开发者称,蓝牙漏洞揭露了阿里巴巴对用户的秘密追踪。
Bluetooth Glitch Exposes Alibaba's Secret Tracking Of Users, Developer Says

原始链接: https://www.zerohedge.com/technology/bluetooth-glitch-exposes-alibabas-secret-tracking-users-developer-says

一位开发者最近发现,全球速卖通(AliExpress)一直在使用隐藏的浏览器脚本进行“音频指纹识别”。这是一种能够绕过传统 Cookie 拦截器的隐蔽追踪方法:该网站利用 Web Audio API 播放人耳无法察觉的零音量声波,以此测量用户的特定硬件(如 CPU 和声卡)处理该信号的方式。这些独特的处理差异会与其他设备数据(如屏幕分辨率和内存)相结合,生成一个能够跨网站追踪用户的持久标识符。 这一问题是在该开发者注意到其蓝牙耳机在速卖通页面打开时持续处于连接状态(尽管没有播放任何声音)后被发现的。注重隐私的 Brave 浏览器证实了这些发现,指出即使在静音状态下,这些脚本也会保持电脑音频处理系统的活动状态。 Brave 强调了这一发现,旨在凸显反指纹识别技术的必要性。该公司解释称,其浏览器通过向音频输出中注入随机数据来主动保护用户,从而防止网站生成稳定且可识别的指纹。此事件凸显了隐蔽追踪技术日益复杂化,以及互联网用户正面临持续的隐私挑战。

相关文章

原文

A San Francisco-based developer discovered that Alibaba Group's AliExpress marketplace secretly hijacked his computer's audio system through hidden browser scripts, allowing the website to run inaudible sound waves at zero volume to create "fingerprints" used to track devices without relying on cookies. 

The privacy-focused Brave browser revealed in a series of X posts that the AliExpress marketplace was keeping the developer's computer audio system active through hidden browser scripts, potentially allowing the website to generate a unique identifier for his device.

The issue emerged when the developer's Bluetooth headphones refused to transfer their audio connection from his computer to his phone while AliExpress was open. A deeper dive of the website's code showed background scripts maintaining access to the computer's audio-processing system without producing audible sound.

The scripts allegedly used the browser's Web Audio API to process signals at zero volume. Small differences in how individual computers handle those signals can be measured and combined into an "audio fingerprint," allowing websites to recognize devices even when cookies are deleted or blocked.

The developer also found that the scripts collected other device characteristics, including available memory, screen dimensions, and network information.

Here's what Brave found:

1. Alibaba's AliExpress was caught using users' audio systems to track them. AliExpress wasn't recording users but instead playing a silent sound and measuring how users' specific devices processed it in order to fingerprint them.

2. Fingerprinting is a way that websites can identify you without cookies. Sites will note details about your device like your screen size or installed fonts. These details are then combined into a unique, persistent "fingerprint" that can be used to track you across the Web.

3. There are slight variations in how each device plays the same audio file due to differences in CPU, sound card, browser, etc. When AliExpress played the silent sound, it measured these small variations to help build fingerprints of users' devices.

4. This tracking was discovered due to an unexpected side effect. A user with Bluetooth headphones noticed they couldn't play music on their phone because the headphones were instead playing AliExpress's silent sound from their PC.

Brave turned what it found into a sales pitch for its browser:

1. For 6+ years, Brave has protected users against audio fingerprinting, and other fingerprinting types, by default. Brave injects random data into the browser's output so you show a different fingerprint to different sites. This fingerprint also resets across sessions.

2. Trackers are constantly finding new ways to fingerprint your device, so Brave keeps adding new protections. We recently added defenses against GPU fingerprinting, which stops sites from identifying you with your graphics card or drivers.

The findings raise new questions about browser fingerprinting, a stealthy way that uses silent audio processing for covert tracking. 

联系我们 contact @ memedata.com