Live data from Hacker News

AliExpress runs silent WebAudio fingerprinting that breaks Bluetooth multipoint

blog.laserphile.com

111–120 of 348 posts

Re: AliExpress runs silent WebAudio fingerprinting that breaks Bluetooth multipoint

#111

Earlier quoted context omitted.

I'm an app developer and all my apps have the "Data Not Collected" privacy nutrition label. I love the idea, but Apple's enforcement of it is very lackadaisical. I've reported dozens of apps that were blatantly lying on their privacy nutrition labels to Apple and I'm yet to see any such app's nutrition label change. Here's a good overview of the problem: https://arxiv.org/abs/2206.02658v3

Why have rules (or laws) if they don’t enforce them? Or only enforce them selectively when they feel it necessary, such as when not doing so would threaten your stock price (or re-election campaign)? Maybe I just answered my own question? Reminds me of meat processing regulations. I can sell my animals whole to buyers through a custom processing exemption, but they must go pick up their meat from the butcher. The law…

The cynical way to look at this is that the purpose of the system (the privacy nutrition label) is to support Apple's carefully-crafted and -marketed image as the most privacy-focused of the tech giants. Actually having enforcement of the contents of said labels would be a nice potential byproduct of that, but that's not strictly required to accomplish the system's purpose.

Re: AliExpress runs silent WebAudio fingerprinting that breaks Bluetooth multipoint

#112
post #56

Earlier quoted context omitted.

No, I took the first sentence of my article and then edited the rest of the intro + conclusion to keep it short for HN.

You should make that obvious in some way like using “TLDR”. I assume many people, like me, would attempt to parse your comment as a comment on the article, after all it’s in the comment section, and read that way it’s very confusing lol.

Sorry, this is my first post to HN and in the submission it looked like the description text i added would be part of the post header.

Re: AliExpress runs silent WebAudio fingerprinting that breaks Bluetooth multipoint

#113
post #96

Earlier quoted context omitted.

Not sure if they still do, but a couple years ago prices in the app were lower than on the website. And they promoted installing it to save money.

And someone would install random apps to save $5 on $100 purchases?

[deleted]

Re: AliExpress runs silent WebAudio fingerprinting that breaks Bluetooth multipoint

#114
post #9

Earlier quoted context omitted.

I cannot ever imagine installing something like AliExpress as an app.

Not sure if they still do, but a couple years ago prices in the app were lower than on the website. And they promoted installing it to save money.

It's still the case that you pay less in the app. You get 'coins' for a daily check-in, which are automatically(?) applied as a discount. Most items either don't actually use them or only give you a pointless 1% off or something, but I've gotten a $12 microcontroller for $5, for example. I think some coupons are app-only, too (though most aliexpress sales are fake and are better thought of as the normal price).

Re: AliExpress runs silent WebAudio fingerprinting that breaks Bluetooth multipoint

#115
post #85

Earlier quoted context omitted.

>Obviously apps can tell if they haven't been granted a permission By design. This doesn’t need to be the case. It should be impossible to tell you have denied a permission. In TFA’s case, the browser could just keep processing audio but never hook it up to a real audio sink.

That does nothing but start an arms race. Fine, audio "works" but do you get noise? Can you read back the sounds you play? No, right? It doesn't work, QED. Now the platform needs to fake the noise. Likewise for any other hardware access you want, and most of them are harder. How do you fake local storage without storing anything? How do you fake Bluetooth access without virtualizing an entire device? Do you fake the…

The best you can do on the modern web is reduce your fingerprint footprint, though it comes at a cost of websites breaking from JS disabling, or local time zone anonymisation.

Re: AliExpress runs silent WebAudio fingerprinting that breaks Bluetooth multipoint

#116
post #19

OP please submit the filter to an upstream uBlock filter list.

Will do! edit - How do i do this? through github issues? https://github.com/uBlockOrigin/uAssets/issues

They said they aren't interested

Re: AliExpress runs silent WebAudio fingerprinting that breaks Bluetooth multipoint

#117
post #82

So Apple will remove them from the App Store. Thats their whole argument for their closed system - they’ll protect users from malicious apps. Right?

it's not the app that it's malicious, it's the website

It's both, according to another comment.

Re: AliExpress runs silent WebAudio fingerprinting that breaks Bluetooth multipoint

#118
post #9

Earlier quoted context omitted.

I cannot ever imagine installing something like AliExpress as an app.

Not sure if they still do, but a couple years ago prices in the app were lower than on the website. And they promoted installing it to save money.

They also don't give you a proper tracking number. The only way to track your shipment is in the app.

Re: AliExpress runs silent WebAudio fingerprinting that breaks Bluetooth multipoint

#119
post #91

I thought the App Store review guidelines explicitly prohibit hidden features and using public APIs outside their intended purpose. Is audio-based fingerprinting just not something review can realistically catch?

It's the website. The title of the article literally mentions "WebAudio", and the first paragraph states that the author is using a PC. The second paragraph mentions Chrome and Firefox. Apple and the App Store have zero involvement here.

This is a huge stretch, but if this problem exists in not only the PC versions of Chrome/Firefox but also the Android/iOS versions, then theoretically the app store reviewers could flag the browsers for facilitating this behavior against app store guidelines. In practice, apps of such caliber as popular browsers might be a bit above such reviewers' pay grade, so to speak.

Re: AliExpress runs silent WebAudio fingerprinting that breaks Bluetooth multipoint

#120
post #9

Earlier quoted context omitted.

I cannot ever imagine installing something like AliExpress as an app.

You probably buy things off amazon that are dropshipped from AliExpress all the time. Stop with the elitism

I can't imagine ever wanting to install an amazon app either. Both of these stores have perfectly functional websites. What would I gain installing their spyware? Also, why so defensive?
Post reply on HN