I noticed in the last few weeks that if I’d recently opened the AliExpress iOS app (ie. it was backgrounded) my car audio would freak out thinking I was giving it an audio command. Killing the AliExpress app immediately fixed the problem. After seeing it happen more than once I assumed it was something dodgey and uninstalled the app.
I cannot ever imagine installing something like AliExpress as an app.
AliExpress runs silent WebAudio fingerprinting that breaks Bluetooth multipoint
21–30 of 347 posts
Re: AliExpress runs silent WebAudio fingerprinting that breaks Bluetooth multipoint
#22Earlier quoted context omitted.
Yes, I find it concerning too. I particularly dislike that windows was not aware, nor could it stop the audio stream from effecting the hardware. What other side channels like that exist? Perhaps I can be blamed for using windows
> Perhaps I can be blamed for using windows That would be unreasonable, I argue. No one should have to worry about the security of their devices and data privacy based on which OS they use. Whilst it can be argued that different OSs serve different needs, privacy and security should not be debatable. In fact, most countries have dedicated legislation for this; whether it's just, applied correctly, or serves the publi…
Re: AliExpress runs silent WebAudio fingerprinting that breaks Bluetooth multipoint
#23Re: AliExpress runs silent WebAudio fingerprinting that breaks Bluetooth multipoint
#24JS enabled by default seems every day less secure.
So many website break completely with JS disabled and you end up having to enable it half the time anyway.
Re: AliExpress runs silent WebAudio fingerprinting that breaks Bluetooth multipoint
#25Re: AliExpress runs silent WebAudio fingerprinting that breaks Bluetooth multipoint
#26Re: AliExpress runs silent WebAudio fingerprinting that breaks Bluetooth multipoint
#27Browser fingerprinting can get creative at times, to say the least. eBay's WebSocket port scanner [1] and Reddit's abuse of DRM and JavaScript JIT exploits [2] from years ago are two examples of the kind of in-depth introspection you can perform completely in the background using nothing more than simple non-permission-gated APIs. [1] https://blog.nem.ec/2020/05/24/ebay-port-scanning/ [2] https://iter.ca/post/reddit-…
Re: AliExpress runs silent WebAudio fingerprinting that breaks Bluetooth multipoint
#28JS enabled by default seems every day less secure.
Re: AliExpress runs silent WebAudio fingerprinting that breaks Bluetooth multipoint
#29Re: AliExpress runs silent WebAudio fingerprinting that breaks Bluetooth multipoint
#30Earlier quoted context omitted.
I cannot ever imagine installing something like AliExpress as an app.
It's great for shopping. But in the US you have amazon prime. We don't.