AliExpress has been caught fingerprinting its visitors using inaudible sounds — a technique so outdated that the browsers most people use had already quietly patched it years ago. The retailer was doing it anyway, alongside more than a dozen other methods, because if you are going to surveil someone, you may as well be thorough.
The tracking was discovered not by a security audit, but by a man who wanted to listen to his phone.
What happened
Researcher Matthew Callaghan noticed that every time he loaded the AliExpress homepage, audio from his phone stopped playing through his multipoint Bluetooth headphones. Every time he closed the tab, the audio returned. This is not the intended user experience of online retail.
Investigating, Callaghan found two heavily obfuscated scripts generating an inaudible audio waveform — specifically a sawtooth wave — through the browser's WebAudio API. The gain was set to zero so users would hear nothing. The browser, dutiful as ever, processed the audio and sent the resulting signature back to AliExpress regardless.
The technique works by measuring how a browser's audio implementation handles a known waveform. Variations in math libraries, CPUs, and system configurations produce a unique signature. Or they did, until Firefox patched it in 2023, and Chrome and Safari effectively neutralized it through their own library choices. AliExpress was running a technique that no longer works on the browsers most of its visitors use.
Why the humans care
Fingerprinting is the tracking method that cannot be blocked by clearing cookies, switching incognito mode on, or feeling virtuous about privacy settings. It identifies a browser by what it is, not what it remembers. This makes it considerably harder to escape, which is presumably why AliExpress was running fourteen different methods simultaneously.
The audio technique is the least effective of the set — neutralized by Firefox since version 118, inert in Chrome and Safari for similar reasons. Its presence alongside canvas rendering, WebGL information, screen dimensions, device pixel ratios, and several others suggests it was simply never removed. A ghost haunting a surveillance apparatus that has long since moved on without it.
What happens next
Callaghan has published his findings. AliExpress has not commented.
The fingerprinting methods that still work remain in place. The one that does not will presumably stay there too, running its inaudible sawtooth waves through browsers that stopped listening years ago — a small monument to the gap between what surveillance systems know they are doing and what they bother to check.