Live data from Hacker News

AliExpress runs silent WebAudio fingerprinting that breaks Bluetooth multipoint

blog.laserphile.com

51–60 of 349 posts

Re: AliExpress runs silent WebAudio fingerprinting that breaks Bluetooth multipoint

#51
Ah, so that's what Wolt (Doordash but in Europe) is doing.

I noticed that Voice Over (iOS screen reader) crackles and randomly changes volume when using the app, but I attributed it to standard iOS weirdness, and possibly misuse of some iOS API. Now I'm thinking that this may very well be fingerprinting.

Re: AliExpress runs silent WebAudio fingerprinting that breaks Bluetooth multipoint

#53
post #14

Earlier quoted context omitted.

It's known that some Chinese mobile apps employ this trick to keep the app alive in the background, the rumor is that this way the 'active user' KPI can be better met. edit: quantity qualifier

If it's known, are you suggesting that Apple and Google are complacent in allowing these type of apps in their ecosystem?

I wouldn't think of giant organizations like Apple and Google as mere individuals that can exercise human emotions such as complacency.

Re: AliExpress runs silent WebAudio fingerprinting that breaks Bluetooth multipoint

#54
post #48
post #45

Earlier quoted context omitted.

AE website on mobile is terrible, they basically force you to use the app. I exclusively use the website on my PC

So they're pulling a Reddit, basically. "The app is great because the website is heavily degraded".

I just request the desktop site, it's fine

Re: AliExpress runs silent WebAudio fingerprinting that breaks Bluetooth multipoint

#55

Earlier quoted context omitted.

It's great for shopping. But in the US you have amazon prime. We don't.

I have Prime, but I can't imagine installing the Amazon app either. The website works just fine.

With Firefox, yes. I wouldn't fully trust other browsers to care about my privacy.

Re: AliExpress runs silent WebAudio fingerprinting that breaks Bluetooth multipoint

#56
post #2

Recently I ran into a problem with my Bluetooth headphones. They support multipoint bluetooth audio, so they can be connected to my PC and phone at the same time. Opening the Aliexpress webpage causes a silent audio stream keeping the PC>headphone link active blocking my phone audio. An investigation reveals obfuscated code running device fingerprinting with a side effect being a silent audio stream that firefox, chr…

Is this an AI summary of the article?

No, I took the first sentence of my article and then edited the rest of the intro + conclusion to keep it short for HN.

Re: AliExpress runs silent WebAudio fingerprinting that breaks Bluetooth multipoint

#58

Earlier quoted context omitted.

It's great for shopping. But in the US you have amazon prime. We don't.

I have Prime, but I can't imagine installing the Amazon app either. The website works just fine.

I think you need the app to use the delivery lockers (which I prefer over home delivery)

Re: AliExpress runs silent WebAudio fingerprinting that breaks Bluetooth multipoint

#59
With my previous hearing aid I noticed that visiting a wide variety of web sites would cause a change in the amplification of environmental noise. I always assumed it was doing something with Bluetooth, and probably not for a good reason. This is with an iPhone 13 and one Kirkland/phonak hearing aid.

I haven’t noticed this recently, but I also now have two newer Phonak hearing aids and a few iOS updates have happened. Maybe the silent Bluetooth shenanigans are less disruptive to my new aids or the programming is different. Surely shenanigans continue.

Re: AliExpress runs silent WebAudio fingerprinting that breaks Bluetooth multipoint

#60
Need to rethink the system that allows for (and encourages) this kind of plausible deniability. From "Oh we need this permission for [non essential feature] and you need to accept it if you want the app at all" -> to giving the user ultimate control over what happens on their personal device. Virtualize what the app can see and use fake data/identifiers/devices if necessary to get it to do what its supposed to. If the App isn't going to act in good faith why should the user? Fine grained permissions don't really work in practice because the app can keep annoying the user until they give in and hit Allow.
Post reply on HN