Technology
AliExpress caught using audio browser fingerprinting technique
A security researcher discovered the tracking script after it interfered with his Bluetooth audio playback.
The short version
- Security researcher Matthew Callaghan discovered that Chinese retailer AliExpress was using audio browser fingerprinting on its homepage.
- The stealthy tracking mechanism was uncovered when loading the site disrupted audio playback on Callaghan's multipoint Bluetooth headphones.
- Investigating the issue revealed obfuscated scripts generating WebAudio readings and measuring digital audio waves to identify visiting browsers.
Key facts
- Researcher Matthew Callaghan discovered AliExpress using audio fingerprinting when opening its website interrupted audio playing from his phone to his multipoint Bluetooth headphones.[Ars Technica]
- The tracking relied on two obfuscated scripts that generated a graph analyzing WebAudio readings from visiting browsers.[Ars Technica]
- The scripts functioned as an oscillator measuring digital audio Sawtooth waves to uniquely identify user browsers.[Ars Technica]
What remains uncertain
- It remains unverified whether AliExpress has modified or removed the scripts following the discovery, or how many users were targeted.[Ars Technica]