Privacy

Developer alleges Alibaba uses audio fingerprinting for web tracking

A developer has raised concerns about Alibaba potentially tracking web users by exploiting audio fingerprinting vulnerabilities in browsers. The issue came to light when the developer noticed his Bluetooth headphones malfunctioning when visiting Alibaba’s website, based on information published by The Register.

Software engineer Matt Callaghan discovered that Alibaba's website employed obfuscated audio scripts that generated a waveform and analyzed its output. Although the audio gain was set to zero, preventing users from hearing anything, the WebAudio graph was processed by the browser. This process, Callaghan claims, was sufficient to maintain an active audio path, interfering with his Bluetooth headphones' ability to switch audio sources. Further analysis of the code revealed attempts to collect data such as screen dimensions, device memory, and browser plugins, suggesting a comprehensive device fingerprint.

While Firefox stated its anti-fingerprinting technology, introduced in version 118, effectively neutralizes WebAudio-based fingerprinting by grouping users into broad categories, a small number of users may still be uniquely identifiable. Brave also confirmed its browser blocks such tracking methods by default. Other browsers like Safari have similar protections, while Chrome was noted to have fewer built-in defenses against various fingerprinting techniques, according to privacy consultant Alexander Hanff.

Source: The Register

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds