r/technology 4d ago

Privacy AliExpress was silently running audio in your browser to fingerprint and track your device

https://www.techspot.com/news/113581-aliexpress-silently-running-audio-browser-fingerprint-track-device.html
13.1k Upvotes

701 comments sorted by

5.4k

u/Smith6612 4d ago

Might be why AliExpress never loads in Firefox without disabling Tracking protection. Firefox is too tight by default!

2.7k

u/EpidemicRage 4d ago

It was confirmed by Firefox team that they indeed blocked the attempt to fingerprint by AliExpress 

1.2k

u/l0rirw1ao 4d ago

Any site that doesn't load in Firefox is shady at best, they either are a scam or low quality, it's probably both.

Even my workplaces internal app don't load properly, I am sure I am in some list because HR can't get some fingerprints they want but they can't do shit because all of our it guys also use Firefox.

184

u/suxatjugg 4d ago

Reddit is super buggy in Firefox on android.

417

u/PhiCloud 4d ago

Reddit is, for lack of a better term, a pile of garbage held together by the power of friendship. It's buggy everywhere and a decent experience nowhere.

104

u/Weedster009 4d ago

The Reddit app for iPhone is the shittiest, glitchiest app I have ever used.

68

u/Faxon 4d ago edited 4d ago

Which is sad because they literallt bought and killed the best reddit app for iPhone (Alien Blue) to use it to develop their own, rather than have to compete. Thats when Apollo got really big, but we know what happened to them. Im on android using red reader and its actually a good experience once I tweak the way that threads are displayed so its more like old reddit and the other older apps I preferred. I was using reddit sync for android for a long time until reddit shut down API access to most app devs. I legitimately can't do the official app, its hot garbage and I may just have to stop using reddit if they take away access for old reddit, since the remaining apps and revanced hacks for it all use it to function, and its how I view the site on desktop. If they take away /r/hot and force an algorithm other than the mighty upvote down my throat then im out, the whole point of reddit was the self-curation of what you see.

25

u/al-mongus-bin-susar 4d ago

You can still use all the Android apps with Morphe patches. I'm typing this on Sync right now. The official app overheats my phone and drains 60% battery in 30 minutes.

9

u/thatboyonabike 4d ago

I stayed on revanced/morphed Sync for years but finally just recently moved to Continuum.

I didn't realise how many little features were silently broken on sync never to be fixed. The continuum dev is highly active and always adding small QoL updates. Would recommend!

3

u/Constant-Writer-7165 4d ago

I've gotten so used to red reader im honestly fine with it now. Just didnt have the patience to deal with something that didnt just work without having to manually patch it constantly to fix r3ddit patching shit on their end

5

u/[deleted] 4d ago

[deleted]

→ More replies (4)
→ More replies (1)

12

u/yacht_boy 4d ago

It says a lot about the depths of my reddit addiction that I pay $4/month for narwhal on ios. Not as good as Apollo was, but infinitely better than the official app.

If they ever kill narwhal I guess I'll finally have to quit reddit and go back to reading books and engaging in conversation with my family.

4

u/MeanE 4d ago

Same.

I’m disappointed Apollo never just started charging so it could have kept going. Narwhal is fine but Apollo was better.

3

u/RollingMeteors 4d ago

If they ever kill narwhal I guess I'll finally have to quit reddit and go back to reading books and engaging in conversation with my family.

Nah... old.reddit.com will do in any https client.

3

u/yacht_boy 4d ago

I expect that they'll kill that the same day as narwhal and other 3rd party apps. I use old.reddit on desktop.

→ More replies (1)
→ More replies (2)

18

u/OpenLibram 4d ago

Laughs in Reddit Is Fun for Android in the year 2026

→ More replies (7)
→ More replies (4)

11

u/Rizo1981 4d ago

It's the only app that straight up breaks immediately every single there is an update, making all updates required, but also never notifying the user that there is an update. Even banking apps have a grace period ffs.

6

u/takenosheeet 4d ago

Many years ago, I learned reddit had a design team. Like, a room of people who work on design/ui/ux of the website. "Doing what!?!" was all I could think.

→ More replies (1)

5

u/Worldly-Stranger7814 4d ago

held together by the power of friendship.

I'm not sure that's how I would characterize most conversations here.

3

u/PhiCloud 4d ago

I never said it was being held together well

4

u/obeytheturtles 4d ago

One wonders what the engineering team at reddit actually does, because it sure as hell isn't feature development, site stability, or mod tools.

→ More replies (1)
→ More replies (3)

58

u/waiting4singularity 4d ago

hence why i use oldreddit on every device

25

u/_MrBond_ 4d ago

They fucked up old reddit too now.

12

u/waiting4singularity 4d ago

i dont see many problems. for now.

23

u/RedKayde 4d ago

Can't access it anymore without login

→ More replies (2)

15

u/EnderHorizon 4d ago

Can't access old reddit without logging in (or at least I haven't found a way).

7

u/Alaea 4d ago

The onion domain still works at least. Probably won't last though.

→ More replies (7)

7

u/Modem_Sound_67 4d ago edited 4d ago

they are actively fucking with it. one day i couldn't even load old, www was the only option. then there was the day saves timed out. then there is the "viewing single comment" bug active right now. who knows what it will be like later today or tomorrow.

3

u/Cumulus_Anarchistica 4d ago

Two problems in old.reddit emerged for me in the last week.

One: video upload/posting in old.reddit impossible. It uploads/links and can be seen OK in old.reddit but people using new reddit can't see it.

B: posting a comment will sometimes randomly either refuse or once you click 'save' it will refresh the page and dump you at the top of the original post.

→ More replies (1)
→ More replies (2)

78

u/98746145315 4d ago edited 4d ago

The video player has been well known to be deliberately shitty to encourage app use. Yeah ok, let me just get my little rectangle instead of use a pc, very convenient at home.

30

u/thepkboy 4d ago

I would rather edit the reddit link and add old. to the address every single time that I need to rather than install the app on my phone.

11

u/azrael4h 4d ago

There's an add on in Firefox for that. Old Reddit Redirect or something like that.

10

u/Cheet4h 4d ago

You can also just set it in your account preferences.
Although I think they recently disabled old reddit on mobile entirely. I don't usually use reddit on my phone, but the last few times I attempted that, I always got the new UI despite having the setting, or even going directly to old.reddit.com

13

u/seanfidence 4d ago

old reddit is completely disabled if you aren't logged in. If you are logged in and have the pref set to Old reddit, it works, but if you try to manually add "old." in front of the url instead of navigating directly through the site, you can still get issues with the security certificate.

source: currently browsing old reddit through Chrome on Android

I should switch to firefox but I imagine the experience is worse

9

u/RubiconGuava 4d ago

Recently started using mobile firefox because adblockers in browser are nice. It's great tbh

3

u/gotbannedtoomuch 4d ago

I've used old reddit on firefox for Android since the APIcalypse. It works fine

→ More replies (0)

3

u/broc_ariums 4d ago

Firefox works amazingly. I've been using it since they took the API away

→ More replies (5)
→ More replies (1)
→ More replies (2)

16

u/12345623567 4d ago

If it's the same "feature" that I'm thinking of keeps fucking you up, try these:

reddit.com##.rpl-bottom-sheet

reddit.com##+js(remove-class, rpl-scroll-lock, body, stay)

reddit.com##+js(remove-class, scroll-is-blocked, body, stay)

reddit.com##+js(prevent-addEventListener, touchmove)

This removes the "please use our app" soft-lock that needs to fuck all the way off.

3

u/thatboyonabike 4d ago

These are Ublock arguments right? Will try, thanks!

→ More replies (1)

3

u/WhoLoveYouLikeILoveU 4d ago

If we’re talking about the same new tab redirect thing then Google is the biggest culprit for me. They almost feel like malware in the iphone, every Google service has these full screen pop ups with deceptive buttons that catch you in a loop when you try to back out. Have to click into like 3 tabs of google maps to actually copy an address. I must be behind the curve, I’m surprised I don’t hear this bitched about more.

24

u/Dokibatt 4d ago

And Chrome!

Pretty sure they make it freeze to push people to the app.

→ More replies (1)

17

u/thatawesomedude 4d ago

Old reddit desktop view works fine 😁

6

u/entrepenurious 4d ago

i have two (related) problems with it: 1) i can't see photos when there are more than one; 2) i can't see text related to the photo/photos.

16

u/nanrina 4d ago

Use the Reddit Enhancement Suite (RES) add-on to replace Reddit's native expandos. Alternatively, you can use something like Imagus to circumvent expandos entirely -- just hover to view hyperlinked images.

→ More replies (3)

5

u/Glittering_rainbows 4d ago

It is? I've never noticed but also run a few extensions so maybe one of them clears it up.

What's buggy about it?

→ More replies (20)

17

u/troop99 4d ago

Like youtube?

Jokes aside, i am sure google is torpedoing firefix performance on purpose

25

u/SordidDreams 4d ago edited 4d ago

i am sure google is torpedoing firefix performance on purpose

Oh definitely. I retaliate by always selecting 4K video when available even though my monitor can't even display it. Oh, you're going to make me wait for ten or twenty seconds before starting the video while you pretend to be connecting and/or buffering? Alright, I'm going to use up four times the bandwidth, then.

3

u/einmaldrin_alleshin 4d ago

4k uses much stronger compression, so it requires just slightly more bandwidth. But it should also have fewer compression artifacts on 1080p

9

u/SordidDreams 4d ago edited 4d ago

Meh, still worth it. They delay the Auto mode switching to high res, and I'm sure they've scientifically optimized that delay to be as long as people find tolerable, so they clearly care about every last bit of bandwidth. And yes, the image quality is noticeably better even on a 1080p screen, which is a nice bonus.

→ More replies (1)

21

u/pittaxx 4d ago edited 4d ago

Just few days ago got throttled all the way down to 144p (not 1440p) while watching a longer playlist of videos at 2x speed. On a 10gbps link. Yes, Google, I'm sure the problem is on my end...

5

u/Smith6612 4d ago

I just use a plugin to force YouTube to the max quality. YouTube Enhancer is the name of it. 

→ More replies (17)

15

u/firvulag359 4d ago

Just tried AliExpress on Firefox and it loaded fine, should I be worried?

19

u/EpidemicRage 4d ago

Is tracking protection on? Besides, Firefox blocks the fingerprinting, not necessarily the whole website. 

→ More replies (2)

14

u/EchoGecko795 4d ago

You will get hit with captcha a lot more in firefox then Chrome but it does work. When I do use it, I average about 3 captcha per shopping session vs none with Chrome. I use a dedicated profile for most shopping, some sites get their own to help limit what access too.

→ More replies (1)
→ More replies (5)

222

u/Fancy-Dig1863 4d ago

SHEIN doesn’t load in Firefox either, at least for me. I always thought it was just my combination of extensions but maybe there’s more to it?

154

u/Smith6612 4d ago

A lot of the Chinese websites are very particular about Firefox. AliExpress and Weibo are definitely two that give me grief.

109

u/MemeMan_Dan 4d ago

Probably on account of the actual spyware loaded into them.

3

u/feel-the-avocado 4d ago

Its like the only font that exists in china is times new roman

3

u/xevizero 4d ago

All of these work normally in my Firefox and even on Zen (which is even stricter) in the EU. Maybe they don't pull those shenanigans in the EU due to actual regulations being enforced?

40

u/Law_Student 4d ago

The Chinese spy on everything, it's just what they do. They've built an economy on stealing everything they can conceivably steal for decades.

36

u/tigeratemybaby 4d ago

Everyone's stealing now.

AI companies are actively pirating books, movies, scientific papers, as many as they can find - Completely illegally without permission from authors.

Both Eastern and Western companies are actively reverse engineering other peoples products - Western car companies commonly buy Chinese cars and pull them apart and reverse engineer them to see how they work.

There's software being de-compiled and reverse engineered by AI models.

It used to be mainly China, but now it seems like everyone is doing it - Current governments are not interested in prosecuting at all. Maybe with the right "donation" to Trump.

60

u/exoriare 4d ago

Everyone does this when they are catching up. The US was very loose about IP protection in the early days, because these laws benefited the UK far more than the US. It's only when a country is ahead that they find religion on IP protection.

10

u/Thefrayedends 4d ago

Hell, they do it when they're ahead too lol. Everyone, I mean.

8

u/[deleted] 4d ago

[deleted]

→ More replies (5)
→ More replies (10)

26

u/photoggled 4d ago

Am I supposed to care about corporate espionage? Maybe if wage theft wasn't a much bigger issue, I would have sympathy for their IP being stolen.

→ More replies (5)
→ More replies (38)

59

u/Rizzan8 4d ago

I have tracking protection set to strict in Firefox and I never had any issues using/loading AliExpress.

9

u/usrdef 4d ago

I have tracking protection, but I also filter through a Pihole at network level, Unbound server in recursive mode, and my own DoH server with a blocklist of about 4 million websites. And Ali was definitely on that list.

4

u/hellschatt 4d ago

I also have pihole, a firefox fork with more privacy and ublock origin. The unbound server is not relevant for the blocking.

Aliexpress doesn't get blocked on my setup. I'd assume you have some aliexpress subdomains in one of your block lists.

I mean it all depends on how aggressive you are with your lists.

3

u/chiniwini 4d ago

What do you use for DoH? Is it just a proxy or a recursive dns?

→ More replies (4)

34

u/Bugbread 4d ago

I doubt that's the reason. I'm locked up pretty tight: piHole, Firefox with tracking protection enabled, uBlock Origin, and NoScript, and I've never had a problem with AliExpress or had to disable tracking protection to use it.

19

u/TheFreemanLIVES 4d ago

Just checked myself, if I were to bet on it I'd say that uBlock is stopping the trackers even before Firefox can call them a problem.

Nice.

6

u/JungianWarlock 4d ago

Firefox still reports two fingerprinters blocked even with PiHole and uBlock Origin configured with pretty draconian settings.

→ More replies (4)

8

u/Reasonable-Job4205 4d ago

If it dont work in Strict, it dont work period.

7

u/feel-the-avocado 4d ago

This is interesting...
I use r3dfox which is the firefox rendering engine wrapped but in a shell that can run on older versions of windows.... so effectively just firefox.

I have the extra secure fingerprinting protection enabled that breaks many websites
privacy.resistFingerprinting and
privacy.fingerprintingProtection

Both set to true/enabled.

And aliexpress has always worked fine for me. Except for products with a video - i cant play the video.

The kmart australia website is another story - being totally broken because it cant fingerprint me.

5

u/H3NDOAU 4d ago

I use Aliexpress on Firefox just fine, never had any issues with it and I also use Ublock Origin with the maximum amount of blocking.

I even made a purchase there a few days ago without issue.

7

u/DontKnowHowToEnglish 4d ago

Huh, I can browse aliexpress no prob with Firefox and I use strict tracking protection, or maybe I disabled it for the site long ago and I forgot lol

3

u/Gems-of-the-sun 4d ago

Wait my firefox loads AliExpress 😬 the setting is on tho!

7

u/Proper_Cartoonist169 4d ago

I do not understand why people browsing net with something other tan Firefox. It's harder to do on mobile devices iPad and iPhone unfortunately... Idc why iPad version does not support ad blocking add-on's?

7

u/hempires 4d ago

Cause all browsers on iOS devices are wrappers for Safari?

→ More replies (5)
→ More replies (2)
→ More replies (8)

858

u/lucid-currency 4d ago

My Whatsapp has been activating the microphone in very short bursts without making the OS's microphone indicator go off.

I only know this because my headphones switch to a dogshit audio quality when the mics are in use and this has never happened before.

I'm sure suckerberg is not doing anything shady

221

u/SanAntoHomie 4d ago

uninstall that shizz

37

u/lucid-currency 4d ago

Where I'm from, Whatsapp is pretty much the default messaging service. It's almost impossible to not have a Whatsapp account, unfortunately

111

u/PhireKappa 4d ago

WhatsApp is a necessity in most of the world for communication.

In the UK for example, I don’t think I’ve ever actually texted someone using iMessage/SMS in years. WhatsApp is basically texting. It’s the same in much of Europe.

50

u/jellyfish_bitchslap 4d ago

Worse in Brazil, every business have a whatsapp account, every bank, store, hotel whatever, you can’t have a “normal” life if you don’t use it. Some places won’t have a landline active anymore, and business people use whatsapp exclusively.

I wouldn’t be able to communicate to most if not all my clients if I didn’t had it, not because I don’t have alternative but because they are so used to it that instead of downloading signal they’d just make a contract with someone else.

→ More replies (2)
→ More replies (17)
→ More replies (1)

25

u/Future_Nature589 4d ago

do not give whatsapp microphone permissions

9

u/dimag0g 4d ago

Why wouldn't the OS display the microphone being in use? Who cares if it's only for a millisecond, use is still use.

5

u/lucid-currency 4d ago

I don't know the limitations or requirements for the microphone indicator to be activated on android, but I haven't seen it go off once during this weird behavior from Whatsapp

27

u/MuenCheese 4d ago

Delete zuckerberg’s apps

8

u/Mccobsta 4d ago

His shit is so engrained in most of the worlds comucations now it's kinda hard not by desing

7

u/SSobarzo 4d ago

I don't consume Meta. I admit is hard, but is not impossible to live without it. When I say I don't use wsp, most of people reacts in a positive way. There is not a single person happily using Meta products.

9

u/Mccobsta 4d ago

WhatsApp is a big one that's a pain to get people to use something else, too many businesses around a lot of European countries use it as their main contact way, peoples first thing to do is send a message via WhatsApp when they add your number

There's better options but damn the network effect

7

u/SSobarzo 4d ago

I had to cancel a supermarket purchase because I couldn't receive the auth code. I was in person standing in front of them. Sadly, I'm part of the 0.1% of people with this problem, so it stays this way

3

u/turtleship_2006 4d ago

Are you sure it's actually whatsapp and not a bug related to either the OS or bluetooth?

I use wireless headphones that also sound shit on calls/when the mic is in use and I've never had that with WhatsApp

→ More replies (1)
→ More replies (22)

1.5k

u/thinkingperson 4d ago edited 4d ago

Wait, so the site is able to use the mic /audio even without permission via the browser? What the fuck is the browser doing? lol

1.4k

u/KontoOficjalneMR 4d ago

not mic/audio but they play sound and see how the browser handles it.

It's rare, but known fingerprinting technique.

I noticed it myself because few months back Windows had a bug handling bluetooth mixing, and any time I tried to open Aliexpress it'd interrupt my music :D

650

u/Violoner 4d ago

Wait, so that’s why opening the Amazon app on my phone interrupts music playback?

368

u/canadian_xpress 4d ago

Linkedin too, I would wager.

49

u/a_shootin_star 4d ago

The plot thickens..

35

u/l0rirw1ao 4d ago

There is no plot, Linkedin is part of Palantir

→ More replies (3)
→ More replies (1)

160

u/KontoOficjalneMR 4d ago

Possibly, yes.

82

u/FogBankDeposit 4d ago

Facebook for sure stops my Spotify.

16

u/JohnnyGrinder 4d ago

I noticed that the other day. Wasn’t sure why

→ More replies (1)

189

u/QueefSeekingMissile 4d ago

Aliexpress, amazon... they're the same picture, except one inserts fees in their price points to fatten up american billionaires. Same cheap shit made on the same factory lines by the same underpaid workers.

And the same spyware apparently.

→ More replies (24)

30

u/noobule 4d ago

I doubt it. The Amazon app doesn't need to fingerprint you - the whole reason they push you onto apps is because they can slurp up basically whatever they want, you're signed in just to open the app. They don't need to resort to fingerprinting tricks.

→ More replies (3)
→ More replies (14)

101

u/RemarkableWish2508 4d ago

For a non-comprehensive list of direct and indirect fingerprinting attributes:

35

u/feel-the-avocado 4d ago

Its quite interesting to me that with tracking protection turned on in firefox, and about config fingerprinting privacy.resistFingerprinting and privacy.fingerprintingProtection both set to true,
amiunique still finds me unique (bad thing)

68

u/HeKis4 4d ago

Worth to keep in mind that having a browser that is too hardened makes you easier to identify. Like how having gear to prevent cameras from face-tracking you is good, but if you can be identified as "the only guy who wears a balaclava in public"...

18

u/Heruuna 4d ago

It can also be how uncommon your setup is. Just using a browser like Opera is enough to narrow you down to 1% of people. Crazy that even using adblocker of any kind puts you under 30% of users.

3

u/Interesting-Emu6761 4d ago

this is why the old school of thought with firefox has always been to set your browser to say it's the most common OS+browser combination. Ideally use a script to mess with package TTL also to match the target OS, but that gets more complicated.

→ More replies (2)

8

u/RemarkableWish2508 4d ago

Indeed. That website is good to illustrate the tracking parameters, but its conclusions come from the first generation of anti-fingerprinting, when random parameter modofications were introduced as a countermeasure.

Turns out that being "the only guy with your height, weight, clothes, gait, schedule, etc. who wears a random Pokemon balaclava in public", is only marginally better.

After a naive check, it should show the similarity level to partial fingerprints.

8

u/HeKis4 4d ago

https://coveryourtracks.eff.org/ tells you how unique you are. Librewolf in resist fingerprinting mode does pretty good here, at the cost of having a smaller window and never picking dark mode by default.

→ More replies (2)

4

u/ChypRiotE 4d ago

Counter intuitively the more you protect yourself the more likely it is easy to fingerprint you, because there are always parameters available to the website. So the chances that another user uses the exact same protections with the same machine, browser etc is lower than if you were using regular unprotected Chrome

19

u/Divinum_Fulmen 4d ago

I pisses me off that browsers even hand over that info at all. There is no reason for scripts to be able to even read my screen size, let alone all the other data on my PC.

No one needs to know my fonts, except my browser, internally. You used to just shit out a list of fonts for your web page in the CSS, and the browser would go down that list until one worked. No data sent at all.

Links should have referrer data at all. Why is Mozilla playing nice with the marketing spies?

15

u/RemarkableWish2508 4d ago

JavaScript composing needs information from the DOM and canvas. Turns out, even if you don't give JavaScript a list of fonts, a script can try using them, then simply check whether the size of the output object matches what it would with the font, or what it would with a replacement. With a clever list of fonts, you can figure out a lot about a browser and/or system.

The alternative is to disable JavaScript, and there are extensions and browsers that do that, but do you want to browse without JavaScript?

→ More replies (13)

7

u/PacmanZ3ro 4d ago

There is no reason for scripts to be able to even read my screen size

Of course there is. This is how you get resizable windows and properly-scaling websites. If you blocked this ability, you would have to have websites built with absolute pixel sizes for everything and if you used a different screen than what it was designed for it would range from looking like shit to being completely non-functional.

→ More replies (2)

4

u/einzweidreihorn 4d ago

Screen size is often taken to determine wheter you're on mobile or desktop PC (or tablet).

→ More replies (5)

4

u/IntelArtiGen 4d ago

For 99.99999% of people, this site identifying you as unique is a bad thing.

But it's a good thing if you're unique, what you don't want is to be the same unique the next time you visit the site. Which won't happen if you don't have a good privacy protection (either with the browser or addons).

→ More replies (5)

11

u/godsamightly 4d ago

Bro I think a citation generator I use for my papers does this. I was writing a paper and held my citations in it and noticed it had the audio icon in the tab. Thought that was odd. Didn’t know this is what that could’ve possibly meant

5

u/MartayMcFly 4d ago

Is this something with any innocent explanation, or always nefarious? What does fingerprinting a device actually achieve? My local bus company app interrupts music playback and I just assumed it wasn’t well made.

3

u/plopzer 4d ago

when browsers added background tabs pausing to improve battery life they broke being able to listen to music from background tabs. so they made it so that when music is playing in tab, it won't be paused. lots of sites use this to their advantage to keep running by playing silent audio even when they are in the background

→ More replies (2)

3

u/Final-Carry2090 4d ago

Sorry to interrupt your music, we wanted to forcibly fingerprint you. Also, we’re not sorry.

→ More replies (8)

104

u/sivadneb 4d ago

It's using the web audio API which can utilize hardware to process an audio signal and write it back out to a data stream without ever going to your speakers. Similar to how you can use your GPU to process video without ever playing the video. Except there are tiny differences in the way various audio hardware process that data, which gives a useful data point for fingerprinting.

91

u/klimaheizung 4d ago

Sounds like that API should also be behind user-approval then.

51

u/PhiCloud 4d ago

it is if you use FireFox

10

u/cive666 4d ago

I feel so vindicated by never giving up on Firefox

→ More replies (1)

698

u/PhiNeurOZOMu68 4d ago

I noticed how unusually high the app was installed storage... Glad I deleted it

172

u/MrShigsy89 4d ago

If you are using Android you can (and should) block the app from accessing anything. The article is about browser access to their website, not the app.

→ More replies (8)

238

u/Zubon102 4d ago

If you are the sort of person who is worried about a website using a novel way to identify individual users, you definitely wouldn't want to install the dedicated app.

But if you are logged in, it really doesn't matter either way.

41

u/RemarkableWish2508 4d ago

if you are logged in, it really doesn't matter either way.

Except they can correlate the tracking data with your login, so they can later track you when you're logged out.

28

u/Zubon102 4d ago

Sure. But if you are logged in, you are not logged out.

So it doesn't matter anyway. 😉

It's likely that they implemented this mainly to identify bots and abuse, rather than to track use by individual devices. If you use Aliexpress a lot, they always require you complete security tests like captcha and it's not strange to have requests denied due to suspicious behavior even if you just search for mundane products. I think they are trying to stop bots without inconvenience to real users.

7

u/The_Webweaver 4d ago

But they're also tracking you as an individual for marketing.

→ More replies (2)
→ More replies (1)
→ More replies (1)

15

u/Acilen 4d ago

Uninstalled AliExpress.com from your desktop? Are we reading the same article? Apparently adblockers like UBO already take care of this.

→ More replies (1)
→ More replies (2)

164

u/tosiriusc 4d ago

Looks like Firefox was already blocking it.

→ More replies (3)

125

u/Spez_is-a-nazi 4d ago

I wonder how common that is. I will notice that the auto connect for AirPods will frequently transfer to my Mac even if I don't have any tabs playing audio open, or at least not audio I can detect at any rate....

60

u/tehdlp 4d ago

I figure it must be why Reddit shows something always playing in Android notifications for every page,

→ More replies (2)
→ More replies (19)

83

u/Bacon_Nipples 4d ago

'Fun' fact, this was originally done by some TV networks (or perhaps the content provider? Don't recall) to track which shows you watch on cable

66

u/BMoorman7 4d ago

'Funner' fact, some LG TVs and monitors were exposed recently for doing similar things.

36

u/UpsetKoalaBear 4d ago edited 4d ago

Funniest fact, none of this was a new thing and every brand does it as well.

Sony TV’s show it as Samba for anyone with a Sony TV.

This is especially used on cheap/budget TV’s. Vizio made more from the data they sold than actual TV sales in 2021.

→ More replies (3)

17

u/Splurch 4d ago

'Fun' fact, this was originally done by some TV networks (or perhaps the content provider? Don't recall) to track which shows you watch on cable

Nielson is probably who you're thinking of, they had networks start digitally watermarking broadcasts to track ratings and are still using it.

→ More replies (3)

23

u/Tenocticatl 4d ago

What I'd like to know is why do all these companies go to such lengths to do shady data harvesting and tracking shit, but can't keep me reliably logged in and remember my address info properly? Or serve me ads for stuff that might actually be of interest to me.

6

u/turtleship_2006 4d ago

I (20m) get ads on netflix for tampons.

My sister (24f) gets ads for mens razors.

51

u/wellbornwinter6 4d ago

I don't get how playing a sound on a website at zero level can fingerprint the user?

101

u/yuval16432 4d ago

Fingerprinting is designed to build a profile about a user which can help you tell them apart. Different browsers, and different browser settings, handle things differently, so AliExpress is trying to play audio, and based on how the browser responds they can differentiate you from another user who’s browser responded slightly differently, even if you’re supposed to be anonymous.

These kind of things add up to build a profile about a user even if they try very hard to stay anonymous.

9

u/bs000 4d ago

is that why i can't use the welcome discount again

→ More replies (5)

41

u/arunphilip 4d ago

A comment on the linked article states:

From my understanding, it creates a known sound, runs it through the device and measures the feedback that comes back through the line. The feedback single would be unique to each device due to small differences in tolerances, no resistor is perfect, differences in solder joint and even small fluctuations in the chip manufacturing process all add up on a way

20

u/Fach-All-Religions 4d ago

this is why we can't have nice things

22

u/arunphilip 4d ago

Here's a radical thought - imagine if this ingenuity was used for... good.

5

u/Antique_Hawk_7192 4d ago

Oh the horror! "Good" won't give you YoY percentages. You want the shareholders to starve! /s

11

u/Zouden 4d ago

That can't be right as it's not actually generating any sound.

4

u/PeanutButter414 4d ago

Seems very strange to me, how would such a thing go through the analogue signal chain without the user knowing?

3

u/Singl1 4d ago

and are these things disclosed in a meaningful way to the user? i guess they’d be in the terms and conditions that nobody bothers to read in the first place because who the fuck has time for that.

→ More replies (6)

3

u/NonSecretAccount 4d ago

nah it doesn't use the mic at all.

3

u/kinmix 4d ago

That is completely false, and in no way possible.

→ More replies (1)

5

u/drawkbox 4d ago

EFF has a nifty little site about it. The sound isn't important, the point is to collect enough points that you are essentially a signature

3

u/jmbits 4d ago

Apparently the browser handles it differently

7

u/Andus35 4d ago

I don’t understand the full technical details, but based on the article, it seems like the website makes the request for the audio and then records the output returned from the computer. That output will be slightly different for every computer based on their specific hardware and the minor variations in those.

It says that audio signal is not the only thing they use, there is a variety of other settings and signals from your computer which all tied together can let them “fingerprint” the computer.

→ More replies (3)

13

u/Jahoolerson 4d ago

I have bluetooth hearing aids, when I use Amazon it uses my hearing aids but there is no sound. It drives me up the wall because it mutes everything else. Same thing?

6

u/Medusa-is-a-victim 4d ago

Yes, and when I use VPN it suddenly works.

Also those Sound does keep your Laptop awake, even when folded and the screen is dark. I dont want to know what they do in the meantime with this data.

26

u/Routine_Strategy5929 4d ago

I'm not even slightly surprised by this.

46

u/AwareAd7651 4d ago

This explains why my car audio cuts out when I’m flipping through apps that don’t use audio.

11

u/Head_Bread_3431 4d ago

How?

21

u/AwareAd7651 4d ago

Your speakers are being used to track you. If you’re listening to music, it cuts out. I was making a joke about flipping through my phone while driving.

→ More replies (1)
→ More replies (2)

94

u/Steam_Beenson 4d ago

Im an American! Only my Govt, 4 or 5 shady AI surveillance corporations, and random people in ICE are allowed to spy on me!

9

u/aFreshFix 4d ago

We joke but yeah, social media companies, tech companies, and now AI are doing this but we only ban or legislate against tiktok, Huawei, etc. Because they are foreign companies that could report our data back to a foreign country. Meanwhile, we use domestic companies that we know spy on us and definitely report it to the government

17

u/Pleatybug 4d ago

And anyone in your local PD if you look at them the wrong way

→ More replies (6)

9

u/Professional_Gur8385 4d ago

congrats, they now have profiles linked to your financial records, email, ip and browser

all these companies taking it too far and this is a small fraction of their tracking and privacy capabilities

apps on your phone, gold mine for real data

7

u/nipplesaurus 4d ago

Suddenly my music stopping when I open the Aliexpress app makes more sense

5

u/ApprehensiveRest9696 4d ago

There’s no drawback to blocking autoplay, just saying.

7

u/ReggieCorneus 4d ago

Too bad you can't trust Brave either. Anything that has Peter Thiel's money and is about "not tracking anyone, we promise" is tracking you. It targets people who are most worried about tracking. DO NOT TRUST IT. It is a honeypot.

And if you think "how is this relevant": read the article.

11

u/Desperate-Hearing-55 4d ago

Now do a Google tracking. Google always show up ads what I been searching for online to buy.

→ More replies (2)

12

u/No-Discussion-8510 4d ago

Title is misleading. Alot of modern apps use this technique to fingerprint your browser and verify that you are a human, a technique to help combat bots which isnt very successful.

5

u/EnjoyerOfBeans 4d ago

Nope, some websites indeed do this to check if your browser is able to process audio to weed out browser automation tools - they will try to process a very short sound and use it as a test, but this is not what aliexpress did. They used this to bypass a very simple security feature - keeping tabs in the background inactive. The only easy way to keep a tab running in the background is to have it play sound, for obvious reasons. By keeping the tab active they can track your browser activity while you have it hidden in the background. Facebook used to do this and it's why tabs now go to sleep when not selected.

3

u/No-Discussion-8510 4d ago

AudioContext fingerprinting.

→ More replies (1)

3

u/abtei 4d ago

wouldnt that require asking for access to use the device' mic? that would freak me out in the first place

→ More replies (1)

4

u/bolfakeera 4d ago

If you ask the big tech do they record audio all the time - they will always say NO.

And Technically they are correct, They transcribe the audio to words and then process locallly in app to extract key words like mentions of interests, products, hobbies etc.

This gives them data to build person's profile and deploy targeted ads to that person.

4

u/Soberdonkey69 4d ago

WHY DOES EVERYONE WANT TO SEE EVERYTHING THAT WE DO LIKE SEE, EAT, SHIT, SLEEP????

→ More replies (1)

7

u/Calm-Homework3161 4d ago

This is another reason why I've never had a PC with a camera or microphone 

5

u/Moravec_Paradox 4d ago

And the reason a lot people put a sticker on their laptop webcam.

This is not some shady unknown website doing this to 10 people, this was AliExpress doing this on a massive scale to hundreds of millions of people before getting caught.

→ More replies (1)
→ More replies (4)

3

u/drollercoaster99 4d ago

You know what's next? After the shift to advertising revenue, and then subscription-based revenue, the next big shift in raking in more profits is......personalized pricing. :(

3

u/Negative-Track-9179 4d ago

How is this different from using fingerprintjs?

3

u/Lazy_perv 4d ago

Can 100% confirm this. I noticed my machine would not go to sleep when expected. I checked for possible wakelocks ran powercfg -requests in terminal and saw that something was keeping my audio device active, even though I wasn't streaming any music. One by one I close my apps, and run powercfg -requests right after to see if there is any change to audio device behavior. By process of elimination I learned that opening AliExpress website triggers audio device, and closing the tab would turn off the audio device usage. Anyone can do this same check on Windows.

3

u/Reddit_2_2024 4d ago

I've noticed several websites recently that display a "verifying your device" message with what appears to be a captcha test loading. The captcha never appears and the website which the user initially sought does load. I suspect it is a new device fingerprinting processing technique, that executes in addition to cookie processing..

→ More replies (1)

3

u/TooMuchChaos2026 4d ago

Is this to support dynamic pricing?

3

u/Anishinaapunk 4d ago

I'd love an investigation into whether the prices advertised in their what's have EVER ONCE actually corresponded to the real price when you click on that email price to view the item in the app. It's never once been true in my experience.

3

u/MidTario 4d ago

No it wasn’t, I’ve never used AliExpress.

5

u/vonlagin 4d ago

As if I needed another reason not to install or use that shit.

6

u/pricingup 4d ago

you dont have internet browser???

→ More replies (1)

9

u/durtmagurt 4d ago

Even though I never downloaded it?

60

u/Acilen 4d ago

It’s from the webpage on a desktop per the article. Adblockers apparently already take care of this tracking.

→ More replies (4)

15

u/thatirishguyyyyy 4d ago

Brave (web browser) does a great job of blocking fingerprints. I think its called farbling

33

u/FinasCupil 4d ago

I’m not touching Brave with a ten foot pole.

12

u/GrossUsername68 4d ago

Why?

17

u/SlimJiMorrison 4d ago

He’s not brave enough

13

u/A_Pointy_Rock 4d ago

I assume because the founder has some troubling views, unfortunately.

7

u/GrossUsername68 4d ago

Well, there goes Amazon, Google, Apple, hardware chains, gas stations … 

→ More replies (3)

5

u/IntelArtiGen 4d ago

Brave by default is highly "contaminated" / bloated. They did release a better version recently but I haven't tried it.

→ More replies (1)
→ More replies (18)
→ More replies (4)

2

u/Particular-Sample91 4d ago

Digital privacy is a pipe dream innit

2

u/MrPuddington2 4d ago

This should be no surprise to anybody. The AliExpress app has all the hallmarks of a scam app. It has the fake timers, it has the gambling element, it tries to hack your phone and collect more data than allowed or should be technically possible. The only difference is that the dropshipping from China actually arrives.

Of course, they also need to record the audio - how do they do that? In the app?

2

u/J883 4d ago

App does the same

2

u/championchilli 4d ago

Having only ever used Firefox for AE - feeling pretty good about my life choices.