Inaudible sounds used to fingerprint browsers catch AliExpress red-handed
A security researcher accidentally uncovered an invasive tracking method employed by the e-commerce giant AliExpress.
While browsing the retailer's website, the researcher noticed that his Bluetooth headphones kept disconnecting from his phone because his computer was attempting to process audio. Upon investigating the site's code, he found obfuscated scripts that generate inaudible high-frequency sounds to analyze how a visitor's browser processes audio data. This technique, known as audio fingerprinting, creates a unique identifier for the user's system by exploiting subtle hardware and software differences.\n\nAlthough modern browsers like Chrome, Firefox, and Safari have implemented countermeasures by using standardized internal math libraries to nullify the effectiveness of audio fingerprinting, the script remains active on AliExpress. The retailer reportedly continues to use this legacy mechanism alongside numerous other device-fingerprinting scripts to track visitors. The incident highlights the ongoing battle between privacy-focused browser developers and website operators seeking increasingly sophisticated ways to bypass user tracking protections.
Summary generated August 27, 2026. AI summaries can make mistakes.
Read Original on Ars TechnicaCategory
Topic (AI-estimated)
Cybersecurity & Privacy
95% confidence
Privacy
This category is an AI-estimated classification based on the article's content and may not be fully accurate.
Sentiment
Sentiment
Negative