
An inaudible sound on AliExpress quietly turned your browser into an ID card—and most people never had a clue.
Story Snapshot
- Developers spotted AliExpress using silent audio to fingerprint devices, not record voices.
- Brave confirmed the method and now blocks the exact scripts by default.
- Firefox’s anti-fingerprinting made this audio trick mostly ineffective years ago.
- Reports agree this was covert tracking behavior, not routine analytics.
Silent audio, real identifiers
AliExpress ran code in shoppers’ browsers that created an inaudible sound, then measured how each device processed it. That process captured small, repeatable quirks that can mark a browser like a serial number, a tactic called audio fingerprinting. The sound did not use the microphone. It used built-in Web Audio functions to probe the output path, then logged the results. The process stopped once the tab closed, which helped developers reproduce and isolate it.
Brave, a privacy-focused browser, publicly verified the technique. The company said AliExpress played a silent sound and measured device-specific handling to build a fingerprint. Brave also said it blocks the specific AliExpress scripts involved and has long protected users against audio fingerprinting by default. That confirmation moved this from rumor to record. It also undercut claims that this was just basic analytics. Measuring output variance is a classic tracking move, not click counting.
Why this works, and why it spooks users
Web Audio exposes low-level math and timing paths across chips, drivers, and browsers. Two identical laptops can render a waveform with tiny, stable differences. Scripts can read those numbers and stitch them into a profile that follows you even if you clear cookies. That makes it valuable for tracking, fraud control, or both. Reports tie AliExpress’s behavior to this exact kind of variance measurement, including oscillator and analyzer components with the gain set to zero.
Common sense says shoppers deserve clear notice and a real opt out. People expect stores to remember a cart, not to probe the sound stack for a unique ID. American conservative values favor consent, property rights, and a fair deal. Covert device testing tilts the table. If a business needs anti-bot checks, it should say so plainly and limit data to that task. Stealth methods breed mistrust and push users to tools that fight back.
What browsers did about it
Firefox took the fun out of audio fingerprints back in 2023. An engineer from the Firefox team said version 118 “eliminated the efficacy of WebAudio-based fingerprinting” for most users, largely by normalizing outputs. That move groups users into broad buckets so the signal no longer singles you out. Brave said it not only fuzzes fingerprint surfaces by default, but also blocks the specific AliExpress scripts, cutting off the behavior at the source.
Coverage from security outlets, developer posts, and tech media aligned on the basics. They described silent audio processing used to fingerprint browsers, not spy on speech. Malwarebytes detailed how the script generated and processed an inaudible signal to read stable differences in device handling. InfoQ tied the reports together with the Web Audio variance story and mitigation through bucketing. The Register highlighted how Firefox and Brave blunted the practice for their users.
What we still do not know—and what matters anyway
No public record shows AliExpress’s internal purpose, retention rules, or how it linked these values to user accounts. The public story rests on reproduction by developers and confirmations by browser makers. That establishes behavior but not intent or scope. The lack of a detailed rebuttal from AliExpress leaves an information gap. Still, the core facts hold: the site ran inaudible audio and read the output to profile devices, and major browsers treated it as tracking to be blocked.
A researcher discovered that AliExpress was secretly fingerprinting visitors using more than a dozen tracking techniques, including one that uses inaudible sounds to identify devices through their unique audio signatures. (He only noticed because the silent audio kept… pic.twitter.com/K5SPKm1rrP
— #FreeCuba #FreeIran #FreeBolsonaro #Woke'sAJoke!! (@IRSully) August 29, 2026
Shoppers want clear lines: tell me what you collect, why you collect it, and let me say no. Silent audio fingerprinting crosses that line. The fix is simple. Sites should stick to transparent anti-abuse tools and publish plain-English notices. Regulators should draw bright rules for covert identifiers. Users should update browsers, turn on anti-fingerprinting, and use content blockers. That is not paranoia. It is self-respect online. When silence becomes a tracking channel, noise in defense is wisdom.
Sources:
redstate.com, mallory.ai, hwbusters.com, news.ycombinator.com, infoq.com
© partiallypolitics.com 2026. All rights reserved.












