AliExpress accused of fingerprinting shoppers with silent audio trick that also muted a dev’s headphones

← Back to the feed

AliExpress accused of fingerprinting shoppers with silent audio trick that also muted a dev’s headphones

The Register · 2 hours ago

Developer Matt Callaghan says he caught AliExpress, part of Alibaba, running hidden audio-based fingerprinting scripts that track visitors even though the sound is silenced to zero gain. He discovered the issue after noticing his Bluetooth headphones kept cutting audio from his phone whenever he opened AliExpress in Firefox or Chrome, tracing the cause to obfuscated WebAudio scripts that generate and analyse an inaudible sawtooth waveform, a technique that can also be combined with other device data to build a detailed fingerprint of a user's browser and hardware.

Callaghan found the scripts sat within AliExpress's browser security and anti-abuse tooling, alongside code collecting screen dimensions, device memory, browser plugins, WebGL rendering and mouse events, all of which he says amounts to a "fairly comprehensive" fingerprint that appears to be encrypted and sent to Alibaba's telemetry services. Firefox says its anti-fingerprinting protections, introduced in version 118 back in September 2023, neutralise such WebAudio tricks by grouping 99.24 percent of users into just three hardware-based "buckets" so they look identical, though engineer Tom Ritter noted 48 users worldwide fall outside these groups and remain more exposed to tracking. The Register has approached Alibaba for comment.

  • AliExpress accused of using silent audio scripts to fingerprint browsers
  • Trick also disrupted a developer's Bluetooth headphone switching
  • Firefox says its 2023 anti-fingerprinting update blocks the technique for most users

Software

Read the full article at the source →