← Latest briefing

Technology

AliExpress caught using audio browser fingerprinting technique

A security researcher discovered the tracking script after it interfered with his Bluetooth audio playback.

The short version

  • Security researcher Matthew Callaghan discovered that Chinese retailer AliExpress was using audio browser fingerprinting on its homepage.
  • The stealthy tracking mechanism was uncovered when loading the site disrupted audio playback on Callaghan's multipoint Bluetooth headphones.
  • Investigating the issue revealed obfuscated scripts generating WebAudio readings and measuring digital audio waves to identify visiting browsers.

Key facts

  • Researcher Matthew Callaghan discovered AliExpress using audio fingerprinting when opening its website interrupted audio playing from his phone to his multipoint Bluetooth headphones.[Ars Technica]
  • The tracking relied on two obfuscated scripts that generated a graph analyzing WebAudio readings from visiting browsers.[Ars Technica]
  • The scripts functioned as an oscillator measuring digital audio Sawtooth waves to uniquely identify user browsers.[Ars Technica]

What remains uncertain

  • It remains unverified whether AliExpress has modified or removed the scripts following the discovery, or how many users were targeted.[Ars Technica]

Sources