With my previous hearing aid I noticed that visiting a wide variety of web sites would cause a change in the amplification of environmental noise. I always assumed it was doing something with Bluetooth, and probably not for a good reason. This is with an iPhone 13 and one Kirkland/phonak hearing aid.
I haven’t noticed this recently, but I also now have two newer Phonak hearing aids and a few iOS updates have happened. Maybe the silent Bluetooth shenanigans are less disruptive to my new aids or the programming is different. Surely shenanigans continue.
patspam 4 hours ago [-]
I noticed in the last few weeks that if I’d recently opened the AliExpress iOS app (ie. it was backgrounded) my car audio would freak out thinking I was giving it an audio command. Killing the AliExpress app immediately fixed the problem. After seeing it happen more than once I assumed it was something dodgey and uninstalled the app.
lukeify 4 hours ago [-]
I cannot ever imagine installing something like AliExpress as an app.
ivanjermakov 2 hours ago [-]
Not sure if they still do, but a couple years ago prices in the app were lower than on the website. And they promoted installing it to save money.
wongarsu 1 hours ago [-]
I believe the prices are the same. But the app has a number of "games" to collect tokens that get credited as discounts. Seems to be mostly stuff designed to get you to open the app daily and browse their offers. Which might be "innocent" if it's just to get you to buy more stuff, or maybe they have more reasons they want you to have the app open. Who knows
At least Aliexpress doesn't have all the fake slot machine type games that temu has that always end in variations of "get $200 of discounts for your next order if you order x items from this list"
ornornor 14 minutes ago [-]
There are few things more scammy than AliExpress “discounts”. I have yet to see a cent of the hundreds of dollars of “savings” they gave or advertised to me.
imzadi 25 minutes ago [-]
They also don't give you a proper tracking number. The only way to track your shipment is in the app.
ahofmann 1 hours ago [-]
Now we know why...
coldtea 1 hours ago [-]
And someone would install random apps to save $5 on $100 purchases?
imzadi 22 minutes ago [-]
When I did customer tech support for a major retailer, we had confused customers calling all the time because they would randomly get price-match refunds they never asked for. They were installing apps that were automatically requesting the refunds by searching their emails for orders and checking the prices on the websites. These people had no idea they had even given these apps permission to read their emails.
ivanjermakov 1 hours ago [-]
You'd be surprised on what general public can go to save $5.
vlachen 52 minutes ago [-]
I mean, I'm haunted by the things I did for a Klondike Bar.
39 minutes ago [-]
rigrassm 2 hours ago [-]
> Not sure if they still do, but a couple years ago prices in app were lower than on the website. And they promoted installing it to save money.
Translation: They are able to mine your personal data more completely with an app installed vs the website which they can sell for pure profit. They promoted installing it to extract more value from you.
swores 1 hours ago [-]
That's definitely a feasible explanation (and the one I would assume to be true for AliExpress).
But there is another, slightly less evil, explanation that I know at least some companies have pushed their apps because of: the thinking is that if you're on their website, there is less friction to open a new tab and search for a lower price from their competitors, than if you're in their app. Obviously it's hardly any different - opening a new app (the web browser) vs. opening a new tab in the app you're already in - but the theory is that there's a slight psychological difference.
Of course I'm not saying that trying to prevent your customers from searching for better deals is a nice thing to do. Just adding that data mining isn't the only reason for some companies to want people to use their apps.
MallocVoidstar 37 minutes ago [-]
It's still the case that you pay less in the app. You get 'coins' for a daily check-in, which are automatically(?) applied as a discount. Most items either don't actually use them or only give you a pointless 1% off or something, but I've gotten a $12 microcontroller for $5, for example. I think some coupons are app-only, too (though most aliexpress sales are fake and are better thought of as the normal price).
unixhero 4 hours ago [-]
It's great for shopping. But in the US you have amazon prime. We don't.
dogman1050 3 hours ago [-]
I have Prime, but I can't imagine installing the Amazon app either. The website works just fine.
nntwozz 3 hours ago [-]
This is the way. It's prudent to treat apps with skepticism, it's unfortunate it's come to this.
I study Apple's Privacy Nutrition Labels religiously every time I consider installing an app.
I like the ones with "Data Not Collected".
woadwarrior01 2 hours ago [-]
I'm an app developer and all my apps have the "Data Not Collected" privacy nutrition label. I love the idea, but Apple's enforcement of it is very lackadaisical. I've reported dozens of apps that were blatantly lying on their privacy nutrition labels to Apple and I'm yet to see any such app's nutrition label change.
Why have rules (or laws) if they don’t enforce them? Or only enforce them selectively when they feel it necessary, such as when not doing so would threaten your stock price (or re-election campaign)? Maybe I just answered my own question?
Reminds me of meat processing regulations. I can sell my animals whole to buyers through a custom processing exemption, but they must go pick up their meat from the butcher. The law says I cannot pick up and deliver it, but it is trivial to find people advertising that extra service. Reporting them does not result in any obvious action.
In both of our cases, our honesty is a liability in the marketplace, because people are ignorant of such laws (or simply don’t care). Really, they simply want the product that they want, as conveniently as possible. We are then forced to compete in the marketplace with liars and cheats.
I am sure our peers here can find countless examples in other areas where this flavor of dishonesty prevails. Hell, I would love to hear some counter examples, because I cannot help but view this state of affairs as intentional at this point.
The purpose of system is what it does (or, in this case, does not do).
otherjason 46 minutes ago [-]
The cynical way to look at this is that the purpose of the system (the privacy nutrition label) is to support Apple's carefully-crafted and -marketed image as the most privacy-focused of the tech giants. Actually having enforcement of the contents of said labels would be a nice potential byproduct of that, but that's not strictly required to accomplish the system's purpose.
manbash 2 hours ago [-]
With Firefox, yes.
I wouldn't fully trust other browsers to care about my privacy.
AstralSerenity 2 hours ago [-]
Using web apps on Firefox really is the way given its support for uBlock Origin.
Screen real estate is precious on phones, so being able to permanently block "Install our app!" and even entire navigation categories (shorts on LinkedIn) is quite valuable.
Then you can "install" the site on your home screen or simply place it in collection folders so it's sitting ready on your "New Tab" page.
boobsbr 1 hours ago [-]
AFAIK, the app is just the website in a webview.
HPsquared 2 hours ago [-]
I think you need the app to use the delivery lockers (which I prefer over home delivery)
fragmede 3 hours ago [-]
Where is "we"?
ngl999 3 hours ago [-]
Likely the place where people are "willing to trade privacy for convenience", according to Baidu's CEO.
stinos 12 minutes ago [-]
I always wonder if it's worth it. Like: is it actually convenient, or is it 'solving' inconveniences which actually do not exist or didn't exist before using the service? I have never used Prime or AliExpress but also don't consider our typical shopping very inconvenient. And the most inconvenient parts are actually the ones which seem necessary to to get the proper goods (from past weeks: vegetables/fruits/shoes - it's not really possible to order that online and get exactly what we want). And everything else is available from other webshops.
rcruzeiro 3 hours ago [-]
According to their profile: Norway
embedding-shape 3 hours ago [-]
I don't have Amazon Prime (nor am I in the US) yet use Aliexpress perfectly fine on my mobile phone without using an app. Frankly, I don't understand how the two is related at all?
doubled112 3 hours ago [-]
AliExpress won't allow me to open most pages in the account section on my iPhone. Instead I get a page telling me to install the app.
While browsing, there are also popups offering the app approximately every third link I click. Some of them are telling me to install the app.
Unless the situation has changed recently, it's not perfectly fine, it is unusable on purpose.
emctech 3 hours ago [-]
AE website on mobile is terrible, they basically force you to use the app. I exclusively use the website on my PC
whstl 3 hours ago [-]
So they're pulling a Reddit, basically.
"The app is great because the website is heavily degraded".
Ntrails 2 hours ago [-]
I just request the desktop site, it's fine
coldtea 1 hours ago [-]
Both are web stores. Both have websites AND apps.
They are compared / contrasted. Nobody is saying one is concretely related to the other.
lovestory 3 hours ago [-]
You probably buy things off amazon that are dropshipped from AliExpress all the time. Stop with the elitism
63stack 3 hours ago [-]
This is not about the products that are shipped, but the app itself. I would caution people to never install it as well.
4chandaily 24 minutes ago [-]
I can't imagine ever wanting to install an amazon app either. Both of these stores have perfectly functional websites. What would I gain installing their spyware? Also, why so defensive?
aureate 3 hours ago [-]
I buy directly from AliExpress all the time. I wouldn't install their app.
mark_something 2 hours ago [-]
On AliExpress I see things like 64 TB (no, not GB!) USB flash drives for less than 10 euro, obviously a scam. I also see less spectacular products but still good looking deals, but without a brand name so you can't search the web for reviews.
On Amazon I never see products like that. That's why I prefer Amazon (and Coolblue and bol.com in Belgium).
subscribed 1 hours ago [-]
I see this kind of fakes on eBay or Amazon all the time. It's even harder to report it than on AliExpress and I never had an obvious report of fakes upheld (AND eBay warns they will forward your identity to the seller. Great thing if the organised crime is involved in this)
Case in point, fake 2TB Sandisk ExtremePro microSD:
Agreed, there's more of that on AliExpress but Amazon is not free from that either.
kees99 2 hours ago [-]
Few years back, Amazon had a rampant "fake USB storage" problem too. Then, one day, all the fakes were gone, just like that.
voakbasda 1 hours ago [-]
If you believe that, I have some USB storage to sell you. Huge capacity, barely used. I keep my inventory in storage under this bridge, which I also happen to have for sale. Interested? ;)
prartichoke 1 hours ago [-]
I cannot imagine installing amazon as an App as well. It's a website
somehnguy 2 hours ago [-]
Having bought many things off AliExpress over the years I can say with complete confidence that I've never made a purchase on Amazon that was dropshipped from Ali. The shipping times are far different and it would be immediately obvious.
rootusrootus 56 minutes ago [-]
Yeah it would be hard to hide. When I order from AliExpress it arrives via Chinese carriers I have never even hard of, and about half the time the final delivery is through a Chinese gig delivery company that must pay practically nothing to the driver because they will usually drive up in front of my house and chuck the package out the window onto my front lawn.
subscribed 1 hours ago [-]
I've ordered things from AliExpress shipped from the local warehouses (2-3 days delivery) ; I've ordered things on Amazon UK that were fulfilled and shipped from Amazon UK that were delivered in 3-5 working days.
Not a £1 tat, and not one off. Not that AliExpress is my choice, no, far from it. Sometimes it's better, closer to the manufacturer, that's all.
ohyoutravel 3 hours ago [-]
Love Temu and AliExpress for specialized components at dirt cheap prices. I would never, ever install their app. Ever, security nightmare.
Similar to how I use Amazon Prime but would never order something I ingest, put on my skin, or (usually) wear from it.
Not elitest.
ngl999 4 hours ago [-]
It's known that some Chinese mobile apps employ this trick to keep the app alive in the background, the rumor is that this way the 'active user' KPI can be better met.
edit: quantity qualifier
echoangle 2 hours ago [-]
Why would they manipulate the numbers that way if it’s self-reported anyways? If you want to fake the numbers, couldn’t you just change the number and be done?
voakbasda 60 minutes ago [-]
The people fudging the metric (developers) may not be the same people that are relying on the metrics (managers). Perverse incentives at play could easily motivate this kind of shenanigan.
genidoi 2 hours ago [-]
It's probably quite difficult to manipulate per-user metrics after the data is collected.
SirFatty 3 hours ago [-]
If it's known, are you suggesting that Apple and Google are complacent in allowing these type of apps in their ecosystem?
ngl999 2 hours ago [-]
I wouldn't think of giant organizations like Apple and Google as mere individuals that can exercise human emotions such as complacency.
barrystaes 7 minutes ago [-]
Aha this would explain. I have seen similar behaviour with a news website trying DRM requests (has no reason to ask this info) resulting in stopping playback.. did not consider the impact of multipoint here. Interesting, might be worth looking into if i see this "bug" again.
forestry 2 hours ago [-]
So Apple will remove them from the App Store. Thats their whole argument for their closed system - they’ll protect users from malicious apps. Right?
agos 2 hours ago [-]
it's not the app that it's malicious, it's the website
rob-lag 25 minutes ago [-]
It's both, according to another comment.
miki123211 2 hours ago [-]
Ah, so that's what Wolt (Doordash but in Europe) is doing.
I noticed that Voice Over (iOS screen reader) crackles and randomly changes volume when using the app, but I attributed it to standard iOS weirdness, and possibly misuse of some iOS API. Now I'm thinking that this may very well be fingerprinting.
compsciphd 4 hours ago [-]
i'd argue that perhaps the ability to play audio should be permission gated, much like the ability to use webcam/microphone.
However, I'd bet that many people will gladly allow aliexpress to play audio as there are probably videos on the site that people want to play and listen to.
With that said, its possible that this can be only a use once permission. Even if I want to shop at aliexpress if I know they are doing this, I'll be more willing to be bothered every time I want to play a video with audio to approve it if this bothers me.
rcruzeiro 3 hours ago [-]
I would actually love if I could have iOS prompt me to allow certain apps to use the speakers. I hate using an app and suddenly have a video autoplay loudly.
voakbasda 58 minutes ago [-]
This. This needs to be a thing.
emctech 4 hours ago [-]
The ability to play audio can usually be permission gated with tab muting, however the methods aliexpress use bypass that mechanism completely.
y-curious 2 hours ago [-]
This is the part you should be highlighting aggressively. That’s very uncomfortable
emctech 5 hours ago [-]
Recently I ran into a problem with my Bluetooth headphones. They support multipoint bluetooth audio, so they can be connected to my PC and phone at the same time.
Opening the Aliexpress webpage causes a silent audio stream keeping the PC>headphone link active blocking my phone audio.
An investigation reveals obfuscated code running device fingerprinting with a side effect being a silent audio stream that firefox, chrome and windows does not recognise but which kept the bluetooth connection active.
maximilianthe1 3 hours ago [-]
Is this an AI summary of the article?
emctech 2 hours ago [-]
No, I took the first sentence of my article and then edited the rest of the intro + conclusion to keep it short for HN.
left-struck 52 minutes ago [-]
You should make that obvious in some way like using “TLDR”. I assume many people, like me, would attempt to parse your comment as a comment on the article, after all it’s in the comment section, and read that way it’s very confusing lol.
emctech 43 minutes ago [-]
Sorry, this is my first post to HN and in the submission it looked like the description text i added would be part of the post header.
robtherobber 5 hours ago [-]
Concerning situation, I think. And I suspect (perhaps wrongly) that there are even more reasons for concern with technology that can track, capture, leak etc. information that's more sensitive or valuable, depending on how one wishes to look at it. Mobile phones, computers, routers etc. -- all have the potential to siphon out valuable information to a bad actor, especially when it comes to espionage, military, commercial etc. This has already happened at a significant scael, so it's not a remote scenario.
At the very least, governments and institutions should develop a framework to investigate all acquired technology. The community / civil society could also create something similar, a script that would analyse at a deep level everything that can be analysed with a piece of software even by a complete novice.
emctech 5 hours ago [-]
Yes, I find it concerning too. I particularly dislike that windows was not aware, nor could it stop the audio stream from effecting the hardware. What other side channels like that exist? Perhaps I can be blamed for using windows
robtherobber 5 hours ago [-]
> Perhaps I can be blamed for using windows
That would be unreasonable, I argue. No one should have to worry about the security of their devices and data privacy based on which OS they use. Whilst it can be argued that different OSs serve different needs, privacy and security should not be debatable. In fact, most countries have dedicated legislation for this; whether it's just, applied correctly, or serves the public before any other party are indeed discussions to be had.
lnsru 4 hours ago [-]
I am pretty sure my phone is listening. The ads I see this week are about topics I discussed last week. Week for week. Stupid thing is that I need the phone to have near by as self-employed electrician. Clients want to communicate after regular office hours. Since the phone is rigged why computer shouldn’t?
bobim 4 hours ago [-]
We take everything we have, freedom, privacy, free speech, for granted. The reality seems to be that these concepts are fungible and that we have to be ready to fight for them. Instead we trade these for convenience, and it's very very sad.
3 hours ago [-]
gmueckl 2 hours ago [-]
A part of me is always smiling a little inside when people find creative ways to abuse browsers. It's always one more demonstration that the current web is fundamentally broken by design. The distinction between web browsers and random programs that allow remore arbitrary code execution is becoming more and more academic with every new feature that gets exposed to JavaScript.
Of course, I am also a horrible hypocrite and will actually use websites that use features like WebUSB or WebRTC.
pyaamb 2 hours ago [-]
Need to rethink the system that allows for (and encourages) this kind of plausible deniability. From "Oh we need this permission for [non essential feature] and you need to accept it if you want the app at all" -> to giving the user ultimate control over what happens on their personal device. Virtualize what the app can see and use fake data/identifiers/devices if necessary to get it to do what its supposed to. If the App isn't going to act in good faith why should the user? Fine grained permissions don't really work in practice because the app can keep annoying the user until they give in and hit Allow.
pyaamb 1 hours ago [-]
Also perhaps AI agents are now capable enough to run these apps the way the user would and recognize these dark patterns. Flag those and feed it back to a warning at the point of sale that users can upvote there to signal their disapproval and a threshold score that risks removal of the app from the store. Because bad behaviour continues to make business sense if the rules allow it. Moreover, it penalizes and puts pressure on the good actors as a "missed business opportunity".
ajross 2 hours ago [-]
What you want is basically how it works. On both phone platforms and PWAs, all permissions are visible to the user explicitly. All of them can be revoked at any time. Apps are disallowed from requesting an already-denied permission.
Obviously apps can tell if they haven't been granted a permission (even if you tried to fake this, they aren't dummies and will know if it's not working), and obviously third party software isn't under any obligation to work without them.
But the platforms have done what the platforms can do, at the architecture side, really. The next stage is human-audited enforcement of malware, which this AliExpress nonsense might hopefully run afoul of.
drdexebtjl 2 hours ago [-]
>Obviously apps can tell if they haven't been granted a permission
By design. This doesn’t need to be the case. It should be impossible to tell you have denied a permission.
In TFA’s case, the browser could just keep processing audio but never hook it up to a real audio sink.
victorbjorklund 1 hours ago [-]
Soundd like a nightmare to build legitimate apps if you for example are building an app that uses the camera but you can’t in anyway tell that using the camera fails (because user had denied the permission 6 months ago and has no memory of it) and instead of being able to give a helpful error you are just ending up with I am guessing fake images (maybe just a black screen).
voakbasda 53 minutes ago [-]
The image could contain a message that it is disabled.
ajross 1 hours ago [-]
That does nothing but start an arms race. Fine, audio "works" but do you get noise? Can you read back the sounds you play? No, right? It doesn't work, QED. Now the platform needs to fake the noise.
Likewise for any other hardware access you want, and most of them are harder. How do you fake local storage without storing anything? How do you fake Bluetooth access without virtualizing an entire device? Do you fake the screen dimensions to look like something else? Input latency? Where does it stop?
No, "does this work" is among the easiest questions to answer in technology. We aren't going to win this war.
emctech 37 minutes ago [-]
The best you can do on the modern web is reduce your fingerprint footprint, though it comes at a cost of websites breaking from JS disabling, or local time zone anonymisation.
xnx 2 hours ago [-]
> Obviously apps can tell if they haven't been granted a permission (even if you tried to fake this, they aren't dummies and will know if it's not working),
How can they tell? For the permissions I can think of: location, filesystem, etc. it should be easy to lie/spoof.
buildfocus 4 hours ago [-]
I've seen this on many many other sites as well, most notably Twitter, and lots of common modern captcha pages too. Very annoying!
ibaikov 2 hours ago [-]
I had this (?) happen. I have a soundbar hooked up through spdif in my pc. It automatically switches sources, so I can play music through airplay and then have it play sounds from pc when I open youtube etc. So it switches from airplay music to pc even when nothing is playing on pc. This was happening on some websites and it is extremely annoying.
spicyjpeg 4 hours ago [-]
Browser fingerprinting can get creative at times, to say the least. eBay's WebSocket port scanner [1] and Reddit's abuse of DRM and JavaScript JIT exploits [2] from years ago are two examples of the kind of in-depth introspection you can perform completely in the background using nothing more than simple non-permission-gated APIs.
I thought the App Store review guidelines explicitly prohibit hidden features and using public APIs outside their intended purpose. Is audio-based fingerprinting just not something review can realistically catch?
ValdikSS 2 hours ago [-]
They probe all audio devices, including microphones, which probably temporarily switches Bluetooth devices into HPF mode due to how Bluetooth duplex audio works.
I'd argue it's "silent" though: aliexpress wakes up my audio card if nothing plays, which results in a very faint "pop" sound every time I open the tab.
It's been this way for ~3+ years at least.
lapcat 1 hours ago [-]
It's the website.
The title of the article literally mentions "WebAudio", and the first paragraph states that the author is using a PC. The second paragraph mentions Chrome and Firefox.
Apple and the App Store have zero involvement here.
hunter2_ 24 minutes ago [-]
This is a huge stretch, but if this problem exists in not only the PC versions of Chrome/Firefox but also the Android/iOS versions, then theoretically the app store reviewers could flag the browsers for facilitating this behavior against app store guidelines. In practice, apps of such caliber as popular browsers might be a bit above such reviewers' pay grade, so to speak.
lapcat 12 minutes ago [-]
> This is a huge stretch
This is nonsense. Safari also supports Web Audio. Safari does not, however, support Microsoft Windows, which is why the article author didn't mention it.
Moreover, all web browsers on iOS have to use Apple WebKit, so Web Audio support is not actually the fault of the non-Apple browser vendors.
grishka 1 hours ago [-]
Is there any particular reason these kinds of APIs are not behind permission prompts?
nkjoep 4 hours ago [-]
JS enabled by default seems every day less secure.
emctech 4 hours ago [-]
So many website break completely with JS disabled and you end up having to enable it half the time anyway.
ruuda 3 hours ago [-]
About half of the time, when a website doesn't work with js disabled, I realize that I didn't want to see the page that badly anyway, and I close the tab.
masfuerte 4 hours ago [-]
It was pretty good until about six months ago. Since then loads of sites have added a js requirement to try to stop the AI bots.
MisterTea 3 hours ago [-]
IMO web browser have been enabling all sorts of obnoxious behavior since before JS. One of my all time favorites were the sites that opened pop-ups in a loop faster than you could close them while an audio clip of a guy yelling "Hey everyone! I'm looking at gay porn!" You had to hit reset. Fuck the Web.
afandian 3 hours ago [-]
The web around the late 90s and early 2000s had some really sketchy stuff. I think the difference is that it used to be the sleazy underbelly. Now it's accepted as mainstream.
My local 'newspaper' website is chock full of scam adverts. The print version is dignified. The website people, somehow, turn a blind eye.
And I got an advert on Youtube this week using sexually explicit language to sell pills.
Feels like standards, and expectations, have really slipped.
grishka 55 minutes ago [-]
Opening a popup needs JS though.
ngl999 4 hours ago [-]
Just curious, why silent sound would allow fingerprinting? What are they sampling if it can't be heard?
emctech 4 hours ago [-]
The script generates a known waveform, it is passed through the browser's audio implementation and then the script analyses the result after. Based on your devices settings and hardware the output will be different, e.g. a PC with analog output might have 44KHz audio output bandwidth, but a bluetooth headset might have a lower, different audio bandwidth. That is a datapoint that can be used in device fingerprinting alongside screen and viewport dimensions,
device pixel ratio, browser plugins, etc.
hunter2_ 18 minutes ago [-]
On the one hand, I wouldn't expect too many variations here (the vast majority of devices probably use 48 kHz and 24-bit output, a few use 44.1 kHz and/or 16-bit, etc.) but just like DPR and all the other properties with a very small set of popular values in practice, you only need a bit or two from each measurement to eventually have a high quality fingerprint.
shevy-java 23 minutes ago [-]
We need to find a solution to browsers sniffing on people. This here refers to AliExpress, but which browsers are typically spying on people like that in the first place? That's the real primary problem.
goodpoint 3 hours ago [-]
90% of this stuff should be illegal
CTDOCodebases 4 hours ago [-]
They have been doing this for months.
No sound playing but the audio would change like the microphone was being activated. I checked permissions to make sure there was no mic access and figured that they were fingerprinting.
emctech 4 hours ago [-]
I had noticed it before but I was browsing AE a lot today and i got fed up with it. What browser and OS are you using?
CTDOCodebases 2 hours ago [-]
It was happening when I was using Chrome on iPhone and Windows 11 with Chrome. I can't remember what was causing it since the headphones (Bose Quietcomfort SE) are synced with both devices. For the last couple of months I've been using Android and I haven't noticed it. The headphones seem to work better with Android. IOS is a bit weird with sharing them with my PC.
ankushdograuk 2 hours ago [-]
This is the reason I use adguard everywhere
emctech 2 hours ago [-]
I use ublock origin and by default it wasn't blocking, i had to make a custom filter to block the scripts in order for it to prevent the audio takeover. Maybe adguard does a better job? Someone else suggested just wholesale disabling of JS but it is the nuclear option.
nottorp 4 hours ago [-]
Besides the privacy implications, they are also wasting our fucking batteries on this crap...
echelon_musk 4 hours ago [-]
OP please submit the filter to an upstream uBlock filter list.
Cloudflare challenges also use Web Audio, by the way.
emctech 22 minutes ago [-]
Does it hold an audio stream open constantly or just briefly during the challenge? On AE it never stops
lapcat 10 minutes ago [-]
Just briefly during the challenge.
kappi 1 hours ago [-]
It's not just BT audio. In windows PC, if aliexpress is opened in one tab in chrome, and switching to a tab with youtube opened, audio don't play in this tab if you start playing youtube.
Grombobulous 1 hours ago [-]
If this wasn't such a serious issue I'd be inclined to make a joke about being surprised that AliExpress was capable of such a thing, but I guess the complete shitshow of a website is intentional.
I wouldn't be surprised if what I'm feeling is all a psychological thing where consumers associate jank with low prices so that's why sites like AliExpress and Temu look like a complete technical mess when in reality they're doing pretty advanced stuff like this.
pama 3 hours ago [-]
Another reason why Lockdown mode on iOS is your friend.
eur0pa 3 hours ago [-]
Lockdown mode is great, but it breaks phone calls on your Apple Watch (found that out the hard way)
realusername 3 hours ago [-]
Somebody else mentioned here that they also do it on the iOS app and I don't see how Lockdown mode would change anything, it doesn't prevent to play audio.
spread2009 2 hours ago [-]
[flagged]
handle584 57 minutes ago [-]
Meanwhile ppl freak out over Anthropic using timezone and Unicode for the same purpose, without realizing Chinese are simply ruthless in abusing iOS or Android or Web. Pinduoduo, who owns Temu, is infamous for exploiting an Android 0day vulnerability for such purposes.
Rendered at 15:03:01 GMT+0000 (Coordinated Universal Time) with Vercel.
I haven’t noticed this recently, but I also now have two newer Phonak hearing aids and a few iOS updates have happened. Maybe the silent Bluetooth shenanigans are less disruptive to my new aids or the programming is different. Surely shenanigans continue.
At least Aliexpress doesn't have all the fake slot machine type games that temu has that always end in variations of "get $200 of discounts for your next order if you order x items from this list"
Translation: They are able to mine your personal data more completely with an app installed vs the website which they can sell for pure profit. They promoted installing it to extract more value from you.
But there is another, slightly less evil, explanation that I know at least some companies have pushed their apps because of: the thinking is that if you're on their website, there is less friction to open a new tab and search for a lower price from their competitors, than if you're in their app. Obviously it's hardly any different - opening a new app (the web browser) vs. opening a new tab in the app you're already in - but the theory is that there's a slight psychological difference.
Of course I'm not saying that trying to prevent your customers from searching for better deals is a nice thing to do. Just adding that data mining isn't the only reason for some companies to want people to use their apps.
I study Apple's Privacy Nutrition Labels religiously every time I consider installing an app.
I like the ones with "Data Not Collected".
Here's a good overview of the problem: https://arxiv.org/abs/2206.02658v3
Reminds me of meat processing regulations. I can sell my animals whole to buyers through a custom processing exemption, but they must go pick up their meat from the butcher. The law says I cannot pick up and deliver it, but it is trivial to find people advertising that extra service. Reporting them does not result in any obvious action.
In both of our cases, our honesty is a liability in the marketplace, because people are ignorant of such laws (or simply don’t care). Really, they simply want the product that they want, as conveniently as possible. We are then forced to compete in the marketplace with liars and cheats.
I am sure our peers here can find countless examples in other areas where this flavor of dishonesty prevails. Hell, I would love to hear some counter examples, because I cannot help but view this state of affairs as intentional at this point.
The purpose of system is what it does (or, in this case, does not do).
Screen real estate is precious on phones, so being able to permanently block "Install our app!" and even entire navigation categories (shorts on LinkedIn) is quite valuable.
Then you can "install" the site on your home screen or simply place it in collection folders so it's sitting ready on your "New Tab" page.
While browsing, there are also popups offering the app approximately every third link I click. Some of them are telling me to install the app.
Unless the situation has changed recently, it's not perfectly fine, it is unusable on purpose.
"The app is great because the website is heavily degraded".
They are compared / contrasted. Nobody is saying one is concretely related to the other.
On Amazon I never see products like that. That's why I prefer Amazon (and Coolblue and bol.com in Belgium).
Case in point, fake 2TB Sandisk ExtremePro microSD:
- £17 on eBay: https://www.ebay.co.uk/itm/336728033240 - even the images prove it's a fake (also $570 on sandisk.com)
Agreed, there's more of that on AliExpress but Amazon is not free from that either.
Not a £1 tat, and not one off. Not that AliExpress is my choice, no, far from it. Sometimes it's better, closer to the manufacturer, that's all.
Similar to how I use Amazon Prime but would never order something I ingest, put on my skin, or (usually) wear from it.
Not elitest.
edit: quantity qualifier
I noticed that Voice Over (iOS screen reader) crackles and randomly changes volume when using the app, but I attributed it to standard iOS weirdness, and possibly misuse of some iOS API. Now I'm thinking that this may very well be fingerprinting.
However, I'd bet that many people will gladly allow aliexpress to play audio as there are probably videos on the site that people want to play and listen to.
With that said, its possible that this can be only a use once permission. Even if I want to shop at aliexpress if I know they are doing this, I'll be more willing to be bothered every time I want to play a video with audio to approve it if this bothers me.
At the very least, governments and institutions should develop a framework to investigate all acquired technology. The community / civil society could also create something similar, a script that would analyse at a deep level everything that can be analysed with a piece of software even by a complete novice.
That would be unreasonable, I argue. No one should have to worry about the security of their devices and data privacy based on which OS they use. Whilst it can be argued that different OSs serve different needs, privacy and security should not be debatable. In fact, most countries have dedicated legislation for this; whether it's just, applied correctly, or serves the public before any other party are indeed discussions to be had.
Of course, I am also a horrible hypocrite and will actually use websites that use features like WebUSB or WebRTC.
Obviously apps can tell if they haven't been granted a permission (even if you tried to fake this, they aren't dummies and will know if it's not working), and obviously third party software isn't under any obligation to work without them.
But the platforms have done what the platforms can do, at the architecture side, really. The next stage is human-audited enforcement of malware, which this AliExpress nonsense might hopefully run afoul of.
By design. This doesn’t need to be the case. It should be impossible to tell you have denied a permission.
In TFA’s case, the browser could just keep processing audio but never hook it up to a real audio sink.
Likewise for any other hardware access you want, and most of them are harder. How do you fake local storage without storing anything? How do you fake Bluetooth access without virtualizing an entire device? Do you fake the screen dimensions to look like something else? Input latency? Where does it stop?
No, "does this work" is among the easiest questions to answer in technology. We aren't going to win this war.
How can they tell? For the permissions I can think of: location, filesystem, etc. it should be easy to lie/spoof.
[1] https://blog.nem.ec/2020/05/24/ebay-port-scanning/
[2] https://iter.ca/post/reddit-whiteops/
I'd argue it's "silent" though: aliexpress wakes up my audio card if nothing plays, which results in a very faint "pop" sound every time I open the tab.
It's been this way for ~3+ years at least.
The title of the article literally mentions "WebAudio", and the first paragraph states that the author is using a PC. The second paragraph mentions Chrome and Firefox.
Apple and the App Store have zero involvement here.
This is nonsense. Safari also supports Web Audio. Safari does not, however, support Microsoft Windows, which is why the article author didn't mention it.
Moreover, all web browsers on iOS have to use Apple WebKit, so Web Audio support is not actually the fault of the non-Apple browser vendors.
My local 'newspaper' website is chock full of scam adverts. The print version is dignified. The website people, somehow, turn a blind eye.
And I got an advert on Youtube this week using sexually explicit language to sell pills.
Feels like standards, and expectations, have really slipped.
No sound playing but the audio would change like the microphone was being activated. I checked permissions to make sure there was no mic access and figured that they were fingerprinting.
I wouldn't be surprised if what I'm feeling is all a psychological thing where consumers associate jank with low prices so that's why sites like AliExpress and Temu look like a complete technical mess when in reality they're doing pretty advanced stuff like this.