AliExpress was silently running audio in your browser to fingerprint and track your device

https://www.techspot.com/news/113581-aliexpress-silently-running-audio-browser-fingerprint-track-device.html

274 points · 32 comments · view on lemmy.world

32 Comments

SkaveRat@discuss.tchncs.de · 156 pts · 11d (1 reply)

As this is basically a PR campaign for Brave, here's your reminder to stop using that software:

https://www.spacebar.news/stop-using-brave-browser/

itsjustachairmary@lemmy.world · 35 pts · 11d

No doubt the takeaway from the article is supposed to be 'just use Brave' instead of 'don't fucking use AliExpress'

El_Scapacabra@lemmy.zip · 68 pts · 11d (3 replies)

Is that why any tab (on Firefox) with aliexpress opened on it seems to always be showing that little loudspeaker icon at the top? There are a lot of products that have videos showcasing the product so at first I assumed it had something to do with that, but then I noticed it happens on products that only have photos, too.

SkaveRat@discuss.tchncs.de · 28 pts · 11d (1 reply)

yup

evenglow@lemmy.world · 19 pts · 10d

In that case it's by no means just one site doing this.

ragas@lemmy.ml · 6 pts · 10d

That happens?

I guess it is blocked on my system.

Olap@lemmy.world · 33 pts · 11d (10 replies)

Firefox wouldn't let this happen btw. Just use firefox peoples

pHr34kY@lemmy.world · 29 pts · 11d (8 replies)

The original report showed this exploit occurred with Firefox too.

Sixseven@sh.itjust.works · 7 pts · 11d (2 replies)

Even with uBlock origin?

pHr34kY@lemmy.world · 11 pts · 10d

Yup. The author included custom uBO rules to block it.

Hadriscus@jlai.lu · 3 pts · 11d

even with uMatrix ?

zecg@lemmy.world · 2 pts · 11d

Oh no, I guess it's le shill lion from now on

Olap@lemmy.world · 1 pts · 10d

Old firefox. Removed this fingerprinting some time ago now

paraphrand@lemmy.world · 0 pts · 11d (2 replies)

Safari is slow to add features, did it work there too?

4am@lemmy.zip · 20 pts · 10d (1 reply)

Why yes; Safari did add the ability for a web page to play audio on January 7th, 2003

paraphrand@lemmy.world · 1 pts · 10d

I thought this was about a Bluetooth devices API though.

nymnympseudonym@piefed.social · 8 pts · 11d

LibreWolf

orphigle@lemmy.ml · 24 pts · 10d

They've been doing this for a very long time, and I was forced to stop using their website as a result. Nothing new here. If you're on Firefox, you can use an addon called JShelter to alert you when fingerprinting is taking place (and optionally block it).

drmoose@lemmy.world · 18 pts · 10d (5 replies)

I did some js reverse engineering work on chinese websites few years ago and it's legit industry leading tracking tech. Very few websites in the west are even remotely as sophisticated in that regard.

Unsurprisingly China has the best tracking ecosystem but it's not for the reasons you might think. It's just so competitive in China that tracking and automation blocking is super important for chinese businesses.

Have you noticed that there's no such thing like internet archive in China? It's because nobody wants it. It's too dangerous to have recorded history of any sort.

WhyJiffie@sh.itjust.works · 5 pts · 10d (2 replies)

nobody? you mean, not even the common people? what are the dangers they see?

minfapper@piefed.social · 4 pts · 10d

The CCP disagreeing with your version of recorded history, probably.

drmoose@lemmy.world · 3 pts · 10d

Business dangers from scraping / automation are basically of two types:

  • archival record for proof mostly for legal prosecution and contract negotiation. There's a lot of really bad shit going on on Chinese web despite the great firewall of China and you can hide it in plain sight if it's ephemeral. So if I sell illegal goods but it's not archived ever no one can really prosecute me. Gray/black markets players in China just rebrand every month and get away with everything.
  • real time data for price/trend competition. Prices and trends move incredibly fast in China, people in the west don't even understand how far ahead chinese e-commerce is, Amazon is like 10 years behind. So all that scraped info is incredibly valuable for chasing capitalism.
KarnaSubarna@lemmy.ml · 1 pts · 10d (1 reply)

Will it be possible for you to share your findings?

drmoose@lemmy.world · 1 pts · 10d

I don't think we've discovered anything particularly niche that isn't public knowledge today. Since Fable-line of LLMs dropped deobfuscating and reverse engineering web and phone apps is very approachable. Github is full of resources and you can start with something like cloakbrowser

None of fingerprint tech is illegal in any way so it's a free for all and every browser except Brave (which yeah I know sucks) does basically nothing to fix this.

antonim@lemmy.world · 8 pts · 11d

Cartoon villains envy their creativity.

A_norny_mousse@piefed.zip · 5 pts · 11d

The very few times I had to open AliExpress and give it wide permissions because otherwise it simply refuses to show anything - I always felt dirty afterwards.

CyroSignal@lemmy.world · -1 pts · 10d (1 reply)

It doesn't matter, I've never bought anything there.

floofloof@lemmy.ca · 3 pts · 10d

Well, that's a relief to all of us, I'm sure.

Visstix@lemmy.world · -34 pts · 11d (3 replies)

No it didn't.

4am@lemmy.zip · 21 pts · 10d (2 replies)

Oh thanks for the correction, the whole world was wrong but you saved us bro, how can we ever thank you

Visstix@lemmy.world · -14 pts · 10d (1 reply)

Yeah I have never been on that site.

IAmYouButYouDontKnowYet@reddthat.com · 9 pts · 10d

Oooh!