Smashing Security podcast #484: How websites are tracking you with silence

When a chap called Matt noticed his Bluetooth headphones wouldn’t switch to his phone, he was surprised to realise the reason was a single AliExpress webpage sitting open in his browser – playing nothing at all, at zero volume. And yet somehow his hardware could hear it. Audio fingerprinting is one of the sneakiest tracking tricks on the web.
Meanwhile, the intelligence agencies of the “Five Eyes” (not Five Guys) have got together and published advice on how companies should communicate after a cyber attack. The summary? For the love of God, stop calling every breach “sophisticated.”
All this and more in episode 484 of the “Smashing Security” podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Danny Palmer.
0:00
0:00
Show full transcript
▼
This transcript was generated automatically, probably contains mistakes, and has not been manually verified.
Smashing Security, episode 484: How Websites Are Tracking You with Silence with Graham Cluley and special guest Danny Palmer.
Hello, hello, and welcome to Smashing Security episode 484. My name’s Graham Cluley.
We’ll be hearing more about them later on in the podcast.
So Danny, what are you going to be talking about this week?
When a machine can scope out your network, break in, and start creeping sideways through it faster than you can finish your coffee, you can’t rely on the hope that someone will notice the alert eventually.
And this is where ThreatLocker earns its keep. Default deny and least privilege sit right in the agent’s path, so nothing runs just because it asks nicely.
Application allowlisting decides what’s even allowed to execute. Ring-fencing keeps trusted apps from wandering off and touching things they shouldn’t.
Agentic AI doesn’t make established security principles obsolete. It makes getting them right considerably more urgent.
So you’d hope that my ears would pick up a bit more, like Daredevil, the superhero. He’s blind and he can hear and sense things really well.
But no, I could probably tell you what sort of beer was what, vaguely, if you gave me some blind tasting. But no, nothing useful there, I’m afraid.
And this is a game that I like to call Name That Chime. Listeners, you can play along as well and see how you do compared to Danny. So Danny, are you ready for round 1?
Someone will say it’s service pack number whatever, 1.0b or something, won’t they? But anyway, I think that’s a win. I think that’s close enough to me.
All right, let’s get a little bit harder.
Depending on how well you did, you’ve either just proven you’re a veteran of the analog internet, or you still think punch cards are a pretty neat idea.
Either way, well played, everyone. Fair play, Danny.
Now, funnily enough, sound is what I’m talking about today because something rather odd happened the other day to a chap called Matt Callahan.
I don’t buy fancy ones now, ’cause I’m just losing them all the time. They’re either falling out your pocket, falling down the gap in the tube, they go through the wash.
I kind of miss plugging in.
Until of course your phone suddenly rings and your headphones completely refuse to switch over. And they’re utterly convinced that your laptop is playing some sound.
It’s playing some Finnish death metal.
Anyway, this is what happened to this chap, Matt, and his phone was ringing, but his earphones weren’t swapping over. So he checked Spotify on his computer.
And that was paused and he checked YouTube and that wasn’t playing any videos.
And the only thing which he actually had ultimately running on his laptop was one single browser tab sat on the AliExpress homepage.
It wasn’t actually playing anything as far as he could tell. It was just sitting there, but it was preventing his earphones from switching to his phone.
And he’s a sort of curious chap and he wondered why might this be?
Now, as we all know, websites absolutely love to recognise us when we return to them.
And the traditional way to do that is with cookies, which, you know, if you’re a non-nerd, cookies are like little text files that get left on your computer and they say, this is Graham coming back again, you know, make sure to show him Doctor Who-related t-shirts and things like that.
And because of this, websites have got sneakier over time, and a lot of them now try to fingerprint you when you visit them.
Now, they’re not asking — it’s not like going through security at an airport.
They’re not actually asking for your fingerprints, but what they do is they take a really good look at you and they note down all of the details that when combined make you look different from other people.
They might look at what fonts you have installed. They can look at what browser version you are using, huge amounts of information.
If you can tell what size of monitor you are using, what your fonts are, what else can they see?
One detail, like the resolution of your screen, or the current window size or whatever it may be, or what fonts you have installed — by itself maybe doesn’t narrow you down to one particular individual.
But when it’s hundreds of details all combined, that particular pattern, it might say, well, we’ve only ever seen one person with that particular mix before.
But I reckon if you found my profile and saw which subreddits I posted in, you’d probably easily identify it’s me through sort of my interests, you know, posting about this sports team, this computer game, Doctor Who.
And what Matt found on AliExpress’s website was that it had a piece of code which was doing just that, but it was audio fingerprinting.
And so the site would ask his browser, or any person going to the site, to generate a very specific, very precise sound.
Or rather, it gave the browser complicated maths to generate a sound.
So different web browsers running on different operating systems all crunch those numbers in their own slightly unique way.
There’s microscopic little quirks in the final calculation.
It’s a bit like how you can have two different pianos playing the same sheet music and they would still sound very slightly different.
Can the user hear this noise, or is it so subtle the user themselves can’t hear it, but the device can?
It’s not actually generating anything which is audible. As far as your computer is concerned, there isn’t any media playing at all, just some background calculations happening.
Silence doesn’t mean it can’t be picked up by your hardware. So the calculations do actually go and grab hold of your computer’s real audio system to do the computation.
And on Matt’s setup, that was enough to make his headphones think that audio was actually playing on his laptop, even though it’d been programmed to say absolute zero.
It doesn’t give itself away — well, it does give itself away, because it accidentally annoyed someone else’s Bluetooth headphones. So this kind of thing isn’t new.
It’s not unique to AliExpress. It’s just one of a bunch of tricks which websites have up their metallic sleeves in order to track you. And it could be used for good.
I mean, it can be done to work out if you’re a genuine shopper or a bot, for instance.
I’d written an article for a client of mine and I posted it up on LinkedIn saying, go and read this, you know, fascinating story. Go and read this.
I looked at his reply, you know, sort of summing up my article, and I thought, that wasn’t written by a human.
And I went to look at his other comments and I saw a steady stream of every minute he’s replying to someone else’s article with his own 3-sentence comment on it.
Clearly been written by an AI, some of them even including emojis as well. But it’s just got the stench of AI about it.
Well, yeah, it seems there are people who just sort of farm out everything to AI.
I actually made a LinkedIn post earlier today poking fun at this where I say, you can tell my work is not AI generated because you’ll be able to see the errors in all the first drafts.
So Firefox and Brave, they scramble the reading so that trackers get an unreliable answer. I think what they actually do is they make all of the calculations look a bit generic.
So you can’t distinguish as easily between them.
So you wouldn’t be able to tell with the human ear, but if anything is coming along and trying to work out any difference from the audio, even if it’s silent audio, as in this case, it wouldn’t be able to.
So you might not be going mad if your headphones start behaving strangely when you’re visiting a shopping website.
And if you would rather your browser didn’t do this kind of thing, what you can do is you can run a browser extension.
uBlock Origin is a good one, which can block this kind of behaviour for you and give you that extra little bit of privacy if you don’t want to be tracked online.
The irony is, of course, some of the tech companies which are building these browsers are themselves advertising companies. Let’s not beat around the bush, right?
So no more wrestling spreadsheets, hunting down audit evidence, or slogging through endless questionnaires.
That means I have seen and reported on hundreds of cyberattacks, data breaches, and other, let’s call them incidents.
I mean, retailers, utility providers, government agencies, banks and financial services companies, charities, sports teams, even postal services.
You name the industry, I’ve likely written about a cyberattack, a hack, a data breach, a ransomware attack.
But it is also a bit weird to think about how long I have been doing this.
When I first started at ZDNet back in 2016, one of my first stories was about a ransomware attack against a local council.
And the council didn’t pay because the ransom demand was a whopping £500, which is just amazing to think about in terms of how much ransom demands and things have gone up.
So anyway, loads of these attacks in many, many cases, especially when the entity affected by the cyberattack is here in the UK.
As a cybersecurity reporter, it has been my job to find out exactly what is going on, which sometimes can be harder than other times.
I’ve made phone calls or sent emails to PR communication teams to verify they’ve been hit by a cyberattack.
More often than not, the organisations in question don’t want to speak widely about it because they often cite ongoing issues, which is understandable.
I see their perspective from that.
You know, my job is to try and get information about what’s going on, but then organisations, if they’ve got an ongoing thing, they don’t want to jeopardise that.
I suppose you can think of it like when a court case is ongoing, the news publications can’t really say much about it just because it might impact what is going on.
Not that sophisticated, but I suppose they don’t want to seem like they’ve been foolish, but these things eventually sometimes come out. Anyway, why am I talking about this?
I assure you, Graham, it’s not just ranting.
This week, cyber intelligence agencies from the United States, Canada, the United Kingdom, Australia, and New Zealand, collaboratively known as Five Eyes, they’ve got together and they’ve published advice to organisations on what they should do when they get hacked.
And the advice that Five Eyes have given organisations is that if you get hacked or face a cyber incident, please be a bit clearer in your communications about what has happened.
And that guidance has been published by CISA, which is the agency responsible for securing critical infrastructure in the United States.
But it’s also been written with input from other Five Eyes agencies, including the FBI, the UK’s National Cyber Security Centre, and the Australian Signals Directorate.
The aim of the 9-page document is to provide guidance to organisations on how they can plan and execute what they say is clear, timely, accurate, and audience-appropriate communications during IT and OT outages as a result of cyberattacks and other issues.
As we’ve just discussed, these cyberattack things appear to be quite common these days.
But the advice is based on a handful of key ideas.
And the first around these is to ensure your organisation already has a plan around communications should it be hit by an incident.
Businesses are told to have contingency plans in place for their cybersecurity and other teams on how they should react if they get hacked or breached.
So it only makes sense that the communications team should be a part of that. I mean, there should be some sort of standard document.
Something I’ve just thought of as well is we might have to factor into this: if you’re hit by a certain type of cyberattack, can you even get that information out there into the world?
Often when we’ve seen a company which has been hit by something like ransomware, what you find is they’ve actually been communicating with each other via WhatsApp.
Anyway, so the plan is to have a plan.
So if the worst happens, someone in an organisation knows how to react — stakeholders, partners, customers, and yes, nosy gits like me in the press.
If we have questions, they can actually answer those questions. So that’s tick one.
So that leads to the second piece of advice, which is that those who have been hit with a cyber incident should, quote, practice transparency and avoid PR and marketing language.
Yes.
Get someone in the IT department to describe what’s happened to the company. Now, there may be drawbacks in that approach as well.
You could have an impact on your stock price, could have an impact on your brand reputation, but it’ll be clinically honest. That’s the thing you can guarantee.
There will be absolutely probably far more transparency than you could ever have wanted.
Now, as a reporter, this is frustrating. You know, it just basically sort of barricades me from doing my job in terms of trying to actually find out what has happened.
But it’s even more worrying for customers if they feel like they’ve been left in the dark by vague statements. In the long run, it doesn’t help anyone.
But if you put yourself in the position of a company which has suffered an attack and you are saying, Danny, you need to be transparent and you need to explain what’s happened, it’s not always obvious what has happened.
So it’s like, well, we know this has happened, but we don’t know yet whether our customers are really impacted, or whether it’s 3 of our customers or 3 million of our customers.
And it’s going to take time for us to ascertain that.
So much as I would love companies to be more upfront about these things, there are sometimes quite legitimate reasons why they may find it impossible to confirm everything all at once.
Well, there have actually been some high-profile cyberattacks over the years where the organisation affected has been pretty transparent about what has happened during the incident and its resolution.
I think one of the best examples of this, NotPetya, remember that?
And if I recall correctly, the company’s security and leadership teams were rather transparent. This instance hit us, here’s how we’re dealing with it.
And, you know, they completely gave updates on how they’re trying to fix it.
I mean, this was a major shipping company where a lot of stuff that goes around the world was reliant on it.
Maersk, this huge shipping organisation, their ships weren’t moving.
They were hit by a cybersecurity breach, but they actually turned it in some ways into a great piece of branding for them because they came out looking like heroes.
And what you find is that when you are open, when you do speak to your clients, and your customers and your partners and explain to them what’s happening, you actually get a lot of sympathy.
Other cybersecurity leaders like to hear about these things. They can learn lessons.
I mean, I’ve got an interview that’ll be coming up that we publish shortly for Inverness Security Magazine, where I spoke to a CISO about a ransomware attack that hit them and how he recovered without paying the ransom, which is, yeah, you don’t really get from PR speak.
So, yeah, to answer your questions, what’s the final piece of advice?
It recommends once an incident has been dealt with, organisations should detail the technical information about what happened, what the cause was of the incident.
That sort of thing can help other organisations from falling victim to attacks. So maybe it is those IT workers and those devs that need to write those documents.
Maybe not the ones doing the first PR, but at the end of the cycle, real-world lessons can be really helpful to organisations.
And I’m not just saying that as a reporter with a vested interest in digging out information. I promise.
No scoping calls, no 6-week wait, and it costs a fraction of the traditional price.
Real issues, not noise. You get an audit-ready report within hours.
It flags what’s exploitable, what to fix first, and how, so your team can act without waiting around for the security team.
It could be a funny story, a book that they’ve read, a TV show, a movie, a record, a podcast, a website, or an app, whatever they wish.
It doesn’t have to be security-related necessarily. Well, my pick of the week this week is not security-related. Danny, I don’t know if you consider me a bit of a sportsman.
I once took a shot on goal and it went out for a throw-in. I’ll leave it there.
Because, as I’m sure you’re aware, Danny, it was the World Stone Skimming Championships.
So for anyone who’s ever skimmed a stone, I wouldn’t say I’ve ever successfully skimmed a stone.
When you skim a stone, the idea is that it bounces along the water a bit like a Barnes Wallis bomb going up against a Nazi dam sort of bouncing along and how far can you get it?
Well, they have this competition in Scotland. People come from all around the world. They were coming from Africa. They were coming from the Antipodes.
Now, sometimes it’s quite controversial, it turns out. Last year, there was some controversy. Officials caught some competitors meddling with the stones.
They were sanding their stones into suspiciously perfect discs.
Well, I know lots of people are excited to hear about the World Stone Skimming Championship, but of course you’re thinking that was last weekend and I wasn’t on the island of Easdale last weekend or in the Outer Hebrides.
What can I do? Have I missed it for another year? Well, fear not, fear not, because I have researched this and I’ve found a YouTube video which is 4 and a half hours long.
Danny, I know you love your sport. Will you be checking out?
There may be people introducing each skimmer, but there’s not a lot of, you know, you don’t sort of get Sue Barker or her — do the competitors get big entrances like World Championship boxers?
That’d be fantastic, wouldn’t it? Anyway, the World Stone Skimming Championship is, of course, my pick of the week. Danny, what’s your pick of the week?
So I — it’s taken me a bit of time to sort of come up with my character backstory and lore.
He’s evolved into something of a nautical explorer, someone who is an expert in sailing on the high seas, and searching for long-lost islands for treasures.
Some people might say this sounds a bit like a pirate. Keen to do my research, I’ve been reading a book called The Pirate’s Code: Laws and Life Aboard Ship.
And Graham, I have learned a lot about pirates by reading this book.
That wasn’t actually really a thing — it just became a thing in fiction. I think one pirate maybe tried to do it, but he wasn’t very successful at it.
But something I found interesting while reading this is there’s arguably some similarities between pirates of the 17th and 18th centuries and cybercriminals today.
And no, I don’t mean the software pirates who download movies, music, and games for free from nefarious sources.
You see, something I learned from this book was that one of the reasons that men — and it was for the most part men — signed up for life on a pirate ship was because the paying conditions were much better than working on a legitimate vessel, be it a trading ship or in the Royal Navy or something like that.
And this had me thinking about how a lot of malware developers and BEC scammers try to justify doing this work, saying, oh yeah, we’re doing crimes, but it pays more.
They also see themselves as taking from the rich — they often mean people in Europe and the United States.
If they stole my savings, I don’t think I’d be seeing it as some sort of romantic ideal about stealing from the better off.
But I mean, if you think of how many people are romance scammers or defrauding the elderly out of their savings.
Like cybercrime, piracy — yes, it has potential vast riches, but do it for too long or push things too far and you can get caught, which if anything this book has taught me is that didn’t go very well for pirates if they were caught.
I definitely recommend this book because it ties some real history to think about in a fun way — pirates are very much in the public consciousness, but you think about how much we actually know about them.
So I recommend that book 100%.
They’re very interesting, I promise you.
Or you can follow Smashing Security on Reddit and Bluesky and Mastodon as well. And don’t forget to ensure you never miss another episode.
Follow Smashing Security in your favourite podcast app, such as Apple Podcasts, Spotify, and Pocket Casts for episode show notes, sponsorship info, guest lists, and the entire back catalogue of more than 480 episodes.
Check out smashingsecurity.com. Until next time, cheerio. Bye-bye.
And a huge thank you to Danny Palmer for joining me this week and to this week’s sponsors, ThreatLocker, Intruder, and Vanta, whose money we’ve accepted with enormous enthusiasm and only a small amount of shame.
And a very special thank you to the following fine chums. Travis West, who’s riding in, sorting out his security posture, and riding off again. We’ve got Richard Anand.
Cheers to Panda Bear, whose true identity remains one of the great unsolved mysteries of the world. And also to Panos. Sounds like a Greek loaf of bread if you ask me.
Big love to Billy, a man unbothered by surnames. And to Robert Martin and Govind Acharya, a name that sounds like it belongs to someone who knows something we don’t.
And finally for this week, Jamie Forster, Scotia, and JBSK. Four letters there with zero explanation and maximum intrigue.
Those fine, upstanding, and clearly slightly reckless individuals are members of Smashing Security Plus, which means they get their episodes ad-free earlier than the general public, and perhaps most importantly, they get their names read out at the end of the show in a tone that, well, sort of hovers somewhere between sincere gratitude and mild ridicule.
If you would like to join them in this exclusive club of the wonderful and slightly foolish, head over to smashingsecurity.com/plus where for a modest fee, you too can be publicly mocked by a middle-aged British cybersecurity podcaster.
So yes, you can become a patron, or if you’d rather keep your money, there are plenty of ways to support the show that don’t cost a penny.
You can like, you can subscribe, you can leave a 5-star review wherever you listen, you can tell your friends about us, or you just shout about the podcast in the pub until people politely ask you to leave.
Every little bit helps, and frankly, it really makes all the effort worthwhile. So until next time, cheerio. Bye-bye.
Host:
Graham Cluley:
Guest:
Danny Palmer:
Episode links:
Sponsored by:
- ThreatLocker – Book a demo today and start securing your organisation.
- Vanta – Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!
- Intruder – The depth of a manual pentest, on-demand. Start an AI pentest in minutes – 25% off your first pentest for Smashing Security listeners.
Support the show:
You can help the podcast by telling your friends and colleagues about “Smashing Security”, and leaving us a review on Apple Podcasts or Podchaser.
Join Smashing Security PLUS for ad-free episodes and our early-release feed!
Follow us:
Follow the show on Bluesky, or join us on the Smashing Security subreddit, or visit our website for more episodes.
Thanks:
Theme tune: “Vinyl Memories” by Mikael Manvelyan.
Assorted sound effects: AudioBlocks.

