started · updated
AliExpress uses hidden audio to fingerprint user devices
AliExpress has been found to use hidden Web Audio API processes to perform device fingerprinting. The practice was discovered by a developer who noticed that his Bluetooth multipoint headphones would fail to switch between devices while an AliExpress tab was open in his browser.
Technical analysis revealed that two scripts, collina.js and fireyejs.js, hosted on Alibaba domains, create an audio processing chain that generates inaudible signals. By measuring how a device's hardware, such as the CPU and sound card, processes these signals, the site can create a unique digital fingerprint of the user's device without relying on traditional web cookies.
While the technique raises significant privacy concerns because it operates without explicit user consent and cannot be easily blocked by muting tabs or browsers, experts suggest it is likely part of Alibaba’s anti-fraud and security tooling designed to distinguish human users from automated bots. Privacy-focused browsers like Brave have already implemented protections to block these specific types of audio fingerprinting scripts.
Entities
AliExpress · Alibaba · Brave · Web Audio API