The Unseen Tracker: How AliExpress and Other Sites Are Mapping Your Digital Footprint
In an ongoing game of cat-and-mouse between web browsers and aggressive advertisers, a spotlight has been turned on an outdated but invasive tracking technique. Recently, it was discovered that the retail giant AliExpress has been employing “audio soundprinting”—a method of tracking users by analyzing the subtle, unique mathematical discrepancies in how their hardware processes audio signals.
The Rise and Fall of Audio Soundprinting
For years, websites exploited the fact that different combinations of CPUs, operating systems, and audio drivers produced slightly different mathematical results when processing audio. By triggering an inaudible sound through a browser, a site could create a unique “fingerprint” for a user, effectively tracking them across the web without the use of traditional cookies.
However, the efficacy of this method has dwindled as browser developers have intervened. Starting with Firefox version 118 in 2023, Mozilla implemented a critical fix: the browser began using its own internal math libraries rather than relying on the underlying operating system.
“The move to constant libraries reduced the entropy enough to stop the technique from working,” explained Tom Ritter, a Firefox developer and volunteer for the Tor Project. Similar protections have been adopted by Chrome, which bundles its own libraries to ensure consistency, rendering the audio soundprinting technique largely ineffective on the world’s most popular browser. Apple’s Safari is also believed to utilize similar defensive measures.
A Relic in an Aggressive Ecosystem
If these modern browsers have largely neutralized the threat, why is a major retailer like AliExpress still attempting to use the technique? The answer appears to be inertia. According to security researchers, this specific audio trick is likely an abandoned artifact—code left behind from years past that has gone unnoticed by the site’s developers.
Yet, this “legacy” code is merely a small piece of a much larger, more intrusive puzzle. The investigation revealed that AliExpress is actively utilizing over a dozen other modern fingerprinting methods to identify visitors, including:
- Hardware and System Profiling: Collection of device memory, hardware concurrency, screen dimensions, and pixel ratios.
- Performance Metrics: Analyzing browser performance timing and WebRTC behavior.
- User Interaction Tracking: Monitoring mouse movements, touch events, and scroll patterns.
- Visual Fingerprinting: Utilizing canvas rendering and WebGL renderer information to map a user’s specific graphical configuration.
- Automation Detection: Scanning for properties specifically associated with browser automation software.
The Endless Arms Race
While the rendering of the audio-based tracking method as a failure is a win for privacy, it provides little room for complacency. Industry experts emphasize that AliExpress is far from an outlier; thousands of websites employ similarly sophisticated, multi-layered tracking stacks to deanonymize users.
The battle for online privacy remains a highly dynamic race. As browser developers tighten security, third-party publishers are constantly experimenting with new, creative ways to bypass protections. For the average user, the discovery serves as a stark reminder that while individual tracking “tricks” may fall out of fashion, the drive to build a persistent, unshakeable digital profile is as aggressive as ever.
