Report: AliExpress Caught Fingerprinting Users Through Hidden Audio

He wanted his notifications back and got a lesson in browser telemetry instead.

If you’re tired of censorship and surveillance, subscribe to Reclaim The Net.

It was his Bluetooth headphones that led a developer, Matt Callaghan, of laserphile, to discover that the online retail service AliExpress, owned by China's Alibaba, was fingerprinting him using his computer's audio hardware.

Laserphile said that he usually listens to music on his phone while his PC is connected to the same pair of headphones, and plays notifications and YouTube videos. This works "reliably," he said, "until I open an AliExpress page in Firefox or Chrome."

The headphones would not then switch back to his phone, and he couldn't figure out why. The page was "holding" the computer's audio, but there was nothing visible on the page that would explain this behavior – "zero <audio> or <video> elements" and "zero media play() calls."

"Muting the tab/Firefox/Windows does not help," he added, and said that he had to dig deep to find the cause of the problem. The solution was to instrument the browser's AudioContext – "That finally found it, two hidden audio contexts!"

The two scripts were allegedly coming from Alibaba's own code and were running without producing any sound. "A silent fingerprinting test was able to interfere with Bluetooth multipoint switching," the developer said.

And it wasn't only that. The scripts were collecting a range of data points – canvas rendering, WebGL details, hardware specifications, WebRTC, mouse and touch events, and automation indicators – and sending them to Alibaba's telemetry servers, all without any notice or consent.

None of this is new. A Firefox bug report describing the same behavior on AliExpress has been open for about two years now.

Meanwhile, the good news is that browsers like Brave and Firefox block the fingerprinting attempt.

Explore more on these topics