All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
All NewsHome
← Back to AI & Technology

AliExpress using outdated audio fingerprinting technique

Created at 24 Aug · 7:25 PM1 source↑ Market-relevant
IN SHORT

AliExpress has been found to be using an outdated audio fingerprinting technique, which sends inaudible sounds to browsers to identify visitors. While Firefox and Chrome have implemented fixes, the effectiveness of other methods AliExpress employs remains unclear.

Key Numbers

118Firefox version with audio fingerprinting fix
2023Year Firefox version 118 was released

Who's Involved

AliExpress
Online retailer using multiple fingerprinting techniques
Firefox
Browser that implemented a fix for audio fingerprinting
Tom Ritter
Firefox developer who commented on the fix
Google
Company spokesperson confirming Chrome's protection
Apple
Company likely safe from the technique
AliExpress using outdated audio fingerprinting technique

↳ Why This Matters

This discovery highlights ongoing privacy concerns regarding online tracking and the methods employed by e-commerce platforms. While some specific techniques are being addressed by browser developers, the broader landscape of user data collection remains a complex and evolving challenge.

Key facts

  • AliExpress is employing an audio fingerprinting method that utilizes inaudible sounds sent to browsers.
  • This technique was rendered ineffective in Firefox starting with version 118 due to the browser using its own math libraries.
  • Chrome and likely Safari are also protected against this specific method.
  • The online retailer utilizes numerous other fingerprinting techniques, including canvas rendering, WebGL information, and event tracking.

AliExpress has been identified as using an outdated audio fingerprinting technique, which involves sending inaudible sounds to browsers to create unique visitor signatures. This method, previously reliant on system-shipped math libraries, has been largely neutralized by browser developers.

Firefox addressed this vulnerability starting with version 118, released in 2023, by implementing its own math libraries. Tom Ritter, a Firefox developer also associated with the Tor Project, stated that this change reduced the entropy sufficiently to thwart the technique. Chrome is also unaffected because it utilizes its own proprietary libraries, according to a Google spokesperson. Safari users are presumed to be similarly protected, though Apple has not yet confirmed this.

The continued use of this obsolete method by AliExpress raises questions, especially given that the company employs over a dozen other fingerprinting techniques. These include canvas rendering, WebGL information, audio oscillator output, screen and viewport dimensions, device pixel ratio, hardware concurrency, browser plugins, supported audio/video formats, WebRTC behavior, browser performance timing, and tracking of user interactions like mouse and touch events, as well as device motion and orientation.

It is speculated that the web audio fingerprinting method is a leftover from previous practices that went unnoticed until now. While browser makers have taken steps to protect users from this specific technique, the efficacy of AliExpress's other data collection methods remains uncertain as website publishers continually seek new ways to bypass privacy protections.

Frequently asked questions

Audio fingerprinting is a technique that uses inaudible sounds sent to a browser to create a unique identifier for a visitor, based on variations in math libraries and system hardware.

It is likely a leftover from previous practices, and the company employs many other fingerprinting methods.

Yes, Chrome is safe because it uses its own libraries, and Safari users are likely safe for the same reason.

What Happens Next

01Further scrutiny of AliExpress's other fingerprinting methods is likely.
02Browser developers will continue to adapt to new tracking techniques.

How It Developed

AliExpress was found to be using an audio fingerprinting technique.
The technique involved sending inaudible sounds to browsers.
Variability in math libraries previously allowed for unique browser signatures.
Firefox implemented a fix in version 118 (2023) using its own math libraries.
Chrome and likely Safari are also safe due to using their own libraries.
AliExpress also uses over a dozen other fingerprinting methods.

Sources

T1
AliExpress caught fingerprinting visitors after sending inaudible sounds to browsersvar abtest_2168829 = new ABTest(2168829, 'impression');Ars Technica

Related Stories

Monitors are increasingly pushing ads and tracking users, mirroring smart TV trends
24 Aug · 8:20 PM
Instinct AI assistant faces privacy and security scrutiny
24 Aug · 6:21 PM
Anonymous AI Model Ox Alpha Emerges, Linked to Viral Chinese Cow Movie
24 Aug · 8:56 AM
Chinese researchers develop compact, high-speed camera for ghost imaging
24 Aug · 4:05 AM
LinkedIn's 'AI slop' button sees 1M clicks, reduces content views
24 Aug · 4:10 PM