Tech13:22 · 1h ago

AliExpress Caught Using Hidden Audio Tracking to Collect User Data

MaarivCenter
Translated & summarized from Maariv by baba
The story · English

A recent Bluetooth earphone malfunction revealed a covert tracking mechanism allegedly used by the AliExpress website. The site reportedly created a unique "fingerprint" of users' devices by collecting hardware and behavioral data without their knowledge or consent. This discovery came after a user noticed inconsistencies while trying to connect Bluetooth devices and investigated the website's code, uncovering two hidden scripts named collina.js and fireyejs.js. These scripts kept the computer's audio channel open, preventing Bluetooth switching despite no sound playing.

The tracking method exploited the Web Audio API, a browser tool intended for legitimate audio processing, to emit inaudible sounds at zero volume. Instead of producing noise, the scripts measured how each device processed the silent audio signal. Since every computer processes sound slightly differently due to variations in processors, sound cards, and other hardware and software components, this subtle inconsistency served as a unique device fingerprint.

In response to the revelation, the Brave browser team stated that their software has protected users from such audio-based fingerprinting techniques by default for over six years, injecting random data to confuse trackers. Mozilla Firefox also includes protections against audio feature-based tracking. For browsers lacking built-in safeguards, ad and content blockers like uBlock Origin can block these specific scripts, though this may sometimes disrupt website functionality.

Read the original at Maariv
Open the live terminal