A hidden tracking practice on AliExpress appears to have surfaced because of an odd headphone problem, revealing a form of browser fingerprinting most shoppers would likely never notice.
In some cases, visiting the site may have set off inaudible audio processing that examined a device instead of merely showing the storefront.
Here's what to know
According to Ars Technica, security researcher Matthew Callaghan said he found the behavior by accident.
The outlet noted that Callaghan was using multipoint Bluetooth headphones linked to his phone while browsing on his computer. When he opened the AliExpress homepage, his audio would stop playing. Whenever he closed the tab, the audio would begin again.
The culprit, he said, was a pair of heavily obfuscated scripts on the site that worked together as a graph analyzing visiting browsers' WebAudio output.
According to Ars Technica, the scripts used an oscillator to evaluate Sawtooth waves, a common kind of digital audio output, while keeping the gain at zero so users would hear nothing.
Even without audible sound, the browser still processed the audio path and returned the resulting data to AliExpress.
Rather than trying to play audio for shoppers, the system appears to have been collecting hardware and software traits that could help identify a user.
This kind of "soundprinting" is considered outdated, but it can still raise privacy concerns when a company quietly deploys it on a shopping site, Ars Technica explained.
More background
Browser fingerprinting works by collecting small technical details about a device — such as audio behavior, math libraries, or hardware quirks — to create a profile that can help track someone without relying solely on cookies.
Differences in the math libraries browsers used for audio processing created enough variation that, combined with CPU distinctions and other system traits, they could produce many unique signatures.
That gave companies another way to recognize returning users, even if those users had taken steps to limit standard tracking.
When a retailer uses stealthy identification techniques, it can undermine privacy choices and make it harder for shoppers to control how much data companies collect about them.
What can be done?
Major browsers have taken steps to weaken this specific technique.
Firefox's response began in 2023 with version 118, when it stopped depending on operating system math libraries and used its own instead, Ars Technica explained.
Tom Ritter, a Firefox developer and Tor Project volunteer, said the change reduced the entropy enough to make the technique stop working.
Google said Chrome's use of its own libraries keeps this sound-based fingerprinting from working there, the outlet said, and Safari users are likely protected for the same reason, though Apple did not confirm it.
Get TCD's free newsletters for easy tips, smart advice, and a chance to earn $5,000 toward home upgrades. To see more stories like this one, change your Google preferences here.







