AliExpress runs silent WebAudio fingerprinting that breaks Bluetooth multipoint

emctech 936 points 295 comments August 20, 2026
blog.laserphile.com · View on Hacker News

Discussion Highlights (20 comments)

emctech

Recently I ran into a problem with my Bluetooth headphones. They support multipoint bluetooth audio, so they can be connected to my PC and phone at the same time. Opening the Aliexpress webpage causes a silent audio stream keeping the PC>headphone link active blocking my phone audio. An investigation reveals obfuscated code running device fingerprinting with a side effect being a silent audio stream that firefox, chrome and windows does not recognise but which kept the bluetooth connection active.

robtherobber

Concerning situation, I think. And I suspect (perhaps wrongly) that there are even more reasons for concern with technology that can track, capture, leak etc. information that's more sensitive or valuable, depending on how one wishes to look at it. Mobile phones, computers, routers etc. -- all have the potential to siphon out valuable information to a bad actor, especially when it comes to espionage, military, commercial etc. This has already happened at a significant scael, so it's not a remote scenario. At the very least, governments and institutions should develop a framework to investigate all acquired technology. The community / civil society could also create something similar, a script that would analyse at a deep level everything that can be analysed with a piece of software even by a complete novice.

compsciphd

i'd argue that perhaps the ability to play audio should be permission gated, much like the ability to use webcam/microphone. However, I'd bet that many people will gladly allow aliexpress to play audio as there are probably videos on the site that people want to play and listen to. With that said, its possible that this can be only a use once permission. Even if I want to shop at aliexpress if I know they are doing this, I'll be more willing to be bothered every time I want to play a video with audio to approve it if this bothers me.

patspam

I noticed in the last few weeks that if I’d recently opened the AliExpress iOS app (ie. it was backgrounded) my car audio would freak out thinking I was giving it an audio command. Killing the AliExpress app immediately fixed the problem. After seeing it happen more than once I assumed it was something dodgey and uninstalled the app.

CTDOCodebases

They have been doing this for months. No sound playing but the audio would change like the microphone was being activated. I checked permissions to make sure there was no mic access and figured that they were fingerprinting.

ngl999

Just curious, why silent sound would allow fingerprinting? What are they sampling if it can't be heard?

echelon_musk

OP please submit the filter to an upstream uBlock filter list.

nkjoep

JS enabled by default seems every day less secure.

buildfocus

I've seen this on many many other sites as well, most notably Twitter, and lots of common modern captcha pages too. Very annoying!

spicyjpeg

Browser fingerprinting can get creative at times, to say the least. eBay's WebSocket port scanner [1] and Reddit's abuse of DRM and JavaScript JIT exploits [2] from years ago are two examples of the kind of in-depth introspection you can perform completely in the background using nothing more than simple non-permission-gated APIs. [1] https://blog.nem.ec/2020/05/24/ebay-port-scanning/ [2] https://iter.ca/post/reddit-whiteops/

nottorp

Besides the privacy implications, they are also wasting our fucking batteries on this crap...

pama

Another reason why Lockdown mode on iOS is your friend.

goodpoint

90% of this stuff should be illegal

miki123211

Ah, so that's what Wolt (Doordash but in Europe) is doing. I noticed that Voice Over (iOS screen reader) crackles and randomly changes volume when using the app, but I attributed it to standard iOS weirdness, and possibly misuse of some iOS API. Now I'm thinking that this may very well be fingerprinting.

lapcat

Cloudflare challenges also use Web Audio, by the way.

ankushdograuk

This is the reason I use adguard everywhere

mgerdts

With my previous hearing aid I noticed that visiting a wide variety of web sites would cause a change in the amplification of environmental noise. I always assumed it was doing something with Bluetooth, and probably not for a good reason. This is with an iPhone 13 and one Kirkland/phonak hearing aid. I haven’t noticed this recently, but I also now have two newer Phonak hearing aids and a few iOS updates have happened. Maybe the silent Bluetooth shenanigans are less disruptive to my new aids or the programming is different. Surely shenanigans continue.

pyaamb

Need to rethink the system that allows for (and encourages) this kind of plausible deniability. From "Oh we need this permission for [non essential feature] and you need to accept it if you want the app at all" -> to giving the user ultimate control over what happens on their personal device. Virtualize what the app can see and use fake data/identifiers/devices if necessary to get it to do what its supposed to. If the App isn't going to act in good faith why should the user? Fine grained permissions don't really work in practice because the app can keep annoying the user until they give in and hit Allow.

ibaikov

I had this (?) happen. I have a soundbar hooked up through spdif in my pc. It automatically switches sources, so I can play music through airplay and then have it play sounds from pc when I open youtube etc. So it switches from airplay music to pc even when nothing is playing on pc. This was happening on some websites and it is extremely annoying.

sillyboi

I thought the App Store review guidelines explicitly prohibit hidden features and using public APIs outside their intended purpose. Is audio-based fingerprinting just not something review can realistically catch?

Semantic search powered by Rivestack pgvector
4,128 stories · 37,281 chunks indexed