How should we view the use of hidden Web Audio API processes by AliExpress for browser fingerprinting?

Is AliExpress's Hidden Audio Fingerprinting an Acceptable Security Measure?

A recent investigation has revealed that the AliExpress website uses hidden Web Audio API processes that can disrupt Bluetooth multipoint functionality. The discovery shows that Alibaba's anti-abuse scripts, specifically collina.js and fireyejs.js, create active audio contexts that keep the system audio path engaged even when no sound is audible to the user. By setting the gain to zero, these scripts perform 'audio fingerprinting'-a technique that measures subtle hardware and software variations to create a unique device identifier. This helps Alibaba's security tools identify bots and fraud, but it creates a significant side effect: because the browser is technically 'playing' audio, Bluetooth headphones remain locked to the PC and cannot automatically switch to a connected phone. While this method is a powerful tool for combatting browser abuse and identity theft, it operates stealthily without visible media elements, raising serious questions about the boundary between essential security and invasive device tracking.

Options

  • It is a necessary tool for anti-abuse and fraud prevention.
  • It is an invasive violation of user privacy and tracking.
  • It is acceptable only if it does not impact device usability.
  • Browsers should implement stricter regulations to block it.

Pollopolis — the city of opinion