My Bluetooth Speaker Made Me Think That eBay Was Being A Big Jerk (But It Wasn’t)
I recently added a nice little Bluetooth speaker to my home/office audio setup. I’m liking it a lot! And I’ve discovered a lovely little feature that isn’t listed on the product page:
It helps you spot jerks when they’re being jerks because they’re total jerks!!!
Last night, I was doing a little shopping on eBay, purchasing some items that I deemed to be absolutely essential (I assure you) to the continued peace and stability of the Empire.
I was also finding out what the fellows at Bad Obsession Motorsport had gotten up to since the previous “Project Binky” video. I was watching YouTube on my iPad, which was connected to the speaker.
The video paused itself, for no reason! If you know those incorrigible lunatics Nik and Richard, you wouldn’t put it past them to insert a fake pause as a gag. Nope, genuine pause. I tapped the screen to resume the merriment.
The second time it happened, I identified it as an actual Thing. After blinking my eyes only twice, I gave a world-weary sigh.
“eBay is fingerprinting my MacBook via audio, isn’t it?”
My multipoint Bluetooth speaker was simultaneously connected to the iPad and the MacBook. The behavior is what always happens when the speaker is playing something from Device "A" and then Device "B" starts making noise.
But I hadn’t heard anything from the MacBook. So: eBay.com was definitely manipulating its audio in a stealthy way. The technique is notoriously employed by data brokers, to get around browser privacy controls.
(Coincidentally, I recently introduced the Members/supporters of this site (thank you!) to a new legal principle: Nequita Hominum — “people suck.” It was intended as a one-off joke. I probably ought to save that to a Stickies note or something because I’d definitely get a lot of use out of it.)
Well, normally I’d take my fight directly to the global panopticon and bring it to heel, for the good of all, whatever the personal cost. But I just wanted to watch my video. So I just clicked the little Settings button next to the URL in the address bar and revoked eBay.com’s sound permissions. Problem solved.
I nonetheless still had quite a head of steam worked up today! During my walk to the library I started mentally composing a real ripper of a takedown!
“eBay is a bunch of jerks being jerks, because they’re total jerks,” I said, out loud, as I crossed a footbridge. “Ha! That’s good stuff.” The noise attracted the attention of a squirrel on a nearby fencepost. Whether it agreed or disagreed with my assessment, it kept its opinion to itself.
But much like Giorgio Germont, who furiously confronts Parisian courtesan Violetta Valéry in the climactic Act II baritone aria Pura siccome un angelo, iddio mi diè una figlia, I discovered that my anger was misplaced. A duet along the lines of Dite alla giovine, sì bella e pura was more appropriate to the situation.
(“Oh, God,” you’re thinking. “He’s slapping in a cutaway to a popular Reddit meme, just to look cool. How sad!”)
eBay.com had definitely been interfering with my multipoint speaker. It was manipulating the audio subsystem to fingerprint my MacBook. Though this is all done silently, it was tripping up the speaker.
A little research reveals that it’s not a marketing technology. It’s security tech…LexisNexis ThreatMetrix, specifically.
Yeah, it’s identifying my Mac by performing an end run around whatever privacy tools the browser and I have set up. But it’s all to the good. eBay is a ripe target for all kinds of fraud. This fingerprinting serves as additional reassurance that the user is a known entity; it contributes to a kind of “risk of fraud” score.
Drat. Maybe they’re not being jerks.
This fingerprinting info is shared with entities outside of eBay. As a lover of self-righteous snark, I am disappointed to learn that the group is a consortium of banks, payment processors, and e-commerce platforms. They all use the data in similar fashion: it’s a kind of chain of trust between financial and commercial institutions.
Disabling it as I did won’t prevent me from buying things on eBay. The lack of this additional signal might lead to eBay sending me to two-factor authentication or a reCAPTCHA-type of verification more often than if I left it up and running.
There are even some legal firewalls in place (including the EU’s GDPR) that forbid LexisNexis from exploiting this information outside of its intended purpose (by selling it to data brokers, for example).
Well, that stinks. I was so looking forward to running into the middle of the digital town square, shouting slogans and waving the red banner of revolution.
Wait! I encountered the same issue with X.com on that very same night! It’s run by King Jerk himself! LexisNexis isn’t the only outfit that uses audio browser fingerprinting…surely X was using it nefariously!
Dammit. I just can’t catch a break!
It turns out that X pre-heats your browser so that video autoplay works cleanly. It does that via a clumsy technique that similarly trips up Bluetooth Multipoint.
The core problem here is that “Bluetooth Multipoint” is a marketing term, not a formal industry standard defined by the Bluetooth Special Interest Group. It uses the SIG’s multi-profile specifications and its transport protocols in a way that works…mostly. This is a well-known problem that can affect any speaker, regardless of price.
Well, if it's such a well-known problem, why hasn't it been solved?
It most certainly has! There’s a clean, W3C-standard way for LexisNexis to perform audio fingerprinting that doesn’t trip up Bluetooth. And X.com could solve its (slightly different) problem just by making their code a teensy bit more polite. But neither organization seems to care to care too much about it.
Finally! Something legitimate to snark about! But it’s late in the afternoon and I’m too tired to be mean.
Needless to say, audio fingerprinting is being exploited by plenty of other entities, many of which don’t have site performance or anti-fraud in mind. Privacy-oriented browsers such as Brave still treat it like an active threat, which it is.
That said, if a site is using actual audio fingerprinting, there’s a good chance that it’s to enhance security and reduce fraudulent transactions, especially on a site where money changes hands.
Can’t win ‘em all, I guess. I’m sure I’ll encounter something to legitimately complain about before too long. Nequita Hominum, right?