9 ms·
AliExpress runs silent WebAudio fingerprinting that breaks Bluetooth multipoint
- botanical 1mo agoI noticed this on AliExpress years ago with cheaper Bluetooth earphones. Actually, all Chinese e-commerce sites activate audio for some reason.
- emctech 1mo agoRecently I ran into a problem with my Bluetooth headphones. They support multipoint bluetooth audio, so they can be connected to my PC and phone at the same time. Opening the Aliexpress webpage causes a silent audio stream keeping the PC>headphone link active blocking my phone audio. An investigation reveals obfuscated code running device fingerprinting with a side effect being a silent audio stream that firefox, chrome and windows does not recognise but which kept the bluetooth connection active.
- maximilianthe1 1mo agoIs this an AI summary of the article?
- emctech 1mo agoNo, I took the first sentence of my article and then edited the rest of the intro + conclusion to keep it short for HN.
- left-struck 1mo agoYou should make that obvious in some way like using “TLDR”. I assume many people, like me, would attempt to parse your comment as a comment on the article, after all it’s in the comment section, and read that way it’s very confusing lol.
- emctech 1mo agoSorry, this is my first post to HN and in the submission it looked like the description text i added would be part of the post header.
- lxgr 1mo agoI was just about to highlight this particular HN quirk. I suppose a lot of people here only ever comment (or submit URLs without any text of their own) and aren't familiar with it.
- deleted 1mo ago[deleted]
- 40four 1mo agoDon’t apologize. This was a very fascinating read, and a good technical write up, especially for you first even HN post. It’s not your fault others didn’t look at the username :)
- emctech 1mo agoThanks for the feedback :D
- chrisjj 1mo agoHN's fault entirely. The post form's actioning "text" as a comment is remiss.
- left-struck 1mo agoAh, sorry I wasn’t aware of that either
- left-struck 1mo agoSorry, I didn’t realise you were the author
- 40four 1mo ago
- 40four 1mo agoNo you are talking to the actual author of the article. It’s not weird for the author to comment on their own article
- robtherobber 1mo agoConcerning situation, I think. And I suspect (perhaps wrongly) that there are even more reasons for concern with technology that can track, capture, leak etc. information that's more sensitive or valuable, depending on how one wishes to look at it. Mobile phones, computers, routers etc. -- all have the potential to siphon out valuable information to a bad actor, especially when it comes to espionage, military, commercial etc. This has already happened at a significant scael, so it's not a remote scenario. At the very least, governments and institutions should develop a framework to investigate all acquired technology. The community / civil society could also create something similar, a script that would analyse at a deep level everything that can be analysed with a piece of software even by a complete novice.
- emctech 1mo agoYes, I find it concerning too. I particularly dislike that windows was not aware, nor could it stop the audio stream from effecting the hardware. What other side channels like that exist? Perhaps I can be blamed for using windows
- robtherobber 1mo ago> Perhaps I can be blamed for using windows That would be unreasonable, I argue. No one should have to worry about the security of their devices and data privacy based on which OS they use. Whilst it can be argued that different OSs serve different needs, privacy and security should not be debatable. In fact, most countries have dedicated legislation for this; whether it's just, applied correctly, or serves the public before any other party are indeed discussions to be had.
- compsciphd 1mo agoi'd argue that perhaps the ability to play audio should be permission gated, much like the ability to use webcam/microphone. However, I'd bet that many people will gladly allow aliexpress to play audio as there are probably videos on the site that people want to play and listen to. With that said, its possible that this can be only a use once permission. Even if I want to shop at aliexpress if I know they are doing this, I'll be more willing to be bothered every time I want to play a video with audio to approve it if this bothers me.
- emctech 1mo agoThe ability to play audio can usually be permission gated with tab muting, however the methods aliexpress use bypass that mechanism completely.
- y-curious 1mo agoThis is the part you should be highlighting aggressively. That’s very uncomfortable
- rcruzeiro 1mo agoI would actually love if I could have iOS prompt me to allow certain apps to use the speakers. I hate using an app and suddenly have a video autoplay loudly.
- voakbasda 1mo agoThis. This needs to be a thing.
- GJim 1mo agoTo be fair, it shouldn't need to be a thing. (One should really not tolerate such dodgy software).
- pavel_lishin 1mo agoI wish Android had this as well. There are apps where it's difficult-to-impossible to turn all sound off, and I wish I could just tell my phone that this app is just never allowed to use the speakers.
- patspam 1mo agoI noticed in the last few weeks that if I’d recently opened the AliExpress iOS app (ie. it was backgrounded) my car audio would freak out thinking I was giving it an audio command. Killing the AliExpress app immediately fixed the problem. After seeing it happen more than once I assumed it was something dodgey and uninstalled the app.
- lukeify 1mo agoI cannot ever imagine installing something like AliExpress as an app.
- unixhero 1mo agoIt's great for shopping. But in the US you have amazon prime. We don't.
- fragmede 1mo agoWhere is "we"?
- ngl999 1mo agoLikely the place where people are "willing to trade privacy for convenience", according to Baidu's CEO.
- stinos 1mo agoI always wonder if it's worth it. Like: is it actually convenient, or is it 'solving' inconveniences which actually do not exist or didn't exist before using the service? I have never used Prime or AliExpress but also don't consider our typical shopping very inconvenient. And the most inconvenient parts are actually the ones which seem necessary to to get the proper goods (from past weeks: vegetables/fruits/shoes - it's not really possible to order that online and get exactly what we want). And everything else is available from other webshops.
- 1mo ago
- CTDOCodebases 1mo agoThey have been doing this for months. No sound playing but the audio would change like the microphone was being activated. I checked permissions to make sure there was no mic access and figured that they were fingerprinting.
- emctech 1mo agoI had noticed it before but I was browsing AE a lot today and i got fed up with it. What browser and OS are you using?
- CTDOCodebases 1mo agoIt was happening when I was using Chrome on iPhone and Windows 11 with Chrome. I can't remember what was causing it since the headphones (Bose Quietcomfort SE) are synced with both devices. For the last couple of months I've been using Android and I haven't noticed it. The headphones seem to work better with Android. IOS is a bit weird with sharing them with my PC.
- ngl999 1mo agoJust curious, why silent sound would allow fingerprinting? What are they sampling if it can't be heard?
- emctech 1mo agoThe script generates a known waveform, it is passed through the browser's audio implementation and then the script analyses the result after. Based on your devices settings and hardware the output will be different, e.g. a PC with analog output might have 44KHz audio output bandwidth, but a bluetooth headset might have a lower, different audio bandwidth. That is a datapoint that can be used in device fingerprinting alongside screen and viewport dimensions, device pixel ratio, browser plugins, etc.
- hunter2_ 1mo agoOn the one hand, I wouldn't expect too many variations here (the vast majority of devices probably use 48 kHz and 24-bit output, a few use 44.1 kHz and/or 16-bit, etc.) but just like DPR and all the other properties with a very small set of popular values in practice, you only need a bit or two from each measurement to eventually have a high quality fingerprint.
- cpt_sobel 1mo agoWhat surprises me is that this (additional) fingerprinting is actually needed, in the sense of "don't they have enough from everything else"? Also, if I understood this blog post correctly [0], there is only 2 predominant values from this fingerprinting (?). [0]: https://ritter.vg/blog-webaudio_alibaba.html https://ritter.vg/blog-webaudio_alibaba.html
- echelon_musk 1mo agoOP please submit the filter to an upstream uBlock filter list.
- nkjoep 1mo agoJS enabled by default seems every day less secure.
- emctech 1mo agoSo many website break completely with JS disabled and you end up having to enable it half the time anyway.
- masfuerte 1mo agoIt was pretty good until about six months ago. Since then loads of sites have added a js requirement to try to stop the AI bots.
- ruuda 1mo agoAbout half of the time, when a website doesn't work with js disabled, I realize that I didn't want to see the page that badly anyway, and I close the tab.
- MisterTea 1mo agoIMO web browser have been enabling all sorts of obnoxious behavior since before JS. One of my all time favorites were the sites that opened pop-ups in a loop faster than you could close them while an audio clip of a guy yelling "Hey everyone! I'm looking at gay porn!" You had to hit reset. Fuck the Web.
- afandian 1mo agoThe web around the late 90s and early 2000s had some really sketchy stuff. I think the difference is that it used to be the sleazy underbelly. Now it's accepted as mainstream. My local 'newspaper' website is chock full of scam adverts. The print version is dignified. The website people, somehow, turn a blind eye. And I got an advert on Youtube this week using sexually explicit language to sell pills. Feels like standards, and expectations, have really slipped.
- grishka 1mo agoOpening a popup needs JS though.
- buildfocus 1mo agoI've seen this on many many other sites as well, most notably Twitter, and lots of common modern captcha pages too. Very annoying!
- spicyjpeg 1mo agoBrowser fingerprinting can get creative at times, to say the least. eBay's WebSocket port scanner [1] and Reddit's abuse of DRM and JavaScript JIT exploits [2] from years ago are two examples of the kind of in-depth introspection you can perform completely in the background using nothing more than simple non-permission-gated APIs. [1] https://blog.nem.ec/2020/05/24/ebay-port-scanning/ https://blog.nem.ec/2020/05/24/ebay-port-scanning/ [2] https://iter.ca/post/reddit-whiteops/ https://iter.ca/post/reddit-whiteops/
- emctech 1mo agoThanks for the reads
- nottorp 1mo agoBesides the privacy implications, they are also wasting our fucking batteries on this crap...
- pama 1mo agoAnother reason why Lockdown mode on iOS is your friend.
- realusername 1mo agoSomebody else mentioned here that they also do it on the iOS app and I don't see how Lockdown mode would change anything, it doesn't prevent to play audio.
- eur0pa 1mo agoLockdown mode is great, but it breaks phone calls on your Apple Watch (found that out the hard way)
- goodpoint 1mo ago90% of this stuff should be illegal
- miki123211 1mo agoAh, so that's what Wolt (Doordash but in Europe) is doing. I noticed that Voice Over (iOS screen reader) crackles and randomly changes volume when using the app, but I attributed it to standard iOS weirdness, and possibly misuse of some iOS API. Now I'm thinking that this may very well be fingerprinting.
- lapcat 1mo agoCloudflare challenges also use Web Audio, by the way.
- spread2009 1mo ago[flagged]
- ankushdograuk 1mo agoThis is the reason I use adguard everywhere
- emctech 1mo agoI use ublock origin and by default it wasn't blocking, i had to make a custom filter to block the scripts in order for it to prevent the audio takeover. Maybe adguard does a better job? Someone else suggested just wholesale disabling of JS but it is the nuclear option.
- mgerdts 1mo agoWith my previous hearing aid I noticed that visiting a wide variety of web sites would cause a change in the amplification of environmental noise. I always assumed it was doing something with Bluetooth, and probably not for a good reason. This is with an iPhone 13 and one Kirkland/phonak hearing aid. I haven’t noticed this recently, but I also now have two newer Phonak hearing aids and a few iOS updates have happened. Maybe the silent Bluetooth shenanigans are less disruptive to my new aids or the programming is different. Surely shenanigans continue.
- jonathanlb 1mo agoI wear Phonak CI processors. It's not just you. I've also experienced the volume drop on a few sites and apps. The Amazon iOS app does this. Each time I leave the app, ambient audio returns to normal.
- phoghed 1mo agoThey’re kindly turning down the background noise so you can focus on shopping and buying more stuff.
- lenerdenator 1mo agoIt'd be interesting to see what a lawyer specializing in disability law would think of that. At least in the US, I could see that being something that the ADA prohibits.
- KennyBlanken 1mo agoIt seems far more likely that your cheap hearing aids are sensitive to certain RF frequencies and the background javascript is causing different patterns of load on the phone's CPU. I would suspect that this only happens when you're charging and it is likely the charger or cable not being properly shielded.
- mgerdts 1mo agoThe cheap hearing aid cost $750 for one and is substantially the same as the same thing sold from standalone audiologists for much more. These are not cheap over the counter devices. Charging only happens while in the cradle, not while worn.
- pyaamb 1mo agoNeed to rethink the system that allows for (and encourages) this kind of plausible deniability. From "Oh we need this permission for [non essential feature] and you need to accept it if you want the app at all" -> to giving the user ultimate control over what happens on their personal device. Virtualize what the app can see and use fake data/identifiers/devices if necessary to get it to do what its supposed to. If the App isn't going to act in good faith why should the user? Fine grained permissions don't really work in practice because the app can keep annoying the user until they give in and hit Allow.
- ajross 1mo agoWhat you want is basically how it works. On both phone platforms and PWAs, all permissions are visible to the user explicitly. All of them can be revoked at any time. Apps are disallowed from requesting an already-denied permission. Obviously apps can tell if they haven't been granted a permission (even if you tried to fake this, they aren't dummies and will know if it's not working), and obviously third party software isn't under any obligation to work without them. But the platforms have done what the platforms can do, at the architecture side, really. The next stage is human-audited enforcement of malware, which this AliExpress nonsense might hopefully run afoul of.
- xnx 1mo ago> Obviously apps can tell if they haven't been granted a permission (even if you tried to fake this, they aren't dummies and will know if it's not working), How can they tell? For the permissions I can think of: location, filesystem, etc. it should be easy to lie/spoof.
- drdexebtjl 1mo ago>Obviously apps can tell if they haven't been granted a permission By design. This doesn’t need to be the case. It should be impossible to tell you have denied a permission. In TFA’s case, the browser could just keep processing audio but never hook it up to a real audio sink.
- 1mo ago
- ibaikov 1mo agoI had this (?) happen. I have a soundbar hooked up through spdif in my pc. It automatically switches sources, so I can play music through airplay and then have it play sounds from pc when I open youtube etc. So it switches from airplay music to pc even when nothing is playing on pc. This was happening on some websites and it is extremely annoying.
- sillyboi 1mo agoI thought the App Store review guidelines explicitly prohibit hidden features and using public APIs outside their intended purpose. Is audio-based fingerprinting just not something review can realistically catch?
- ValdikSS 1mo agoThey probe all audio devices, including microphones, which probably temporarily switches Bluetooth devices into HPF mode due to how Bluetooth duplex audio works. I'd argue it's "silent" though: aliexpress wakes up my audio card if nothing plays, which results in a very faint "pop" sound every time I open the tab. It's been this way for ~3+ years at least.
- lapcat 1mo agoIt's the website. The title of the article literally mentions "WebAudio", and the first paragraph states that the author is using a PC. The second paragraph mentions Chrome and Firefox. Apple and the App Store have zero involvement here.
- hunter2_ 1mo agoThis is a huge stretch, but if this problem exists in not only the PC versions of Chrome/Firefox but also the Android/iOS versions, then theoretically the app store reviewers could flag the browsers for facilitating this behavior against app store guidelines. In practice, apps of such caliber as popular browsers might be a bit above such reviewers' pay grade, so to speak.
- lapcat 1mo ago> This is a huge stretch This is nonsense. Safari also supports Web Audio. Safari does not, however, support Microsoft Windows, which is why the article author didn't mention it. Moreover, all web browsers on iOS have to use Apple WebKit, so Web Audio support is not actually the fault of the non-Apple browser vendors.
- sillyboi 1mo ago
- gmueckl 1mo agoA part of me is always smiling a little inside when people find creative ways to abuse browsers. It's always one more demonstration that the current web is fundamentally broken by design. The distinction between web browsers and random programs that allow remore arbitrary code execution is becoming more and more academic with every new feature that gets exposed to JavaScript. Of course, I am also a horrible hypocrite and will actually use websites that use features like WebUSB or WebRTC.
- __MatrixMan__ 1mo agoIt was a mistake to normalize blindly executing whatever code the server sends your browser. One day we'll look back on this era and wish we had pulled the plug sooner.
- forestry 1mo agoSo Apple will remove them from the App Store. Thats their whole argument for their closed system - they’ll protect users from malicious apps. Right?
- Grombobulous 1mo agoIf this wasn't such a serious issue I'd be inclined to make a joke about being surprised that AliExpress was capable of such a thing, but I guess the complete shitshow of a website is intentional. I wouldn't be surprised if what I'm feeling is all a psychological thing where consumers associate jank with low prices so that's why sites like AliExpress and Temu look like a complete technical mess when in reality they're doing pretty advanced stuff like this.
- kappi 1mo agoIt's not just BT audio. In windows PC, if aliexpress is opened in one tab in chrome, and switching to a tab with youtube opened, audio don't play in this tab if you start playing youtube.
- grishka 1mo agoIs there any particular reason these kinds of APIs are not behind permission prompts?
- handle584 1mo agoMeanwhile ppl freak out over Anthropic using timezone and Unicode for the same purpose, without realizing Chinese are simply ruthless in abusing iOS or Android or Web. Pinduoduo, who owns Temu, is infamous for exploiting an Android 0day vulnerability for such purposes.
- shevy-java 1mo agoWe need to find a solution to browsers sniffing on people. This here refers to AliExpress, but which browsers are typically spying on people like that in the first place? That's the real primary problem.
- barrystaes 1mo agoAha this would explain. I have seen similar behaviour with a news website trying DRM requests (has no reason to ask this info) resulting in stopping playback.. did not consider the impact of multipoint here. Interesting, might be worth looking into if i see this "bug" again.
- kinnth 1mo agoThis sounds like a GDPR issue no? Couldn't they be taken to the EU!
- kenniskrag 1mo agoYes. In this case probably not fineeprinting is not allowed because not strictly necessary (cookie law) and therefore needs consent from user.
- edelbitter 1mo agoGoing batshit with browser APIs is also a formidable GDPR defense. e.g. try browsing the privacy-related forms for Google (https://myaccount.google.com https://myaccount.google.com) on Firefox :D (entire browser freezes up every other second for me, because of some extremely important work Google needs to run on my CPU to let me scroll down on a static site containing roughly 30 words)
- amelius 1mo agoAre there any EU/GDPR laws against fingerprinting?
- kenniskrag 1mo agoYes. In this case probably not allowed because not strictly necessary (cookie law) and therefore needs consent from user.
- amelius 1mo agoDo we have any jurisprudence on fingerprinting?
- hoppp 1mo agoAre you not required to grant an explicit permission for it to access audio? If not that is highly disturbing.
- big_dave212 1mo agoTrying to debug this as a normal user is basically hopeless, you would never think to suspect a shopping tab. Glad someone did the legwork.
- emctech 1mo agoIt just annoyed me so much that it was interrupting my music!
- gaudystead 1mo agoHell hath no fury like an inconvenienced power user.
- tecleandor 1mo agoThat could explain the multipoint problems I've had in the last weeks, where audio would get "stuck" to one of my devices even when (apparently) nothing is playing.
- lxgr 1mo agoI've had these issues on and off as early as 10 years ago when I got my first multipoint headphones.
- lxgr 1mo agoI wish such shenanigans would simply trigger the little speaker icon most browser display on tabs these days. Given that they don't (at least in my experience), I'm assuming "playing silent audio" is a sufficiently common thing for websites to do to have motivated browsers into doing the slightly more complicated thing of actually analyzing audio streams for content... Now I wonder, does this also allow websites to continue running in the background on mobile browsers? Playing media is one of the very few things that can convince iOS Safari to keep a tab running indefinitely, in my experience.
- emctech 1mo agoI wonder if it is something firefox and chrome devs need to look at because if it is accessing the audio device surely it should be notified to the user.
- lxgr 1mo agoAs I mentioned, I suspect that this is an active choice, as just displaying the icon whenever a media context exists seems much easier than inspecting the audio stream for non-zero volume media. I can only assume that there are legitimate reasons for this as well, e.g. websites preparing/maintaining audio context for lower latency when they intermittently play audio etc.
- emctech 1mo agoSomeone else mentioned that cloudflare uses the webaudio for verification challenge, but only triggers it briefly.
- lxgr 1mo agoUgh... Seems like we need an audio API web permission, or maybe do something like browser already do for some of the other APIs and actually require API users to actually play something or display a warning/play an annoying chime otherwise.
- 1mo ago
- admax88qqq 1mo agoSomebody (Mozilla?) should make a browser that just proactively blocks shit like this I’m sure some Adblock addon could do it but at the browser level would be preferred. A browser vendor that just proactively does security and “correctness” tweaks to live sites would actually be in my interests as a user
- Flow 1mo agoI wonder if this is something the iOS Facebook app also does? It constantly pauses my Apple Music playing. Soooo irritating.
- prima-facie 1mo agoThis is not limited to Bluetooth in any way. In pavucontrol I can see Firefox outputting audio when on AliExpress even though nothing is playing. The uBlock filter fixed it.
- ErrorNoBrain 1mo ago> The uBlock filter fixed it. what filter ?
- prima-facie 1mo agoFrom the article: To block the scripts open the uBlock dashboard, select My filters, and add: ! AliExpress AWSC fingerprinting scripts ||assets.aliexpress-media.com/g/AWSC/uab/*/collina.js$script,domain=aliexpress.com ||assets.aliexpress-media.com/g/AWSC/fireyejs/*/fireyejs.js$script,domain=aliexpress.com
- qurren 1mo ago> distinguish normal shoppers from automated Why? Are you afraid of robots making you rich?
- downrightmike 1mo agoThere is no legit reason to be doing this.
- fg137 1mo agoThis at least partially contributed to a sleep related Firefox bug on Windows: https://bugzilla.mozilla.org/show_bug.cgi?id=1863193 https://bugzilla.mozilla.org/show_bug.cgi?id=1863193
- docmars 1mo agoSounds like we're gonna need browsers to pop an audio playback permission, as annoying as that seems. Abusive sites just can't help themselves.
- __MatrixMan__ 1mo agoBluetooth is such a mess. You know what didn't have this problem? Cables.
- aembleton 1mo agoAlso, non-multipoint Bluetooth.
- mdavidn 1mo agoI notice this all of the time on sites with ads. I use AirPods to listen to music on my phone at work. Opening websites on my Mac routinely steals the AirPod connection but plays nothing audible.
- SadErn 1mo ago[dead]
- theyeenzbeanz 1mo agoCan we just limit web APIs to cookies and the likes as before? I don’t like how JavaScript has access to so many devices on the host. It’s a security and privacy nightmare.
- spawrks 1mo ago[dead]
- ninalanyon 1mo agoWhy are web pages allowed by default to do such things? Browsers should give the user the ability to forbid all sorts of thing and have them forbidden by default.
- fuzzy2 1mo agoWhen I visit an article on a popular German tech news website, it interrupts music playback on my iPad (the website takes audio focus). I bet they do something similar.
- rootsudo 1mo agoI’ve noticed this and on other apps too, it breaks AirPods and when background playing Spotify it’s very obvious. Thanks for investigating! Makes sense it’s also in the taobao app on ios too.
- dzonga 1mo agoI think x.com does this too - haven't been able to dig deeper.
- jiehong 1mo agoThis article writing is really clean and enjoyable to read. And I learnt something. Thank you very much.
- br0ceph 1mo agoaliexpress is largely a bait and switch site. most of the prices change during checkout in the most frustrating ways. one u ready to check out, and provide ur payment into, and click to pay... they interrupt this fake checkout with a popover, inform u the price is actually much higher, and dangle a button which is one click to accept the new higher price. this is total scam behaviour and probably illegal in most US states.
- sva_ 1mo agoI did not have that experience at all, ordered there dozens of times.
- tomrittervg 1mo agoWebAudio fingerprinting is largely mitigated (in Firefox, potentially other browsers) - I wrote a quick overview that talks about the current distribution of values as well as our more recent efforts. https://ritter.vg/blog-webaudio_alibaba.html https://ritter.vg/blog-webaudio_alibaba.html
- emctech 1mo agoThanks for your input and perspective! Do you think it is a bug that the muting of the firefox tab doesn't stop the audio stream? It is frustrating that companies would use such an annoying tactic to track their users with it also ineffective.
- tomrittervg 1mo agoYes, it is a bug, in fact it's this bug: https://bugzilla.mozilla.org/show_bug.cgi?id=1863193#c9 https://bugzilla.mozilla.org/show_bug.cgi?id=1863193#c9 which is of course getting some more attention now =)
- emctech 1mo agoGood to know! I have added a note and link to my post.
- IX-103 1mo agoThis is actually a really common form of fingerprinting. At one point in time, it could generally tell the website what operating system and CPU architecture you're running on. I know this type of fingerprinting was fixed in Chrome so it always gives the same answers regardless of platform. I think it was also fixed in Firefox and Safari, but I don't follow their releases as closely. Of course, even though it's probably useless now, things like that hang around because it costs more for trackers to remove the code than it does to keep it in.
- nazgulsenpai 1mo ago> screen and viewport dimensions I remember trying I think it was the Tor browser, being puzzled at why the viewable area of the window constantly changed when resized but would never occupy the full window. I feel a little silly now.
- corentin88 1mo agoGetting the same issue when opening Stripe Dashboard with AirPod on.
- Animats 1mo agoYou could make a good case for 'exceeds authorized access' under the Computer Fraud and Abuse Act for this. You might even get some action if you filed a complaint, because it's from China.
- julianlam 1mo agoI experienced something similar with the AliBaba app. Whenever I had it installed, my Bluetooth devices would only ever send audio in "headset" mode — very poor quality. Uninstalling the app fixed it up.
- zx8080 1mo agoNow, that's why leaving some sites in background empties my phone battery.
- like_any_other 1mo agoGetting a list of emails from a website by guessing a predictable ID gets your house raided by the FBI and a criminal conviction for accessing a computer without authorization [1]. Why isn't fingerprinting treated the same? And I mean exactly the same - first an FBI raid, arrest, and confiscation of computers, and then they get their day in court. [1] https://en.wikipedia.org/wiki/Goatse_Security#AT&T/iPad_email_address_leak https://en.wikipedia.org/wiki/Goatse_Security#AT&T/iPad_emai...
- emctech 1mo agoI doubt the FBI will be flying to china to knock down any doors! You aren't wrong though, and countries which enforce GDPR I would expect to make noise if this was happening to their constituents.
- cyteeditor 1mo ago[dead]
- tinlid 1mo ago[dead]
- TheqO 1mo agoalways a good idea to use NoScript too for more fine grained control.It's ridiculous how many seperate calls a simple web page can make https://noscript.net/getit/ https://noscript.net/getit/
- danielEM 1mo agoI'm confused, doesn't access to microphone raise pop up asking for permissions? I'm nearly sure I saw it
- emctech 1mo agoPerhaps accessing the microphone is something else they do, however that is not the issue in my case nor what my article is about.
- jeffybefffy519 1mo agoI dont get how this fingerprints the browser? Are they able to read back the playback of audio somehow?
- emctech 1mo agoThe Web Audio API has the ability to extract frequency, waveform, and other data from an audio source, that source is generated at runtime on your device. A firefox developer did a further dive into what the WebAudio based fingerprinting can actually return in firefox. https://developer.mozilla.org/en-US/docs/Web/API/AnalyserNode https://developer.mozilla.org/en-US/docs/Web/API/AnalyserNod...
- cyzanfar 1mo ago[flagged]
- arendtio 1mo agoI wonder how many other websites are doing such stuff. Lately, KDE Plasma often shows me that audio is being played by Firefox, but no tab in Firefox has the speaker icon. So far, I have not found which page causes this issue (I don't use AliExpress).
- alliao 1mo agothe fingerprint exists to do dynamic/adaptive pricing... if you never return anything they assume you'll take any price as you enjoy their services more
- break-the-build 1mo ago[dead]
- ceres-c 1mo ago[dead]