news.volyx.in

AliExpress runs silent WebAudio fingerprinting that breaks Bluetooth multipoint (blog.laserphile.com)

1057 points by emctech · 6 days ago · 337 comments on HN

Article summary

The AliExpress website creates a silent audio stream using WebAudio fingerprinting, which can interfere with Bluetooth multipoint audio switching. This is done through obfuscated code in scripts from Alibaba's security tooling. The audio stream is not audible to the user but can prevent the browser from releasing the audio path, causing issues with multipoint headphones. The issue can be mitigated by blocking the responsible scripts using uBlock Origin.

Main themes

  • WebAudio fingerprinting
  • Bluetooth multipoint audio
  • browser security
  • user privacy
  • app vs website
  • online shopping trade-offs

What commenters say

  • Some commenters find the situation concerning and believe that users should be able to control which websites can play audio.
  • Others think that the ability to play audio should be permission-gated, similar to webcam or microphone access.
  • A few commenters have experienced similar issues with other apps or websites and are skeptical of installing apps due to privacy concerns.
  • There is a debate about whether the benefits of using apps or websites like AliExpress outweigh the potential risks to user privacy and security.
  • Some argue that Apple's privacy nutrition labels are not effectively enforced, allowing apps to collect data without consequence.
  • Others believe that using web apps on browsers like Firefox with uBlock Origin is a more private and secure alternative to installing apps.
  • A few commenters have noted that AliExpress's mobile website is intentionally degraded to encourage app installation, which can be frustrating for users.
  • There is a discussion about the trade-offs between convenience and privacy, with some arguing that users should be willing to accept some risks in exchange for the benefits of online shopping.