Brands
Brave accuses AliExpress of secretly fingerprinting users through hidden audio tracking
Brave says silent audio processing could identify devices without cookies or consent
NEW DELHI: There may be more than meets the ear on AliExpress. Alibaba-owned e-commerce platform AliExpress has allegedly been using hidden Web Audio processes on its homepage to fingerprint users’ devices, according to privacy-focused browser Brave.
Brave said the technique involves generating a silent audio signal and analysing tiny variations in how a device processes it. These variations can differ based on a system’s processor, sound hardware, browser and other software characteristics, potentially creating another component of a user’s digital fingerprint.
“Fingerprinting is a way that websites can identify you without cookies,” Brave said while detailing the issue.
The alleged practice came to light after a researcher noticed that multipoint Bluetooth headphones were not switching audio properly between a computer and a phone while an AliExpress tab remained open. Closing the tab restored normal behaviour, prompting an investigation into what the website was doing in the background.
A technical analysis published around August 20 found that AliExpress scripts were creating audio-processing graphs connected to the system’s audio destination, despite operating at zero volume. Because the process did not rely on conventional media elements, standard browser mute controls did not necessarily stop it.
The investigation alleged that the resulting audio measurements were combined with other signals, including canvas rendering, WebGL information and hardware characteristics, to create a broader device fingerprint. The data was reportedly sent to Alibaba servers.
Unlike traditional cookies, fingerprinting does not necessarily require a website to store a small tracking file on a user’s device. Instead, it can combine seemingly ordinary characteristics of a device and browser to create a relatively distinctive identifier.
Audio fingerprinting takes that idea a step further by measuring how a system processes a particular audio signal. Even when the signal itself cannot be heard, small differences in its processing can potentially provide information about the underlying hardware and software environment.
Such techniques can have legitimate applications. E-commerce platforms and other online services use device fingerprinting for purposes including fraud detection, bot prevention and risk assessment, particularly because users can delete or block cookies.
The privacy concern arises when these techniques operate without clear visibility or meaningful user control, particularly when multiple signals are combined to create a persistent profile.
Brave said its browser has defended users against audio fingerprinting and other fingerprinting techniques by default for more than six years.
The browser said it can introduce randomised data into certain outputs, making it harder for websites to obtain a consistent device fingerprint. Brave also said those protections reset across sessions and that it blocks the specific scripts associated with the AliExpress technique.
The company added that users do not need to change their settings to activate these protections.
Brave has also been expanding its fingerprinting defences, including protections designed to limit tracking based on graphics processing units and related hardware characteristics.
The episode highlights a familiar problem for the modern web: the same technology that can help online platforms identify suspicious activity can also make users easier to recognise across sessions.
For e-commerce businesses, device fingerprinting can be useful in detecting fraud and automated abuse. For privacy advocates, however, increasingly sophisticated fingerprinting methods raise concerns because they can work without cookies and may be difficult for ordinary users to detect.
Users on other browsers can attempt to block the identified scripts using content-blocking tools such as uBlock Origin, although doing so may affect some website functions.
For now, the AliExpress case adds another example to the growing cat-and-mouse game between online platforms developing new anti-fraud tools and browsers trying to keep users’ digital identities harder to track.




