The reports leave earlier than the page finishes drawing itself.

  4. 4

    Repeat it inside a profile

    Compare what leaves an ordinary window with what leaves a profile.

What this does not claim

  • This is not the whole list of what the network reads. It names eight address fragments and two requests, and the network publishes no list of its own anywhere.
  • What each report carries inside is not visible from outside. The names in the table are read exactly as they stand in the address, and the network explains none of them.
  • Blocked reports do not make an account safe. Behaviour, pace and the history of complaints stay yours, and no browser changes any of them.
  • The numbers above describe the rules as they stand today. The network moves its own addresses, and the set follows after it.

Where you can see this yourself

Every number above comes out of code you can open and run.

The eight address fragments and two query rules sit in one list
apps/desktop/src/lib/tracker-rules.js
On somebody else's site not one of these words fires
apps/desktop/test/слежка-по-хостам.js
The built-in engine and ARMANOS Browser block the same things on a profile
apps/desktop/test/слежка-по-хостам.js
The outside counters are listed by kind, address by address
apps/desktop/assets/trackers_linkedin.json
The daily ceilings of the scenarios live in one place
packages/shared/src/index.js
The marks that leave your link are named in a list
packages/shared/src/index.js

Questions

I pressed nothing, so what is there to count?
Arriving is the event: the page reports that it opened, who opened it and where the visit came from. A click adds detail, but none of it waits for the click.
Does private browsing close this?
It forgets cookies when the window closes and does nothing about the reports: they leave any window alike. The network recognises the machine and the route you came by, not the cookie.
Will an ordinary ad blocker handle it?
It handles the outside counters, whose addresses are already in its lists. A request to the network's own site goes through, because by domain it cannot be told from a feed load.
Does a proxy help here?
A proxy changes the address you arrive from and touches nothing inside the reports. A view of someone else's page goes into a report from any address at all.
If these reports are blocked, will the network notice?
A blocked report looks like a request that failed, and any browser has plenty of those without you. The louder signal is your pace over a day, which the network counts on its own server.
How many such accounts will one computer carry?
The count is not in accounts but in how unlike your profiles are and how calm your pace is. Once screen, fonts and memory differ, the question turns into another one: how unlike.

See what your own browser answers

The check reads 12 values and sends nothing anywhere.