AliExpress runs silent WebAudio fingerprinting that breaks Bluetooth multipoint
blog.laserphile.com715 points by emctech 9 hours ago
715 points by emctech 9 hours ago
I wish such shenanigans would simply trigger the little speaker icon most browser display on tabs these days.
Given that they don't (at least in my experience), I'm assuming "playing silent audio" is a sufficiently common thing for websites to do to have motivated browsers into doing the slightly more complicated thing of actually analyzing audio streams for content...
Now I wonder, does this also allow websites to continue running in the background on mobile browsers? Playing media is one of the very few things that can convince iOS Safari to keep a tab running indefinitely, in my experience.
Recently I have been getting a request from chrome for access to local network devices. I can’t figure out which site I’m visiting is doing this, because the request doesn’t specify which tab. I would LOVE a little icon for something like that.
Any chance it was a macOS prompt? Chrome needs local network permissions for WebRTC, Cast etc. even without any website accessing your local network.
Chrome says "this site", no? Isn't it the tab you have in focus?
I wonder what kind of person says 'Yes' to this prompt. It gives me the heebie jeebies.
Yeah, that’s always an automatic nope. No explanation of who/what is really asking or why so, no: your shit software or website can’t go snooping around on whatever network I happen to be on, whether that’s at home or at work.
I wonder if it is something firefox and chrome devs need to look at because if it is accessing the audio device surely it should be notified to the user.
As I mentioned, I suspect that this is an active choice, as just displaying the icon whenever a media context exists seems much easier than inspecting the audio stream for non-zero volume media.
I can only assume that there are legitimate reasons for this as well, e.g. websites preparing/maintaining audio context for lower latency when they intermittently play audio etc.
Someone else mentioned that cloudflare uses the webaudio for verification challenge, but only triggers it briefly.
Ugh... Seems like we need an audio API web permission, or maybe do something like browser already do for some of the other APIs and actually require API users to actually play something or display a warning/play an annoying chime otherwise.
It does on my Firefox, I had to close their tab because it also tricks kde into thinking I'm playing audio.
Thaaaaaaat explains why an open Aliexpress tab always bumps my thermals ever so slightly.
It should instead trigger a little germ icon, like a virus, because it's like a virus.
It's insane that browsers just hand over API access to my microphone and/or camera to rando web developers. Yes, I know things like Zoom exist. IMO software like that simply shouldn't be possible on browsers, period.
Making the browser into a general purpose system SDK was a mistake--maybe the biggest mistake in personal computing's history.
I do not have the Zoom app in any form installed. I'd much rather use it in the browser. When I close the tab, Zoom is gone. After the COVID era bullshit of Zoom installing a utility that gives root access to anything, I've never installed it. Luckily, all of that came out before I started using Zoom.
This issue is about audio output. Audio and video input are both behind per-site permissions.
Also, people can and should go to the firefox settings > Permissions and data > Autoplay and change the Default for all websites to "Block Audio" (at least).
You can set per-hostname exceptions if you like! CTRL + I > Permissions
> You can set per-hostname exceptions if you like! CTRL + I > Permissions
1. Thank you, that's very nice to know about.
2. I really wish this was exposed more directly, probably from the permissions button that is already in the address bar. I can't believe Chrome does this better.
The speaker icon would be handy but I think that it depends from both the good will of Firefox and the installed add ons. Of course if an add on blocks the audio file there is no need to display the speaker icon for that file.
To give you the idea of what is going on, this is what uMatrix shows about www.aliexpress.com in my Firefox browser on my laptop. It would be more difficult to copy and paste from uMatrix on my Android phone. It shows a number of sites. Nothing in first party and these that I must fully enable to make the site work (css, image, script, xhr)
* aliexpress.com
* ase.aliexpress.com
* it.aliexpress.com (my country two letters domain)
* umdc-global.aliexpress.com
* aidcgroup.net
* ase.aidcgroup.net
* 67372.ase.aidcgroup.net
* alibaba-inc.com
* epss.alibaba-inc.com
* alicdn.com
* ae01.alicdn.com
* assets.alicdn.com
* aliexpress-media.com
* ae-pic-a1.aliexpress-media.com
* assets.aliexpress-media.com
* aliyun.com
* acjs.aliyun.com
Scary list, right? According to google aidcroup is
> Alibaba International IPP Platform
> Alibaba International is committed to the protection of intellectual property rights. Right holders and their agents can enforce intellectual property ...
Let me add a /s to the last line
There are two more sites that I can completely block
* googlesyndication.com
* pagead2.googlesyndication.com
so even Alibaba runs ads on Google.
I did not instrument the browser like the author of the post did, so I don't know where the audio comes from. There is nothing listed in the media column of uMatrix. This does not mean that the post is inaccurate. It could be that the browser gets the audio stream from a request in one of the other categories.
uBlockOrigin blocks two of other requests.
1. https://g.alicdn.com/code/npm/@ali/gmod-pop-disclosure-code/...
and this one that I anonymize
2. https://aplus.aliexpress.com/g.gif?logtype=0&title=WebPush Permission&pre=https://it.aliexpress.com/?gatewayAdapt=glo2ita&scr=1920x1080&_p_url=https://it.aliexpress.com/wp.html&cna=<whatever cna is>&category=&aplus=&$${beacon_mini}$$=&yunid=&=&trid=<trid>&asid=<base64 stuff>$${get_sign}$$&p=1&o=linux&b=firefox153&s=1920x1080&w=gecko&ism=other&cache=<7 letters>&lver=8.15.25&jsver=aplus_std&pver=0.7.12&_pw=0&_ph=0&tag=1&stag=-1&lstag=-1&_slog=0
Probably the audio file is coming from one of the unblocked requests but my Debian laptop does not pair with my Bluetooth earpieces so I can't test it.
It doesn't actually stream an audio file, the scripts generate audio at runtime using a sawtooth oscillator. It also only happens after several seconds.
Thanks. So one of the downloaded scripts is generating the audio and the browser should detect it.
I wish the browser would classify the fingerprinting and not load the site and show a security risk warning like it does for http sites. Then Advanced > Accept risk to continue.
@FireFoxDudes You need to be addressing fingerprinting
How? How would a browser "know" what classifies as finger printing? Literally every piece of the engine is used for finger printing.
It can be mitigated, a bit, but I don't see how browsers can win that battle.
Finger printing is a lost battle in my opinion, unless we drastically reduce what a web engine can do (like Tor does).
I feel like there are two levels of fingerprinting here, and a lot of the confusion is downstream of not properly distinguishing them:
There's the kind that tries to find out what browser vendor, OS, and sometimes hardware you use, and the kind that tries to identify you across visits, unrelated origins etc.
I agree that the former is probably inherently impossible to avoid to a large extent, but the latter is both a bigger privacy issue and at least in theory possible to prevent.
I've only encountered the latter described as fingerprinting. Which makes sense side, like fingerprints, the information is being used to uniquely identify an individual.
The former is traditional analytics and is not enough to uniquely identify an individual.
Not all analytics are as privacy invasive as fingerprinting.
With my previous hearing aid I noticed that visiting a wide variety of web sites would cause a change in the amplification of environmental noise. I always assumed it was doing something with Bluetooth, and probably not for a good reason. This is with an iPhone 13 and one Kirkland/phonak hearing aid.
I haven’t noticed this recently, but I also now have two newer Phonak hearing aids and a few iOS updates have happened. Maybe the silent Bluetooth shenanigans are less disruptive to my new aids or the programming is different. Surely shenanigans continue.
It's the Bluetooth; when Bluetooth connects most hearing aids reduce the environmental volume slightly so you can hear the streaming content. Some app has started to play audio (perhaps silently). I notice it on some websites.
How much HAs reduce environmental sounds when streaming is configurable by the way, but only by the audiologist if you don't have your own programmer. I don't like the effect and prefer to just turn down the volume manually.
Is this tunable per hearing program? When in an even moderately noisy environment I find myself switching to AirPods if I’m streaming. I would love for the HA to give separate controls for BT audio vs ambient like AirPods do.
I wear Phonak CI processors. It's not just you. I've also experienced the volume drop on a few sites and apps. The Amazon iOS app does this. Each time I leave the app, ambient audio returns to normal.
They’re kindly turning down the background noise so you can focus on shopping and buying more stuff.
It'd be interesting to see what a lawyer specializing in disability law would think of that.
At least in the US, I could see that being something that the ADA prohibits.
I noticed my MBP had a periodic stutter sometimes: every 3 seconds or so the mouse would lock up for a few milliseconds.
I tracked it down to American Express's login page (auto loads if you leave the site idle) relying on Akamai's anti bot measures polling some web Bluetooth feature, causing Chrome to trigger a BT scan: https://castle.io/research/fingerprint-harvesting-in-the-bot...
Turning off Bluetooth solves it, but that's not a great solution when using a Bluetooth mouse... and it sounds like it might be causing your issue too.
It seems far more likely that your cheap hearing aids are sensitive to certain RF frequencies and the background javascript is causing different patterns of load on the phone's CPU.
I would suspect that this only happens when you're charging and it is likely the charger or cable not being properly shielded.
The cheap hearing aid cost $750 for one and is substantially the same as the same thing sold from standalone audiologists for much more. These are not cheap over the counter devices.
Charging only happens while in the cradle, not while worn.
I noticed in the last few weeks that if I’d recently opened the AliExpress iOS app (ie. it was backgrounded) my car audio would freak out thinking I was giving it an audio command. Killing the AliExpress app immediately fixed the problem. After seeing it happen more than once I assumed it was something dodgey and uninstalled the app.
I cannot ever imagine installing something like AliExpress as an app.
Not sure if they still do, but a couple years ago prices in the app were lower than on the website. And they promoted installing it to save money.
I believe the prices are the same. But the app has a number of "games" to collect tokens that get credited as discounts. Seems to be mostly stuff designed to get you to open the app daily and browse their offers. Which might be "innocent" if it's just to get you to buy more stuff, or maybe they have more reasons they want you to have the app open. Who knows
At least Aliexpress doesn't have all the fake slot machine type games that temu has that always end in variations of "get $200 of discounts for your next order if you order x items from this list"
There are few things more scammy than AliExpress “discounts”. I have yet to see a cent of the hundreds of dollars of “savings” they gave or advertised to me.
Very true, I almost never use Ali Express because I have no clue what anything is going to cost until I get to roughly the final step of checking out.
They also don't give you a proper tracking number. The only way to track your shipment is in the app.
This is not correct. I do not have the app and get tracking for my orders.
I get email updates but whenever I click the track link it tells me I need the app.
I have a package on the way with AliExpress. It is headed from somewhere in China to somewhere in the US.
Using my computer just now, I looked at one of the emails that AliExpress sent about this order. It had a clickable tracking number displayed; I clicked it.
That brought me to their website, where I landed on a page that included the last update for my order and also a link to "View Details".
That works for me. It was very easy to where along the line my stuff is (and that it is not in the US yet).
---
Meanwhile: I also copied the tracking number from the email. I pasted that tracking number into the box at usps.com.
The USPS knows of my tracking number and they do not have my item yet. Fair enough.
I ticked some boxes and told them to send me updates, which I'm sure they'll do once they have updates to send -- just as they have done for ~decades now.
This also works for me.
Many sites will work fine in a desktop browser but refuse to do anything in a mobile browser, demanding you install their app or just immediately redirecting you to the iOS or Android app store.
It does show a popup to that effect, but if you dismiss it you can still see the tracking info. Definitely annoying, but not unworkable.
If on mobile, ticking "desktop mode" in your browser usually goes around that dark pattern.
You just have to press the right link on the site and you get the tracking page (despite saying you need the app).
Depends on the shipping company, and likely on your location. I get tracking numbers for most but not all shipments
And someone would install random apps to save $5 on $100 purchases?
When I did customer tech support for a major retailer, we had confused customers calling all the time because they would randomly get price-match refunds they never asked for. They were installing apps that were automatically requesting the refunds by searching their emails for orders and checking the prices on the websites. These people had no idea they had even given these apps permission to read their emails.
eBay keeps pushing their app with a $5 discount, advertised using a focus-stealing popup interrupting your attempt to give them money, so some people must be taking the bait.
It's still the case that you pay less in the app. You get 'coins' for a daily check-in, which are automatically(?) applied as a discount. Most items either don't actually use them or only give you a pointless 1% off or something, but I've gotten a $12 microcontroller for $5, for example. I think some coupons are app-only, too (though most aliexpress sales are fake and are better thought of as the normal price).
You pay less money in the app.
Companies are not going to hire a mobile dev team to create an app to give you a way to pay them less for a good.
They hire a mobile dev team to create an app to give you a way to hand over data that you otherwise wouldn't, is technically impossible to do through a web browser, and is worth more than the discount that they give you for using the app.
>You get 'coins' for a daily check-in, which are automatically(?) applied as a discount.
This should be illegal
> Not sure if they still do, but a couple years ago prices in app were lower than on the website. And they promoted installing it to save money.
Translation: They are able to mine your personal data more completely with an app installed vs the website which they can sell for pure profit. They promoted installing it to extract more value from you.
That's definitely a feasible explanation (and the one I would assume to be true for AliExpress).
But there is another, slightly less evil, explanation that I know at least some companies have pushed their apps because of: the thinking is that if you're on their website, there is less friction to open a new tab and search for a lower price from their competitors, than if you're in their app. Obviously it's hardly any different - opening a new app (the web browser) vs. opening a new tab in the app you're already in - but the theory is that there's a slight psychological difference.
Of course I'm not saying that trying to prevent your customers from searching for better deals is a nice thing to do. Just adding that data mining isn't the only reason for some companies to want people to use their apps.
It's quickly getting to the point for me that "find the thing I want locally and buy online if it's cheaper" is reversing. I've actually been to one of the few remaining electronics retailers to look for a PC for my kid recently, and it was nice not to be assailed by dark patterns (yes, there are dark patterns in b&m retail, but they're much more obvious).
It also all goes to the party, who are the owners of Alibaba (and every other company in China).
Should you ever need someone in a foreign country to do something for you, it's good to have as much information as possible at your disposal about them.
Absolutely crazy the amount of dodgy apps people install and giving permissions to read the system when asked...
Yesterday on here, somebody was demo'ing a sun clock website that asks for your position.......
....and yes, many HN'ers were clearly happy to give there precise GNSS coordinates to some random scrote who askes for them.
A lot of people install TikTok. Or Instagram.
Or Claude/etc on their personal computers and then even live dangerously.
It's great for shopping. But in the US you have amazon prime. We don't.
I have Prime, but I can't imagine installing the Amazon app either. The website works just fine.
This is the way. It's prudent to treat apps with skepticism, it's unfortunate it's come to this.
I study Apple's Privacy Nutrition Labels religiously every time I consider installing an app.
I like the ones with "Data Not Collected".
I'm an app developer and all my apps have the "Data Not Collected" privacy nutrition label. I love the idea, but Apple's enforcement of it is very lackadaisical. I've reported dozens of apps that were blatantly lying on their privacy nutrition labels to Apple and I'm yet to see any such app's nutrition label change.
Here's a good overview of the problem: https://arxiv.org/abs/2206.02658v3
Why have rules (or laws) if they don’t enforce them? Or only enforce them selectively when they feel it necessary, such as when not doing so would threaten your stock price (or re-election campaign)? Maybe I just answered my own question?
Reminds me of meat processing regulations. I can sell my animals whole to buyers through a custom processing exemption, but they must go pick up their meat from the butcher. The law says I cannot pick up and deliver it, but it is trivial to find people advertising that extra service. Reporting them does not result in any obvious action.
In both of our cases, our honesty is a liability in the marketplace, because people are ignorant of such laws (or simply don’t care). Really, they simply want the product that they want, as conveniently as possible. We are then forced to compete in the marketplace with liars and cheats.
I am sure our peers here can find countless examples in other areas where this flavor of dishonesty prevails. Hell, I would love to hear some counter examples, because I cannot help but view this state of affairs as intentional at this point.
The purpose of system is what it does (or, in this case, does not do).
The cynical way to look at this is that the purpose of the system (the privacy nutrition label) is to support Apple's carefully-crafted and -marketed image as the most privacy-focused of the tech giants. Actually having enforcement of the contents of said labels would be a nice potential byproduct of that, but that's not strictly required to accomplish the system's purpose.
Shopping works better on web sites because can open multiple tabs to browse multiple products. Especially important on big stores like Aliexpress and Amazon where need to compare lots of products. Desktop is better for that but mobile browsers are still better than apps.
I uninstalled the app recently; despite having layers of ad tracking protection, I would see my Amazon searches appearing in my social media feed in near real time, and this irked me.
I dropped their .com into a Home Screen icon, and this completely stopped (at least as far as I’ve observed). It’s definitely more janky from an experience perspective, but still easier than driving to the store.
With Firefox, yes. I wouldn't fully trust other browsers to care about my privacy.
Using web apps on Firefox really is the way given its support for uBlock Origin.
Screen real estate is precious on phones, so being able to permanently block "Install our app!" and even entire navigation categories (shorts on LinkedIn) is quite valuable.
Then you can "install" the site on your home screen or simply place it in collection folders so it's sitting ready on your "New Tab" page.
I think you need the app to use the delivery lockers (which I prefer over home delivery)
I don't have Amazon Prime (nor am I in the US) yet use Aliexpress perfectly fine on my mobile phone without using an app. Frankly, I don't understand how the two is related at all?
AliExpress won't allow me to open most pages in the account section on my iPhone. Instead I get a page telling me to install the app.
While browsing, there are also popups offering the app approximately every third link I click. Some of them are telling me to install the app.
Unless the situation has changed recently, it's not perfectly fine, it is unusable on purpose.
AE website on mobile is terrible, they basically force you to use the app. I exclusively use the website on my PC
So they're pulling a Reddit, basically.
"The app is great because the website is heavily degraded".
Reddit is fine, just a small popup at the bottom. Facebook kn the other hand turned off most functions on mobile, e.g. chat. Good thing though if you don't use the chat long enough, friends start using other means of communication.
Reddit is NOT FINE. They throw up full page modals now telling you to continue in the app.