I wish such shenanigans would simply trigger the little speaker icon most browser display on tabs these days.
Given that they don't (at least in my experience), I'm assuming "playing silent audio" is a sufficiently common thing for websites to do to have motivated browsers into doing the slightly more complicated thing of actually analyzing audio streams for content...
Now I wonder, does this also allow websites to continue running in the background on mobile browsers? Playing media is one of the very few things that can convince iOS Safari to keep a tab running indefinitely, in my experience.
show comments
mgerdts
With my previous hearing aid I noticed that visiting a wide variety of web sites would cause a change in the amplification of environmental noise. I always assumed it was doing something with Bluetooth, and probably not for a good reason. This is with an iPhone 13 and one Kirkland/phonak hearing aid.
I haven’t noticed this recently, but I also now have two newer Phonak hearing aids and a few iOS updates have happened. Maybe the silent Bluetooth shenanigans are less disruptive to my new aids or the programming is different. Surely shenanigans continue.
show comments
corentin88
Getting the same issue when opening Stripe Dashboard.
patspam
I noticed in the last few weeks that if I’d recently opened the AliExpress iOS app (ie. it was backgrounded) my car audio would freak out thinking I was giving it an audio command. Killing the AliExpress app immediately fixed the problem. After seeing it happen more than once I assumed it was something dodgey and uninstalled the app.
show comments
forestry
So Apple will remove them from the App Store. Thats their whole argument for their closed system - they’ll protect users from malicious apps. Right?
show comments
nazgulsenpai
> screen and viewport dimensions
I remember trying I think it was the Tor browser, being puzzled at why the viewable area of the window constantly changed when resized but would never occupy the full window.
I feel a little silly now.
tomrittervg
WebAudio fingerprinting is largely mitigated (in Firefox, potentially other browsers) - I wrote a quick overview that talks about the current distribution of values as well as our more recent efforts. https://ritter.vg/blog-webaudio_alibaba.html
compsciphd
i'd argue that perhaps the ability to play audio should be permission gated, much like the ability to use webcam/microphone.
However, I'd bet that many people will gladly allow aliexpress to play audio as there are probably videos on the site that people want to play and listen to.
With that said, its possible that this can be only a use once permission. Even if I want to shop at aliexpress if I know they are doing this, I'll be more willing to be bothered every time I want to play a video with audio to approve it if this bothers me.
show comments
miki123211
Ah, so that's what Wolt (Doordash but in Europe) is doing.
I noticed that Voice Over (iOS screen reader) crackles and randomly changes volume when using the app, but I attributed it to standard iOS weirdness, and possibly misuse of some iOS API. Now I'm thinking that this may very well be fingerprinting.
IX-103
This is actually a really common form of fingerprinting. At one point in time, it could generally tell the website what operating system and CPU architecture you're running on. I know this type of fingerprinting was fixed in Chrome so it always gives the same answers regardless of platform. I think it was also fixed in Firefox and Safari, but I don't follow their releases as closely.
Of course, even though it's probably useless now, things like that hang around because it costs more for trackers to remove the code than it does to keep it in.
emctech
Recently I ran into a problem with my Bluetooth headphones. They support multipoint bluetooth audio, so they can be connected to my PC and phone at the same time.
Opening the Aliexpress webpage causes a silent audio stream keeping the PC>headphone link active blocking my phone audio.
An investigation reveals obfuscated code running device fingerprinting with a side effect being a silent audio stream that firefox, chrome and windows does not recognise but which kept the bluetooth connection active.
show comments
robtherobber
Concerning situation, I think. And I suspect (perhaps wrongly) that there are even more reasons for concern with technology that can track, capture, leak etc. information that's more sensitive or valuable, depending on how one wishes to look at it. Mobile phones, computers, routers etc. -- all have the potential to siphon out valuable information to a bad actor, especially when it comes to espionage, military, commercial etc. This has already happened at a significant scael, so it's not a remote scenario.
At the very least, governments and institutions should develop a framework to investigate all acquired technology. The community / civil society could also create something similar, a script that would analyse at a deep level everything that can be analysed with a piece of software even by a complete novice.
show comments
gmueckl
A part of me is always smiling a little inside when people find creative ways to abuse browsers. It's always one more demonstration that the current web is fundamentally broken by design. The distinction between web browsers and random programs that allow remore arbitrary code execution is becoming more and more academic with every new feature that gets exposed to JavaScript.
Of course, I am also a horrible hypocrite and will actually use websites that use features like WebUSB or WebRTC.
show comments
pyaamb
Need to rethink the system that allows for (and encourages) this kind of plausible deniability. From "Oh we need this permission for [non essential feature] and you need to accept it if you want the app at all" -> to giving the user ultimate control over what happens on their personal device. Virtualize what the app can see and use fake data/identifiers/devices if necessary to get it to do what its supposed to. If the App isn't going to act in good faith why should the user? Fine grained permissions don't really work in practice because the app can keep annoying the user until they give in and hit Allow.
show comments
spicyjpeg
Browser fingerprinting can get creative at times, to say the least. eBay's WebSocket port scanner [1] and Reddit's abuse of DRM and JavaScript JIT exploits [2] from years ago are two examples of the kind of in-depth introspection you can perform completely in the background using nothing more than simple non-permission-gated APIs.
This article writing is really clean and enjoyable to read. And I learnt something.
Thank you very much.
br0ceph
aliexpress is largely a bait and switch site.
most of the prices change during checkout in the most frustrating ways.
one u ready to check out, and provide ur payment into, and click to pay... they interrupt this fake checkout with a popover, inform u the price is actually much higher, and dangle a button which is one click to accept the new higher price.
this is total scam behaviour and probably illegal in most US states.
show comments
rootsudo
I’ve noticed this and on other apps too, it breaks AirPods and when background playing Spotify it’s very obvious.
Thanks for investigating! Makes sense it’s also in the taobao app on ios too.
buildfocus
I've seen this on many many other sites as well, most notably Twitter, and lots of common modern captcha pages too. Very annoying!
fuzzy2
When I visit an article on a popular German tech news website, it interrupts music playback on my iPad (the website takes audio focus). I bet they do something similar.
Flow
I wonder if this is something the iOS Facebook app also does? It constantly pauses my Apple Music playing. Soooo irritating.
ninalanyon
Why are web pages allowed by default to do such things? Browsers should give the user the ability to forbid all sorts of thing and have them forbidden by default.
admax88qqq
Somebody (Mozilla?) should make a browser that just proactively blocks shit like this
I’m sure some Adblock addon could do it but at the browser level would be preferred. A browser vendor that just proactively does security and “correctness” tweaks to live sites would actually be in my interests as a user
nkjoep
JS enabled by default seems every day less secure.
show comments
barrystaes
Aha this would explain. I have seen similar behaviour with a news website trying DRM requests (has no reason to ask this info) resulting in stopping playback.. did not consider the impact of multipoint here. Interesting, might be worth looking into if i see this "bug" again.
ibaikov
I had this (?) happen. I have a soundbar hooked up through spdif in my pc. It automatically switches sources, so I can play music through airplay and then have it play sounds from pc when I open youtube etc. So it switches from airplay music to pc even when nothing is playing on pc. This was happening on some websites and it is extremely annoying.
grishka
Is there any particular reason these kinds of APIs are not behind permission prompts?
dzonga
I think x.com does this too - haven't been able to dig deeper.
sillyboi
I thought the App Store review guidelines explicitly prohibit hidden features and using public APIs outside their intended purpose. Is audio-based fingerprinting just not something review can realistically catch?
show comments
ngl999
Just curious, why silent sound would allow fingerprinting? What are they sampling if it can't be heard?
show comments
mdavidn
I notice this all of the time on sites with ads. I use AirPods to listen to music on my phone at work. Opening websites on my Mac routinely steals the AirPod connection but plays nothing audible.
hoppp
Are you not required to grant an explicit permission for it to access audio? If not that is highly disturbing.
fg137
This at least partially contributed to a sleep related Firefox bug on Windows:
This is not limited to Bluetooth in any way. In pavucontrol I can see Firefox outputting audio when on AliExpress even though nothing is playing. The uBlock filter fixed it.
show comments
tecleandor
That could explain the multipoint problems I've had in the last weeks, where audio would get "stuck" to one of my devices even when (apparently) nothing is playing.
show comments
big_dave212
Trying to debug this as a normal user is basically hopeless, you would never think to suspect a shopping tab. Glad someone did the legwork.
show comments
__MatrixMan__
Bluetooth is such a mess. You know what didn't have this problem? Cables.
show comments
goodpoint
90% of this stuff should be illegal
CTDOCodebases
They have been doing this for months.
No sound playing but the audio would change like the microphone was being activated. I checked permissions to make sure there was no mic access and figured that they were fingerprinting.
show comments
ankushdograuk
This is the reason I use adguard everywhere
show comments
nottorp
Besides the privacy implications, they are also wasting our fucking batteries on this crap...
theyeenzbeanz
Can we just limit web APIs to cookies and the likes as before? I don’t like how JavaScript has access to so many devices on the host. It’s a security and privacy nightmare.
kinnth
This sounds like a GDPR issue no? Couldn't they be taken to the EU!
show comments
docmars
Sounds like we're gonna need browsers to pop an audio playback permission, as annoying as that seems. Abusive sites just can't help themselves.
echelon_musk
OP please submit the filter to an upstream uBlock filter list.
show comments
downrightmike
There is no legit reason to be doing this.
qurren
> distinguish normal shoppers from automated
Why? Are you afraid of robots making you rich?
shevy-java
We need to find a solution to browsers sniffing on people. This here refers to AliExpress, but which browsers are typically spying on people like that in the first place? That's the real primary problem.
lapcat
Cloudflare challenges also use Web Audio, by the way.
show comments
amelius
Are there any EU/GDPR laws against fingerprinting?
show comments
kappi
It's not just BT audio. In windows PC, if aliexpress is opened in one tab in chrome, and switching to a tab with youtube opened, audio don't play in this tab if you start playing youtube.
Grombobulous
If this wasn't such a serious issue I'd be inclined to make a joke about being surprised that AliExpress was capable of such a thing, but I guess the complete shitshow of a website is intentional.
I wouldn't be surprised if what I'm feeling is all a psychological thing where consumers associate jank with low prices so that's why sites like AliExpress and Temu look like a complete technical mess when in reality they're doing pretty advanced stuff like this.
pama
Another reason why Lockdown mode on iOS is your friend.
show comments
handle584
Meanwhile ppl freak out over Anthropic using timezone and Unicode for the same purpose, without realizing Chinese are simply ruthless in abusing iOS or Android or Web. Pinduoduo, who owns Temu, is infamous for exploiting an Android 0day vulnerability for such purposes.
I wish such shenanigans would simply trigger the little speaker icon most browser display on tabs these days.
Given that they don't (at least in my experience), I'm assuming "playing silent audio" is a sufficiently common thing for websites to do to have motivated browsers into doing the slightly more complicated thing of actually analyzing audio streams for content...
Now I wonder, does this also allow websites to continue running in the background on mobile browsers? Playing media is one of the very few things that can convince iOS Safari to keep a tab running indefinitely, in my experience.
With my previous hearing aid I noticed that visiting a wide variety of web sites would cause a change in the amplification of environmental noise. I always assumed it was doing something with Bluetooth, and probably not for a good reason. This is with an iPhone 13 and one Kirkland/phonak hearing aid.
I haven’t noticed this recently, but I also now have two newer Phonak hearing aids and a few iOS updates have happened. Maybe the silent Bluetooth shenanigans are less disruptive to my new aids or the programming is different. Surely shenanigans continue.
Getting the same issue when opening Stripe Dashboard.
I noticed in the last few weeks that if I’d recently opened the AliExpress iOS app (ie. it was backgrounded) my car audio would freak out thinking I was giving it an audio command. Killing the AliExpress app immediately fixed the problem. After seeing it happen more than once I assumed it was something dodgey and uninstalled the app.
So Apple will remove them from the App Store. Thats their whole argument for their closed system - they’ll protect users from malicious apps. Right?
> screen and viewport dimensions
I remember trying I think it was the Tor browser, being puzzled at why the viewable area of the window constantly changed when resized but would never occupy the full window.
I feel a little silly now.
WebAudio fingerprinting is largely mitigated (in Firefox, potentially other browsers) - I wrote a quick overview that talks about the current distribution of values as well as our more recent efforts. https://ritter.vg/blog-webaudio_alibaba.html
i'd argue that perhaps the ability to play audio should be permission gated, much like the ability to use webcam/microphone.
However, I'd bet that many people will gladly allow aliexpress to play audio as there are probably videos on the site that people want to play and listen to.
With that said, its possible that this can be only a use once permission. Even if I want to shop at aliexpress if I know they are doing this, I'll be more willing to be bothered every time I want to play a video with audio to approve it if this bothers me.
Ah, so that's what Wolt (Doordash but in Europe) is doing.
I noticed that Voice Over (iOS screen reader) crackles and randomly changes volume when using the app, but I attributed it to standard iOS weirdness, and possibly misuse of some iOS API. Now I'm thinking that this may very well be fingerprinting.
This is actually a really common form of fingerprinting. At one point in time, it could generally tell the website what operating system and CPU architecture you're running on. I know this type of fingerprinting was fixed in Chrome so it always gives the same answers regardless of platform. I think it was also fixed in Firefox and Safari, but I don't follow their releases as closely.
Of course, even though it's probably useless now, things like that hang around because it costs more for trackers to remove the code than it does to keep it in.
Recently I ran into a problem with my Bluetooth headphones. They support multipoint bluetooth audio, so they can be connected to my PC and phone at the same time. Opening the Aliexpress webpage causes a silent audio stream keeping the PC>headphone link active blocking my phone audio. An investigation reveals obfuscated code running device fingerprinting with a side effect being a silent audio stream that firefox, chrome and windows does not recognise but which kept the bluetooth connection active.
Concerning situation, I think. And I suspect (perhaps wrongly) that there are even more reasons for concern with technology that can track, capture, leak etc. information that's more sensitive or valuable, depending on how one wishes to look at it. Mobile phones, computers, routers etc. -- all have the potential to siphon out valuable information to a bad actor, especially when it comes to espionage, military, commercial etc. This has already happened at a significant scael, so it's not a remote scenario.
At the very least, governments and institutions should develop a framework to investigate all acquired technology. The community / civil society could also create something similar, a script that would analyse at a deep level everything that can be analysed with a piece of software even by a complete novice.
A part of me is always smiling a little inside when people find creative ways to abuse browsers. It's always one more demonstration that the current web is fundamentally broken by design. The distinction between web browsers and random programs that allow remore arbitrary code execution is becoming more and more academic with every new feature that gets exposed to JavaScript.
Of course, I am also a horrible hypocrite and will actually use websites that use features like WebUSB or WebRTC.
Need to rethink the system that allows for (and encourages) this kind of plausible deniability. From "Oh we need this permission for [non essential feature] and you need to accept it if you want the app at all" -> to giving the user ultimate control over what happens on their personal device. Virtualize what the app can see and use fake data/identifiers/devices if necessary to get it to do what its supposed to. If the App isn't going to act in good faith why should the user? Fine grained permissions don't really work in practice because the app can keep annoying the user until they give in and hit Allow.
Browser fingerprinting can get creative at times, to say the least. eBay's WebSocket port scanner [1] and Reddit's abuse of DRM and JavaScript JIT exploits [2] from years ago are two examples of the kind of in-depth introspection you can perform completely in the background using nothing more than simple non-permission-gated APIs.
[1] https://blog.nem.ec/2020/05/24/ebay-port-scanning/
[2] https://iter.ca/post/reddit-whiteops/
This article writing is really clean and enjoyable to read. And I learnt something.
Thank you very much.
aliexpress is largely a bait and switch site.
most of the prices change during checkout in the most frustrating ways. one u ready to check out, and provide ur payment into, and click to pay... they interrupt this fake checkout with a popover, inform u the price is actually much higher, and dangle a button which is one click to accept the new higher price.
this is total scam behaviour and probably illegal in most US states.
I’ve noticed this and on other apps too, it breaks AirPods and when background playing Spotify it’s very obvious.
Thanks for investigating! Makes sense it’s also in the taobao app on ios too.
I've seen this on many many other sites as well, most notably Twitter, and lots of common modern captcha pages too. Very annoying!
When I visit an article on a popular German tech news website, it interrupts music playback on my iPad (the website takes audio focus). I bet they do something similar.
I wonder if this is something the iOS Facebook app also does? It constantly pauses my Apple Music playing. Soooo irritating.
Why are web pages allowed by default to do such things? Browsers should give the user the ability to forbid all sorts of thing and have them forbidden by default.
Somebody (Mozilla?) should make a browser that just proactively blocks shit like this
I’m sure some Adblock addon could do it but at the browser level would be preferred. A browser vendor that just proactively does security and “correctness” tweaks to live sites would actually be in my interests as a user
JS enabled by default seems every day less secure.
Aha this would explain. I have seen similar behaviour with a news website trying DRM requests (has no reason to ask this info) resulting in stopping playback.. did not consider the impact of multipoint here. Interesting, might be worth looking into if i see this "bug" again.
I had this (?) happen. I have a soundbar hooked up through spdif in my pc. It automatically switches sources, so I can play music through airplay and then have it play sounds from pc when I open youtube etc. So it switches from airplay music to pc even when nothing is playing on pc. This was happening on some websites and it is extremely annoying.
Is there any particular reason these kinds of APIs are not behind permission prompts?
I think x.com does this too - haven't been able to dig deeper.
I thought the App Store review guidelines explicitly prohibit hidden features and using public APIs outside their intended purpose. Is audio-based fingerprinting just not something review can realistically catch?
Just curious, why silent sound would allow fingerprinting? What are they sampling if it can't be heard?
I notice this all of the time on sites with ads. I use AirPods to listen to music on my phone at work. Opening websites on my Mac routinely steals the AirPod connection but plays nothing audible.
Are you not required to grant an explicit permission for it to access audio? If not that is highly disturbing.
This at least partially contributed to a sleep related Firefox bug on Windows:
https://bugzilla.mozilla.org/show_bug.cgi?id=1863193
This is not limited to Bluetooth in any way. In pavucontrol I can see Firefox outputting audio when on AliExpress even though nothing is playing. The uBlock filter fixed it.
That could explain the multipoint problems I've had in the last weeks, where audio would get "stuck" to one of my devices even when (apparently) nothing is playing.
Trying to debug this as a normal user is basically hopeless, you would never think to suspect a shopping tab. Glad someone did the legwork.
Bluetooth is such a mess. You know what didn't have this problem? Cables.
90% of this stuff should be illegal
They have been doing this for months.
No sound playing but the audio would change like the microphone was being activated. I checked permissions to make sure there was no mic access and figured that they were fingerprinting.
This is the reason I use adguard everywhere
Besides the privacy implications, they are also wasting our fucking batteries on this crap...
Can we just limit web APIs to cookies and the likes as before? I don’t like how JavaScript has access to so many devices on the host. It’s a security and privacy nightmare.
This sounds like a GDPR issue no? Couldn't they be taken to the EU!
Sounds like we're gonna need browsers to pop an audio playback permission, as annoying as that seems. Abusive sites just can't help themselves.
OP please submit the filter to an upstream uBlock filter list.
There is no legit reason to be doing this.
> distinguish normal shoppers from automated
Why? Are you afraid of robots making you rich?
We need to find a solution to browsers sniffing on people. This here refers to AliExpress, but which browsers are typically spying on people like that in the first place? That's the real primary problem.
Cloudflare challenges also use Web Audio, by the way.
Are there any EU/GDPR laws against fingerprinting?
It's not just BT audio. In windows PC, if aliexpress is opened in one tab in chrome, and switching to a tab with youtube opened, audio don't play in this tab if you start playing youtube.
If this wasn't such a serious issue I'd be inclined to make a joke about being surprised that AliExpress was capable of such a thing, but I guess the complete shitshow of a website is intentional.
I wouldn't be surprised if what I'm feeling is all a psychological thing where consumers associate jank with low prices so that's why sites like AliExpress and Temu look like a complete technical mess when in reality they're doing pretty advanced stuff like this.
Another reason why Lockdown mode on iOS is your friend.
Meanwhile ppl freak out over Anthropic using timezone and Unicode for the same purpose, without realizing Chinese are simply ruthless in abusing iOS or Android or Web. Pinduoduo, who owns Temu, is infamous for exploiting an Android 0day vulnerability for such purposes.