Should companies like Alibaba be permitted to use the Web Audio API for browser fingerprinting if it interferes with hardware features like Bluetooth multipoint?

AliExpress's Silent Audio: A Security Measure or a Privacy Intrusion?

A recent investigation has revealed how AliExpress, utilizing Alibaba's security scripts collina.js and fireyejs.js, employs the Web Audio API for browser fingerprinting. While these scripts are designed for anti-abuse and security, they use a method involving an AudioContext that generates an oscillator and an analyzer. Although the gain is set to zero-making the audio inaudible to the user-the browser is still actively processing the audio graph. This seemingly harmless process has a significant side effect on hardware functionality: it keeps the system's audio path active. Specifically, for users with Bluetooth multipoint headphones, this prevents the headphones from automatically switching audio streams from a PC back to a mobile phone when the PC is idle. This technique, known as audio fingerprinting, allows companies to identify unique devices by measuring subtle differences in how audio is processed by various hardware and software configurations. The discovery highlights a growing tension between the need for robust anti-fraud measures and the preservation of user privacy and device interoperability.

Options

  • It is a necessary security measure to prevent fraud and bot abuse.
  • It should be permitted only if it does not impact hardware functionality.
  • It is an invasive privacy violation that should be strictly regulated.
  • Browsers should implement stricter controls to block silent audio processing.

Pollopolis — the city of opinion