About Us
Imagen destacada
  • Business
  • Politics
By 4ever.news
18 hours ago
National Security Alarm: Chinese AliExpress Caught Covertly Spying on Millions of American Devices
Chinese-Owned AliExpress Caught Fingerprinting Americans' Devices
Chinatopix via AP

It has long been a foundational principle of American freedom that citizens have a right to privacy, especially in their own homes and with their own devices. Yet, a recent revelation exposes a disturbing breach of that trust, courtesy of a Chinese-owned shopping giant that has been quietly running surveillance code deep inside Americans' browsers. This isn't just about cookies; it's about digital fingerprinting, and it took a broken pair of Bluetooth headphones to pull back the curtain on this shadowy operation.

AliExpress, the online marketplace controlled by Chinese behemoth Alibaba, was discovered to be running hidden audio-processing scripts in visitors' browsers, all part of an extensive and deeply concerning device-fingerprinting scheme. The astonishing discovery came to light when developer Matthew Callaghan noticed a bizarre anomaly: every time he opened AliExpress on his computer, music playing through his phone would inexplicably stop.

Callaghan, who uses Bluetooth headphones capable of connecting to both his phone and PC simultaneously, observed that his headphones typically revert to his phone when his computer ceases audio output. AliExpress, however, disrupted this normal behavior, despite the site playing no visible video, advertisements, music, or any other audible content. The immediate fix? Closing the AliExpress tab. Neither muting the tab, the browser, nor Windows itself made a difference. This glaring inconsistency prompted him to start digging into the site's hidden code.

What Callaghan uncovered was far more insidious than a simple malfunctioning advertisement.

Two heavily obfuscated scripts, part of Alibaba's browser security and "anti-abuse" tools, were creating hidden WebAudio processes. These scripts covertly generated an inaudible waveform, analyzed how the user's browser processed it, and then meticulously read the resulting data. The volume was deliberately set to zero, ensuring users heard nothing – a perfectly silent digital spy.

Callaghan laid bare the technical deceit:

"The oscillator generates a known waveform. The analyser measures the result after it has passed through the browser's audio implementation, and the script reads frequency data from it."

It is critical to understand that AliExpress was not activating users' microphones or recording conversations. Instead, this system generated its own internal signal and meticulously examined how a specific computer processed it. Subtle variations in processors, operating systems, drivers, browsers, and audio libraries all produce distinct results. These unique digital signatures can then be compiled into an unalterable "digital fingerprint" used to distinguish one device from another, regardless of user attempts to clear cookies or use private browsing modes.

And this audio component was just one piece of a much larger puzzle.

Callaghan further exposed that the same scripts were querying and measuring a vast array of other data points: canvas rendering, WebGL graphics information, screen and viewport dimensions, device memory, browser plugins, WebRTC behavior, browser performance, mouse and touch activity, and even device motion. He also found explicit code designed for encrypting and transmitting these results directly to Alibaba telemetry services. His conclusion? This amounted to a "fairly comprehensive browser and device fingerprint."

This distinction is paramount because traditional cookies are relatively easy for Americans to delete or block. Browser fingerprinting, by contrast, seeks to identify and track a machine based on its inherent, unique characteristics. While Alibaba predictably claims its security tools merely fight fraud, Callaghan's analysis of the browser code revealed no way to determine how the company actually uses this sensitive data once it leaves an American's machine, or for how long it is retained. Even more alarming, there’s no way to know if this extensive fingerprint follows users across other Alibaba properties. Americans innocently shopping on AliExpress are left entirely in the dark, with no knowledge of what Beijing-linked servers are doing with a detailed profile of their personal devices.

While modern browsers like Firefox and Chrome have reportedly addressed the specific audio fingerprinting technique, this offers cold comfort. The audio trick was merely one of more than a dozen data collection methods running simultaneously. The rest of this sprawling surveillance operation remains fully intact and active.

The same AliExpress scripts were harvesting countless other data points crucial for creating a robust device fingerprint, all while users received no discernible indication that a simple shopping homepage had begun deeply probing their hardware and browser environment.

"Personally I do not want a shopping homepage silently exercising my graphics, audio, WebRTC, hardware, and motion APIs, etc, to track my behaviours, especially if it has such an annoying effect as blocking my music."

For those seeking to protect their privacy, the Brave browser reportedly blocks these AliExpress scripts outright. Callaghan, a meticulous investigator, chose a different path, adding specific rules to uBlock Origin, which he confirmed stopped the hidden audio processes. The lesson is clear: clearing cookies is ineffective here because the fingerprint is not built upon them. Similarly, Incognito mode offers no shield, as it doesn't make your unique hardware or browser setup vanish. Unless a browser explicitly blocks these techniques or the user manually configures advanced filter rules, AliExpress can, and does, run these invasive checks every time the page loads.

Just recently, Congress attempted to force TikTok out of the American market, citing grave fears about Chinese access to American user data. Now, Alibaba, another massive Chinese entity, operating AliExpress—a platform utilized by millions of American shoppers—has been caught red-handed, quietly and extensively fingerprinting their devices. The question writes itself: why the double standard? Why is one Chinese data threat addressed, while another, equally insidious, operates in the shadows, compromising American privacy and national security? This isn't merely about inconvenient headphones; it's about safeguarding America's digital sovereignty and holding foreign adversaries accountable for their covert surveillance on our soil.