3 ms·
> They also use audio fingerprinting to identify visitors. This doesn’t mean they actually use your microphone or speaker. Instead they generate a sound interna
by JTon 7y ago
> They also use audio fingerprinting to identify visitors. This doesn’t mean they actually use your microphone or speaker. Instead they generate a sound internally and record the bitstream, which also differs from device to device.
I don't understand. Can anyone unpack this concept for me? How does one generate a sound without a speaker or record without a mic.
- ldjb 7y agoI'm guessing they're using the Web Audio API which allows you to generate audio samples: https://developer.mozilla.org/en-US/docs/Web/API/Web_Audio_API https://developer.mozilla.org/en-US/docs/Web/API/Web_Audio_A...
- munk-a 7y agoAnd I assume that different audio drivers and software will produce minutely different outputs. It's also possible that they're queueing a sound to be played then canceling the sound after reading the raw computed signal out of the buffer. Sleezy sleezy crap.
- mmcwilliams 7y agoIt was my understanding that these methods profile performance of the API which will execute at different speeds on different devices. The samples themselves shouldn't be different if they're using AudioBuffer and typed arrays.
- sudosysgen 7y agoTime to add random delay and noise then.
- wizzwizz4 7y agoI believe Firefox adds random delays, if you enable one of the Tracking Protection settings.
- mmcwilliams 7y agoTrue, but I think the technique points to the way that other timing attacks used as fingerprinting vectors can and will work. Profiling performance of network requests, image rendering time, etc will always be risks unless all Javascript features employ that kind of mitigation.
- deleted 7y ago[deleted]