Back

AliExpress runs silent WebAudio fingerprinting that breaks Bluetooth multipoint

165 points2 hoursblog.laserphile.com
patspam2 hours ago

I noticed in the last few weeks that if I’d recently opened the AliExpress iOS app (ie. it was backgrounded) my car audio would freak out thinking I was giving it an audio command. Killing the AliExpress app immediately fixed the problem. After seeing it happen more than once I assumed it was something dodgey and uninstalled the app.

lukeify2 hours ago

I cannot ever imagine installing something like AliExpress as an app.

unixhero1 hour ago

It's great for shopping. But in the US you have amazon prime. We don't.

dogman105056 minutes ago

I have Prime, but I can't imagine installing the Amazon app either. The website works just fine.

nntwozz41 minutes ago

This is the way. It's prudent to treat apps with skepticism, it's unfortunate it's come to this.

I study Apple's Privacy Nutrition Labels religiously every time I consider installing an app.

I like the ones with "Data Not Collected".

embedding-shape54 minutes ago

I don't have Amazon Prime (nor am I in the US) yet use Aliexpress perfectly fine on my mobile phone without using an app. Frankly, I don't understand how the two is related at all?

+1
doubled11225 minutes ago
fragmede1 hour ago

Where is "we"?

ngl99947 minutes ago

Likely the place where people are "willing to trade privacy for convenience", according to Baidu's CEO.

rcruzeiro21 minutes ago

According to their profile: Norway

lovestory46 minutes ago

You probably buy things off amazon that are dropshipped from AliExpress all the time. Stop with the elitism

63stack42 minutes ago

This is not about the products that are shipped, but the app itself. I would caution people to never install it as well.

aureate38 minutes ago

I buy directly from AliExpress all the time. I wouldn't install their app.

ohyoutravel34 minutes ago

Love Temu and AliExpress for specialized components at dirt cheap prices. I would never, ever install their app. Ever, security nightmare.

Similar to how I use Amazon Prime but would never order something I ingest, put on my skin, or (usually) wear from it.

Not elitest.

ngl9991 hour ago

It's known that some Chinese mobile apps employ this trick to keep the app alive in the background, the rumor is that this way the 'active user' KPI can be better met.

edit: quantity qualifier

SirFatty26 minutes ago

If it's known, are you suggesting that Apple and Google are complacent in allowing these type of apps in their ecosystem?

compsciphd2 hours ago

i'd argue that perhaps the ability to play audio should be permission gated, much like the ability to use webcam/microphone.

However, I'd bet that many people will gladly allow aliexpress to play audio as there are probably videos on the site that people want to play and listen to.

With that said, its possible that this can be only a use once permission. Even if I want to shop at aliexpress if I know they are doing this, I'll be more willing to be bothered every time I want to play a video with audio to approve it if this bothers me.

rcruzeiro18 minutes ago

I would actually love if I could have iOS prompt me to allow certain apps to use the speakers. I hate using an app and suddenly have a video autoplay loudly.

emctech2 hours ago

The ability to play audio can usually be permission gated with tab muting, however the methods aliexpress use bypass that mechanism completely.

emctech2 hours ago

Recently I ran into a problem with my Bluetooth headphones. They support multipoint bluetooth audio, so they can be connected to my PC and phone at the same time. Opening the Aliexpress webpage causes a silent audio stream keeping the PC>headphone link active blocking my phone audio. An investigation reveals obfuscated code running device fingerprinting with a side effect being a silent audio stream that firefox, chrome and windows does not recognise but which kept the bluetooth connection active.

robtherobber2 hours ago

Concerning situation, I think. And I suspect (perhaps wrongly) that there are even more reasons for concern with technology that can track, capture, leak etc. information that's more sensitive or valuable, depending on how one wishes to look at it. Mobile phones, computers, routers etc. -- all have the potential to siphon out valuable information to a bad actor, especially when it comes to espionage, military, commercial etc. This has already happened at a significant scael, so it's not a remote scenario.

At the very least, governments and institutions should develop a framework to investigate all acquired technology. The community / civil society could also create something similar, a script that would analyse at a deep level everything that can be analysed with a piece of software even by a complete novice.

emctech2 hours ago

Yes, I find it concerning too. I particularly dislike that windows was not aware, nor could it stop the audio stream from effecting the hardware. What other side channels like that exist? Perhaps I can be blamed for using windows

robtherobber2 hours ago

> Perhaps I can be blamed for using windows

That would be unreasonable, I argue. No one should have to worry about the security of their devices and data privacy based on which OS they use. Whilst it can be argued that different OSs serve different needs, privacy and security should not be debatable. In fact, most countries have dedicated legislation for this; whether it's just, applied correctly, or serves the public before any other party are indeed discussions to be had.

lnsru1 hour ago

I am pretty sure my phone is listening. The ads I see this week are about topics I discussed last week. Week for week. Stupid thing is that I need the phone to have near by as self-employed electrician. Clients want to communicate after regular office hours. Since the phone is rigged why computer shouldn’t?

bobim2 hours ago

We take everything we have, freedom, privacy, free speech, for granted. The reality seems to be that these concepts are fungible and that we have to be ready to fight for them. Instead we trade these for convenience, and it's very very sad.

buildfocus1 hour ago

I've seen this on many many other sites as well, most notably Twitter, and lots of common modern captcha pages too. Very annoying!

nkjoep1 hour ago

JS enabled by default seems every day less secure.

emctech1 hour ago

So many website break completely with JS disabled and you end up having to enable it half the time anyway.

ruuda14 minutes ago

About half of the time, when a website doesn't work with js disabled, I realize that I didn't want to see the page that badly anyway, and I close the tab.

masfuerte1 hour ago

It was pretty good until about six months ago. Since then loads of sites have added a js requirement to try to stop the AI bots.

MisterTea59 minutes ago

IMO web browser have been enabling all sorts of obnoxious behavior since before JS. One of my all time favorites were the sites that opened pop-ups in a loop faster than you could close them while an audio clip of a guy yelling "Hey everyone! I'm looking at gay porn!" You had to hit reset. Fuck the Web.

afandian52 minutes ago

The web around the late 90s and early 2000s had some really sketchy stuff. I think the difference is that it used to be the sleazy underbelly. Now it's accepted as mainstream.

My local 'newspaper' website is chock full of scam adverts. The print version is dignified. The website people, somehow, turn a blind eye.

And I got an advert on Youtube this week using sexually explicit language to sell pills.

Feels like standards, and expectations, have really slipped.

spicyjpeg1 hour ago

Browser fingerprinting can get creative at times, to say the least. eBay's WebSocket port scanner [1] and Reddit's abuse of DRM and JavaScript JIT exploits [2] from years ago are two examples of the kind of in-depth introspection you can perform completely in the background using nothing more than simple non-permission-gated APIs.

[1] https://blog.nem.ec/2020/05/24/ebay-port-scanning/

[2] https://iter.ca/post/reddit-whiteops/

emctech59 minutes ago

Thanks for the reads

ngl9991 hour ago

Just curious, why silent sound would allow fingerprinting? What are they sampling if it can't be heard?

emctech1 hour ago

The script generates a known waveform, it is passed through the browser's audio implementation and then the script analyses the result after. Based on your devices settings and hardware the output will be different, e.g. a PC with analog output might have 44KHz audio output bandwidth, but a bluetooth headset might have a lower, different audio bandwidth. That is a datapoint that can be used in device fingerprinting alongside screen and viewport dimensions, device pixel ratio, browser plugins, etc.

CTDOCodebases2 hours ago

They have been doing this for months.

No sound playing but the audio would change like the microphone was being activated. I checked permissions to make sure there was no mic access and figured that they were fingerprinting.

emctech1 hour ago

I had noticed it before but I was browsing AE a lot today and i got fed up with it. What browser and OS are you using?

goodpoint23 minutes ago

90% of this stuff should be illegal

pama35 minutes ago

Another reason why Lockdown mode on iOS is your friend.

realusername21 minutes ago

Another commenter mentioned here, they also do it on the iOS app and I don't see how Lockdown mode would change anything, it doesn't prevent to play audio.

echelon_musk1 hour ago

OP please submit the filter to an upstream uBlock filter list.

emctech1 hour ago

Will do! edit - How do i do this? through github issues? https://github.com/uBlockOrigin/uAssets/issues

nottorp1 hour ago

Besides the privacy implications, they are also wasting our fucking batteries on this crap...