A hot potato: As cookies become a less reliable way to track people online, AliExpress may be showing how far companies will go to fill that gap. Researchers found code on the site’s homepage that ran silent audio processes in the browser. Tied to Alibaba’s security systems, the scripts tap a device’s own audio hardware to generate a signal and measure the tiny, device-specific ways it comes back – producing something close to a fingerprint that doesn’t need a single cookie to work. It’s the kind of tracking a user would likely never notice.

The issue only surfaced after a developer had trouble using multipoint Bluetooth headphones while an AliExpress tab was open: the headphones wouldn’t switch properly from the computer to a phone. Once the tab was closed, the problem disappeared.

Digging into the site’s code, the developer found it was using the Web Audio API to build audio-processing graphs set to zero volume. The process produced no audible sound, but it still connected to the computer’s audio system, keeping the audio path active in the background, which appears to be what interfered with the headphones’ ability to switch devices.

This wasn’t the kind of audio activity tied to a normal media player. Because the processing graph ran at zero gain and connected directly to the system’s audio output, muting the browser tab did nothing to stop it: the browser kept processing the signal even though there was nothing to hear.

  • just another dev@lemmy.my-box.dev
    link
    fedilink
    English
    arrow-up
    7
    ·
    17 hours ago

    For what it’s worth, the European tracking law doesn’t give a shit whether you use cookies, localstorage, fingerprinting or pigeons to track people. If you do not consent, it’s not allowed.

    Then again, good luck enforcing China to comply.

    • Zerush@lemmy.ml
      link
      fedilink
      arrow-up
      1
      ·
      2 hours ago

      It’s irrelevant if the provider is from the EU or not, all of these are forced to fullfit the privacy law if they want to operate in the EU, even Microsoft itself: big difference between Microsoft US, full of trackers and even keyloggers (Towerdata), and Microsoft DE with 2 cookies.

    • ohshit604@lemmy.halstead.host
      link
      fedilink
      arrow-up
      4
      ·
      edit-2
      16 hours ago

      Then again, good luck enforcing China to comply

      I mean, can’t they force DNS providers and ISP’s to block the domain in their region until they come into compliance?