Ethical Hacking News
AliExpress has been accused of using audio fingerprinting to track users' browsing habits without their consent. The move has sparked a heated debate about the ethics of online tracking and the need for greater transparency and accountability in the industry.
AliExpress has been accused of using audio fingerprinting to track users' browsing habits without their consent. The technique involves a silent audio trick that generates a unique audio fingerprint of the user's device, allowing the platform to collect sensitive data. Brave browser has protected users from fingerprinting for six years by injecting random data into the browser's output. Firefox's anti-fingerprinting technology has thwarted AliExpress's tracking tricks, but has a limitation that makes it less effective against a small minority of users. Chrome lacks protection against WebAudio-based fingerprinting, and there are at least thirty distinct fingerprinting techniques that work in Chrome right now. The incident highlights the need for greater transparency and accountability in online tracking practices. The company's actions have sparked a heated debate about the ethics of audio fingerprinting and the importance of protecting online privacy.
AliExpress, the popular online retail platform, has found itself at the center of a controversy surrounding audio fingerprinting, a technique used to track users' browsing habits without their consent. The accusations were made by Matt Callaghan, a software engineer who claimed that his Bluetooth headphones stopped working whenever he visited AliExpress's website. Initially, Callaghan suspected that the issue was related to his headphones' compatibility with the website's audio format, but further investigation revealed a more sinister plot.
According to Callaghan, AliExpress employed a silent audio trick that took advantage of a vulnerability in the WebAudio API, a browser-based audio processing technology. The platform's scripts, which were "extremely obfuscated," built a WebAudio graph that introduced a sawtooth oscillator to generate a waveform. This, in turn, was used to measure the waveform's frequency data, creating a unique audio fingerprint of the user's device. The script's gain was set to zero, meaning that the end user would not be able to hear anything, but the browser would still process the audio, allowing AliExpress to collect sensitive data about the user's device.
Callaghan's findings were corroborated by Brave, a privacy-centric browser that also stated that it had protected users from fingerprinting for six years. Brave's developers inject random data into the browser's output to show a different fingerprint to different sites, and the browser also blocks specific scripts used by AliExpress for the tracking method mentioned above.
The situation was further complicated when Firefox, another popular browser, issued a statement claiming that its anti-fingerprinting technology had thwarted AliExpress's tracking tricks. Firefox's security engineer, Tom Ritter, explained that as of version 118 (September 2023), the protections introduced by the browser eliminated the efficacy of WebAudio-based fingerprinting. However, Ritter noted that the protections worked by grouping all users together, making it look like all fingerprinted users were the same, effectively nullifying the tracking attempts.
Ritter also pointed out that 48 users worldwide did not fall into the three buckets, or 0.76 percent whose machines did not allow the scripts to run. These users fell into 23 other minuscule buckets, which meant that fingerprinting was more effective on this vast minority of users. Nevertheless, Ritter emphasized that WebAudio fingerprinting was nearly useless and that browser fingerprinting would still be effective against a majority of users on the web.
Chrome, on the other hand, lacks protection against WebAudio-based fingerprinting. As Alexander Hanff, a privacy consultant, noted earlier this year, there are at least thirty distinct fingerprinting techniques that work in Chrome right now. Hanff warned that these techniques were not theoretical attacks from academic papers but real, production techniques deployed on millions of websites to identify and track users without their knowledge or consent.
The incident highlights the ongoing concern about digital privacy and the need for browsers to implement robust security measures to protect users' data. It also underscores the challenges faced by browsers in keeping up with the evolving landscape of online tracking techniques.
In light of these findings, AliExpress has been accused of violating users' trust and exploiting their personal data without consent. The company's actions have sparked a heated debate about the ethics of audio fingerprinting and the need for greater transparency and accountability in online tracking practices.
As the debate rages on, it is essential to recognize the implications of this incident and to take steps to protect our online privacy. It is also crucial to hold companies like AliExpress accountable for their actions and to push for greater regulations and standards in the industry.
In conclusion, the audio fingerprinting scandal surrounding AliExpress serves as a reminder of the importance of digital privacy and the need for robust security measures to protect our personal data. As we navigate the complex and ever-evolving online landscape, it is essential to stay vigilant and to demand greater accountability from companies like AliExpress.
Related Information:
https://www.ethicalhackingnews.com/articles/AliExpress-Embroiled-in-Audio-Fingerprinting-Scandal-A-Web-of-Deceit-and-Digital-Intrusion-ehn.shtml
https://www.theregister.com/security/2026/08/24/aliexpress-accused-of-fingerprinting-shoppers-with-silent-audio-trick-that-also-muted-a-devs-headphones/5291662
https://www.fbi.gov/wanted/cyber/apt-41-group
https://attack.mitre.org/groups/G0096/
Published: Mon Aug 24 09:29:25 2026 by llama3.2 3B Q4_K_M