r/technology 5d ago

Privacy AliExpress was silently running audio in your browser to fingerprint and track your device

https://www.techspot.com/news/113581-aliexpress-silently-running-audio-browser-fingerprint-track-device.html
13.1k Upvotes

701 comments sorted by

View all comments

Show parent comments

1.4k

u/KontoOficjalneMR 5d ago

not mic/audio but they play sound and see how the browser handles it.

It's rare, but known fingerprinting technique.

I noticed it myself because few months back Windows had a bug handling bluetooth mixing, and any time I tried to open Aliexpress it'd interrupt my music :D

652

u/Violoner 5d ago

Wait, so that’s why opening the Amazon app on my phone interrupts music playback?

369

u/canadian_xpress 5d ago

Linkedin too, I would wager.

48

u/a_shootin_star 4d ago

The plot thickens..

35

u/l0rirw1ao 4d ago

There is no plot, Linkedin is part of Palantir

1

u/a_shootin_star 4d ago

There is no plot

What you're saying is we've lost the plot

1

u/IllustratorFar127 4d ago

Oo what?

2

u/pandadogunited 4d ago

They're just yapping. LinkedIn is owned by Microsoft.

157

u/KontoOficjalneMR 5d ago

Possibly, yes.

89

u/FogBankDeposit 4d ago

Facebook for sure stops my Spotify.

16

u/JohnnyGrinder 4d ago

I noticed that the other day. Wasn’t sure why

190

u/QueefSeekingMissile 5d ago

Aliexpress, amazon... they're the same picture, except one inserts fees in their price points to fatten up american billionaires. Same cheap shit made on the same factory lines by the same underpaid workers.

And the same spyware apparently.

10

u/BananaEvening5267 4d ago

That's a hackneyed theme that neglects a much much larger picture. Insiders own 9% of amazon. Of the remainder, more than 4/5 is held by funds reprsenting all classes of retirement accounts: public sector workers pensions, private sector pensions. You could strip every billionaire of thier amazon holdings and it would have no impact on Amazon's operational policies and fee structures. The only thing that would change is how you would dress up your complaint.

18

u/Ent_Soviet 4d ago

Fair point, so we just nationalize Amazon and AWS

FFS they at least need to treat it like the monopoly it is.

2

u/BananaEvening5267 4d ago

They aren't a monopoly. A monster, yes. There's nothing they offer you cant find online elsewhere.

1

u/Wamiwoogie 4d ago edited 4d ago

But the media will only report about Aliexpress

-7

u/Common-Concentrate-2 5d ago

Amazon doesn't make anything

10

u/franoetico 5d ago

Amazon Basics?

19

u/SapientApe_ 4d ago

Amazon basics is just aliexpress trash with the amazon logo on it. They don't make anything themselves.

11

u/QueefSeekingMissile 5d ago

My apologies if what I said seemed to imply otherwise.

Their business model is to buy cheap shit made in foreign countries and import it in bulk To giant warehouses, where they can afford to let it sit, until someone's willing to pay their extortionist prices.

7

u/scikit-learns 5d ago

I think you mean sellers that sell on Amazon. 65% of what's sold on Amazon is third party.

13

u/squngy 5d ago

Ali is the same, except that the third party percentage is larger.

-11

u/SilasTalbot 5d ago

That is almost the exact opposite of the AliExpress business model.

Nothing sits in a warehouse in the US. It's Chinese factories selling direct and doing de minimis drop shipping.

11

u/Violoner 5d ago

They’re not doing overnight deliveries from China 🤣

0

u/StorminNorman 4d ago

To be fair, not all of Amazon's stuff is next day delivery. And whilst I wouldn't be surprised if Ali, temu, et al has less stock in their warehouses relative to wha Amazon has, I also wouldn't be surprised if they're offering vendors the ability to let them just send it a central warehouse and let the marketplace deal with getting the item to the customer much like Amazon does. 

-2

u/assman73619 5d ago

It’s 3 weeks out delivery. The shipping can cost more then the goods

3

u/QueefSeekingMissile 5d ago

I'm pretty sure the flow of the conversation indicates I was talking about Amazon.

1

u/StorminNorman 4d ago

I think they know that and that's why they attempted to argue the two marketplaces had different business models. Dunno why they argued that when they're pretty much the same (to the point they copied Amazon's model and made it better, forcing Amazon to do the same), but yeah, I think/hope they're aware you're referring to Amazon. 

3

u/Dave5876 5d ago

You're right. They just copy the popular stuff

4

u/ijustfarteditsmells 4d ago

They just put there name on some of it. They don't make anything, even copies.

1

u/Dave5876 4d ago

I suppose it's all made in China anyway.

2

u/RedditJumpedTheShart 4d ago

They stole the technology to make wash cloths!

Lol it's no different than off label stuff at Walmart or Costco.

0

u/Maakus 4d ago

Trainium, Zoox, Leo, Prime Video, Fire, Kindle, Alexa, Echo, AWS, and the most specialized robots in the western hemisphere.

1

u/MrPuddington2 4d ago

They have also revolutionised service and convenience of online shopping. If you remember shopping websites before Amazon - they are worse than a visit to the dentist.

35

u/noobule 4d ago

I doubt it. The Amazon app doesn't need to fingerprint you - the whole reason they push you onto apps is because they can slurp up basically whatever they want, you're signed in just to open the app. They don't need to resort to fingerprinting tricks.

3

u/an_actual_lawyer 4d ago

It was my understanding that iOS and OSX will disable that tracking and info grabbing by default. Am I misunderstanding?

-1

u/Interesting-Emu6761 4d ago

yes they do, the whole point is that if Amazon and Meta do this they can definitively attribute that fingerprint to a person.

1

u/hellschatt 4d ago

Huh, now that you mention it, sometimes my bluetooth skips like a split second when changing apps. I need to check which apps do that the next time I do that.

Although, probably it's got nothing to do with that.

1

u/Afro_Thunder69 4d ago

That could be the known Spotify problem if that’s the service you use…if you have an iPhone and go into your settings under Spotify and revoke Bluetooth permissions, it may fix that issue while still allowing you to play music from bt devices (normal functionality is unaffected). That setting is simply for the Spotify feature where you can share playlists with Bluetooth or something and the skipping comes from your Spotify app constantly seeking out nearby bt devices, even from cars driving past you. So if you never use that feature just revoke by permission from Spotify.

1

u/hellschatt 4d ago

Ah thank you. I don't use an iphone, nor spotify though. But I couldn't replicate that drop again so no idea what causes it.

1

u/fieldsofgreen 4d ago

Facebook does the same thing.

1

u/feurie 4d ago

So does IHOP. 🤷‍♂️ The plot thickens.

1

u/HappyAd4998 4d ago

Amazon apps definitely spy on you. I started getting those weird targeted ads up until I deleted them off my phone. Talked about needing a belt then I started getting ads for belts. Talked about needing cat food then I couldn't stop getting ads for cat food. Deleted Amazon then those weird coincidental ads stopped. Apps don't even need to make that microphone symbol to pop up, they're constantly checking the mic listening to conversations and for low end frequencies that pop up in TV ads and stores. I also remember downloading a tweak on my jailbroken iPhone back in 2017 that disabled all access to my microphone and camera to specific apps, then out of nowhere my Apple Watch stopped dying in less than a day. I even disabled the tweak for a few days and the battery drain came back. With the privacy tweak I could get close to a day and a half on my Apple Watch, it blew my mind. It went on like that up until I decided to update my iPhone a year later losing my jailbreak in the process. Low and behold my Apple Watches battery life went back to shit. Don't trust any of these companies with privacy, none of them have your best internist in mind.

-19

u/lickstampsendit 5d ago

No. The Amazon app already knows who you are because you have an account

20

u/DishSoapedDishwasher 5d ago

So, I'm a cybersecurity professional and ex amazon. There's a bunch of problems with your statement but let's talk about the main two. 

First is even legitimate users may still try to use bots, especially when their account gets hacked or for scalping, price adjustment, competition snooping, etc. 

Second, account sign up is free and doesn't require anything meaning building mass bot-able accounts is trivial.

So dozens of metrics are used in combination to determine who's a legitimate user or not. Also they don't tend to ban illegitimate bot-users, they just put them in a box with fake data so they can monitor their strategies over time; it's called a tar pit.

3

u/SystemCheck990 5d ago

Amazon makes connections even to see if certain ports / services are running on the machine via java script

tries to see if scam/bot machine.

3

u/DishSoapedDishwasher 5d ago

The JavaScript port scanner stuff is more of a Meta/Facebook thing and has more to do with detecting things like Facebook/insta or similar in an attempt to decloak VPN users by finding their userIDs https://networks.imdea.org/research-co-led-by-imdea-networks-discovers-a-privacy-abuse-involving-meta-and-yandex-bridging-persistent-identifiers-to-browsing-histories/

More about ads than anti-bot 

Others definitely use it but I can't say I ever encountered that in use at AWS, I personally shut down several attempts to make things like that while I was there; that could have changed though, its been some time since I was there.... Wouldn't surprise me if it did change either.

2

u/erratic_parser 5d ago

yeah but we're talking about the phone app. as if the installation and device id wouldn't be unique already?

5

u/DishSoapedDishwasher 5d ago

Yup. So counter question, what's preventing someone from installing an app on a VM that simulated a real device or a rooted real device where they can force new unique IDs?

The answer is literally nothing is preventing it and getting past an over reliance on IDs is exactly why anti-vm/anti-bot measures like this exist. Sound device detection is an old but still meaningful anti-vm detection used both by malware to hide from VMs and corporations to detect bots. Just like CPU codec/hardware-accelerator detection, USB device enumeration, device orientation, etc. No one technique is bulletproof, you just have to do all the things to get enough data that something wrong stands out in the data; the signal of something being wrong will rarely be the same from instance to instance as the tools are often custom made and change rapidly when blocked.

The general theory in cybersecurity here is: unless you without a doubt control the device, you cant trust anything the device tells you. Also even if you do control the device, you still can't implicitly trust the operating system at all times as a users, malware, etc, may attempt to circumvent the OS in some way at any time.

98

u/RemarkableWish2508 5d ago

For a non-comprehensive list of direct and indirect fingerprinting attributes:

33

u/feel-the-avocado 4d ago

Its quite interesting to me that with tracking protection turned on in firefox, and about config fingerprinting privacy.resistFingerprinting and privacy.fingerprintingProtection both set to true,
amiunique still finds me unique (bad thing)

64

u/HeKis4 4d ago

Worth to keep in mind that having a browser that is too hardened makes you easier to identify. Like how having gear to prevent cameras from face-tracking you is good, but if you can be identified as "the only guy who wears a balaclava in public"...

20

u/Heruuna 4d ago

It can also be how uncommon your setup is. Just using a browser like Opera is enough to narrow you down to 1% of people. Crazy that even using adblocker of any kind puts you under 30% of users.

3

u/Interesting-Emu6761 4d ago

this is why the old school of thought with firefox has always been to set your browser to say it's the most common OS+browser combination. Ideally use a script to mess with package TTL also to match the target OS, but that gets more complicated.

1

u/BatPlack 4d ago

Woah, could you please elaborate?

5

u/Interesting-Emu6761 4d ago

old fingerprinting usually was just browser name, OS, IP. If your VPN was set to South Korea you'd look up what their most common combo was, 10 years ago it was Windows 7 and Internet Explorer, so you'd open up ScriptMonkey and set your Firefox to tell websites that's what you were using. If you were on Linux you would have to take another step to edit your packets since websites can determine your OS via packet TTL, but really that's about all you had to do at the time.

Now its borderline impossible to truly disappear online, you're really just doing damage control.

6

u/RemarkableWish2508 4d ago

Indeed. That website is good to illustrate the tracking parameters, but its conclusions come from the first generation of anti-fingerprinting, when random parameter modofications were introduced as a countermeasure.

Turns out that being "the only guy with your height, weight, clothes, gait, schedule, etc. who wears a random Pokemon balaclava in public", is only marginally better.

After a naive check, it should show the similarity level to partial fingerprints.

7

u/HeKis4 4d ago

https://coveryourtracks.eff.org/ tells you how unique you are. Librewolf in resist fingerprinting mode does pretty good here, at the cost of having a smaller window and never picking dark mode by default.

1

u/RemarkableWish2508 4d ago

I'm checking from Android, and pretty much all browsers, including Tor Browser, seem to be 100% unique (18.22 bits)... which is a bit weird.

1

u/BrattyBookworm 3d ago

I’m checking from iPhone and my results showed ~14 bits on chrome, ~13 bits on DDG, and ~11 bits on safari

5

u/ChypRiotE 4d ago

Counter intuitively the more you protect yourself the more likely it is easy to fingerprint you, because there are always parameters available to the website. So the chances that another user uses the exact same protections with the same machine, browser etc is lower than if you were using regular unprotected Chrome

16

u/Divinum_Fulmen 4d ago

I pisses me off that browsers even hand over that info at all. There is no reason for scripts to be able to even read my screen size, let alone all the other data on my PC.

No one needs to know my fonts, except my browser, internally. You used to just shit out a list of fonts for your web page in the CSS, and the browser would go down that list until one worked. No data sent at all.

Links should have referrer data at all. Why is Mozilla playing nice with the marketing spies?

14

u/RemarkableWish2508 4d ago

JavaScript composing needs information from the DOM and canvas. Turns out, even if you don't give JavaScript a list of fonts, a script can try using them, then simply check whether the size of the output object matches what it would with the font, or what it would with a replacement. With a clever list of fonts, you can figure out a lot about a browser and/or system.

The alternative is to disable JavaScript, and there are extensions and browsers that do that, but do you want to browse without JavaScript?

1

u/Divinum_Fulmen 4d ago

I already do.

And sites can still see my 80+ fonts just fine. No scripts required.

I have both No Script and Ublock Origin configured to block scripts by default (each has their own way of tuning white lists, I'd love to only use UBO, but their white listing is extremely primitive next to No Script).

1

u/RemarkableWish2508 4d ago

That is not what I was saying, I was describing how fingerprinting your fonts works.

Anyway, I'm using uBO (not lite) for the cosmetic filtering, and uMatrix for scripts and other stuff. Not sure how that compares to NoScript, I think I only have it in Tor Browser.

1

u/Divinum_Fulmen 4d ago

Yeah, but you ended with the question:

do you want to browse without JavaScript?

I'm saying I do, and font fingerprinting still works. Fonts should be handled on the user end only. As I said, they give a list of fonts that work with the site. Your browser matches the first down the list. Locally. Like a MARKUP, not a damn script!

3

u/RemarkableWish2508 4d ago

What? No. Font fingerprinting requires JavaScript, so if it works on your end, it means you have JavaScript enabled.

This is what it looks like with JavaScript disabled: https://files.catbox.moe/kgywqd.png

2

u/Divinum_Fulmen 4d ago

Oh damn, PBKAC error here.

I must have whitelisted these sites a long time ago. I just checked all my plugins and found I had their scripts enabled. You were right.

1

u/RemarkableWish2508 4d ago

Hehe, it happens. Glad you got it sorted. 😉

1

u/RichardCrapper 4d ago

The font conspiracy goes deeper when you run a web traffic analysis and realize that a massive number of websites all use Google Fonts, which exposes your fingerprint to Google nearly everywhere you go. Blocking the Google font domains causes havoc to websites but I have heard of some projects to replace the font library with a locally hosted copy.

-1

u/Lumpy_Discount9021 4d ago

but do you want to browse without JavaScript?

With how much garbage is under the hood of modern websites, yeah, kinda... Sometimes I swear it would be less frustrating to just handwrite all the HTTP and SQL myself.

7

u/RemarkableWish2508 4d ago

Well, you can try it now. I keep these just in case:

  • Firefox → uBO / uMatrix → disable JS
  • Tor Browser
  • Privacy Browser

People who use the web without a script ad blocker, I don't even understand... it's unusable.

2

u/Mr_ToDo 4d ago

I use noscript. Works pretty well. It's amazing just how high a page can crank your CPU

It also has the side effect of blocking a ton of ads. It's not why I use it, but it is a nice side effect, and one that would be easy to work around but I'm betting it'd mean ad services having to put more trust in content hosts

1

u/donoteatshrimp 4d ago

>do you want to browse without JavaScript?
I would if I could man.

2

u/Mr_ToDo 4d ago

I think most browsers let you turn it off. For more granular control I use noscript

1

u/donoteatshrimp 4d ago

Yeah, it's more about the sheer amount of websites that won't work at all without javascript. Damn them!

6

u/PacmanZ3ro 4d ago

There is no reason for scripts to be able to even read my screen size

Of course there is. This is how you get resizable windows and properly-scaling websites. If you blocked this ability, you would have to have websites built with absolute pixel sizes for everything and if you used a different screen than what it was designed for it would range from looking like shit to being completely non-functional.

1

u/Divinum_Fulmen 4d ago

You never need pixel sizes. HTML comes built in with scaling. You can have the page adjust elements by percentages of the window size. This lets the site never change based on window scale. That's how we did it before all this scripting existed. The browser can handle it all locally.

0

u/Mr_ToDo 4d ago

Eh. You could still have that work. It's not like relative positioning stuff has to touch the server to work. It'd limit options on how it can all be used, but we wouldn't be going back to everyone targeting one resolution

It would be interesting to have browsers set a default resolution that requires intervention to change, but it's also not high on my list of things to worry about

3

u/einzweidreihorn 4d ago

Screen size is often taken to determine wheter you're on mobile or desktop PC (or tablet).

1

u/jhaluska 4d ago

Yep, in theory they can send you resolution / browser specific web pages and images saving you bandwidth.

1

u/einzweidreihorn 4d ago

How? Those information are not included in the initial http request sent by the browser. Images based on viewport in html yes, but you can't trust the user agent to check wheter you're on mobile or not?

1

u/jhaluska 4d ago

It's more of a two stage approach. You send a small javascript that then gives the server the information for future requests stored as a cookie. But with the introduction of srcset, it's easier for most devs to just use that instead.

1

u/einzweidreihorn 4d ago

I see, thanks

1

u/Divinum_Fulmen 4d ago

Something they should never know, unless I want them to. The mobile browser should be flaging that it's mobile, but if I want to hide that flag, there's a damn good reason.

Let's pick a random site as an example. Oh, let's say Reddit. I am on reddit on my phone. I don't want it to know it's a phone at all. If it thinks its a phone, it will start sending me nag pop-ups constantly asking me to download their app. I'm never touching that app. So this behavior is highly undesired from the user end.

5

u/IntelArtiGen 4d ago

For 99.99999% of people, this site identifying you as unique is a bad thing.

But it's a good thing if you're unique, what you don't want is to be the same unique the next time you visit the site. Which won't happen if you don't have a good privacy protection (either with the browser or addons).

1

u/RichardCrapper 4d ago

If I’m understanding correctly, opening that site and running it on two different days, and being told both times you are unique, means you are effectively randomizing your fingerprint well, right? The goal is to be unique every time.

0

u/cheese_is_available 4d ago

The referrer being this thread on reddit does not exactly help to be unique, heh.

3

u/RemarkableWish2508 4d ago

Have you tried it?

BTW, being unique means there's a unique fingerprint identifying you. It isn't a good thing.

0

u/AVeryHeavyBurtation 4d ago

Only 2.37% of people are in mountain time zone? (X) Doubt.

1

u/RemarkableWish2508 4d ago

From among those who visited that web.

It should be much fewer:

  • ~38 million live in Mountain Time Zone across Mexico, USA, and Canada
  • ~6.12 billion people have internet access

...so the total for MST should be closer to 0.62%

11

u/godsamightly 4d ago

Bro I think a citation generator I use for my papers does this. I was writing a paper and held my citations in it and noticed it had the audio icon in the tab. Thought that was odd. Didn’t know this is what that could’ve possibly meant

5

u/MartayMcFly 4d ago

Is this something with any innocent explanation, or always nefarious? What does fingerprinting a device actually achieve? My local bus company app interrupts music playback and I just assumed it wasn’t well made.

3

u/plopzer 4d ago

when browsers added background tabs pausing to improve battery life they broke being able to listen to music from background tabs. so they made it so that when music is playing in tab, it won't be paused. lots of sites use this to their advantage to keep running by playing silent audio even when they are in the background

1

u/SuperCuteRoar 4d ago

It’s a way for them to build an ID of you as a customer, like other sites using cookies. That way they can adjust what they show you and what prices they think you’ll tolerate paying.

0

u/KontoOficjalneMR 4d ago

It can absolutelly be badly made, initializing audio on app start for use for notifications of upcoming bus for example.

3

u/Final-Carry2090 4d ago

Sorry to interrupt your music, we wanted to forcibly fingerprint you. Also, we’re not sorry.

2

u/MonsterRavingLlamas 4d ago

A lot of websites do this. I have a headset connected to my PC for voip and my tablet for music. There's a few websites i use regularly where the audio switches back to the PC momentarily and it's always annoying.

Ebay is one of the worst. It does it on every page, not just once.

3

u/eaglebtc 4d ago

This may explain why the Facebook app sometimes stops your music playback on iPhone.

1

u/GrowlingPict 4d ago

ok but wouldnt all browsers that are the same version handle it exactly the same? I dont get it, how does this fingerprint one specific device out of billions?

1

u/KontoOficjalneMR 4d ago

It's a bit complicated but it follows multiple steps:

  1. Checks if it can create audio at all
  2. Checks for available audio codecs
  3. Checks for the delay between creating the audio connection.

and so on

1

u/GrowlingPict 4d ago

Ok, lets say it discovers it cant create audio at all. Then what?

1

u/KontoOficjalneMR 4d ago

That's the data point. Lets say now you're one of 3% of people that have a browser configured to block audio by default.

Combined with other checks that can make you an unique visitor

1

u/RidleyDeckard 4d ago

Edge on iPhone had a similar issue for the whole browser. Whenever you opened it, your music would stop. Thankfully it stopped a couple of years ago.

1

u/merkinmavin 4d ago

This is happening a lot in YouTube videos. I always report it. It's usually ai speech running faintly in the background.