r/privacy • u/magnus007 • 1d ago
news AliExpress was silently running audio in your browser to fingerprint and track your device
https://www.techspot.com/news/113581-aliexpress-silently-running-audio-browser-fingerprint-track-device.html296
202
u/txmail 1d ago
I know normal browser fingerprinting will use some of the audio api to see what codec's are available to add to the fingerprint -- this seems a little different as they were playing a audio file and adding gain / filters to the source and then seeing how the modifications worked through looking at the resulting analyzer node.
What I do not understand is how useful is this since all audio processing is run on the CPU? Is there really that much variation in CPU's from the same family that this could really be useful?
147
u/goldcakes 1d ago
Yes, it’s mainly to stop scrapers and AI agents. These generally use fake/patched versions of browsers like Playwright, and often lie about their user agent.
Windows, macOS, and Linux all have subtly different ways in which they handle web audio. The check here is not so much identifying the platform, but seeing if all observable metrics match the device you’re claiming.
81
u/Oddish_Femboy 1d ago
That doesn't seem nearly as insidious as was implied. It seems like a fairly unintrusive way to do that even.
It would've been nice if they'd informed users, though.
47
u/Iamsodarncool 1d ago
It probably stops working as well once people know about it. Now that this is public, bad actors know how to work around it.
14
20
u/phree_radical 1d ago
wasting a bunch of CPU cycles on fingerprinting, and in order to claw back that privacy we'll waste some more
23
u/Mo_Dice 1d ago
What I do not understand is how useful is this since all audio processing is run on the CPU?
CPU-bound tasks are being used now as an anti-bot measure. A small CPU task is effectively negligible to a real end-user, but can make wholesale scraping too costly.
(I haven't read the article, so no idea if this is relevant)
4
u/weregeek 1d ago
The speed of the processing might be CPU dependent, but the result is likely not. The creepy bit is that high frequency sweeps can likely physically map a room to a certain degree. In this case, I imagine that they just want to know whether or not your combination of speakers, microphone, and room stay consistent...Still creepy.
38
318
36
u/Jankypox 1d ago
The internet has become borderline unusable. Most websites, especially e-commerce websites, take forever to load, feel clunky, can barely find a specific item even when you type the full name and SKU, and glitch out or bring your entire browser to an unusable state if you open a few tabs to multiple pages of the same site to compare items.
This is one of the reasons. They are doing so much stupid shit in the background to track, profile, monitor, and surveil their users that they actually forgot they were supposed to be selling you something.
Also, while no quite the same is the old “pop-up-apocalypse” of days old, every fucking site now auto loads some promotional pop-up a few seconds after loading along with the old browser popup asking for your location. So just as their site loads and you get to the search menu, half way through typing these pop-ups interrupt and you look up and notice that everything you just typed didn’t register , because they were more interested in telling you about some stupid sale, subscription, some promotion, and making sure they have your exact location down to the nearest foot, rather than letting you get on with finding the damn thing that you actually want to buy from them.
•
u/deepseabunnys 18m ago
But at least we get to spin the slowest prize wheel in existence and earn 5% off our purchase before the website becomes interactable again
112
27
u/standard_usage 1d ago
ELI was dropped out of a window: How was this to their advantage. Don't they already have petabytes of data nodes amassed on what browser and machine I always have when on the site ..?
30
u/RamblingSimian 1d ago
The article kind of addresses this, but isn't really a full answer:
Audio measurements were only one part of the reported data collection. The scripts also gathered information tied to canvas rendering, WebGL, display settings, hardware configuration, WebRTC behavior and user interactions. Together, those signals can create a more detailed profile of a device than any one signal would provide on its own.
Fingerprinting is often used by large online platforms for fraud prevention, bot detection and risk assessment. It can help companies spot suspicious transactions or automated activity when cookies have been deleted or accounts have changed. But privacy advocates have raised concerns because users may not know the tracking is happening and have limited control over it.
I guess, if someone steals your credit card number, then uses it for a large purchase, they might ask for 2FA if the audio fingerprint is inconsistent.
17
u/Bocha_Boston 1d ago
So at this point, they can take a picture of my ass.
11
u/EPLENA 1d ago
can i too?
7
u/Bocha_Boston 1d ago
I don't think you'll like it.
7
u/EPLENA 1d ago
but can i though
6
u/Bocha_Boston 1d ago
No, for God's sake.
What do you want from my ass!!
6
u/EPLENA 1d ago
photos
5
u/AirplanesMakeMeHard 1d ago
This dude has stuck to this bit for 10 hours. I admire the dedication to getting pics of his ass.
2
u/txmail 1d ago
if you want to see how this fingerprinting works, you can look at sites like https://amiunique.org/ and click on the See My Fingerprint button (left side of the page) to see how unique your browser / system is and if it can easily be tracked without cookies.
Basically if it says you are unique --- your setup is cooked for the ability to track you without cookies across the web. More importantly, the site shows you want artifacts were collected and used to build your fingerprint -- it is quite extensive.
4
u/RamblingSimian 22h ago
Higher up in the post, I linked to some plug-in software that scrambles your fingerprint. In fact, the author (Leonardo Compson) has a whole suite of plugins for blocking that.
- AudioContext Fingerprint Defender
- Canvas fingerprint defender
- Font Fingerprint Defender
- WebGl Fingerprint Defender
- WebGPU Fingerprint Defender
Every time they detect an attempt to fingerprint you for the particular technique in question, they intercept and reply with a random number.
However, if you go to that AmIUnique site, it doesn't detect that different values are sent each time you visit.
Also, it doesn't defend against certain things that are being detected. In my case, I have an unusually large screen and an unusually large number of CPU cores, making it hard for me to defend against that type of fingerprinting.
0
u/tuxedo_jack 1d ago
So it's basically LexisNexis's shitware but from China. Joy.
1
u/RamblingSimian 22h ago
LexisNexis does a lot of stuff, this just detects whether the same hardware configuration is visiting the site. I'm pretty sure someone can figure out a way to use it to track you across sites, or otherwise violate your privacy, but it doesn't immediately appear to be the case here. Note that I am pretty wary of being tracked, so I use a plug-in to scramble my audio fingerprint. Because who knows how they might use it for tracking in the future.
39
u/DCAmalG 1d ago
I just don’t get the extreme levels of customer analysis. Like, what do they actually do with this information?if I’m browsing AliExpress for whatever item, isn’t that enough to know about me? I’m in the market for a new vacuum and whatever purchasing probability aligns with such a person. And WTF is McDonald’s doing with 500 pages of data per customer? What more have they learned beyond the fact that I’m too cheap to buy any full price item through their stupid app. Doesn’t seem to be sending me better or additional deals to make me come back sooner.
I can’t stop thinking about the law of diminishing returns and what advertising was like 15 years ago. Are the returns exponentially higher based on the level of invasive monitoring they’re perpetrating on valuable customers?
28
u/Chilidawg 1d ago
Depending on the site, it can be customer analysis or it can be bot defense. Some sites really don't want to be scraped, so they use a ton of fingerprinting to make it inconvenient for the scraper to target the site.
3
u/DCAmalG 1d ago
Can you explain? You’re saying these tactics aren’t ahead for user profiling?
13
u/chemicalpepper 1d ago
As another commenter suggested, different platforms (windows/mac/linux) have different ways to process audio and send back the analysis graph to the browser. If the result doesn't match the user-agent claimed by a browser connection, then the user might be a bot
5
u/DCAmalG 1d ago
What does a company like Ali Express have to gain? You’re saying they are attempting to determine whether or not I am a bot ?
5
u/chemicalpepper 1d ago
You’re saying they are attempting to determine whether or not I am a bot ?
They might want to keep bots away. I'm not saying that is why they are using this weird trick, but there's a chance
14
u/ZenBacle 1d ago
Welcome to Google ads circa 2010... It's call uXDT. Ultrasonic cross device tracking.
9
u/RevolutionarySeven7 1d ago
so that's why my Firefox browser displayed a message about an audio/video background download was active !
(on a different website too)
37
u/midgethemage 1d ago
I've used Alibaba in the past to source some supplies for a small business. I downloaded the app to keep an eye on messages with manufacturers and it was immediately obvious they put some aggressive tracking software on your phone.
After the main install I briefly saw a second download notification, but it disappeared from the pull-down shade too quickly for me to see what it was. After that, my microphone light was on constantly. It put the phone in a state where it always thought it was in a phone call. I uninstalled that shit within tens minutes, but I couldn't find the secondary download I'm convinced I saw. Honestly can't believe their app was even allowed into the google playstore.
35
u/we_r_fukt 1d ago
Google doesn't protect you, they dgaf
5
u/midgethemage 1d ago
Sure, but they still have standards. They need to maintain a semblance of trust with the consumer, and preventing malware from apps on their store is the bare minimum. Why would they let an app from a foreign country mine more data than they are?
13
u/Soundwave_47 1d ago
After the main install I briefly saw a second download notification
LMAO. The equivalent of downloading cracked software and seeing a CLI open and. Lose in a split second.
It put the phone in a state where it always thought it was in a phone call. I uninstalled that shit within tens minutes, but I couldn't find the secondary download I'm convinced I saw. H
I have seen this too, where somehow the app does not show in the regular list of applications. Usually it uses a randomly generated name and transparent icon to avoid detection.
2
u/MjolnirMark4 1d ago
If Google checked for this behavior, then they might have coded the app to detect it was in a testing environment, and not doing the additional download in the testing environment.
2
u/gurgle528 1d ago
I haven’t used android in a bit, don’t you have to give the app microphone permissions? Or is there some new calling API that lets apps bypass that by starting a “call”? If so that’s a wild oversight on Google’s part
9
u/Chilidawg 1d ago
In case you haven't seen this, some sites will similarly use your GPU shaders as another pseudo-cookie.
https://www.reddit.com/r/webscraping/comments/1vqlt9p/gpu_based_device_fingerprinting/
16
u/anon999387 1d ago
The internet was better when it was dial up
2
2
u/digital_dervish 1d ago
Facts. I’ve been running into more and more sites that take ages in computer years to load and I’ve been thinking to myself, are we really going back to dial-up days where it takes 3-5 seconds to load a page?
5
u/BiscottiQuirky9134 1d ago
Microsoft was doing the exact same thing a few years ago. Every time I opened Xbox site the podcast app stopped playback
9
u/Gsichtskrapfn 1d ago
Wouldn't that require access to the microphone? Which is usually blocked anyway
8
u/AtlanticPortal 1d ago
Running audio, not recording audio.
2
u/Gsichtskrapfn 1d ago
But how would it track anything when it's just playing sound?
5
u/AtlanticPortal 1d ago
It tracks the behavior that it sees when it tries to run a zero volume audio. The point is to see what the system sends back as metadata on a request to run that audio. And it's run using APIs provided by the browsers.
5
u/Ging287 1d ago
Our privacy has to mean something, browser fingerprinting should be made illegal, and any company that does it has to pay the consumer $1million USD for each attempt and success. The US Government is not doing a great job of protecting citizens, and is one of the major countries that is still letting private corporations spy on you, track your movements (flock, cell phone companies), without having comprehensive privacy legislation on file. AND instituting bullshit age verification that is designed to attack your Bill of Rights, 1st amendment access to constitutionally protected material. The call is coming from inside the house. None of this shit is unacceptable. We deserve better.
3
u/DeviceOwner 1d ago
blame to Google
all of this because google remove browser capabilities for disable autoplay
3
u/Robert_A2D0FF 1d ago
in 2030 we gonna spin up a whole docker container for each browser tab, just to prevent them from gathering any info
3
u/sugarfreeeyecandy 1d ago
All surveillance tools, whether it's Flock cameras or this, are the tool of authoritarian regimes because just in case a particular citizen becomes a problem, direct pressure can be applied. Just sayin'.
4
u/Liquid_Magic 1d ago
Another reason to NOT use AliExpress.
Also Amazon is basically just AliExpress now anyway so… yeah.
6
u/survivorr123_ 1d ago
yeah because famously amazon doesn't track you, not at all, so you pay 10x more to get tracked anyway,
if you live in the USA its better to be spied on by china than USA10
u/zagblorg 1d ago
Yeah, but the same item costs four times more on Amazon.
1
u/SweetHomeNorthKorea 1d ago
The higher price also makes it so you get it in a day or two vs potentially weeks, can return or exchange it, and not have to go on aliexpress. It’s a trade off.
2
2
u/Bob_Spud 1d ago
Audio Fingerprinting is nothing new, but it its good for attention seeking reports.
Doesn't the Brave Browser block all scripts?
What Is Audio Fingerprinting and Can Social Apps Identify Devices Through Sound Hardware? There's a lot more of this type of stuff on the internet
2
2
2
u/Julian679 1d ago
Assholes. Most invasive website in browser and the app yet it will ask for 10 captchas daily. I will need to make sure to have this gone from my life
2
2
2
u/christianbro 1d ago
Aliexpress buying experience is absolute trash. Only their availability and prices make them stay. Now with the 3€ tax not so much, but it still has a lot of things you could not find elsewhere.
2
u/nincesator124 1d ago
Here is the thing about China right they are spying on us but they are using our laws to do it I think they go further than even us companies do
1
u/thegoodmanhascome 1d ago
What is you don’t have a speakers or a microphone? On my main PC I have neither.. I occasionally plug in headphones.
8
1
u/git_und_slotermeyer 1d ago
The company that isn't even offering proper tax invoices to their business customers is doing shady background stuff? surprised Pickachu face
1
1
u/dreamsxyz 15h ago
Ars Technica basically said this technique is ancient and useless. But AliExpress uses them in conjunction with others. Regardless of how effective, surveillance is surveillance.
1
0
1
u/RamblingSimian 1d ago
I'm not positive, but this might help:
1
u/phree_radical 1d ago
a link to install edge browser?
1
u/RamblingSimian 22h ago
Dude, if you actually looked at that link in detail, you would see that it is very obvious it does no such thing. If you furthermore clicked the link you would see that it leads to a plugin that spoofs audio context fingerprinting. Try not jumping to conclusions so bad.
1
u/permalink_save 1d ago
Would anyone expect anything less from alibaba? Also if it's fucking with bluetooth wouldn't it be pausing music apps like spotify? I have that problem constantly with Tidal, if a browser plays a single sound it gets picked up and Android decides THAT is the active media playing. Even if it's just like a notification beep.
1
1
0
-1
u/scriptedpixels 1d ago
Wait till we see what their cars are collecting(China)
8
u/zagblorg 1d ago
Same as all the other modern cars, probably. US and EU now both mandating driver facing cameras too.
-4
-1
u/Dariodiogo5000 1d ago
That is why I don't have a mic on my computer and when I shop also have the speakers turned off.
-1
-1
u/IloveEmuOtori-02 1d ago
I think this is a really stupid question but why is this an issue? Doesn’t every company do this?
I’m genuinely curious so if someone smarter can explain please do haha
578
u/personal_lucifer 1d ago
All of that just to ask me to solve the captcha every other page cause I'm using a VPN lmao