Chinese-Owned Retailer Caught Fingerprinting Americans’ Devices

Smartphone with padlock and small flag on map of China
Photo: Ivan Marc / Shutterstock

A silent sound on a shopping site turned into a secret ID tag for your device.

Story Snapshot

  • Developers caught AliExpress running hidden audio to fingerprint devices, not recording voices.
  • Brave confirmed the method and says it blocks AliExpress’s scripts by default.
  • Firefox reduced Web Audio fingerprinting effectiveness starting in version 118.
  • The technique measured tiny hardware and browser differences to tag visitors.

What investigators found on AliExpress pages

Developers traced sudden Bluetooth headphone cutouts to AliExpress tabs. They found scripts starting a Web Audio session with the volume set to zero, then measuring how the device processed it. The audio did not record from the microphone. It generated an inaudible signal and analyzed the output to create a fingerprint that could help tag the browser and hardware across visits. Reports linked the behavior to obfuscated scripts that built an oscillator and analyzer with gain at zero.

Brave stated that AliExpress played a silent sound and measured device-specific output to build fingerprints. Brave emphasized it blocks the exact scripts used for this method by default for its users. The company also noted its broader anti-fingerprinting features, which randomize or normalize signals so trackers cannot form stable IDs from a single visit or across sessions. That on-record confirmation pushed the story from rumor to a concrete, testable behavior.

Why silent audio works as a device tag

Every device and browser handles sound with tiny, repeatable quirks. Small differences in processors, drivers, and math routines can change the waveform in ways that are stable enough to help identify a setup. Web Audio fingerprinting has appeared in research for years as one of many signals that, combined, can make a strong identifier. Malwarebytes reported the AliExpress case fit that model: no microphone capture, only processing of a generated signal and reading unique output values.

Mozilla engineers previously moved to blunt this exact trick. Firefox version 118 changed Web Audio outputs to reduce the spread of values. That normalization makes most users look the same for this signal, cutting its value as a tracking key. This tug-of-war tracks the wider trend. Trackers add new signals when one surface gets noisy. Browsers answer with bucketing, randomization, or direct blocking. The AliExpress case shows the race in real time.

What remains unknown about scope and intent

Public reporting has not shown AliExpress’s internal policy, data retention rules, or how results tied back to accounts. No public code dump fully mapped the production script line by line. Those gaps leave open questions about purpose and scale. The facts on record show audio-derived measurements were taken. They do not show how many users were uniquely tagged, for how long, or whether the output fed fraud defenses or broader tracking databases.

From a common-sense and conservative view of privacy, hidden fingerprinting crosses a line. People can choose to accept cookies or sign in. They cannot meaningfully consent to a silent waveform test buried in a script. China-based ownership also raises supply chain risk concerns that Washington debates often flag. That does not prove harmful intent, but it raises the bar for transparency and restraint when collecting data from Americans.

How shoppers can protect themselves now

Close any suspicious shopping tabs if you see unexplained Bluetooth hiccups. Use browsers with strong, default anti-fingerprinting defenses. Brave says it blocks the specific AliExpress scripts. Firefox’s anti-fingerprinting mode and its Web Audio changes reduce this technique’s value. Disable website sound permissions you do not need, and avoid letting commerce sites run in background tabs. Consider tracker-blocking extensions from reputable developers that publish test results and accept public audits.

Lawmakers and regulators should demand clear statements of purpose for any covert fingerprinting on consumer sites. Require plain-language disclosures and easy opt-outs before scripts run. Encourage independent auditing and bug bounty programs that let researchers verify claims without fear. The market also has a role. Payment networks and ad partners can set standards that deny business to sites that profile users through covert device tests. Sunlight and friction change behavior fast.

Sources:

redstate.com, mallory.ai, hwbusters.com, news.ycombinator.com

© ournationnews.com 2026. All rights reserved.