A hot potato: As cookies become a less reliable way to track people online, AliExpress may be showing how far companies will go to fill that gap. Researchers found code on the site’s homepage that ran silent audio processes in the browser. Tied to Alibaba’s security systems, the scripts tap a device’s own audio hardware to generate a signal and measure the tiny, device-specific ways it comes back – producing something close to a fingerprint that doesn’t need a single cookie to work. It’s the kind of tracking a user would likely never notice.

The issue only surfaced after a developer had trouble using multipoint Bluetooth headphones while an AliExpress tab was open: the headphones wouldn’t switch properly from the computer to a phone. Once the tab was closed, the problem disappeared.

Digging into the site’s code, the developer found it was using the Web Audio API to build audio-processing graphs set to zero volume. The process produced no audible sound, but it still connected to the computer’s audio system, keeping the audio path active in the background, which appears to be what interfered with the headphones’ ability to switch devices.

This wasn’t the kind of audio activity tied to a normal media player. Because the processing graph ran at zero gain and connected directly to the system’s audio output, muting the browser tab did nothing to stop it: the browser kept processing the signal even though there was nothing to hear

  • terabyterex
    link
    fedilink
    arrow-up
    15
    ·
    24 hours ago

    holy fuck i am tired. everytime i read something like this is think “what kind of things do we not know about”

    • IceFoxX
      link
      fedilink
      arrow-up
      1
      ·
      23 hours ago

      Dafuq… Want a top super secret tipp? Snowden leaks… and wikileaks…