HomeMalware & ThreatsAlibaba's AliExpress Employs Hidden Audio for Device Fingerprinting

Alibaba’s AliExpress Employs Hidden Audio for Device Fingerprinting

Published on

spot_img

Endpoint Security,
Fraud Management & Cybercrime,
Internet of Things Security

Bluetooth Routing Error Exposes Probe Designed to Operate Invisibly

A security researcher revealed that AliExpress employs hidden audio objects within its browser security and anti-abuse tools to gather device information. (Image: Shutterstock)

In an alarming discovery, a software developer noticed that his Bluetooth headphones ceased functioning whenever he navigated to the shopping page of the Chinese retailer Alibaba. Upon investigation, it was revealed that the website utilized silent audio functions to fingerprint devices and users, raising significant concerns about privacy and data collection practices.

According to the developer, Matt Callaghan, AliExpress incorporates hidden audio objects in its security measures to gather a variety of device information. These details encompass installed browser plugins and interactions, such as mouse movement and scrolling behavior. The method relies on minute variations in the device’s processing of audio signals to track users, as he detailed in a recent blog post.

Experts in cybersecurity underscore that such tracking techniques, primarily known as browser fingerprinting, have become standard across the industry. However, the current controversy surrounding Alibaba stems from an error in implementation that caused audio signals intended to operate in the background to inadvertently surface in a user’s audio output. This anomaly not only disrupted the user experience but also highlighted potential flaws in user invisibility that fingerprinting methods typically uphold.

Collin Hogue-Spears, a senior director at Black Duck, noted that the incident violated a fundamental principle of fingerprinting practices, stating that these methodologies should always remain unobtrusive. He elaborated that typically, fingerprint probes are designed to render into an off-screen buffer that a user’s operating system overlooks. In this case, however, the scripts managed to route audio to the active system output, which resulted in connected devices, such as a Bluetooth headset, inadvertently shifting from one device to another due to what was perceived as an active audio stream.

In conducting his tests, Callaghan discovered that the scripts utilized a sawtooth oscillator to produce a waveform when operating within both Firefox and Chrome browsers, which were the only two platforms examined. Interestingly, Firefox managed to respond swiftly by reinforcing its privacy measures, asserting that its protection mechanisms were effectively preventing such intrusive tracking methods.

AliExpress sought to discreetly monitor users’ activities; however, it faced challenges from Firefox’s anti-fingerprinting capabilities. The Firefox team took to social media platform X to underscore that their browser had resisted the tracking efforts.

Despite attempts to obtain a comment from Google regarding its Chrome browser’s performance against these tracking methods, details remain sparse. Nonetheless, a security engineer at Firefox, Tom Ritter, indicated that Chrome, Brave, and Safari likely have built-in defenses to mitigate such privacy invasions.

Brave, another privacy-centric web browser, reemphasized that fingerprinting presents a technique for websites to identify users without the reliance on cookies. Unlike traditional cookies, which maintain user activity history, WebAudio fingerprinting segments devices based on their distinctive operational characteristics. This method inherently lacks the transparent mechanisms that cookies offer, creating a more secretive data collection environment.

Brave described the method: slight discrepancies occur in how different devices reproduce the same audio file, influenced by a range of factors, including the CPU architecture and sound card variations. When AliExpress played the silent sound, these nuances were measured to formulate device fingerprints, making the site capable of tracking user activities without overt detection.

To combat various forms of fingerprinting, including audio and GPU-based techniques, Brave implements random data injections into the output from its browser, effectively altering the fingerprint presented to different sites and ensuring that it resets across user sessions. This proactive strategy is designed to enhance user privacy and limit unwanted data collection.

More than three years prior, Firefox integrated enhanced fingerprinting protections within version 118, categorizing its users into broad groups. This grouping effectively disguises unique identifiers of individual systems, allowing users to look similar within each defined category. However, Ritter highlighted that this protective layer wasn’t foolproof, as a small percentage of Firefox users—less than one percent—might still be vulnerable due to potential hardware issues or unique computational architectures.

Although these protective measures exist, concerns linger about the broader implications of such transparent user profiling methodologies. Jason Soroko, a senior fellow at Sectigo, expressed apprehension regarding the silent profiling taking place on commonplace shopping pages prior to users entering sensitive areas like login or payment gateways. He emphasized the need for legitimate data collection practices that align with ethical standards regarding necessity, proportionality, retention, and user disclosure. Even an ineffective audio fingerprint posed risks as evidence of overreaching profiling techniques.

Source link

Latest articles

Researchers Discover Thousands of Exposed AWS Keys

The Ongoing Threat of Leaked AWS Keys: A Security Wake-Up Call Recent revelations from security...

Zimbra Collaboration Suite Vulnerability Actively Exploited to Execute Arbitrary Commands

Urgent Security Alert: Exploitation of Vulnerability in Zimbra Collaboration Suite A critical security vulnerability has...

Fake Codex Download Utilizes Google Sites to Distribute macOS Malware

A recent investigation by Cato Networks has unveiled a sophisticated fraudulent campaign masquerading as...

AnMed Confirms Data Theft and Warns Patients About Criminal Scams

Ransomware Gang The Gentlemen Claims Theft of 6TB of Sensitive Patient Information from AnMed...

More like this

Researchers Discover Thousands of Exposed AWS Keys

The Ongoing Threat of Leaked AWS Keys: A Security Wake-Up Call Recent revelations from security...

Zimbra Collaboration Suite Vulnerability Actively Exploited to Execute Arbitrary Commands

Urgent Security Alert: Exploitation of Vulnerability in Zimbra Collaboration Suite A critical security vulnerability has...

Fake Codex Download Utilizes Google Sites to Distribute macOS Malware

A recent investigation by Cato Networks has unveiled a sophisticated fraudulent campaign masquerading as...