AliExpress Exposed for Using Inaudible Sounds to Fingerprint Browser Visitors

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

AliExpress has come under scrutiny for employing an outdated method of browser fingerprinting that utilizes inaudible sounds to track visitors. This technique, which exploits variability in audio processing across different systems, has been largely rendered ineffective by recent updates in major web browsers. According to reporting by Ars Technica, Firefox addressed this issue in version 118, released in 2023, by implementing its own unique math libraries for audio processing, thus reducing the entropy that made the technique viable.

Google’s Chrome browser also mitigates this fingerprinting method by using its own libraries, while Safari users are likely protected for similar reasons, although Apple has not confirmed this. The persistence of AliExpress in using this obsolete method raises questions about its overall tracking strategy, which reportedly includes over a dozen other fingerprinting techniques.

Multiple Tracking Techniques

Among the various methods employed by AliExpress are canvas rendering, WebGL renderer information, and audio oscillator outputs, as well as metrics related to screen dimensions, device memory, and installed browser plugins. This extensive use of fingerprinting techniques highlights a broader trend where many websites are likely employing similar tracking methods, prompting ongoing concerns about user privacy.

While browser developers have made strides in enhancing user privacy, the effectiveness of the other metrics used by AliExpress remains uncertain. As the battle between site publishers and browser developers continues, it is clear that the landscape of online tracking is dynamic and evolving.

Follow Cyber Warriors Middle East for further global cybersecurity developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Cybercriminals Leak Grand Theft Auto VI Footage, Prompting Legal Action from Take-Two Interactive

Grand Theft Auto VI, anticipated as the game event of the decade, faced a major setback last week when a cybercriminal leaked gameplay footage...

Cybersecurity Patch Window Collapses, Urging New Control Strategies for Risk Management

For decades, cybersecurity defenders have relied on a straightforward model: when a vulnerability is disclosed, security teams assess exposure, test fixes, deploy patches, and...

Tehran-linked hackers shut down UK power plant in recent cyber attack

A recent cyber attack attributed to hackers linked to the Iranian regime has resulted in the shutdown of a small power plant in the...

AI-Enabled Malware Analysis Reveals 97% Remains in Research Environments, with Limited Production Activity

  AI-Enabled Malware Analysis: Limited Production Activity Observed Research conducted by Palo Alto Networks reveals that while AI-enabled malware is a growing concern, approximately 97% of...