Close Menu
GeekBlog

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Diablo 5 Just Got Announced, and This Time You Don’t Stop the Apocalypse, You Survive It

    September 14, 2026

    Meta Spent Three Years Flattening Management for AI. Now It’s Rebuilding the Layer It Cut.

    September 14, 2026

    A Hacker Ran Hundreds of AI Agents at Once. GreyNoise Says It Breached 440 Servers in Four Hours.

    September 14, 2026
    Facebook X (Twitter) Instagram Threads
    GeekBlog
    • Home
    • Mobile
    • Tech News
    • Blog
    • Gaming
    • Smartwatch
    • How-To Guides
    • AI & Software
    Facebook
    GeekBlog
    Home»Tech News»AliExpress Was Playing Silent Sound Through Your Speakers to Work Out Who You Are
    Tech News

    AliExpress Was Playing Silent Sound Through Your Speakers to Work Out Who You Are

    Olivia HartmanBy Olivia HartmanAugust 24, 20268 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    A person browsing on a laptop while wearing headphones, illustrating how AliExpress used silent browser audio to fingerprint devices
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link

    It started with a pair of Bluetooth headphones that refused to behave.

    A developer was using multipoint headphones, the kind that hold a connection to two devices at once and hand audio back and forth between them. The handoff from laptop to phone stopped working. Nothing obvious explained it. Then they closed an AliExpress tab, and the headphones started behaving normally again.

    That is the sort of coincidence most people shrug off. Instead, they went looking, and what they found on the AliExpress homepage was a pair of obfuscated scripts quietly building audio processing graphs through the browser and keeping a live connection open to the system’s sound hardware. No sound you could hear. No indicator anywhere. Muting the tab did not stop it.

    The point of the silent audio was not to listen to anything. It was to identify the machine it was playing on.

    The short version

    • What was found: two obfuscated scripts on the AliExpress homepage creating running audio contexts wired to the system’s speakers
    • How it was noticed: the audio contexts interfered with multipoint Bluetooth headphone switching. Closing the tab fixed it.
    • What it does: the Web Audio API generates an inaudible signal, then measures how this particular device processed it
    • Why that matters: tiny differences in CPU, audio stack, browser build and drivers produce a repeatable value that helps identify you
    • Not a recording: your microphone is not involved, and nothing you say is captured
    • What else was collected: canvas rendering output, display settings, hardware configuration and interaction signals, bundled and sent to Alibaba servers
    • Who called it out: Brave, which says its browser has blocked audio fingerprinting by default for more than six years

    Audio fingerprinting, explained without the jargon

    Every browser ships an interface called the Web Audio API. It exists so that web apps can synthesize and process sound: a music sequencer, a game engine, a video editor in a tab. To do that, a page builds a small graph of nodes. Something generates a tone, something shapes it, something reads the result.

    Fingerprinting abuses the last step. Set the volume to zero so nobody hears it, push a signal through the graph, then read the numbers that come out the other end. Those numbers are not identical across machines. Floating point math behaves slightly differently depending on the processor. Audio drivers round differently. Browser builds implement the same math with small variations. The output is stable on your device and subtly different on someone else’s.

    On its own that value is not enough to identify anyone. Combined with a dozen other measurements, it gets close. This is the part people underestimate: no single signal is incriminating, and the combination usually is.

    Recommended for you:

    Chrome Deletes the Last Real Ad Blockers on August 31, and Firefox Is the Way Out
    Tech News·Aug 16, 2026

    Chrome Deletes the Last Real Ad Blockers on August 31, and Firefox Is the Way Out

    SignalWhat the site measuresWhy it helps identify you
    AudioHow a silent signal comes back out of the audio graphReflects your CPU, audio stack and browser build
    CanvasPixel output from drawing hidden text and shapesReflects your GPU, drivers and installed fonts
    WebGLRenderer strings and how 3D scenes rasterizeNarrows you to a graphics chip and driver version
    DisplayResolution, color depth, pixel ratio, available screen areaUnusual monitor setups are surprisingly rare
    HardwareCore count, memory, platform, touch supportSplits the population into small buckets
    BehaviorMouse movement, scroll cadence, typing rhythmSeparates humans from bots, and people from each other

    What actually happens in the two seconds after the page loads

    How a silent sound becomes an ID

    AudioContext created on load

    Oscillator generates a tone

    Gain = 0 you hear nothing

    Read back raw sample values

    Hash stable per device

    Canvas output GPU and fonts

    Display settings resolution, depth

    Hardware config cores, memory

    Interactions how you move

    One profile, sent to the server

    The developer also documented scripts pulling canvas rendering results, display configuration, hardware details and user interaction patterns. Those were bundled with the audio value and shipped off to Alibaba infrastructure. Individually, unremarkable. Together, a profile.

    Why a shopping site would bother

    Here is the part that gets flattened in most coverage. Fingerprinting is not automatically an advertising play. It has a legitimate and very common security use, and marketplaces have a genuine problem to solve.

    AliExpress deals with account takeovers, coupon farming, fake reviews, scripted checkout bots on limited stock, and refund fraud. Cookies are useless against all of that, because the attacker simply clears them. A device signal that survives a cleared cookie jar is exactly what an anti fraud team wants, and every large retailer, bank and ticketing site runs some version of it.

    The problem is that the same measurement, taken by the same code, is equally good at building a persistent advertising identity that follows you across sessions and ignores every privacy control you thought you had turned on. The technique does not announce which purpose it is serving. You cannot tell from the outside, and neither can a regulator without seeing what happens to the data afterward.

    The consent problem

    Cookie banners exist because storing an identifier on your device generally requires asking first. Fingerprinting sidesteps that framing entirely, since nothing is stored on your machine at all. Regulators in the EU and UK have said for years that fingerprinting falls under the same rules as cookies, and the UK’s ICO has been explicit that it is harder to justify precisely because users cannot see it, cannot clear it and cannot opt out of it. Enforcement, so far, has not matched the rhetoric.

    Brave’s response, and what it is actually claiming

    Brave amplified the finding on X, writing that “Alibaba’s AliExpress was caught using users’ audio systems to track them. AliExpress wasn’t recording users but instead playing a silent sound and measuring how users’ specific devices processed it in order to fingerprint them.”

    The second half of that sentence deserves highlighting, because plenty of people read the headline and assumed a shopping site was listening to their living room. It was not. No microphone permission was involved. Playback, not capture.

    Brave says it has defended against audio fingerprinting by default for more than six years, using a technique it calls farbling: rather than blocking the API outright, it injects small amounts of randomized noise into the values a site can read. The site still gets an answer, so nothing breaks. The answer is just different for every site and resets between sessions, which makes it useless for stitching your activity together.

    That approach is worth understanding because it differs from the alternatives. Firefox leans toward normalization, reporting the same generic values as everyone else so you blend into a crowd. Safari trims the surface area, returning simplified system information. Chrome, which still exposes canvas, WebGL, AudioContext and a long list of navigator properties, does the least of the four.

    BrowserApproachEffort required from you
    BraveRandomizes canvas, WebGL and audio output per site and per sessionNone, it is on by default
    FirefoxNormalizes signals, spoofs timezone and screen size, blocks canvas readbackOn in private windows, opt in elsewhere
    SafariReports simplified system information to shrink the fingerprint surfaceNone, but limited to Apple platforms
    ChromeNo dedicated anti fingerprinting defenseExtensions and manual hardening, with mixed results
    Tor BrowserAggressive normalization so every user looks identicalNone, but expect broken sites and slow pages

    One correction worth making, because it comes up every single time this subject does: private browsing does nothing here. Incognito clears cookies and history when you close the window. Your fingerprint gets computed fresh each time from hardware you did not change, so it comes out the same. If anything, the smaller population of people browsing privately makes you marginally easier to pick out.

    Recommended for you:

    Apple Just Put a Spyware Warning on the iPhone Lock Screen for the First Time
    Tech News·Aug 15, 2026

    Apple Just Put a Spyware Warning on the iPhone Lock Screen for the First Time

    What to actually do about it

    You are not going to make yourself fingerprint proof, and anyone selling that idea is selling something. What you can do is stop being trivially linkable.

    • Switch the browser you shop in. Not your whole life, just the tab where you compare prices on marketplaces. Brave or a hardened Firefox profile covers most of this.
    • Turn on Firefox’s fingerprinting protection outside private windows if Firefox is your daily driver. It is a setting, not a download.
    • Stop treating incognito as a privacy mode. It is a shared computer mode.
    • Cut your extension count. An unusual combination of installed extensions is itself a strong identifying signal, which is the quiet irony of installing five privacy tools.
    • Pick the app or the website, not both. Splitting your behavior across two identities gives any profile less to join up.
    • Test yourself. The EFF’s Cover Your Tracks tool will tell you how unique your current setup looks in about thirty seconds.

    The browser you choose matters more than any single toggle, which is one reason the fight over what browsers are allowed to block keeps mattering. When Chrome moved to finish off the old extension platform that real ad blockers depend on, it narrowed the options for anyone trying to defend themselves inside Chrome specifically. On phones the calculus is similar, and our ranking of Android browsers weighs tracking protection heavily for exactly this reason.

    It also fits a pattern that has been hard to ignore this year: the surveillance most people should worry about is not dramatic, it is ambient. Sometimes it takes a vendor putting a warning directly on your lock screen to make it visible. Most of the time nobody tells you at all, and it takes a developer with misbehaving headphones and a free afternoon.

    Neither AliExpress nor Alibaba has publicly addressed the finding. The scripts, as of this week, are still there.

    Browsers Privacy Security
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
    Previous ArticleNvidia’s AI Security Alliance Tripled to 120 Members. OpenAI and Anthropic Still Won’t Join.
    Next Article A Laptop Caught Fire Mid Cabin on American Airlines 2398, and the FAA Wants to Know Why
    Olivia Hartman

      Olivia Hartman is GeekBlog's general technology reporter, covering the wider world of tech beyond smartphones: AI and software, laptops and PCs, gaming, streaming, space, science, consumer gadgets, deals and the policy stories shaping the industry. A versatile journalist with a nose for what actually matters, Olivia turns breaking news and product launches into accessible, no-hype reporting for everyday readers.

      Related Posts

      5 Mins Read

      Meta Spent Three Years Flattening Management for AI. Now It’s Rebuilding the Layer It Cut.

      6 Mins Read

      A Hacker Ran Hundreds of AI Agents at Once. GreyNoise Says It Breached 440 Servers in Four Hours.

      7 Mins Read

      A Golf YouTuber Is Owed $1.4 Million by a Bankrupt League. He Is Sixteenth in Line.

      6 Mins Read

      Apple Revealed Burgundy on Wednesday. Android Phones in Almost the Same Shade Were Already on Sale.

      7 Mins Read

      Prime Video Is Now Reshaping Actors’ Mouths to Match the Dub. The Voices Are Still Human.

      9 Mins Read

      Your Apple Watch Can Replay the Last 15 Seconds You Missed. Apple Says It Never Recorded Them.

      Top Posts

      Gal Gadot’s Lawyers Spent Six Months on One AI Clause. Then SAG Called Them for Pointers.

      September 2, 20264 Views

      Every iPhone Camera Ranked in 2026 (Best to Worst)

      July 6, 20263 Views

      The Mesh Router Placement Strategy That Finally Gave Me Full Home Coverage

      September 9, 20262 Views
      Stay In Touch
      • Facebook

      Subscribe to Updates

      Get the latest tech news from FooBar about tech, design and biz.

      Most Popular

      How to Change HEIC to JPG on iPhone, Mac, Android and Windows (No Software Needed)

      September 3, 20266 Views

      Gal Gadot’s Lawyers Spent Six Months on One AI Clause. Then SAG Called Them for Pointers.

      September 2, 20265 Views

      How to Spot AI Generated Images in 2026 (The Old Tricks Stopped Working)

      September 3, 20263 Views
      Our Picks

      Diablo 5 Just Got Announced, and This Time You Don’t Stop the Apocalypse, You Survive It

      September 14, 2026

      Meta Spent Three Years Flattening Management for AI. Now It’s Rebuilding the Layer It Cut.

      September 14, 2026

      A Hacker Ran Hundreds of AI Agents at Once. GreyNoise Says It Breached 440 Servers in Four Hours.

      September 14, 2026

      Subscribe to Updates

      Get the latest creative news from FooBar about art, design and business.

      HEICJPG.online - Convert HEIC to JPG online
      Facebook
      • About Us
      • Contact us
      • Privacy Policy
      • Disclaimer
      • Terms and Conditions
      • Editorial Policy
      • Cookie Policy
      © 2026 GeekBlog

      Type above and press Enter to search. Press Esc to cancel.