AliExpress Exposed for Using Inaudible Sounds to Fingerprint Browser Visitors

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

AliExpress has come under scrutiny for employing an outdated method of browser fingerprinting that utilizes inaudible sounds to track visitors. This technique, which exploits variability in audio processing across different systems, has been largely rendered ineffective by recent updates in major web browsers. According to reporting by Ars Technica, Firefox addressed this issue in version 118, released in 2023, by implementing its own unique math libraries for audio processing, thus reducing the entropy that made the technique viable.

Google’s Chrome browser also mitigates this fingerprinting method by using its own libraries, while Safari users are likely protected for similar reasons, although Apple has not confirmed this. The persistence of AliExpress in using this obsolete method raises questions about its overall tracking strategy, which reportedly includes over a dozen other fingerprinting techniques.

Multiple Tracking Techniques

Among the various methods employed by AliExpress are canvas rendering, WebGL renderer information, and audio oscillator outputs, as well as metrics related to screen dimensions, device memory, and installed browser plugins. This extensive use of fingerprinting techniques highlights a broader trend where many websites are likely employing similar tracking methods, prompting ongoing concerns about user privacy.

While browser developers have made strides in enhancing user privacy, the effectiveness of the other metrics used by AliExpress remains uncertain. As the battle between site publishers and browser developers continues, it is clear that the landscape of online tracking is dynamic and evolving.

Follow Cyber Warriors Middle East for further global cybersecurity developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Supply Chain Attacks Target Developer Tools and CI/CD Pipelines, Research Reveals

In recent years, supply chain attacks have evolved dramatically, shifting from targeting finished software to infiltrating the very tools and code that developers use...

NordVPN Alerts Android Users to Malware Posing as Ryanair, Emirates, and Qatar Airways Apps

NordVPN has issued a warning to Android users about a sophisticated malware campaign that impersonates over 65 well-known brands, including Ryanair, Emirates, and Qatar...

ReliaQuest Confirms Targeting by ShinyHunters in Limited Social Engineering Attack

Cybersecurity firm ReliaQuest has confirmed being targeted by hackers affiliated with the notorious ShinyHunters group, but claims the impact of the attack was limited. ReliaQuest...

U.S. Postal Service Finalizes Mail-in Ballot Regulations Amid Supreme Court Appeal

The U.S. Postal Service (USPS) has announced the finalization of new regulations that could grant the federal government significant control over mail-in ballots for...