AliExpress Gets Caught Using Audio Fingerprinting

Researchers find AliExpress using obsolete audio fingerprinting technique that Firefox and Chrome have already rendered ineffective.

By Central
AliExpress deployed audio fingerprinting, a tracking method that modern browsers have largely neutralized.
Highlights
  • AliExpress was caught using audio fingerprinting, which creates a unique identifier from a device's sound output.
  • Firefox and Chrome neutralized audio fingerprinting by standardizing audio math libraries in the browser.
  • The cat-and-mouse game between browsers and trackers continues as new techniques emerge when old ones are blocked.

The online retail giant AliExpress has been caught deploying a controversial and largely obsolete tracking technique known as audio fingerprinting on its website, reigniting a long-simmering arms race between browser privacy protections and the data-collection ambitions of major e-commerce platforms. Researchers discovered the code embedded in the site’s tracking infrastructure, revealing that the platform is harvesting subtle, unique variations in how a user’s device produces sound through the browser to generate a persistent identifier. This practice, which once posed a significant threat to user anonymity, has been largely neutralized by modern browsers like Firefox and Chrome, yet its continued presence on one of the world’s largest online marketplaces raises pressing questions about the depth and opacity of modern web surveillance.

How Audio Fingerprinting Works and Why It Was Once So Powerful

Audio fingerprinting, also known as audio soundprinting or the Web Audio API fingerprint, exploits the fact that no two computers produce sound in exactly the same way. When a browser generates an audio signal using the Web Audio API, the resulting digital waveform is shaped by a complex chain of hardware and software components. These include the central processing unit (CPU), the operating system, the sound card, and critically, the specific math libraries used to perform the digital signal processing calculations. Small differences in how these libraries handle floating-point arithmetic are amplified by the browser’s audio processing pipeline, producing a unique “noise fingerprint” for each device.

In the past, the variability in different math libraries was high enough that when combined with differences in CPUs, GPU drivers, and other system-level components, the technique could generate a massively large number of uniquely different signatures. This made audio fingerprinting one of the most reliable and difficult-to-detect methods for tracking users across the web without using cookies, HTTP headers, or IP addresses. Because it operated silently in the background, requiring no user interaction or permission, it became a favored tool for advertisers, analytics firms, and fraud detection services.

Firefox and Chrome Have Rendered the Technique Largely Ineffective

After the audio soundprinting technique became widely known within the web security community, browser developers moved to close the vulnerability. Mozilla implemented a definitive fix starting with Firefox version 118, released in September 2023. Beginning then, as documented in a Bugzilla entry, the browser began using its own unique math libraries for audio processing rather than relying on the ones that shipped with the operating system. Tom Ritter, a Firefox developer who has also volunteered for the Tor Project, explained that this move to constant, browser-controlled libraries reduced the entropy available for fingerprinting enough to stop the technique from working effectively. The result is that all Firefox users now produce nearly identical audio signatures, making the method useless for distinguishing between different devices.

The technique has never been particularly effective in Chrome because Google’s browser, too, ships with its own standardized math libraries, a Google spokesperson confirmed. Safari users are likely safe for the same reason, although Apple did not immediately confirm that its browser includes similar protections. This means that for the vast majority of internet users on modern, updated browsers, the audio fingerprinting method employed by AliExpress is essentially a blunt instrument that generates no useful identifying data.

An Artifact from Years Past: Why AliExpress Is Still Using an Obsolete Method

The discovery that AliExpress is using an obsolete fingerprinting method immediately raises a logical question: why is it bothering to use a technique that, on most modern browsers, produces no unique signal? The most likely answer has to do with the scale and complexity of the company’s tracking infrastructure. According to the researcher who identified the code, AliExpress is not relying on audio fingerprinting in isolation. Instead, it is deploying more than a dozen other fingerprinting methods simultaneously. The audio technique is likely a remnant from years earlier, a piece of code that was originally implemented when it was a powerful tracking tool and has simply remained in the company’s tracking scripts, perhaps forgotten or deprioritized for removal.

The full list of additional fingerprinting techniques observed on the site includes:

  • Canvas rendering and toDataURL()
  • WebGL renderer information, extensions, and shader precision
  • Audio oscillator and analyzer output
  • Screen and viewport dimensions
  • Device pixel ratio
  • Hardware concurrency and device memory
  • Installed browser plugins
  • Supported audio and video formats
  • WebRTC behavior
  • Browser performance timing
  • Mouse, touch, focus, and scroll events
  • Device motion and orientation
  • Properties commonly associated with browser automation

This comprehensive suite of data-gathering methods is designed to create an aggregate profile of each visitor, one that is resilient to the failure of any single technique. By combining dozens of subtle signals, the site can still generate a highly reliable fingerprint even when individual components—like audio processing—are neutralized. The presence of the obsolete audio code is therefore less a sign of malicious intent and more an indicator of the sheer inertia and complexity of modern third-party tracking systems.

What Is the Full Scope of AliExpress’s Fingerprinting Operation?

The variety and sophistication of the techniques deployed raise a deeper question: just how effective are the remaining metrics that AliExpress is using? While audio fingerprinting has been effectively blocked by browser updates, other methods like canvas rendering, WebGL fingerprinting, and performance timing are far more resilient. Canvas fingerprinting, for example, relies on subtle differences in how a browser renders text, shapes, and colors—differences that are tied to the GPU, the graphics driver, and the operating system. These variations are extremely difficult to eliminate without breaking core web functionality. WebGL fingerprinting goes even deeper, extracting specific characteristics of the GPU hardware, including the exact model, driver version, shader precision, and supported extensions. This information can be nearly as unique as an audio fingerprint once was, and it works on all browsers.

The inclusion of device motion and orientation data is particularly notable. This technique is typically associated with mobile devices, where accelerometers and gyroscopes produce distinctive calibration biases and noise patterns. On smartphones, this can create a fingerprint that is so precise it can remain stable even after a factory reset. The fact that AliExpress is gathering this data suggests the company is actively tracking mobile shoppers with the same, if not greater, intensity as desktop users.

Hardware concurrency and device memory measurements provide another layer of identification. Chrome, for instance, exposes the number of logical CPU cores through the navigator.hardwareConcurrencycodecodecode API and the device memory through navigator.deviceMemorycodecodecode. While these are coarse measurements, they become powerful when combined with dozens of other data points. A user with a 16-core processor and 8 GB of RAM visiting from a 2560×1440 screen with a specific GPU is already a rare combination; adding performance timing, installed plugins, and mouse event patterns can narrow the field to a single individual.

How Does This Practice Affect the Average Shopper?

For the average user, the immediate implication is that there is no private way to browse AliExpress. Even if a user clears their cookies, uses a VPN, or switches to a private browsing window, the site can still recognize them on a subsequent visit. This persistent identification enables the platform to build detailed profiles of browsing history, search behavior, product interests, and price sensitivity. It allows AliExpress to track users across different sessions, devices, and even different accounts, creating a unified view of an individual’s shopping habits that is extremely difficult to escape.

The practice is particularly concerning for users in regions with strong privacy protections. While the European Union’s General Data Protection Regulation (GDPR) and California’s Consumer Privacy Act (CCPA) impose requirements on companies that collect personal data, fingerprinting often operates in a legal gray area. The data collected is not explicitly “personal” in the traditional sense—there is no name, email address, or phone number involved. Yet it serves the same function, allowing the site to uniquely identify and track an individual without their knowledge or explicit consent. Regulators in Europe and the United States are increasingly scrutinizing this practice, but enforcement has been slow, and the technical complexity of fingerprinting makes it difficult for both regulators and consumers to detect.

What Are the Technical Limitations of Current Browser Defenses?

While browser makers have made significant progress in blocking specific fingerprinting techniques, the broader challenge remains formidable. The very nature of modern web browsing requires that browsers expose a vast amount of information to websites. Screen dimensions, GPU capabilities, supported fonts, installed plugins, and even the user’s typing speed are all accessible through standard JavaScript APIs. Each individual piece of data may seem innocuous, but when aggregated, they form a unique signature. This is known as “entropy farming,” and it is exceedingly difficult to stop without breaking legitimate website functionality.

Firefox has taken the most aggressive stance with its Enhanced Tracking Protection, which blocks known fingerprinters and restricts access to certain APIs. Brave browser goes even further by randomizing some of its fingerprintable attributes, making each visit appear to come from a different device. Chrome, meanwhile, has proposed the Privacy Sandbox initiative, which aims to replace third-party cookies and fingerprinting with more privacy-preserving alternatives, but the rollout has been delayed, and critics argue that the proposed replacement APIs still leak significant amounts of identifying information.

The fundamental problem is that any API that allows a website to render content differently based on the user’s hardware or software capabilities is a potential fingerprinting vector. Until browsers can decouple feature detection from identification, the arms race will continue. A site like AliExpress, which has the engineering resources to deploy and maintain a dozen different fingerprinting techniques, is effectively betting that at least one of them will survive browser defenses.

The Broader Implications for the Web Tracking Ecosystem

What makes the AliExpress case particularly significant is not the specific technique used—audio fingerprinting is, after all, a solved problem for modern browsers. Rather, it is the revelation that one of the world’s largest e-commerce platforms maintains an extensive,

multi-layered fingerprinting infrastructure that operates outside the bounds of cookie consent mechanisms. This suggests that thousands of other sites are almost certainly employing similar tactics. The code used for audio fingerprinting is widely available in commercial tracking libraries and open-source scripts. It is trivial to implement and, until recently, highly effective. The fact that AliExpress was caught still using it likely means that many smaller sites, which lack the engineering oversight to regularly audit their tracking code, are still running it as well.

The tracking ecosystem is characterized by a dynamic race between browser developers and site publishers. Browser vendors are constantly releasing new privacy protections, and site publishers are constantly looking for new ways to break or circumvent them. This cat-and-mouse game has no endpoint. Each time Firefox or Safari closes a fingerprinting vector, another emerges. When Apple blocked the most common canvas fingerprinting techniques, developers shifted to WebGL and performance timing. When those were mitigated, they moved on to the Web Audio API. Now that audio is largely neutralized, the next frontier may be the Web Bluetooth API, the Web NFC API, or even the way browsers handle power consumption readings. As long as there is commercial value in tracking users, companies will find ways to do it.

The search for a lasting solution is ongoing. Some researchers advocate for a “privacy-preserving attribution” model where advertisers can measure campaign effectiveness without identifying individual users. Others argue for legislation that explicitly bans fingerprinting as a form of surveillance. But neither approach has gained universal adoption. For now, the burden falls on individual users to protect their own privacy through the use of browser extensions, privacy-focused browsers, and a careful awareness of what information they are sharing with every site they visit. The AliExpress incident serves as a stark reminder that the fight for privacy is not a single battle won or lost with any one browser update—it is a prolonged engagement in which vigilance must be continuous.

Share This Article