WEB Signal 106
AliExpress caught using inaudible audio to fingerprint browsers, a technique Firefox patched in 2023
AliExpress was caught using an outdated audio fingerprinting technique that Firefox has already patched, but the site still employs many other tracking methods.
This incident shows that even outdated fingerprinting techniques can still be deployed in the wild, and that browser defenses are not always effective. For engineers building privacy tools or browsers, it highlights the need to continuously audit and update anti-fingerprinting measures. It also underscores that sites like AliExpress are using a wide array of tracking methods, making it hard for users to protect themselves.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
Researcher Matthew Callaghan discovered AliExpress's audio fingerprinting when it interfered with his Bluetooth headphones.
The technique uses WebAudio to generate Sawtooth waves and measure the browser's audio output, with gain set to zero to keep it inaudible.
Firefox patched this technique in version 118 (2023) by using its own math libraries, and Chrome and Safari are likely safe.
THE CLUSTER
↗