Inaudible sounds used to fingerprint browsers catch AliExpress red-handed
| Source: Ars Technica AI
Tags: AliExpress, browser fingerprinting, WebAudio API, privacy, GDPR, canvas fingerprinting, tracking
AliExpress was caught deploying 13+ simultaneous browser fingerprinting techniques, including an obsolete audio soundprinting method sending inaudible WebAudio oscillator signals — discovered by researcher Matthew Callaghan when the tracking kept cutting his Bluetooth headphones. Firefox (since v118, 2023) and Chrome are immune to the audio vector, but the broader fingerprinting operation continues.
Details
Chinese e-commerce giant AliExpress was caught running a comprehensive browser fingerprinting operation, discovered by researcher Matthew Callaghan after his multipoint Bluetooth headphones kept disconnecting whenever he loaded the AliExpress homepage. Tracing the cause, he found two heavily obfuscated scripts using the WebAudio API to send inaudible oscillator signals (gain set to zero) and measure the browser's frequency response — a technique called audio soundprinting that exploits hardware and math library differences to produce unique device signatures. The audio technique was once powerful: variability in OS-level math libraries, combined with CPU differences, produced a massive entropy pool for fingerprinting. But Firefox neutered it in v118 (September 2023) by switching to browser-bundled math libraries, and Chrome and Safari were already immune for the same reason. AliExpress is still running the script, which now contributes minimal identifying value. The more concerning finding is the remaining 12+ fingerprinting vectors in parallel: canvas rendering and toDataURL(), WebGL renderer info and shader precision, screen dimensions, device pixel ratio, and more. These remain effective across modern browsers and can build stable cross-session user profiles without cookies. From a compliance standpoint, covert fingerprinting without explicit consent is a clear GDPR and CCPA violation. Enterprises running consumer-facing sites should audit vendor scripts for similar behavior — third-party embeds frequently introduce fingerprinting code outside the primary engineering team's awareness.