AliExpress was silently running audio in your browser to fingerprint and track your device
The issue only surfaced after a developer had trouble using multipoint Bluetooth headphones while an AliExpress tab was open: the headphones wouldn't switch properly from the computer to a phone. Once the tab was closed, the problem disappeared. Read Entire Article
AliExpress has been silently running audio processes in users' browsers to track and fingerprint devices, according to researchers. This technique, which leverages Alibaba's security systems, taps into a device's audio hardware to produce a unique signal that can identify a device without relying on cookies. The issue came to light when a developer encountered problems using multipoint Bluetooth headphones while browsing AliExpress, as the headphones failed to switch between a computer and a phone.
Upon investigating, the developer discovered that AliExpress was utilizing the Web Audio API to create audio-processing graphs with zero volume, which still engaged the device's audio system and prevented the headphones from switching devices. This behavior is distinct from typical media player audio and continues processing even when the browser tab is muted.
Additionally, the code supports browser fingerprinting, a method that collects device-specific details to recognize a browser over time. The scripts measure variations in how a device processes an identical audio signal, shaped by factors like the processor, sound hardware, operating system, browser, and drivers. The gathered data helps form a comprehensive profile of the device.
AliExpress is not the only site employing such tactics; Brave, a browser, has blocked the scripts responsible for this audio-based tracking, citing its six-year history of default protections against audio fingerprinting. However, users on other browsers may still be vulnerable and can employ content blockers like uBlock Origin to mitigate the issue, though this may interfere with certain AliExpress functionalities relying on the same code for security or fraud prevention.
This incident highlights the ongoing trade-off between enhanced online security and user privacy, as companies strive to identify suspicious activities while users seek limits on tracking without explicit consent.
Written by urgent.news from TechSpot's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.