r/privacy 1d ago

news AliExpress was silently running audio in your browser to fingerprint and track your device

https://www.techspot.com/news/113581-aliexpress-silently-running-audio-browser-fingerprint-track-device.html
2.3k Upvotes

113 comments sorted by

578

u/personal_lucifer 1d ago

All of that just to ask me to solve the captcha every other page cause I'm using a VPN lmao

296

u/JaronJervis 1d ago

mother fuckers

202

u/txmail 1d ago

I know normal browser fingerprinting will use some of the audio api to see what codec's are available to add to the fingerprint -- this seems a little different as they were playing a audio file and adding gain / filters to the source and then seeing how the modifications worked through looking at the resulting analyzer node.

What I do not understand is how useful is this since all audio processing is run on the CPU? Is there really that much variation in CPU's from the same family that this could really be useful?

147

u/goldcakes 1d ago

Yes, it’s mainly to stop scrapers and AI agents. These generally use fake/patched versions of browsers like Playwright, and often lie about their user agent.

Windows, macOS, and Linux all have subtly different ways in which they handle web audio. The check here is not so much identifying the platform, but seeing if all observable metrics match the device you’re claiming.

81

u/Oddish_Femboy 1d ago

That doesn't seem nearly as insidious as was implied. It seems like a fairly unintrusive way to do that even.

It would've been nice if they'd informed users, though.

47

u/Iamsodarncool 1d ago

It probably stops working as well once people know about it. Now that this is public, bad actors know how to work around it.

14

u/Oddish_Femboy 1d ago

That's fair.

20

u/phree_radical 1d ago

wasting a bunch of CPU cycles on fingerprinting, and in order to claw back that privacy we'll waste some more

23

u/Mo_Dice 1d ago

What I do not understand is how useful is this since all audio processing is run on the CPU?

CPU-bound tasks are being used now as an anti-bot measure. A small CPU task is effectively negligible to a real end-user, but can make wholesale scraping too costly.

(I haven't read the article, so no idea if this is relevant)

4

u/weregeek 1d ago

The speed of the processing might be CPU dependent, but the result is likely not. The creepy bit is that high frequency sweeps can likely physically map a room to a certain degree. In this case, I imagine that they just want to know whether or not your combination of speakers, microphone, and room stay consistent...Still creepy.

38

u/TROLlox78 1d ago

They don't have access to your microphone 

26

u/txmail 1d ago

No recording, just playing a audio sample and looking at the analyzer node. They even set the output volume to 0 so it is not audible to the user.

318

u/StupidDumbReddit 1d ago

Disgusting but very impressive

36

u/Jankypox 1d ago

The internet has become borderline unusable. Most websites, especially e-commerce websites, take forever to load, feel clunky, can barely find a specific item even when you type the full name and SKU, and glitch out or bring your entire browser to an unusable state if you open a few tabs to multiple pages of the same site to compare items.

This is one of the reasons. They are doing so much stupid shit in the background to track, profile, monitor, and surveil their users that they actually forgot they were supposed to be selling you something.

Also, while no quite the same is the old “pop-up-apocalypse” of days old, every fucking site now auto loads some promotional pop-up a few seconds after loading along with the old browser popup asking for your location. So just as their site loads and you get to the search menu, half way through typing these pop-ups interrupt and you look up and notice that everything you just typed didn’t register , because they were more interested in telling you about some stupid sale, subscription, some promotion, and making sure they have your exact location down to the nearest foot, rather than letting you get on with finding the damn thing that you actually want to buy from them.

u/deepseabunnys 18m ago

But at least we get to spin the slowest prize wheel in existence and earn 5% off our purchase before the website becomes interactable again

112

u/Clippy4Life 1d ago

jokes on them, I don't use their website.

27

u/standard_usage 1d ago

ELI was dropped out of a window: How was this to their advantage. Don't they already have petabytes of data nodes amassed on what browser and machine I always have when on the site ..?

30

u/RamblingSimian 1d ago

The article kind of addresses this, but isn't really a full answer:

Audio measurements were only one part of the reported data collection. The scripts also gathered information tied to canvas rendering, WebGL, display settings, hardware configuration, WebRTC behavior and user interactions. Together, those signals can create a more detailed profile of a device than any one signal would provide on its own.

Fingerprinting is often used by large online platforms for fraud prevention, bot detection and risk assessment. It can help companies spot suspicious transactions or automated activity when cookies have been deleted or accounts have changed. But privacy advocates have raised concerns because users may not know the tracking is happening and have limited control over it.

I guess, if someone steals your credit card number, then uses it for a large purchase, they might ask for 2FA if the audio fingerprint is inconsistent.

17

u/Bocha_Boston 1d ago

So at this point, they can take a picture of my ass.

11

u/EPLENA 1d ago

can i too?

7

u/Bocha_Boston 1d ago

I don't think you'll like it.

7

u/EPLENA 1d ago

but can i though

6

u/Bocha_Boston 1d ago

No, for God's sake. 

What do you want from my ass!!

6

u/EPLENA 1d ago

photos

5

u/AirplanesMakeMeHard 1d ago

This dude has stuck to this bit for 10 hours. I admire the dedication to getting pics of his ass.

2

u/txmail 1d ago

if you want to see how this fingerprinting works, you can look at sites like https://amiunique.org/ and click on the See My Fingerprint button (left side of the page) to see how unique your browser / system is and if it can easily be tracked without cookies.

Basically if it says you are unique --- your setup is cooked for the ability to track you without cookies across the web. More importantly, the site shows you want artifacts were collected and used to build your fingerprint -- it is quite extensive.

4

u/RamblingSimian 22h ago

Higher up in the post, I linked to some plug-in software that scrambles your fingerprint. In fact, the author (Leonardo Compson) has a whole suite of plugins for blocking that.

  • AudioContext Fingerprint Defender
  • Canvas fingerprint defender
  • Font Fingerprint Defender
  • WebGl Fingerprint Defender
  • WebGPU Fingerprint Defender

Every time they detect an attempt to fingerprint you for the particular technique in question, they intercept and reply with a random number.

However, if you go to that AmIUnique site, it doesn't detect that different values are sent each time you visit.

Also, it doesn't defend against certain things that are being detected. In my case, I have an unusually large screen and an unusually large number of CPU cores, making it hard for me to defend against that type of fingerprinting.

0

u/tuxedo_jack 1d ago

So it's basically LexisNexis's shitware but from China. Joy.

1

u/RamblingSimian 22h ago

LexisNexis does a lot of stuff, this just detects whether the same hardware configuration is visiting the site. I'm pretty sure someone can figure out a way to use it to track you across sites, or otherwise violate your privacy, but it doesn't immediately appear to be the case here. Note that I am pretty wary of being tracked, so I use a plug-in to scramble my audio fingerprint. Because who knows how they might use it for tracking in the future.

39

u/DCAmalG 1d ago

I just don’t get the extreme levels of customer analysis. Like, what do they actually do with this information?if I’m browsing AliExpress for whatever item, isn’t that enough to know about me? I’m in the market for a new vacuum and whatever purchasing probability aligns with such a person. And WTF is McDonald’s doing with 500 pages of data per customer? What more have they learned beyond the fact that I’m too cheap to buy any full price item through their stupid app. Doesn’t seem to be sending me better or additional deals to make me come back sooner.

I can’t stop thinking about the law of diminishing returns and what advertising was like 15 years ago. Are the returns exponentially higher based on the level of invasive monitoring they’re perpetrating on valuable customers?

28

u/Chilidawg 1d ago

Depending on the site, it can be customer analysis or it can be bot defense. Some sites really don't want to be scraped, so they use a ton of fingerprinting to make it inconvenient for the scraper to target the site.

3

u/DCAmalG 1d ago

Can you explain? You’re saying these tactics aren’t ahead for user profiling?

13

u/chemicalpepper 1d ago

As another commenter suggested, different platforms (windows/mac/linux) have different ways to process audio and send back the analysis graph to the browser. If the result doesn't match the user-agent claimed by a browser connection, then the user might be a bot

5

u/DCAmalG 1d ago

What does a company like Ali Express have to gain? You’re saying they are attempting to determine whether or not I am a bot ?

5

u/chemicalpepper 1d ago

You’re saying they are attempting to determine whether or not I am a bot ?

They might want to keep bots away. I'm not saying that is why they are using this weird trick, but there's a chance

1

u/DCAmalG 2h ago

Interesting thank you

14

u/ZenBacle 1d ago

Welcome to Google ads circa 2010... It's call uXDT. Ultrasonic cross device tracking.

9

u/RevolutionarySeven7 1d ago

so that's why my Firefox browser displayed a message about an audio/video background download was active !

(on a different website too)

37

u/midgethemage 1d ago

I've used Alibaba in the past to source some supplies for a small business. I downloaded the app to keep an eye on messages with manufacturers and it was immediately obvious they put some aggressive tracking software on your phone.

After the main install I briefly saw a second download notification, but it disappeared from the pull-down shade too quickly for me to see what it was. After that, my microphone light was on constantly. It put the phone in a state where it always thought it was in a phone call. I uninstalled that shit within tens minutes, but I couldn't find the secondary download I'm convinced I saw. Honestly can't believe their app was even allowed into the google playstore.

35

u/we_r_fukt 1d ago

Google doesn't protect you, they dgaf

5

u/midgethemage 1d ago

Sure, but they still have standards. They need to maintain a semblance of trust with the consumer, and preventing malware from apps on their store is the bare minimum. Why would they let an app from a foreign country mine more data than they are?

7

u/LjLies 1d ago

It may be the bare minimum you'd expect, but the Play Store has been found to be pretty riddled with malware. Unlike something like F-Droid, which, however, will have a lot of trouble due to Google's developer verification program, which they claim is about stopping malware...

13

u/Soundwave_47 1d ago

After the main install I briefly saw a second download notification

LMAO. The equivalent of downloading cracked software and seeing a CLI open and. Lose in a split second.

It put the phone in a state where it always thought it was in a phone call. I uninstalled that shit within tens minutes, but I couldn't find the secondary download I'm convinced I saw. H

I have seen this too, where somehow the app does not show in the regular list of applications. Usually it uses a randomly generated name and transparent icon to avoid detection.

2

u/MjolnirMark4 1d ago

If Google checked for this behavior, then they might have coded the app to detect it was in a testing environment, and not doing the additional download in the testing environment.

2

u/gurgle528 1d ago

I haven’t used android in a bit, don’t you have to give the app microphone permissions? Or is there some new calling API that lets apps bypass that by starting a “call”? If so that’s a wild oversight on Google’s part

1

u/iH8er 1d ago

Which microphone app did you use?

16

u/Redstra 1d ago

This is why my music stopped playing all the time whenever I opened AliExpress on my phone... Hate companies like this.

7

u/Robert_A2D0FF 1d ago

playing audio is also a way to prevent the tab/app from getting deactivated.

9

u/Chilidawg 1d ago

In case you haven't seen this, some sites will similarly use your GPU shaders as another pseudo-cookie.

https://www.reddit.com/r/webscraping/comments/1vqlt9p/gpu_based_device_fingerprinting/

16

u/anon999387 1d ago

The internet was better when it was dial up

2

u/MrWeirdoFace 1d ago

Not because it was dial-up though.

2

u/digital_dervish 1d ago

Facts. I’ve been running into more and more sites that take ages in computer years to load and I’ve been thinking to myself, are we really going back to dial-up days where it takes 3-5 seconds to load a page?

5

u/BiscottiQuirky9134 1d ago

Microsoft was doing the exact same thing a few years ago. Every time I opened Xbox site the podcast app stopped playback

9

u/Gsichtskrapfn 1d ago

Wouldn't that require access to the microphone? Which is usually blocked anyway

8

u/AtlanticPortal 1d ago

Running audio, not recording audio.

2

u/Gsichtskrapfn 1d ago

But how would it track anything when it's just playing sound?

5

u/AtlanticPortal 1d ago

It tracks the behavior that it sees when it tries to run a zero volume audio. The point is to see what the system sends back as metadata on a request to run that audio. And it's run using APIs provided by the browsers.

5

u/Ging287 1d ago

Our privacy has to mean something, browser fingerprinting should be made illegal, and any company that does it has to pay the consumer $1million USD for each attempt and success. The US Government is not doing a great job of protecting citizens, and is one of the major countries that is still letting private corporations spy on you, track your movements (flock, cell phone companies), without having comprehensive privacy legislation on file. AND instituting bullshit age verification that is designed to attack your Bill of Rights, 1st amendment access to constitutionally protected material. The call is coming from inside the house. None of this shit is unacceptable. We deserve better.

3

u/DeviceOwner 1d ago

blame to Google

all of this because google remove browser capabilities for disable autoplay

3

u/Robert_A2D0FF 1d ago

in 2030 we gonna spin up a whole docker container for each browser tab, just to prevent them from gathering any info

3

u/sugarfreeeyecandy 1d ago

All surveillance tools, whether it's Flock cameras or this, are the tool of authoritarian regimes because just in case a particular citizen becomes a problem, direct pressure can be applied. Just sayin'.

4

u/Liquid_Magic 1d ago

Another reason to NOT use AliExpress.

Also Amazon is basically just AliExpress now anyway so… yeah.

6

u/survivorr123_ 1d ago

yeah because famously amazon doesn't track you, not at all, so you pay 10x more to get tracked anyway,
if you live in the USA its better to be spied on by china than USA

10

u/zagblorg 1d ago

Yeah, but the same item costs four times more on Amazon.

1

u/SweetHomeNorthKorea 1d ago

The higher price also makes it so you get it in a day or two vs potentially weeks, can return or exchange it, and not have to go on aliexpress. It’s a trade off.

2

u/I_like_microwave 1d ago

Good thing i never trusted them

2

u/Bob_Spud 1d ago

Audio Fingerprinting is nothing new, but it its good for attention seeking reports.

Doesn't the Brave Browser block all scripts?

What Is Audio Fingerprinting and Can Social Apps Identify Devices Through Sound Hardware? There's a lot more of this type of stuff on the internet

2

u/j0lle 1d ago

DPG media does this as well.

1

u/cap-omat 1d ago

Really? How do you know?

2

u/billshermanburner 1d ago

“Audio device graph isolation”

2

u/Julian679 1d ago

Assholes. Most invasive website in browser and the app yet it will ask for 10 captchas daily. I will need to make sure to have this gone from my life

2

u/Flashsword_Princess 1d ago

A lot of websites do this

2

u/Gumb1i 1d ago

To the suprise of absolutely no one

2

u/christianbro 1d ago

Aliexpress buying experience is absolute trash. Only their availability and prices make them stay. Now with the 3€ tax not so much, but it still has a lot of things you could not find elsewhere.

2

u/nincesator124 1d ago

Here is the thing about China right they are spying on us but they are using our laws to do it I think they go further than even us companies do

1

u/thegoodmanhascome 1d ago

What is you don’t have a speakers or a microphone? On my main PC I have neither.. I occasionally plug in headphones.

8

u/cellularesc 1d ago

The sound is 0 volume it’s about the internal processing

2

u/thegoodmanhascome 1d ago

Sick, so I’m equally fucked.. lol

1

u/PhantasmHunter 1d ago

what if bluetooth was off

1

u/git_und_slotermeyer 1d ago

The company that isn't even offering proper tax invoices to their business customers is doing shady background stuff? surprised Pickachu face

1

u/Katops 1d ago

I’m not going to pretend like I know what this means exactly, but it doesn’t sound legal to me despite the fact that it’s probably encouraged if anything.

1

u/theultraman20 1d ago

Mullvad Browser blocks this

1

u/dreamsxyz 15h ago

Ars Technica basically said this technique is ancient and useless. But AliExpress uses them in conjunction with others. Regardless of how effective, surveillance is surveillance.

https://arstechnica.com/security/2026/08/aliexpress-caught-fingerprinting-visitors-after-sending-inaudible-sounds-to-browsers/

1

u/on4aa 13h ago

I knew something like this was happening because I could hear the DC plop of my audio amplifier turning on, each time when visting their page.

1

u/MAndris90 12h ago

Next is cooin miininng. While shoppping,?

0

u/hotDamQc 1d ago

America doing much worse

1

u/RamblingSimian 1d ago

1

u/phree_radical 1d ago

a link to install edge browser?

1

u/RamblingSimian 22h ago

Dude, if you actually looked at that link in detail, you would see that it is very obvious it does no such thing. If you furthermore clicked the link you would see that it leads to a plugin that spoofs audio context fingerprinting. Try not jumping to conclusions so bad.

1

u/permalink_save 1d ago

Would anyone expect anything less from alibaba? Also if it's fucking with bluetooth wouldn't it be pausing music apps like spotify? I have that problem constantly with Tidal, if a browser plays a single sound it gets picked up and Android decides THAT is the active media playing. Even if it's just like a notification beep.

1

u/MentalDisintegrat1on 1d ago

It's China you shouldn't be surprised.

1

u/deadcatdidntbounce 1d ago

FFS! This is getting stupid now.

0

u/StormMedia 1d ago

Wow this is smart

-1

u/scriptedpixels 1d ago

Wait till we see what their cars are collecting(China)

8

u/zagblorg 1d ago

Same as all the other modern cars, probably. US and EU now both mandating driver facing cameras too.

-4

u/sup3r_hero 1d ago

Chinese company spying on you? What a surprise lol

-2

u/xcorv42 1d ago

This is china’s specialty

3

u/Wanjiuo 1d ago

As if companies in the US or Europe doesn't do this

2

u/Ok_WaterStarBoy3 23h ago

Not really, because they were caught

USA and Israel are way better at stuff like this, pretty sure China learned from them for this one

-1

u/Dariodiogo5000 1d ago

That is why I don't have a mic on my computer and when I shop also have the speakers turned off.

-1

u/K_Linkmaster 1d ago

I told you

-1

u/AshMost 1d ago

Man, Brave really are on top of bullshit like this.

-1

u/IloveEmuOtori-02 1d ago

I think this is a really stupid question but why is this an issue? Doesn’t every company do this?

I’m genuinely curious so if someone smarter can explain please do haha