Tech

AliExpress caught fingerprinting browsers with inaudible sounds

Researcher Matthew Callaghan identified an outdated audio tracking technique on the Chinese retailer’s site, revealing a broader suite of privacy-invasive methods.

Editorial persona
Owen Mercer
Markets and Finance Editor
Published
Draft
Source: Ars Technica · View original source
Inaudible sounds used to fingerprint browsers catch AliExpress red-handed
Technology

Chinese retailer AliExpress has been identified as fingerprinting visitors by sending inaudible sounds to their browsers, a discovery that highlights the persistent tension between site publishers and browser developers. Researcher Matthew Callaghan stumbled upon the technique by accident when audio from his phone stopped playing over his multipoint Bluetooth headphones. He noticed that the phone audio would cease whenever he loaded the AliExpress homepage and resume when he closed the tab, indicating that the site was processing audio in the background.

Upon investigating the anomaly, Callaghan found two highly obfuscated scripts on the site. These scripts rendered a graph that analysed WebAudio readings, acting as an oscillator to measure Sawtooth waves, which are common in digital audio output. The oscillator generated a known waveform, and the analyser measured the result after it passed through the browser’s audio implementation. The scripts read frequency data from this process to create unique browser signatures based on how the system processed the audio.

To prevent users from hearing the sound, the scripts set the gain to zero. However, because the graph remained connected to the selected system audio, the browser continued to process the signal and eventually sent the frequency data to AliExpress. This method relies on variability in different math libraries used when audio is produced through browsers, which, when combined with different CPUs and system differences, can generate a large number of unique signatures.

Despite its effectiveness in the past, the audio soundprinting technique is now considered largely outdated. Firefox implemented a fix in version 118, released in 2023, by using its own unique math libraries rather than relying on those shipped with the operating system. Tom Ritter, a Firefox developer who has also volunteered for the Tor Project, noted that this move to constant libraries reduced the entropy enough to stop the technique from working.

The technique is similarly ineffective in Chrome, as the browser ships with its own libraries, according to a Google spokesperson. Safari users are likely safe for the same reason, although Apple has not immediately confirmed this. The presence of this obsolete method on AliExpress raises questions about the retailer’s broader tracking strategy, as Callaghan noted that the site is likely employing more than a dozen other fingerprinting methods alongside the audio trick.

While it is comforting that browser makers have taken precautions against this specific technique, it is not yet clear how effective the other dozen-plus metrics AliExpress is using are. The incident suggests that the web audio trick may be a leftover from years earlier that went unnoticed until now. It is almost a certainty that thousands of other sites are employing similar tracking, illustrating the dynamic race between browser developers and site publishers who constantly seek new ways to bypass privacy protections.

Continue reading

More from Tech

Read next: Ethernet Cable Length Matters Most at Higher Network Speeds
Read next: Engadget weighs MagSafe against USB-C for MacBook charging
Read next: Essay challenges reported claims of a 10% AI extinction risk