10 interesting stories served every morning and every evening.

I'm Upset Again About a Co-Creator of RSS Being Prosecuted For Something Meta Is Doing With Little Consequence

blog.curiousquail.com

Also here’s a cool un­re­lated photo of a chip­munk

Look at this lit­tle guy. They don’t know what an AI model is and they’re so much bet­ter off

It’s noth­ing short of an in­dict­ment of our so­ci­ety at large that Aaron Swartz, one of the co-cre­ators of the RSS pro­to­col (among many other things) was ef­fec­tively as­sas­i­nated by our le­gal sys­tem for illegally” down­load­ing about 70 gi­ga­bytes of aca­d­e­mic ar­ti­cles from JSTOR - charged so ex­ces­sively to be made an ex­am­ple of (we’re talk­ing 35 years in prison, $1million USD fine, and as­set for­fei­ture) to the point where he felt the need to take his own life rather than deal with the court cir­cus and im­pend­ing fi­nan­cial ruin - while Facebook (oh I’m sorry Meta) has tor­rented 80 TERABYTES of books to train their AI mod­els with vir­tu­ally no con­se­quences other than a court case they will most likely get some sort of fi­nan­cial slap on the wrist for while their AI mod­els con­tinue to print them money.

Swartz’ use case was the dis­sem­i­na­tion and archival of knowl­edge; Meta’s use case is pow­er­ing up their pro­pri­etary pla­gia­rism code that cooks the en­vi­ron­ment while giv­ing CEOs psy­chosis and mak­ing one of the world’s rich­est peo­ple even richer.

I never met Aaron but I get mad on his be­half so of­ten and I don’t know what to do with it other than get more rad­i­cal­ized.

Maybe that’s for the best.

Anyway, here’s your end-of-post cat photo. Her name is Lilith and she’s won­der­ing why we don’t do some­thing about all these tech bil­lionares.

OpenLogi

openlogi.org

HID++BoltUnifyingBluetoothUSB

Your Logitech mouse,fi­nally lo­cal.

A lo­cal-first al­ter­na­tive to Logitech Options+, writ­ten in Rust.Remap but­tons, drive DPI and SmartShift over HID++.No ac­count, no teleme­try.

$brew in­stall –cask open­logi

.dmg.deb / .rpm / .pkg.tar.zst.msiMIT / Apache-2.0Not af­fil­i­ated with Logitech

Click a but­ton, bind an ac­tion.

The cen­ter of the app, work­ing right here: a mouse di­a­gram with click­able hotspots and a per-but­ton ac­tion picker. Choose a hotspot, then bind any of the built-in ac­tions.

con­fig.tomlschema_ver­sion = 2

schema_ver­sion = 2selected_device = 2b042”[devices.2b042.bindings]MiddleClick = MissionControl”DpiToggle = CycleDpiPresets”Thumbwheel = VolumeUp”Forward = BrowserForward”Back = BrowserBack”GestureButton = AppExpose”

schema_ver­sion = 2

se­lect­ed_de­vice = 2b042”

[devices.2b042.bindings]

MiddleClick = MissionControl”

DpiToggle = CycleDpiPresets”

Thumbwheel = VolumeUp”

Forward = BrowserForward”

Back = BrowserBack”

GestureButton = AppExpose”

MX Master 4Writes straight to con­fig.toml, the file you own.

Everything Options+ does, with­out the ac­count.

OpenLogi dri­ves your mouse over HID++ di­rectly: but­tons, DPI and SmartShift, from a na­tive app that never phones home.

HID++ 2.044 ac­tions

Remap any but­ton

Bind any of 44 built-in ac­tions to each phys­i­cal but­ton, per de­vice. Custom short­cuts, app launch­ers and scripted ac­tions too.

DPI con­trol & pre­sets

Set pointer res­o­lu­tion and cy­cle your own pre­sets, writ­ten straight to the sen­sor over HID++.

HID++ 0x2201

SmartShift

Flip the wheel be­tween ratchet and free-spin, or let it switch au­to­mat­i­cally by scroll speed.

HID++ 0x2111

Per-app pro­file­sCom­ing soon

Per-application over­lays that switch the mo­ment your fo­cused app does. Ships in a later re­lease.

Bolt, Unifying, Lightspeed, Bluetooth or wired

Reach de­vices over a Logi Bolt, Unifying or Lightspeed re­ceiver, a di­rect Bluetooth pair­ing, or a USB ca­ble. No re­ceiver re­quired.

Live de­vice view

A carousel of paired de­vices with bat­tery per­cent­age and charge state for every­thing on­line.

HID++ 0x1004

Nothing be­tween your mouse and your ma­chine.

No ac­count, no teleme­try, no cloud. Bindings live in a plain TOML file you own, and every change goes straight to the de­vice over HID++.

NetworkDevice ren­ders only

Up and run­ning in a minute.

Signed builds for ma­cOS, Linux and Windows. Pick your plat­form be­low. Step-by-step setup lives in the docs.

.dmg.deb.rpm.msi

ma­cOS

$brew in­stall –cask open­logi

Homebrew is rec­om­mended, or grab the signed .dmg for Apple sil­i­con or Intel.

Linux

Packages for amd64 and ar­m64, with .rpm and Arch .pkg.tar.zst builds also avail­able.

Windows

New

The newest port: signed x86_64 and ar­m64 in­stallers, val­i­dated on Windows 11.

Quit Logi Options+ be­fore launch­ing: the two fight over HID++ ac­cess, and only one app can own a re­ceiver at a time. On Linux, the same ap­plies to Solaar.

It’s on the roadmap, at the far end: a cross-com­puter pointer and clip­board bridge is a very large fea­ture. The half that lives in the pro­to­col al­ready ships. OpenLogi dri­ves Easy-Switch host switch­ing over HID++ (0x1814/0x1815), and paired mice fol­low the key­board when it switches hosts. If the rest lands, it will be opt-in and lo­cal-net­work only.

Bolt pair­ing ships in the GUI, and Unifying and Lightspeed pair­ing is in progress. Until it lands, pair once with Logitech’s tool or Solaar; OpenLogi dri­ves the de­vice from then on.

Not yet, though an im­porter is in progress. In the mean­time, bind­ings are a short TOML file you can re­build in min­utes, and un­like Options+ they stay in one portable, hand-ed­itable file.

OpenLogi remaps the side but­tons (Back, Forward, mid­dle click) through a CGEventTap, and ma­cOS puts event taps be­hind the Accessibility per­mis­sion. The HID++ paths (gesture but­ton, thumb wheel, DPI, SmartShift) don’t need it.

Only when you ask. The in-app up­date check is opt-in and off by de­fault; new builds come from Homebrew (brew up­grade –cask open­logi) or the signed in­stallers on the re­leases page.

Copy the TOML file. Devices are keyed by phys­i­cal iden­tity (receiver se­r­ial and slot, or the de­vice’s own se­r­ial), so the same mouse keeps its bind­ings wher­ever the file goes. Built-in sync may come one day, but it’s hard to square with the no-ac­count prin­ci­ple.

The Amazon tax

seths.blog

It’s not tech­ni­cally a tax. Taxes pro­duce valu­able pub­lic ben­e­fits, like med­ical re­search and parks. This is sim­ply le­gal theft.

Amazon makes nearly a bil­lion dol­lars in profit from search ads. Every week. Each week, they sell mer­chants and pub­lish­ers enough search-dis­tort­ing ads to cap­ture a bil­lion dol­lars in rev­enue. Amazon makes enough in search ad rev­enue to give every sin­gle one of their em­ploy­ees a $35,000 cash bonus and still have change left over.

My pub­lisher is ter­rific, and they’re work­ing hard to in­tro­duce peo­ple to my new book. Last week, they be­gan buy­ing search ads on Amazon.

At first glance, this is com­pelling. Someone who is­n’t sure what they’re look­ing for, who is look­ing for a book or a kitchen ap­pli­ance, might find one if the right ad showed up at the right time.

But of course, that’s not what yields, or what most of the ads you see on Amazon do.

If you’re search­ing for an air fryer, Amazon al­ready knows quite a bit. They know the best-re­viewed, least-re­turned, best-priced model. The only pur­pose of the ads is to get you to pick an air fryer that is­n’t that one (or for the best air fryer, to keep you on track to buy the one you wanted in the first place). The ads make the search worse. [Cory wrote about this three years ago, and the scale has al­ready dou­bled.]

When there are plenty of ads, the maker of the best air fryer now has to bid on ads as well, if only to pro­tect the sales they were en­ti­tled to in the first place. Businesses con­tinue to buy the ads—not be­cause they’re dumb, but be­cause the sys­tem has cre­ated a sit­u­a­tion with few op­tions. Folklore im­plies that buy­ing the ads some­how shifts how search re­sponds in the long run, even af­ter the ads stop run­ning, but there’s lit­tle data to con­firm this.

Traditional ads in­crease de­mand. We see some­thing that’s clearly an ad, it might spark de­sire, and sales go up. But zero-sum search ads aren’t like that–the to­tal sales in the cat­e­gory stay the same, and mer­chants are merely com­pet­ing for a share of a sta­tic pie. This study ar­gues that an ecom­merce site with search ads ac­tu­ally sells fewer items than the same site with­out ads.

The high­est-yield­ing ad my pub­lisher has tested so far is the search Seth Godin The Knot“. It costs about a dol­lar per click. My pub­lisher is pay­ing Amazon a dol­lar to show you an ad for the book you went to buy in the first place.

Who ends up pay­ing the more than $50 bil­lion a year spent on these ads? It’s not the sell­ers. Sellers can’t make heart­felt do­na­tions for long. It’s you. By mak­ing the mar­ket­ing of prod­ucts sig­nif­i­cantly less ef­fi­cient, Amazon’s theft makes prod­ucts more ex­pen­sive or sucks the en­ergy out of the de­vel­op­ment of new prod­ucts.

It leads to two per­verse side ef­fects. First, pro­duc­ers re­al­ize that if brand rep­u­ta­tion mat­ters less than a bud­get for clicks, they will shift to shoddy and cheap ver­sions of their prod­ucts so they have a big­ger bud­get for clicks. And sec­ond, Amazon (and Google be­fore it) have an in­cen­tive to make their or­ganic search re­sults worse–giv­ing pro­duc­ers more in­cen­tive to buy more ads.

For decades, Amazon cre­ated value for con­sumers by low­er­ing the price of just about every­thing. And they opened the doors to mer­chants who did­n’t have suf­fi­cient dis­tri­b­u­tion. They claimed to be cus­tomer-cen­tric, and they were.

I don’t think they can claim this any longer. The ad sys­tem they built is­n’t il­le­gal, but it’s pretty clear who it’s for.

Amazon is steal­ing from the cus­tomers they said they were here to serve.

Changelog - Kagi Search

kagi.com

August 21st, 2026 - A new Stocks wid­get and a bet­ter every­day Assistant ex­pe­ri­ence #

Kagi Search

Bringing Stocks up to speed

We’ve re­vamped our Stocks wid­get. It should ap­pear more of­ten when you need it. It can now dis­play in­for­ma­tion about ex­change-traded funds in ad­di­tion to stocks. Most im­por­tantly, it now fea­tures a price chart, with an­i­ma­tions be­tween time win­dows that in­stantly con­tex­tu­ral­ize how big the price fluc­tu­a­tions you’re see­ing are com­pared to the wider story:

As well, we’ve added a set­ting for re­mov­ing pay­walled links from search re­sults au­to­mat­i­cally.

Kagi Assistant

Everyday use just got smoother

Richer mes­sages User mes­sages now ren­der links, Markdown, and LaTex. #6674 @oxlvlnle, #3283 @EvacuatedTerminal

More pow­er­ful search Search across all your threads, sort by re­cency or al­pha­bet­i­cally, and start with / to fil­ter by folder.

More con­trol with calmer set­tings Now you can choose whether tem­po­rary threads stick around for 24h, 7 or 30 days. All within a calmer, eas­ier-to-scan set­tings ex­pe­ri­ence.

Other im­prove­ments and bug fixes

Kagi Search

Direct URLs for search pages with our built-in lenses are now eas­ier to use, with names re­plac­ing num­bers: https://​kagi.com/​search?lens=fo­rums

Shortcuts should not trig­ger with mod­i­fiers held #9385 @poacher2k

kag­ifeeed­back xss vuln tag fix #10767 @unknown

Upstream con­nect er­ror or dis­con­nect/​re­set be­fore head­ers. re­set rea­son: con­nec­tion ter­mi­na­tion #10680 @TheToby

Select text and Search in Assistant #11242 @mb

Homepage Companions - Random or Rotate #9077 @Anonymous12

Extract API re­turns empty data for an en­tire batch when one page times out #11176 @fredcy

Currency con­ver­sion wid­get does not han­dle of­fi­cial name of cur­rency #11175 @Keli

A way to find sim­i­lar web­sites #1152 @Protech

Blocked do­mains are used as sources in Quick Answer #11257 @bausauce

CHATGPT Wikipedia ar­ti­cle is flagged as slop #10192 @fxgn

Surveillance Watch for play.google.com goes to a page about Zalo #9146 @pma_snek

Assistant no longer de­codes URL en­cod­ing from !ai bang #11096 @arijan

Kagi Assistant

Ability to ex­port all Assistant chats in one go #5221 @Thibaultmol

In Assistant, add an op­tion to re­quire ⌘+⏎ to sub­mit a prompt #6110 @dudeofawesome

Click to Expand” on Thinking” Section #8004 @KagiFeedbackDuder

Assistant: do not close think­ing block if user opened it dur­ing ex­tended think­ing #6675 @DomW

Assistant prompt code fence syn­tax high­light­ing #4775 @slater

FIXED - !ai bang - Query not work­ing #11077 @fanged_bagful

Prevent Search Engine Indexing of Shared Assistant Threads #7867 @Hanbyeol

Web Search tog­gle state not main­tained be­tween app switches #11140 @ryonic

Improvement to code snip­pet in­put #6254 @Leward

Choppy an­i­ma­tion in Assistant app #11134 @Temanor

Assistant prompt code fence syn­tax high­light­ing #4775 @slater

Speech-to-text doesnt sup­port pauses in Android Assistant app #11265 @jeroenpelgrims

Assistant Mobile Apps

Keyboard short­cut pref­er­ence to sub­mit prompts on iPads with con­nected key­boards

Back swipe on left side of Kagi Assistant in­ter­feres with Android gues­tures #11126 @mb

After open­ing Kagi Assistant, back swipe on the right side closes the app #11127 @mb

Choppy an­i­ma­tion in Assistant app #11134 @Temanor

Web Search tog­gle state not main­tained be­tween app switches #11140 @ryonic

Cannot Login Kagi Assistant 1.0.4 on iOS #11146 @hirsheykiss

Kagi Translate

Kagi Translate Reloads the page when us­ing web­site trans­late #10852 @tijol

Kagi Translate ex­ten­sion RSS feed 503 er­ror #10831 @Albi

Translate ex­ten­sion con­text menu op­tions don’t work every­where #10813 @WorstWizard

Alternative-translations re­quest pay­load has blank context” string in new up­date #11278 @Drexont

Regression: saved pre­sets do not au­to­mat­i­cally ap­ply con­text to trans­la­tions #11218 @Drexont

American alias for English (US) #11143 @mb

July 30th, 2026 - Kagi Assistant on the go and de­sign re­fine­ments for Search #

Announcing the of­fi­cial Kagi Assistant apps

Kagi Assistant is now avail­able as a na­tive app for iOS and Android!

Ask a ques­tion, ex­plore the web, work with files, con­duct in-depth re­search, or choose from lead­ing AI mod­els, all from your phone. Your threads and Custom Assistants stay with you, so you can pick up wher­ever you left off.

These are the first steps to­wards de­liv­er­ing a fan­tas­tic Kagi Assistant ex­pe­ri­ence on mo­bile, with much more to come.

Download it now:

App store: https://​apps.ap­ple.com/​app/​6755965340

Play store: https://​play.google.com/​store/​apps/​de­tails?id=com.kagi.as­sis­tant

Give it a spin and let us know what you think!

Report re­sponses di­rectly from Kagi Assistant

You can now re­port an as­sis­tant re­sponse with­out leav­ing the con­ver­sa­tion. Hover over any as­sis­tant mes­sage and se­lect the thumbs-down but­ton to open the feed­back form, where you can re­port is­sues for rea­sons rang­ing from UI bugs to harm­ful con­tent.

Note that when you sub­mit a re­port, the full thread is shared with Kagi for re­view. The re­port and its as­so­ci­ated copy of the thread are au­to­mat­i­cally deleted from Kagi’s re­view records af­ter 30 days.

Export or delete all your threads

We’ve also added im­por­tant con­trols, so you can now ex­port all your threads or per­ma­nently delete them at once from Settings > General.

Kagi Search

A sharper search ex­pe­ri­ence

We’ve pol­ished the search re­sults page to make its con­trols eas­ier to find and un­der­stand. From the fil­ter bar to do­main-re­lated op­tions and menus, these up­dates bring greater clar­ity and ease of use to the fea­tures you rely on most.

Exchange rates, right in your search re­sults

Next up in our broader ef­fort to im­prove search wid­gets: cur­rency con­ver­sion. Comes handy when you’re plan­ning a trip, shop­ping abroad, or sim­ply want to keep tabs on ex­change rates.

Other im­prove­ments and bug fixes

Kagi Search

Fixed sev­eral an­i­ma­tions that did­n’t re­spect the sys­tem’s prefers-re­duced-mo­tion set­ting

Open first re­sult’ short­cut sug­ges­tion tries to es­cape dou­ble-quotes #8752 @craftypersimmon

Fake 1337x do­main #9279 @fxgn

Dice Number get­ting cut off in the thou­sands #10964 @Flossiii

Some Kagi lenses not work­ing for me in Kagi search #10970 @Fearce

NSFW re­sults when search­ing for xteink black vs white” while safe search is turned on #10905 @ciccero040

Incorrect de­f­i­n­i­tion of socialism” #10988 @thoroughly

Nothing trig­gers the weather wid­get when the in­ter­face lan­guage is set to German #4612 @laiz

Cannot Manually Select Location in Privacy Settings #11005 @iamjameswalters

More and share but­tons dis­ap­peared - Mobile DOM #10957 @NyraSyn

Slopstop blocks whole do­mains #11039 @kslays

Unable to re­port AI im­age slop on mo­bile due to popup clo­sure #11066 @Hanbyeol

Kagi adding ex­tra {{{s}}} in bang redi­rect when no query #9885 @jadams9

Profile not found for ki_re­search” er­ror when us­ing ?? short­hand #11020 @paying_customer

Kagi Knowledge an­swer for Labour Day 2025” gives wrong date #8713 @wanion

Delete re­cent lan­guage op­tion #8549 @ten

Stopwatch should not start from searches like 0424:2422 #6061 @xfhrnozxqnrnqrsvntp

[Android] Quick Switch Doesn’t work #7695 @cr0ntab

Save a round trip: Advertise HTTP/3 sup­port in an HTTPS DNS record #10829 @drrlvn

Searching for <script> re­turns no re­sults #11117 @Bonarc

Kagi Assistant

Camera but­ton in as­sis­tant #5261 @Arnaud

Assistant er­ror something went wrong…” when web ac­cess” is se­lected #6687 @Nyaa

Gemma 4 31B fail­ing to read im­ages #10947 @Dustin

Assistant: Remove whole his­tory #6971 @Wanja

Didn’t like a Quick Answer re­sponse? post it here #9082 @Thibaultmol

Hourglass de­sign is bad #11034 @shurik

Everything I own, owned

schlarp.com

Over the past cou­ple weeks I’ve been do­ing agent-dri­ven re­verse en­gi­neer­ing of pe­riph­er­als that hap­pen to be within ar­m’s reach. From those de­vices, I’ve come away with a full plain­text com­mand shell in­side my mi­cro­phone, a we­b­cam whose ac­tiv­ity LED I can switch off while it records, and a key light that hands out mem­ory writes to any­one on the WiFi. Peripherals have proven to be an ideal tar­get for agen­tic RE - they’re tiny com­put­ers at­tached to my com­puter, with a data con­nec­tion to the host and usu­ally a firmware up­date mech­a­nism, so an agent has some­thing to it­er­ate against. The net out­come is bet­ter con­trol and un­der­stand­ing of my ma­chine.

My process was pretty much the same for each of these de­vices: grab a copy of the de­vice’s firmware and as­so­ci­ated up­date tool from the man­u­fac­turer, throw it into my re­verse en­gi­neer­ing en­vi­ron­ment, tell Claude Opus 5 what my goals are, and let it churn. Depending on the de­vice, the goals were some­what dif­fer­ent, but they usu­ally looked some­thing like:

In this di­rec­tory is the firmware and up­date util­ity for ___. The de­vice is also at­tached to this com­puter, and you may in­ter­act with it in non-mu­tat­ing ways. Exhaustively doc­u­ment and cross-val­i­date the en­tire firmware, in­clud­ing the fol­low­ing goals:

* re­verse en­gi­neer the firmware up­date for­mat and up­date pro­to­col * im­ple­ment our own up­date util­ity * de­ter­mine the se­cu­rity prop­er­ties of the up­date pro­to­col, in­clud­ing check­sums, sig­na­ture val­i­da­tion, se­cure boot * use sta­tic and dy­namic analy­sis to de­ter­mine all pro­to­col sur­faces and com­pletely enu­mer­ate func­tion­al­ity * find any hid­den or de­bug func­tion­al­ity in the prod­uct and how to ac­cess it

Depending on the re­sults, there were dif­fer­ent di­rec­tions of fol­low-up, but you should get the gen­eral idea. Let’s run through the list - each de­vice links to a GitHub repo full of gen­er­ated-slop docs and scripts, most of which have been val­i­dated live against real hard­ware. I’ve also in­cluded the ef­fort each de­vice took, pulled out of the Claude Code ses­sion tran­scripts. Churn” is the time Claude was ac­tu­ally work­ing, with the long idle gaps re­moved. Prompts from me” is every mes­sage I typed, in­clud­ing the one-word ones telling it to keep go­ing. All five de­vices to­gether came out to about 13 hours of churn and 98 prompts, spread across two weeks of evenings.

Everything I own

Insta360 Link we­b­cam

GitHub repo - 3.7 hours of Claude churn, 33 prompts from me

I use an Insta360 Link we­b­cam, which is a nice gim­baled pan-tilt-zoom cam­era that does face track­ing for au­to­mat­i­cally fram­ing the shot. I wanted to know if it was pos­si­ble to sub­vert the ac­tiv­ity LED, like in the clas­sic iSeeYou ex­ploit.

Interestingly, it was im­me­di­ately ob­vi­ous that this cam­era has a lot go­ing on in­side it. It turns out that it runs a whole RTOS (ThreadX) sourced from the up­stream SoC ven­dor, Ambarella. The RTOS hosts sev­eral small vi­sion mod­els that pro­vide things like the afore­men­tioned face track­ing, as well as ges­ture de­tec­tion for con­trol­ling set­tings. Pretty amaz­ing com­plex­ity in­side a tiny we­b­cam, but it also means there’s some ex­cit­ing at­tack sur­face here.

Over the USB Video Class in­ter­face, there’s an XU (Extension Unit) com­mand that kicks the de­vice into mass stor­age” mode. This then lets us trans­fer a staged firmware up­date to the de­vice’s in­ter­nal FAT filesys­tem, which the de­vice then ap­plies to it­self on re­boot. This route does re­quire user in­ter­ven­tion to re­boot with a re­plug, but there’s ac­tu­ally an­other com­mand chan­nel that ex­poses ar­bi­trary read/​write of files and a re­boot com­mand over the USB ven­dor class. With this, we can fully flash the de­vice with­out any user in­ter­ac­tion. Once the firmware is in the right place, there’s ef­fec­tively no anti-tam­per, just an ap­pended MD5 hash to en­sure in­tegrity.

The in­di­ca­tor LED turns out to have a well-struc­tured set of patterns” in the firmware that dic­tate color, blink pat­tern, etc. that are in­dexed into for var­i­ous de­vice states. I had Claude write a tool to patch out the table en­try for cam­era ac­tiv­ity, fix up the in­tegrity hash, and flash it to the cam­era. A quick test showed that the green LED that nor­mally il­lu­mi­nates while record­ing no longer turned on. Horrifying! On this de­vice, the gim­bal it­self also de­flects down when not record­ing, so it’s not com­pletely stealth, but it still does­n’t feel great.

The LED be­hav­ior be­fore and af­ter patch­ing.

ASUS ROG Swift PG42UQ mon­i­tor

GitHub repo - 1.2 hours of Claude churn, 13 prompts from me

My ASUS ROG Swift PG42UQ mon­i­tor was ac­tu­ally where I started, be­cause I got an­noyed at the pop-up over­lay that comes up every once in a while that tells me to run pixel clean­ing”. I have never in­ten­tion­ally run pixel clean­ing on this mon­i­tor and I never will, I don’t care, and I would like for that over­lay to go away for­ever. Maybe there’s a de­bug menu or some­thing that can turn it off, or worst case we patch a branch in the firmware?

Claude found that the firmware has ef­fec­tively no pro­tec­tion what­so­ever - there’s a two-slot A/B scheme and a sim­ple check­sum, but ul­ti­mately we can write what­ever we want to the thing. Firmware up­dates run over an I2C bus bridged over USB.

The pixel clean­ing warn­ing turns out to have no na­tive way to dis­able it, and it’ll al­ways show up af­ter 8 hours of run­time. Oh well. Claude did find the ap­pro­pri­ate area to patch to kill the func­tion­al­ity though. I haven’t ac­tu­ally been brave enough to write a mod­i­fied firmware to the thing yet - it’s a pretty ex­pen­sive mon­i­tor - but I’ll get there at some point.

Another neat thing was ex­plor­ing the DDC/CI in­ter­face. This is the con­trol chan­nel avail­able over the dis­play ca­ble it­self, al­low­ing the host to change in­puts and other set­tings. I be­lieve ASUS of­fers this through their Windows util­ity, DisplayWidget, but that does lit­tle for me on Linux. So, now I have a shell script that can flip through some of the DDC/CI fea­tures like the hard­ware crosshair or zoom over­lays, FPS counter, and count­down timer. I might set up some of these on hotkeys in the fu­ture for easy ac­cess.

Shure MV7 mi­cro­phone

GitHub repo - 4.2 hours of Claude churn, 32 prompts from me

At this point, there’s less ac­tual in­cen­tive to keep pop­ping these de­vices and more just mor­bid cu­rios­ity. My mi­cro­phone, the Shure MV7, con­nects over USB and ob­vi­ously has some amount of smarts to it, with on-de­vice dig­i­tal vol­ume con­trols and such.

The firmware for this one turned out to be hid­den in­side the Windows soft­ware, MOTIV Mix, so Claude in­stalled that in Wine, found the up­date server, and pulled it down. I was­n’t on the lat­est, so there was ac­tu­ally a rea­son­able in­cen­tive here to get this work­ing just to up­date my mi­cro­phone from Linux. The firmware turned out to con­tain both DSP and MCU firmware, and was hon­estly pretty bor­ing as you might ex­pect. Again, no real se­cu­rity on the firmware flash it­self.

However, the up­date pro­to­col re­vealed that the en­tire thing ac­tu­ally runs over a USB HID ven­dor class pro­to­col that im­ple­ments a full plain­text com­mand shell, with 48 dif­fer­ent com­mands. Since it’s HID, we can ac­tu­ally hit this over WebHID from a web­page in Chrome, so I had Claude build a web in­ter­face for us­ing the shell. There’s all sorts of in­ter­est­ing set­tings in here in­clud­ing a dozen DSP knobs, ar­bi­trary mem­ory read/​write, LED con­trol, and a 4-tier user priv­i­lege sys­tem whose en­tire au­then­ti­ca­tion is a string com­par­i­son against the name of the tier you asked for. su sup just works, and the top tier can dis­able the touch panel so you can’t mute at the de­vice, and drive the mute LED in­de­pen­dently of whether the mi­cro­phone is ac­tu­ally muted. It’s the we­b­cam LED trick again, on a mi­cro­phone. Obviously, be aware that you could prob­a­bly break your de­vice if you use that UI and do some­thing stu­pid with it.

The WebHID shell in­ter­face. The DSP knobs on the left are the de­vice’s own set­tings; the con­sole on the right is the plain­text com­mand shell talk­ing over HID.

Elgato Cam Link 4K video cap­ture

GitHub repo - 1.5 hours of Claude churn, 10 prompts from me

The Elgato Cam Link 4K is just an HDMI video cap­ture de­vice, and hon­estly was just more of the same. The in­ter­est­ing thing for this one was that I let it go fully un­at­tended - I lit­er­ally kicked off the process be­fore go­ing to sleep and woke up to a tear­down and func­tion­ing firmware up­dater. The firmware con­tains an MCU im­age and an FPGA bit­stream for the ac­tual HDMI han­dling, so you could po­ten­tially do some­thing fun with the FPGA if you went deep enough into the re­verse en­gi­neer­ing there. There’s no pro­tec­tion on the firmware up­date path.

I was able to pull out all the EDID in­for­ma­tion used for ne­go­ti­at­ing video pa­ra­me­ters, so we know ex­actly what res­o­lu­tions, re­fresh rates, color spaces, and chroma sub­sam­pling op­tions are of­fered to de­vices.

The ven­dor HID pro­to­col does in­clude tun­neled ac­cess to the in­ter­nal I2C bus, which is kinda neat as you can poke the in­ter­nal HDMI re­ceiver reg­is­ters.

Elgato Key Light Mini

GitHub repo - 2.4 hours of Claude churn, 10 prompts from me

Finally, I poked at some­thing that was­n’t con­nected over USB but WiFi in­stead, the Elgato Key Light Mini. This one turned out to be way more in­ter­est­ing than I ex­pected: it’s the only one with mean­ing­ful firmware in­tegrity pro­tec­tion. Elgato signs the firmware up­dates with Ed25519 over a SHA-512 hash of the firmware pay­load, and re­jects firmware that does­n’t val­i­date. This makes sense to do, as the de­vice ba­si­cally con­nects to a WiFi net­work and then pro­vides unau­then­ti­cated ac­cess to any­one on the same net­work, so the threat model is in­her­ently dif­fer­ent.

Unfortunately, while that’s an im­prove­ment over all of the other de­vices we’ve looked at, it pro­tects the firmware at ex­actly one point in time: when an up­date is hap­pen­ing. It’s not a boot time check en­forced by the boot­loader or any other kind of se­cure boot scheme, and the up­dater hap­pens to be run­ning while every­thing else in the de­vice is still op­er­at­ing, mean­ing there’s huge at­tack sur­face to try to dis­able that sig­na­ture val­i­da­tion. I asked Claude to look for an ex­ploit that might en­able this, and it found a doozy: an HTTP POST re­quest that drops a pay­load straight into the in­ter­nal UART, which in­cludes a mem­ory poke com­mand. This means that a sin­gle HTTP POST of ATSE=0200ED94,0E001009 turns the sig­na­ture check into a no-op, and we can freely up­date to a firmware im­age with­out a le­git­i­mate sig­na­ture. I suc­cess­fully tested this with a sim­ple patch that changed the name of the de­vice, so uh, yeah, don’t put these on an un­trusted net­work.

…, owned

I have a lot of feel­ings about this whole thing. As I wrote back in March, this is in­cred­i­ble for in­ter­op­er­abil­ity and fix­ing things that don’t work how we want them to. Hardware is al­most uni­ver­sally open” for tin­ker­ing at this point with just a cou­ple hours of mostly hands-off ma­chine-dri­ven la­bor each, and I look for­ward to a near fu­ture where I can add fea­tures to my we­b­cam firmware as eas­ily as I can to soft­ware that runs on my Linux ma­chine it­self.

On the other hand, as a se­cu­rity pro­fes­sional, this scares me for sev­eral rea­sons. I would work from the op­er­at­ing as­sump­tion that any de­vice at­tached to a com­puter could have had a ma­li­cious firmware im­plant per­formed, where pre­vi­ously that re­quired sig­nif­i­cant per-model in­vest­ment and was stereo­typed as a state ac­tor” kind of ac­tiv­ity. Operating sys­tems aren’t re­ally equipped to work with the user to en­sure that a mi­cro­phone stays a mi­cro­phone, and does­n’t spon­ta­neously turn into a key­board that hits Win+R and drops a pay­load to steal all your data when the room is quiet enough that it can as­sume you aren’t watch­ing. And the ex­is­tence of WebUSB, WebHID, and WebBluetooth mean that for some de­vices, de­pend­ing on the specifics of which classes are used, a mo­ment of user in­dis­cre­tion in ac­cept­ing a per­mis­sions prompt could per­ma­nently back­door one of their at­tached de­vices.

Network-connected de­vices seem near uni­ver­sally fucked at this point? There are a few oth­ers I’ve poked at that I haven’t doc­u­mented here, but I’ve got­ten a root shell on a com­mer­cial Dell dis­play, and RCE on an Eaton UPS. Obviously it was never best prac­tice to let un­trusted clients touch these things, but the speed and scale at which this can be ex­e­cuted makes the risk so much higher now.

Finally, I can’t help but think about what an AI-equipped au­to­mat­i­cally-re­verse-en­gi­neer­ing worm could do to­day. It’s only a tiny leap to imag­ine that some­one could make a self-repli­cat­ing piece of mal­ware that probes its en­vi­ron­ment, re­lay­ing re­con­nais­sance back to a smart com­mand-and-con­trol that ac­tively works to push it­self into ac­ces­sories and IoT de­vices and in­dus­trial equip­ment found ad­ja­cent to an in­fected tar­get. Two things have kept this from hap­pen­ing: every de­vice model needs its own re­verse en­gi­neer­ing, and val­i­dat­ing any of it needs the hard­ware in hand. The first is the la­bor I just handed to an agent. The sec­ond is free to mal­ware al­ready sit­ting on an in­fected host. Honestly, I would­n’t be sur­prised if this al­ready ex­ists, and I think the next few years are go­ing to be ex­tremely in­ter­est­ing. 🫠

AI;DR (AI; Didn’t Read)

www.rickmanelius.com

I’m SUPER jeal­ous that I did­n’t think of this first…

Alas! Hat tip to se­clilc for tweet­ing this gem out two days ago.

lil c@se­clilc

AI;DR

(AI; did­n’t read)

4:13 PM · Aug 15, 2026 · 346K Views

83 Replies · 2.09K Reposts · 16.6K Likes

I’ve been think­ing about it ever since. Why? Because there is grow­ing grum­bling among every­one about AI writ­ing. And it’s not just oth­ers; it’s me! I am get­ting to the point where I phys­i­cally flinch (sometimes drop­ping my shoul­ders and hunch­ing, or hav­ing a slight eye twitch) when some­one I re­spect sends me un­fil­tered and unedited AI out­put.

Look, I get it. It’s Q3 2026, and we should ex­pect that every­one is uti­liz­ing AI at SOME point in their process (sourcing ideas, cre­at­ing out­lines, re­fin­ing prose, etc.).

However, I have a new pol­icy.

If you’re not both­ered enough to re­view and edit it…

…then I’m not go­ing to bother read­ing it.

Yes, there are cer­tain sit­u­a­tions in which we should ex­pect 100% AI-generated copy. Customer sup­port would be a per­fect ex­am­ple. We’re not look­ing for ar­ti­sanal did you make sure to re­set your phone” style di­a­logue.

But if you’re my col­league and we’re in a Slack dis­cus­sion and you post a wall of Claude out­put, then I’m afraid I re­ceived a dif­fer­ent mes­sage than you in­tended.

The same is true for peo­ple’s newslet­ters and so­cial con­tent. It’s your name on it; are you proud of the prose and weird AI-isms sprin­kled through­out it? If so, great. But I can ask Claude di­rectly if I wanted to.

TL;DR (too long; did­n’t read) was the so­lu­tion for so­cial me­dia.

AI;DR (AI; did­n’t read) is the so­lu­tion for AI slop.

May you em­brace this pol­icy your­self and seek out those will­ing to care enough to pri­or­i­tize a hu­man touch when they talk to you.

Update 1 2026 – 08-17: Daniel in the com­ments shared a won­der­ful web­site dont­pasteth­eai.com. Amazing. I es­pe­cially loved the Take me to the Angry Version ver­sion.

The in­tro header says it all (polite ver­sion be­low).

Update 2 2026 – 08-18: This made it to #1 on Hacker News on 2026 – 08-18 with >600 com­ments. It ap­par­ently struck a cord.

No posts

nytimes.com

www.nytimes.com

Please en­able JS and dis­able any ad blocker

403 Forbidden

responsiblestatecraft.org

Error 403 Forbidden

Forbidden

Error 54113

Details: cache-bos-kbos510033-BOS 1787172821 3285793255

Varnish cache server

Don't paste the AI, please.

dontpastetheai.com

Prefer an­other lan­guage?

Don’t pastethe AI, please.

When some­one asks you some­thing, they want your an­swer. Not a wall of ChatGPT text. A short an­swer from a hu­man will al­ways be worth more than one from a ro­bot, even if the ro­bot is right.

What hap­pened

Someone asked you an hon­est ques­tion. You dumped it into a chat­bot, copied the an­swer, and sent it back. It felt fast. It felt help­ful. It was­n’t.

It might not look like it, but the per­son on the other side has the same tools you do. If they wanted the generic an­swer, they’d have it in a cou­ple of sec­onds. They asked you be­cause they wanted your take… Your con­text, your taste, your judg­ment.

The world is full of peo­ple who don’t want to read or think things through. Don’t be one of them.

Do this in­stead

You can use AI. Seriously! It’s a great tool for draft­ing. Just read what it gave to you , then write your own ver­sion, or pol­ish the text. Don’t be a mid­dle­man be­tween it and the an­swer.

Take the part that ac­tu­ally an­swers the ques­tion and ig­nore the rest. Three sen­tences is all it takes, and even if they’re copied, at least you read them.

If some part of the mod­el’s an­swer is gen­uinely use­ful, quote it and ex­plain why. I asked Claude and this bit here makes sense:”.

If you have noth­ing to add, just say so. No strong opin­ion here”. Silence is also an op­tion.

Want to send this to some­one?

If some­one just com­mit­ted a wall of LLM text in your DMs, Slack or code re­view, you can send them this link.

Click to copy.

Want a rougher ver­sion?

If you’d rather send a ver­sion with stronger feel­ings in­volved, we got you!

I wanna burn bridges 🔥

Might not have an amaz­ing re­cep­tion at work, but you do you

You’re a teacher?

If your stu­dents send you an AI-generated dis­ser­ta­tion or pro­ject, you can send them this link:

Send them to class

AliExpress webpage keeping multipoint Bluetooth headphones active with WebAudio fingerprinting

blog.laserphile.com

Recently I ran into a strange prob­lem with my Bluetooth head­phones. They sup­port mul­ti­point Bluetooth au­dio, so they can be con­nected to my PC and phone at the same time. Normally the PC takes pri­or­ity play­ing au­dio, with my phone be­ing able to play au­dio when noth­ing is play­ing on the PC.

Usually I lis­ten to mu­sic on my phone but with no­ti­fi­ca­tions or Youtube play­ing through the PC, this works re­li­ably un­til I open an AliExpress page in Firefox or Chrome (other browsers untested).

Shortly af­ter load­ing the AliExpress home­page, au­dio from my phone would stop play­ing. Closing the AliExpress tab fixes it im­me­di­ately. Muting the tab/​Fire­fox/​Win­dows does not help, and there is no vis­i­ble video, mu­sic, or other me­dia play­ing on the page.

This seemed sus­pi­cious enough to in­ves­ti­gate.

Looking for hid­den me­dia

My first thought was an au­to­play­ing prod­uct video or ad­ver­tise­ment, so I checked for the usual sus­pects:

<audio> and <video> el­e­ments

calls to HTMLMediaElement.play()

ac­tive Media Session meta­data

me­dia re­quests

em­bed­ded frames con­tain­ing me­dia

None of these showed any­thing use­ful. There were no au­dio or video el­e­ments, no me­dia play­back calls, and nav­i­ga­tor.me­di­aSes­sion.play­back­State re­mained none.

A clue was that the prob­lem did not be­gin im­me­di­ately. It ap­peared af­ter the page had been sit­ting idle for sev­eral sec­onds. I in­stru­mented the page be­fore load­ing it and watched the Web Audio API in­stead of only look­ing for con­ven­tional me­dia el­e­ments.

The ba­sic idea was to wrap the AudioContext con­struc­tor and record when­ever a page cre­ated an au­dio-pro­cess­ing con­text:

const OriginalAudioContext = win­dow.Au­dio­Con­text;

win­dow.Au­dio­Con­text = class ex­tends OriginalAudioContext {

con­struc­tor(…args) {

su­per(…args);

con­sole.log(“Au­dio­Con­text cre­ated”, {

state: this.state,

stack: new Error().stack

});

}

};

I also wrapped AudioNode.prototype.connect() so I could see whether any­thing was con­nected to the con­tex­t’s au­dio des­ti­na­tion.

That fi­nally found it, two hid­den au­dio con­texts!

During an idle cap­ture of the AliExpress home­page, the page cre­ated two AudioContext ob­jects. Both en­tered the run­ning state and both con­nected nodes to AudioContext.destination.

At the same time there were still:

zero <audio> or <video> el­e­ments

zero me­dia play() calls

no ac­tive Media Session

no au­di­ble sound

The con­struc­tor stack traces pointed to two scripts:

https://​as­sets.aliex­press-me­dia.com/​g/​AWSC/​uab/​1.140.0/​col­lina.jshttps://​as­sets.aliex­press-me­dia.com/​g/​AWSC/​fireyejs/​1.231.67/​fireyejs.js

https://​as­sets.aliex­press-me­dia.com/​g/​AWSC/​uab/​1.140.0/​col­lina.js

https://​as­sets.aliex­press-me­dia.com/​g/​AWSC/​fireyejs/​1.231.67/​fireyejs.js

The first con­text was cre­ated by col­lina.js, while the sec­ond came from fireyejs.js. Both sit un­der an AWSC di­rec­tory and ap­pear to be part of Alibaba’s browser se­cu­rity and anti-abuse tool­ing.

The scripts are ex­tremely ob­fus­cated, but enough names and op­er­a­tions sur­vive for AI to work out what the au­dio code is do­ing.

What the au­dio code does

Both scripts build a WebAudio graph re­sem­bling this:

Sawtooth os­cil­la­tor    -> AnalyserNode    -> ScriptProcessorNode    -> GainNode set to zero    -> AudioContext.destination

Sawtooth os­cil­la­tor

-> AnalyserNode

-> ScriptProcessorNode

-> GainNode set to zero

-> AudioContext.destination

The os­cil­la­tor gen­er­ates a known wave­form. The analyser mea­sures the re­sult af­ter it has passed through the browser’s au­dio im­ple­men­ta­tion, and the script reads fre­quency data from it.

The gain is set to zero, so the user should not hear any­thing. However, the graph is still con­nected to the sys­tem au­dio des­ti­na­tion. Connecting it to the des­ti­na­tion causes the browser to ac­tively process the graph, even though the fi­nal vol­ume is zero.

This is very dif­fer­ent from an au­to­play­ing video. There is no me­dia el­e­ment for the browser’s nor­mal tab mute con­trol to stop. As far as the page is con­cerned, it is per­form­ing live au­dio pro­cess­ing.

In my case, that ap­pears to have been enough for Firefox or Windows to keep the Bluetooth au­dio path ac­tive, pre­vent­ing my mul­ti­point head­phones from switch­ing cleanly back to the phone.

Edit - There seems to be a fire­fox bug ticket open for the is­sue: https://​bugzilla.mozilla.org/​show_bug.cgi?id=1863193#c9

This looks like fin­ger­print­ing

The WebAudio test is not the only mea­sure­ment in these scripts. Inspection of the bun­dles found code that queries or mea­sures:

can­vas ren­der­ing and to­DataURL()

WebGL ren­derer in­for­ma­tion, ex­ten­sions, and shader pre­ci­sion

au­dio os­cil­la­tor and analyser out­put

screen and view­port di­men­sions

de­vice pixel ra­tio

hard­ware con­cur­rency and de­vice mem­ory

in­stalled browser plu­g­ins

sup­ported au­dio and video for­mats

WebRTC be­hav­iour

browser per­for­mance tim­ing

mouse, touch, fo­cus, and scroll events

de­vice mo­tion and ori­en­ta­tion

prop­er­ties com­monly as­so­ci­ated with browser au­toma­tion

There is also code for se­ri­al­is­ing and en­crypt­ing re­sults, mak­ing re­quests to Alibaba teleme­try ser­vices, and send­ing data with fetch() or send­Bea­con().

This is a fairly com­pre­hen­sive browser and de­vice fin­ger­print.

Audio fin­ger­print­ing works be­cause small dif­fer­ences in browser ver­sions, op­er­at­ing sys­tems, au­dio li­braries, and hard­ware can pro­duce slightly dif­fer­ent re­sults from the same gen­er­ated sig­nal. It is not nec­es­sar­ily enough to uniquely iden­tify a de­vice by it­self, but it be­comes much more use­ful when com­bined with can­vas, WebGL, hard­ware, tim­ing, and in­ter­ac­tion data.

Edit - tom­rit­tervg, a fire­fox de­vel­oper, has done a fur­ther dive into what is be­ing fin­ger­printed with the WebAudio: https://​rit­ter.vg/​blog-we­bau­dio_al­ibaba.html

Edit - tom­rit­tervg, a fire­fox de­vel­oper, has done a fur­ther dive into what is be­ing fin­ger­printed with the WebAudio: https://​rit­ter.vg/​blog-we­bau­dio_al­ibaba.html

I can­not see what AliExpress does with the re­sult­ing data af­ter it reaches their servers. It may be used as a per­sis­tent de­vice iden­ti­fier, but it could also be one in­put into a fraud or bot-de­tec­tion score.

Why AliExpress would want this

AliExpress has plenty of rea­sons to dis­tin­guish nor­mal shop­pers from au­to­mated or sus­pi­cious clients as well as track­ing users brows­ing habits. The site has to deal with ac­count takeovers, fake ac­counts, scrap­ing, au­to­mated pur­chas­ing, pay­ment fraud, re­view ma­nip­u­la­tion, and abuse of coupons or new-cus­tomer pro­mo­tions. They also, like most large busi­nesses, make use of large datasets of user be­hav­iour to bet­ter mar­ket prod­ucts and ser­vices.

Cookies are not es­pe­cially re­li­able for this pur­pose be­cause they can be cleared, copied, or re­placed. A fin­ger­print made from many in­de­pen­dent browser mea­sure­ments is harder to ma­nip­u­late con­sis­tently.

Interaction data can also help de­ter­mine whether a browser is con­trolled by a per­son or au­toma­tion. From AliExpress’s per­spec­tive, this could re­duce fraud and al­low trusted cus­tomers through with­out show­ing a CAPTCHA every few pages. Not that Aliexpress shies away from their AI gen­er­ated CAPTCHAs.

Personally I do not want a shop­ping home­page silently ex­er­cis­ing my graph­ics, au­dio, WebRTC, hard­ware, and mo­tion APIs, etc, to track my be­hav­iours, es­pe­cially if it has such an an­noy­ing ef­fect as block­ing my mu­sic. Per­haps if AliExpress was­n’t block­ing my mu­sic I never would’ve looked into what the site was do­ing.

Blocking it with uBlock Origin

I tested block­ing the two iden­ti­fied script fam­i­lies. With both re­quests blocked, the AliExpress home­page con­tin­ued to ren­der and no AudioContext ob­jects or des­ti­na­tion con­nec­tions ap­peared dur­ing the con­trol cap­ture.

In Firefox, I use the of­fi­cial uBlock Origin ex­ten­sion by Raymond Hill. To block the scripts open the uBlock dash­board, se­lect My fil­ters, and add:

! AliExpress AWSC fin­ger­print­ing scripts||as­sets.aliex­press-me­dia.com/​g/​AWSC/​uab/*/​col­lina.js$script,do­main=aliex­press.com||as­sets.aliex­press-me­dia.com/​g/​AWSC/​fireyejs/*/​fireyejs.js$script,do­main=aliex­press.com

! AliExpress AWSC fin­ger­print­ing scripts

||as­sets.aliex­press-me­dia.com/​g/​AWSC/​uab/*/​col­lina.js$script,do­main=aliex­press.com

||as­sets.aliex­press-me­dia.com/​g/​AWSC/​fireyejs/*/​fireyejs.js$script,do­main=aliex­press.com

Click Apply changes, close any ex­ist­ing AliExpress tabs, and open the site again. Existing tabs need to be closed be­cause block­ing a script does not shut down an au­dio con­text that it has al­ready cre­ated.

These rules are de­lib­er­ately nar­row. They block only the two ob­served script fam­i­lies and only when re­quested by AliExpress. I would not be sur­prised if this stops work­ing in the fu­ture, I’ll cross that bridge when it comes to it.

Because these scripts ap­pear to be con­nected with anti-fraud sys­tems, block­ing them may cause ex­tra CAPTCHAs or prob­lems dur­ing lo­gin or check­out. So far the home­page and or­di­nary prod­uct brows­ing still work, but I would tem­porar­ily dis­able the rules if AliExpress re­fuses a le­git­i­mate lo­gin or pay­ment.

Why I am block­ing it

The anti-fraud use case is un­der­stand­able, but this im­ple­men­ta­tion has real world prob­lems.

It runs on the gen­eral shop­ping home­page be­fore I per­form a sen­si­tive ac­tion. It col­lects a broad set of de­vice and be­hav­ioural mea­sure­ments, the im­ple­men­ta­tion is de­lib­er­ately dif­fi­cult to in­spect, and there is no vis­i­ble in­di­ca­tion that the page has started a live au­dio-pro­cess­ing graph.

It also pro­duced a very real hard­ware side ef­fect. A silent fin­ger­print­ing test was able to in­ter­fere with Bluetooth mul­ti­point switch­ing, while the browser’s mute con­trol did noth­ing!

If a hid­den an­a­lyt­ics or se­cu­rity fea­ture can take own­er­ship of an au­dio path strongly enough to change how ex­ter­nal hard­ware be­haves, block­ing it seems like a rea­son­able trade-off.

I also can­not prove how long AliExpress stores the fin­ger­print or whether it is used across other Alibaba prop­er­ties. The client code proves that ex­ten­sive fin­ger­print-like mea­sure­ments are col­lected and trans­mit­ted, but server-side re­ten­tion and iden­tity link­age are not vis­i­ble from the browser. Can you re­ally trust any­one on the in­ter­net to have your best in­ter­ests at heart?

TL;DR

The AliExpress home­page silently cre­ates two run­ning WebAudio graphs from heav­ily ob­fus­cated Alibaba se­cu­rity scripts. The graphs gen­er­ate and analyse a wave­form as part of a much larger browser fin­ger­print, then con­nect through a zero-gain node to the sys­tem au­dio des­ti­na­tion pre­vent­ing the user from hear­ing any­thing.

On my setup, this ap­pears to keep the PCs Bluetooth au­dio path ac­tive and pre­vents mul­ti­point head­phones from switch­ing back to a phone. Muting the tab does not fix it be­cause there is no con­ven­tional me­dia el­e­ment to mute.

Blocking col­lina.js and fireyejs.js with the two uBlock Origin rules above pre­vented the hid­den au­dio con­texts from be­ing cre­ated and means I can hap­pily lis­ten to my mu­sic with­out be­ing in­ter­rupted while brows­ing AliExpress.

Edit - There have been some great dis­cus­sions on Hacker News that are worth check­ing out: https://​news.ycombi­na­tor.com/​item?id=49372583

Edit - There have been some great dis­cus­sions on Hacker News that are worth check­ing out: https://​news.ycombi­na­tor.com/​item?id=49372583

To add this web app to your iOS home screen tap the share button and select "Add to the Home Screen".

10HN is also available as an iOS App

If you visit 10HN only rarely, check out the the best articles from the past week.

Visit pancik.com for more.