Inaudible sounds used to fingerprint browsers catch AliExpress red-handed
Is the technique outdated? Yes. Is it still creepy? Also yes.
Chinese e-commerce giant AliExpress has been exposed for covertly tracking visitors using a hidden technique that involves inaudible sounds embedded in webpages. This surreptitious monitoring was inadvertently uncovered by researcher Matthew Callaghan, who stumbled upon the clandestine tracking while attempting to troubleshoot issues with his Bluetooth headphones.
While browsing AliExpress, Callaghan noticed that audio playback on his phone ceased when the website loaded. Intrigued by this odd behavior, he adjusted his headphones settings to allow sound output from his phone, except when his PC generated audio. Upon reloading the AliExpress homepage, Callaghan observed that his phone audio remained muted until he closed the tab.
Upon further investigation, Callaghan discovered two obfuscated scripts embedded within AliExpress' code. These scripts colluded to create a graph that analyzed the WebAudio readings of each browser visiting the site. This graph functioned as a type of oscillator, measuring the Sawtooth waves commonly produced by digital audio systems.
By analyzing these inaudible sounds, the scripts effectively created a unique fingerprint for each browser, allowing AliExpress to track and identify individual users without their knowledge. The company's use of this covert tracking method has come to light, shedding light on their clandestine data collection practices.
Written by urgent.news from Ars Technica's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.