The latest episode of the security podcast Smashing Security has pulled back the curtain on a quietly invasive tracking technique that most internet users will never hear, see, or notice — but that could be following them across the web anyway. Host Graham Cluley and guest Danny Palmer, a veteran technology journalist, walked listeners through a discovery made by developer Matt Callahan, who found that an apparently silent browser tab was hijacking his Bluetooth headphones. The culprit was a piece of code on the AliExpress homepage using what is known as audio fingerprinting, a method that exploits the subtle, inaudible differences in how devices process sound to create a unique identifier for each visitor. The revelation arrives alongside a separate but equally significant story: a rare joint advisory from the Five Eyes intelligence agencies urging companies to abandon vague, PR-laden language when reporting cyberattacks and to communicate with clarity and transparency instead.
The Silent Trackers: How Audio Fingerprinting Works
Matt Callahan, a developer, was using Bluetooth headphones when his phone rang, but the headphones refused to switch over from his laptop. After ruling out Spotify, YouTube, and every other likely source of audio, he traced the problem to a single browser tab: the AliExpress homepage. The page was not visibly playing any media, yet it had engaged his laptop’s audio hardware just enough to convince the headphones that audio was active. Curious, Callahan dug into the site’s code and uncovered a script designed to perform what is known as audio fingerprinting.
Audio fingerprinting is a subset of browser fingerprinting, a practice that has grown increasingly common as websites seek to identify returning visitors without relying on traditional cookies. Whereas cookies are small text files that can be blocked, deleted, or bypassed with private browsing windows, fingerprinting assembles a far more persistent identifier by collecting dozens of device characteristics — screen resolution, installed fonts, browser version, operating system, and more. The combination of these details can be so distinctive that it singles out an individual user even when they have never visited the site before under their own name.
What Is Audio Fingerprinting and How Does It Track You?
Audio fingerprinting takes this concept one step further by leveraging the Web Audio API, a standard browser feature that allows websites to generate and manipulate sound. In the case of the AliExpress script, the website instructed the browser to perform a complex mathematical calculation that produced a specific waveform. Critically, the volume was set to absolute zero — no audible sound was ever played. Yet the calculation itself was executed using the device’s actual audio subsystem. Because different browsers, operating systems, and hardware configurations handle these calculations with microscopic variations, the resulting waveform is subtly unique, much like the way two pianos playing the same sheet music will sound slightly different. That unique result becomes a digital fingerprint that can identify the device on future visits.
What made Callahan’s discovery particularly striking was the unintended side effect: the silent calculation was enough to make his Bluetooth headphones believe that audio was actively playing on his laptop, preventing them from switching to his ringing phone. The incident revealed just how deeply this invisible tracking can reach into a user’s everyday experience.
The Arms Race Between Tracking and Privacy
Audio fingerprinting is not new, nor is it exclusive to AliExpress. It represents one of many techniques in an ongoing, largely invisible arms race between websites that want to identify users and browser makers that want to protect privacy. Firefox, Brave, and Safari (in private browsing mode) all employ countermeasures. They scramble or inject random noise into the Web Audio API’s output, so that any fingerprinting script receives a distorted, unreliable reading. This means that even if a site requests the calculation, the result will be too generic to distinguish one user from another.
The irony, as Cluley pointed out, is that some of the companies building these privacy-focused browsers are themselves part of larger advertising ecosystems. The conflict between user privacy and commercial tracking is built into the very fabric of the modern internet. For users who want an extra layer of protection, extensions such as uBlock Origin can block fingerprinting scripts outright, although the battle is unlikely to end anytime soon.
From Silent Tracking to Smarter Cyber Crisis Communications
The Smashing Security episode also turned to a subject close to the heart of anyone who has ever tried to understand what really happened during a high-profile breach: the maddening opacity of corporate cyberattack statements. Danny Palmer, a journalist who has covered cybersecurity for more than a decade, described the all-too-familiar pattern of a company issuing a generic press release claiming it suffered a “sophisticated cyberattack” — only for the truth to emerge weeks or months later that the root cause was something embarrassingly simple, like a publicly exposed admin panel protected by the password “1234.”
In response to this persistent problem, cyber intelligence agencies from the United States, Canada, the United Kingdom, Australia, and New Zealand — collectively known as the Five Eyes — have published a joint guidance document titled Communicating Under Pressure: Best Practices for Service Providers. Led by CISA (the U.S. agency responsible for critical infrastructure security), with input from the FBI, the UK’s National Cyber Security Centre, and the Australian Signals Directorate, the nine-page document sets out a framework for clear, timely, accurate, and audience-appropriate communication during IT and OT outages caused by cyberattacks and other incidents.
The Five Eyes Advice: Plan Ahead, Ditch the PR Fluff
The guidance rests on two core principles. First, organisations must have a crisis communications plan in place before an incident occurs. This plan should not be an afterthought drafted by the marketing department but a coordinated playbook that involves security teams, legal counsel, and executives. It should account for the possibility that the attack itself may knock out email and other communication tools, forcing teams to fall back to WhatsApp, Signal, or other out-of-band channels — a scenario that has played out repeatedly in ransomware incidents.
Second, the advisory explicitly urges organisations to “practice transparency and avoid PR and marketing language.” Palmer noted that this advice is both refreshing and overdue. In journalistic shorthand, “sophisticated” has become a red flag — a word that often signals an attempt to deflect blame rather than inform. The Five Eyes document recommends that affected organisations explain what happened, what data or systems were impacted, what steps are being taken to contain and recover, and what customers and partners should do. After the incident is resolved, the guidance goes further: publish detailed technical information about the root cause and the attack vector, so that other organisations can learn from the experience and defend themselves.
When Transparency Becomes a Competitive Advantage
Palmer pointed to the 2017 NotPetya attack on shipping giant Maersk as a case study in how to get it right. Maersk’s security and leadership teams were unusually open about the scale of the disruption, the steps they were taking to restore operations, and the lessons they learned. The result, Cluley observed, was that Maersk emerged from the disaster with its reputation enhanced, not diminished. “They came out looking like rock stars,” he said. “They demonstrated real fantastic leadership.” By contrast, companies that hide behind vague statements often erode the trust of their customers, partners, and the security community — a cost that can far outweigh the short-term comfort of saying nothing.
The advisory acknowledges that complete transparency may not always be possible in the heat of an incident, when the full scope of the breach is still unknown. But it recommends that organisations communicate what they do know, update stakeholders regularly, and resist the temptation to spin uncertainty into a narrative of control. For journalists like Palmer, the difference between a useful statement and a meaningless one often comes down to whether the organisation is willing to confirm even the most basic facts: what type of attack it was, when it was detected, and whether customer data was involved.
Pick of the Week: Stone Skimming, Pirate Codes, and the Enduring Appeal of Offline Obsessions
The episode closed with a lighter segment that nonetheless underscored a theme running through the entire discussion: the unexpected ways in which technology, history, and human behaviour intersect. Cluley’s pick was the World Stone Skimming Championships, held on the tiny Scottish island of Easdale, where a population of 60 swelled to 350 as competitors from around the globe gathered to skip stones across the water. The event was not without controversy — last year, officials caught competitors sanding their stones into suspiciously perfect discs, prompting the organisers to hire a geologist to police the integrity of the rocks. Cluley pointed to a four-and-a-half-hour YouTube livestream of the event for anyone who missed it.
Palmer’s pick was a book titled The Pirate’s Code: Laws and Life Aboard Ship by historian Dr. Rebecca Simon. Reading it to inspire the backstory of his Dungeons & Dragons character — a nautical explorer with pirate-like tendencies — Palmer was struck by the parallels between 17th-century pirates and modern cybercriminals. Both groups, he noted, often rationalise their activities as a form of rebellion against unjust systems, and both are attracted by the prospect of outsized rewards in high-risk environments. The comparison is imperfect, but it serves as a reminder that the human impulses behind crime — greed, desperation, a desire for autonomy — have changed far less than the tools used to pursue them.
What the Silence on AliExpress Reveals About the Future of Web Privacy
The audio fingerprinting incident on AliExpress is more than a curiosity about misbehaving headphones. It is a glimpse into the future of web tracking, where the battle lines are drawn not around cookies and consent banners but around the fundamental capabilities of the browser itself. As users and regulators push back against visible tracking methods, the industry is quietly shifting toward techniques that are invisible, silent, and extremely difficult to detect without technical expertise. The fact that a major e-commerce platform was deploying such a method on its homepage — and that it was only discovered because it accidentally interfered with a user’s Bluetooth headset — suggests that countless other sites may be using similar techniques without ever being noticed.
For the average internet user, the takeaway is not to panic but to become more deliberate about browser choice and extensions. For the cybersecurity community, it is a reminder that the arms race will continue, with each new defensive measure met by an even more inventive workaround. And for the organisations that fall victim to cyberattacks, the Five Eyes advisory offers a clear, if demanding, alternative to the tired script of “sophisticated attackers” and “we take security very seriously.” Clarity, honesty, and a willingness to share lessons learned may not prevent the next breach, but they can prevent the next cover-up — and that, in a world of silent trackers and digital fingerprints, is a form of security worth pursuing.