Tag

Fingerprinting

All articles tagged with #fingerprinting

privacy1 day ago

Silent audio fingerprinting: AliExpress tracks devices without consent

A researcher found that AliExpress quietly fingerprints devices by emitting silent audio via the WebAudio API and collecting data like canvas, WebGL, hardware, and interaction details, sending fingerprints to Alibaba telemetry servers with no user notice or consent. Privacy-focused browsers such as Brave can block these scripts, highlighting concerns over fraud controls vs. user privacy.

AliExpress fingerprinting exposed as obsolete inaudible-audio trick
technology2 days ago

AliExpress fingerprinting exposed as obsolete inaudible-audio trick

Researchers found AliExpress used an obsolete inaudible-audio WebAudio fingerprinting trick to identify visitors via hidden scripts that analyze audio waveforms; Firefox’s 2023 fix with constant libraries and protections in Chrome/Safari have largely neutralized this method, though the retailer still relies on a suite of other fingerprinting techniques.

AliExpress accused of stealth audio fingerprinting that even disrupts Bluetooth headsets
cybersecurity2 days ago

AliExpress accused of stealth audio fingerprinting that even disrupts Bluetooth headsets

A security researcher alleges AliExpress used an obfuscated WebAudio-based fingerprinting method that emits inaudible audio to the browser to gather device/browser data, which reportedly disrupted Bluetooth headphones for a user; Firefox says its anti-fingerprinting protections mitigate this technique, Brave says it blocks the involved scripts, while Chrome/Safari have defenses; AliExpress has not commented publicly.

Silent Web Audio Fingerprinting Sparks Privacy Debate on AliExpress
technology2 days ago

Silent Web Audio Fingerprinting Sparks Privacy Debate on AliExpress

Researchers found a zero-volume Web Audio API script on AliExpress that taps the computer's audio hardware to generate a device fingerprint without cookies, collecting a range of signals and raising privacy concerns. Brave has blocked the script and warned fingerprinting will keep evolving, while other blockers may mitigate it at the cost of some site functionality, and the technique could even interfere with hardware like Bluetooth headphones.

Europe’s New EES Border System Triggers Hours-Long Airport Delays
travel1 month ago

Europe’s New EES Border System Triggers Hours-Long Airport Delays

European airports are facing up to five-hour waits due to the EU’s new Entry/Exit System (EES), which fingerprints travelers and scans faces at border checks. The rollout overwhelmed many hubs, prompting calls from industry groups to suspend EES as peak travel season looms. While the European Commission has shown limited flexibility, delays persist; travelers—especially Americans—are urged to pre-register, avoid short layovers, and keep up with entry requirements, with airlines pressing for relief and guidance.

FROST attack uses browser storage timing to fingerprint open sites and apps
technology3 months ago

FROST attack uses browser storage timing to fingerprint open sites and apps

Researchers describe FROST, a browser-based side-channel that measures SSD access latency via the origin private file system (OPFS) to infer which sites a user has open and which apps are running, enabling cross-site fingerprinting with no user interaction. The attack relies on large OPFS files and reads from the same SSD, limiting scale and making detection likely; mitigations include capping OPFS size or other browser changes. The work was demonstrated on macOS and is slated for presentation at the DIMVA conference.

OPSEC Playbook Reveals How Threat Actors Stay Hidden at Scale
technology3 months ago

OPSEC Playbook Reveals How Threat Actors Stay Hidden at Scale

Flare researchers analyze a threat actor’s OPSEC playbook for high-volume fraud, detailing a three-tier architecture (public, operational, extraction) designed to separate exposure, execution, and monetization, along with common mistakes like identity reuse, weak fingerprinting evasion, and poor stage separation. The attacker also describes resilience techniques (time-delayed triggers, behavioral randomization, distributed verification, dead-man’s switches) to extend operational longevity. Defenders are advised to focus on cross-platform identity correlation, advanced behavioral analytics, end-to-end monitoring of the attack chain, metadata analysis, and preparing for resilient adversaries.

"Human-Caused Climate Change Evidenced by Sea Surface Temperature Research"
environment2 years ago

"Human-Caused Climate Change Evidenced by Sea Surface Temperature Research"

New research on sea surface temperatures provides clear evidence of a human "fingerprint" on climate change, showing that specific signals from human activities have altered the seasonal cycle amplitude of sea surface temperatures. The study reveals a strong human-caused signal in the seasonal cycle of ocean surface temperature, with significant impacts on marine ecosystems and potential wide-ranging effects on fisheries and nutrient distribution. The research also emphasizes the importance of understanding the anthropogenic influence on seasonality and the critical role of oceans in regulating planetary climate systems.

technology3 years ago

Apple strengthens privacy measures in App Store API rules

Apple is implementing new rules in its App Store API to crack down on apps that collect data on users' devices for fingerprinting purposes. Starting with the release of iOS 17, developers will be required to explain why they are using certain APIs, and apps failing to provide a valid reason will be rejected. Fingerprinting apps use API calls to retrieve device characteristics and create a unique "fingerprint" to track users across different apps and websites. This move follows Apple's previous efforts to enhance user privacy, including requiring permission for app tracking in iOS 14.5.

Mullvad Browser: The Ultimate Privacy Solution with VPN and Tor Integration.
technology3 years ago

Mullvad Browser: The Ultimate Privacy Solution with VPN and Tor Integration.

The Tor Project has partnered with Mullvad VPN to launch a privacy-focused browser called Mullvad browser, which connects to a VPN instead of the decentralized onion network. The browser aims to reduce a user's browser fingerprint, making it harder for advertisers and other companies to track them across the internet. It blocks third-party cookies and trackers and comes with few pre-installed plugins to reduce a user's fingerprint even further. However, the measures are less helpful if a user is trying to hide from government and law enforcement tracking.