Latest News

AliExpress Caught Secretly Listening to Users for Fingerprinting

AliExpress has been found using hidden browser scripts that can listen to users while they’re browsing the website. These scripts generate inaudible audio signals as part of a wider system for fingerprinting visitors’ devices.

The discovery came from developer Matthew Callaghan, who noticed that music playing from his phone would suddenly stop whenever the AliExpress website was open on his PC.

His headphones supported Bluetooth multipoint, allowing simultaneous connections to his phone and computer. Closing the AliExpress tab immediately restored playback, while muting the website, Firefox, or Windows made no difference.

How AliExpress Was Listening

Callaghan investigated the issue and found that AliExpress was not playing a hidden video, advertisement, or conventional audio file.

Instead, two heavily obfuscated Alibaba scripts called collina.js and fireyejs.js were creating active WebAudio processing contexts in the browser.

The scripts generated a known sawtooth waveform, analysed how the browser and computer processed it, and read the resulting frequency data.

The final volume was set to zero, meaning users could not actually hear the sound.

However, because the audio processing graph remained connected to the computer’s audio output, the browser continued processing it. On Callaghan’s setup, this was enough to keep the PC audio connection active and prevent his Bluetooth headphones from switching properly back to his phone.

It Collects More Than Audio Data

The WebAudio test is only one part of a much broader browser fingerprint.

Callaghan found that the scripts also collected or measured information involving Canvas rendering, WebGL, screen and viewport size, device pixel ratio, hardware concurrency, device memory, supported media formats and WebRTC behaviour.

They also examined browser performance data, plugins, mouse and touch activity, scrolling, focus events, motion and orientation information, and signals commonly associated with browser automation.

Combining these characteristics can help distinguish one browser or device from another even without relying solely on conventional tracking cookies.

The scripts appear to form part of Alibaba’s AWSC security and anti-abuse infrastructure, suggesting the technology may be intended for fraud prevention.

However, Callaghan noted that the fingerprinting runs on the general AliExpress homepage before users perform sensitive actions such as logging in or making payments.

Blocking the Scripts Stops the Audio Issue

The developer tested blocking the two fingerprinting script families with uBlock Origin.

After they were blocked, AliExpress continued loading normally during his test, while the hidden AudioContext connections disappeared and his Bluetooth multipoint problem stopped.

He cautioned that blocking security-related scripts could potentially cause additional CAPTCHAs or interfere with login and payment checks.

The investigation does not establish how long Alibaba keeps these fingerprints or whether the information is linked across other Alibaba services. It does, however, show that extensive device and behavioural measurements are being collected and transmitted from the AliExpress website.

The post AliExpress Caught Secretly Listening to Users for Fingerprinting appeared first on ProPakistani.

Show More

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button

Adblock Detected

Please consider supporting us by disabling your ad blocker