AliExpress Caught Using Silent Audio Tracking: A New Privacy Concern
Online retail giant Alibaba Group Holding Limited (HKG:9988) subsidiary AliExpress has been caught employing a nearly invisible method to identify users: silent audio fingerprinting. This sophisticated tracking technique, which bypasses traditional ad blockers and privacy settings, came to light when users noticed their Bluetooth headphones disconnecting from their phones while browsing the site, switching instead to their PC.
How Silent Audio Fingerprinting Works
The mechanism involves JavaScript generating an inaudible sound. While the volume is set to zero, the sound still gets processed by the computer's audio hardware. Every CPU and browser combination processes audio with minute, unique variations. AliExpress exploited these differences to create a persistent digital fingerprint of a user's device. This goes beyond common tracking methods like cookies, combining with other identifiers like canvas and WebGL data to build a comprehensive user profile.
Browser Defenses Against Advanced Tracking
The discovery quickly drew responses from privacy-focused browsers. Brave, a browser known for its built-in privacy protections, confirmed that it has been defending against audio fingerprinting for over six years. Brave achieves this by injecting random data into the browser's audio output, making each fingerprint appear different across sites and resetting it across sessions. The browser also specifically blocks the scripts AliExpress used for this tracking method.
Firefox also highlighted its anti-fingerprinting technology thwarted AliExpress's efforts. These browser-level interventions are becoming increasingly critical as trackers develop more elusive methods. Beyond audio, Brave recently added defenses against GPU fingerprinting, which stops sites from identifying users based on their graphics card or drivers. This ongoing arms race between trackers and privacy tools defines much of the modern web experience. StartupHub.ai data shows Brave holds a score of 62/100, indicating its strong position in the privacy browser market. When compared to competitors we track, Brave performs comparably to LayerX (score 63/100) and slightly ahead of Octen (score 54/100) and Parallel Web Systems (score 54/100).
Alibaba's History of Privacy Concerns
This incident with Alibaba Group Holding Limited (HKG:9988) and its AliExpress platform is not an isolated event. Alibaba has faced scrutiny for its data practices previously. In 2022, a massive data leak from a database hosted on Alibaba Cloud exposed the personal information of roughly 1 billion Chinese citizens. That breach stemmed from a publicly exposed database dashboard lacking password protection.
Like other major e-commerce platforms, AliExpress collects extensive user data, including full names, physical addresses, financial information, precise device fingerprints, and browsing histories. Given the parent company's base in China, Western intelligence agencies and privacy advocates consistently voice concerns over China's national intelligence laws, which could compel Alibaba to provide global user data to the Chinese government. These laws create a structural risk that is difficult for users to mitigate.
Regulatory bodies have also penalized Alibaba. In July 2026, the European Union fined AliExpress €550 million under the Digital Services Act (DSA) for systemic failures in blocking illegal and counterfeit goods. While this fine was not for data theft, it points to broader compliance issues. In 2021, Chinese anti-monopoly regulators fined Alibaba $2.75 billion for abusing its market dominance. Concerns about Chinese tech company security are not new, and this latest fingerprinting incident adds another layer to that discussion.
Broader Risks on AliExpress
Beyond Alibaba's direct actions, shopping on AliExpress carries third-party risks. Security researchers have found malware-infected Android TV boxes and smart devices sold on the platform, pre-loaded from factories to steal data or join botnets. "Brushing scams," where rogue sellers send random items to addresses to post fake, verified reviews, also highlight the platform's vulnerabilities. The AliExpress audio fingerprinting Bluetooth headphones incident underscores the persistent challenge of online privacy. The recent news about aliexpress caught using silent audio tracking highlights the constant evolution of tracking methods and the critical need for robust privacy tools. Related topics include the amazon bee wearable security privacy focus, demonstrating the breadth of privacy considerations in emerging technologies. For more insights on cybersecurity trends, you can refer to discussions on platforms like Bluesky at https://bsky.app/profile/startuphub.bsky.social/post/3mtpocekudc2b.
Top comments (0)