
One developer accidentally discovered that popular online shopping platform AliExpress is actually spying on its users, with an audio 'fingerprinting' tool hidden on the web page.
Fingerprinting in this form isn't necessarily unique to AliExpress or a new phenomenon altogether, as it has been around for years and is used in part to spot suspicious activity and filter out bots, yet it does also raise privacy concerns — especially if it's being hidden from those who use the site.
It's part of wider concerns surrounding data collection as your personal information, interests, and activities are becoming increasingly more valuable to companies than anything you could buy with money, especially as the internet continues to remain 'free' in some form.
It might make you think twice about your own cybersecurity going forward, as websites you could be going on every single day might be collecting more about you than you think.
How was the discovery made?
As reported by TechSpot, one developer revealed how a Bluetooth bug led them down a rabbit hole that exposed AliExpress' (and parent company Alibaba's) attempts to track users visiting the site via audio fingerprinting.
Advert
It started when they encountered an issue with multipoint Bluetooth headphones where it wasn't able to switch from their computer to a phone, yet that problem surprisingly disappeared when closing the AliExpress tab they had open.

Understandably this led them to wonder whether there was a link, and it was soon unveiled that AliExpress had been using the Web Audio API at zero volume to build audio-processing graphs.
These allowed the site to maintain a connection to your computer's audio systems despite being otherwise indetectible — and even persisted when directly muting the tab too.
It's expected that this is linked to a process known as 'fingerprinting', where a website can collect device-specific details like your processor, sound hardware, operating system, browser, and drivers, using this to create an overall profile that's linked to you.
The developer also discovered various scripts that linked to canvas rendering, display settings identification, your hardware configuration, and user interactions, making many worried that their privacy is being breached simply by existing on the internet.
How can you avoid fingerprinting online?
One of the best (and frankly, only) ways you can avoid fingerprinting when browsing the web these days is by using specific browsers that block activity from sites attempting to track users.
Brave is by far the most prominent of these, as it is openly proud of its ability to keep your information safe and prevent sites from secretly tracking you through these methods.

It even directly addressed the discovery surrounding AliExpress on social media, declaring on X:
"Alibaba's AliExpress was caught using users' audio systems to track them. AliExpress wasn't recording users but instead playing a silent sound and measuring how users' specific devices processed it in order to fingerprint them. But don't worry because Brave stops this."
The browser noted that "for 6+ years, Brave has protected users against audio fingerprinting, and other fingerprinting types, by default. Brave injects random data into the browser's output so you show a different fingerprint to different sites. This fingerprint also resets across sessions."
If you care about protecting your privacy on the internet then, Brave might be the way to go.