search

LEMON BLOG

Brave Says AliExpress Used Audio Fingerprinting to Track Users Without Cookies

Online tracking is becoming increasingly sophisticated, and cookies are no longer the only way websites can recognise visitors. Privacy-focused browser Brave has now accused Alibaba-owned AliExpress of using the Web Audio API as part of a device-fingerprinting system, potentially allowing the shopping platform to distinguish one device from another using characteristics of its audio hardware and software.

The discovery is particularly interesting because it reportedly began with something completely unrelated to privacy. A researcher noticed that multipoint Bluetooth headphones were behaving strangely whenever an AliExpress browser tab remained open. Closing the tab restored normal audio switching, leading to a deeper investigation into what the website was doing in the background.

What researchers reportedly discovered was a silent audio-processing system that could contribute information to a much broader browser fingerprint.

What Exactly Is Audio Fingerprinting?

Traditional online tracking commonly relies on cookies or account identifiers. Those methods leave relatively obvious traces and can often be blocked, deleted or restricted through browser privacy settings.

Fingerprinting approaches the problem differently.

Instead of storing an identifier on your device, a website can examine characteristics that make your particular browser and computer slightly different from millions of others.

Those signals could include your screen configuration, browser version, operating system, graphics hardware, fonts, WebGL behaviour and other technical properties.

Audio fingerprinting adds the device's audio-processing characteristics to that collection of signals.

Computers do not always process audio calculations in precisely the same way. Differences between processors, operating systems, drivers, browsers and audio hardware can produce tiny variations in the resulting output.

Individually, those differences may tell a website very little.

Combined with dozens of other signals, however, they can contribute to a surprisingly distinctive device fingerprint.

AliExpress Allegedly Generated Audio You Couldn't Hear

According to Brave's findings, AliExpress was using the browser's Web Audio API, a legitimate technology normally used by websites for audio processing and interactive media.

The reported technique generated an audio signal, processed it through an audio graph and analysed the resulting output.

But users would not necessarily hear anything.

The process reportedly connected to the system's audio output while the volume was effectively set to zero.

From the visitor's perspective, the AliExpress tab appeared silent.

Behind the scenes, however, the browser was still performing audio calculations.

It was apparently this background activity that interfered with the researcher's multipoint Bluetooth headphones and ultimately exposed what was happening.

The Audio Data Was Only One Part of the Fingerprint

The audio result reportedly did not operate alone.

According to the investigation, the information could be combined with other fingerprinting signals, including Canvas rendering, WebGL characteristics and hardware-related information.

This is where fingerprinting becomes much more powerful.

A single characteristic such as screen resolution might be shared by millions of people. The same applies to a CPU model or browser version.

But combine enough attributes together and the number of devices matching exactly the same configuration becomes progressively smaller.

Think of it like identifying someone from several ordinary details.

Knowing that someone wears glasses tells you very little.

Knowing their approximate height still does not identify them.

Add their age, profession, location, hairstyle and several other characteristics, however, and the group of possible people becomes much narrower.

Browser fingerprinting works on a similar principle.

Why Websites Use Fingerprinting in the First Place

It is important to recognise that fingerprinting is not always used purely for advertising.

Brave reportedly found that the AliExpress scripts were associated with the company's anti-fraud and security systems.

Large e-commerce platforms deal with account theft, automated bots, payment fraud, fake accounts and other abuse every day.

Recognising whether several suspicious transactions originate from the same device can therefore be useful even when cookies have been removed or accounts are different.

From the perspective of a fraud-prevention team, device fingerprinting can be a valuable security tool.

The privacy concern arises because the same technology can also recognise users without relying on conventional identifiers and may operate largely invisibly.

That creates a difficult balance between legitimate fraud prevention and user privacy.

Why Fingerprinting Is More Difficult to Avoid Than Cookies

Cookies are relatively straightforward.

A website places a small piece of data in your browser, and the browser can later send it back.

Users can delete that cookie.

Browsers can block third-party cookies.

Privacy modes can isolate them.

Fingerprinting does not necessarily need to store anything locally.

The website can simply examine the characteristics of your device again on your next visit and calculate whether the resulting fingerprint resembles one it has previously encountered.

That is why fingerprinting has become such an important battleground for privacy-focused browsers.

Simply clearing browsing history may not necessarily change the underlying characteristics being measured.

Brave Says Its Browser Already Blocks the Technique

Brave says its browser has included protections against audio fingerprinting and other fingerprinting techniques for more than six years.

According to the company, its existing privacy protections already block the scripts associated with the AliExpress technique, meaning Brave users should not need to change additional settings specifically for this discovery.

The browser has also been expanding its defences against other forms of device identification.

One recent area of focus is GPU fingerprinting, where websites examine subtle characteristics of graphics hardware, drivers and rendering behaviour to differentiate devices.

As browsers close one tracking method, researchers and tracking systems inevitably explore others.

It has become something of a technological arms race.

uBlock Origin Can Also Block the Identified Scripts

Users of other browsers are not necessarily powerless.

Content blockers such as uBlock Origin can reportedly prevent the scripts identified in the AliExpress investigation from loading.

However, aggressive script blocking always comes with a trade-off.

If the same scripts are responsible for anti-fraud checks or other functionality, blocking them could cause parts of AliExpress to behave differently or stop working altogether.

That is a recurring challenge with modern privacy protection.

Websites increasingly bundle analytics, security, advertising and functionality together, making it difficult to block one behaviour without potentially affecting another.

The Bluetooth Headphone Discovery Is the Most Fascinating Part

Perhaps the most interesting part of this story is how the alleged fingerprinting was discovered.

There was no obvious privacy warning.

There was no suspicious pop-up.

Nobody noticed an audible tone being played.

Instead, Bluetooth headphones stopped switching properly between devices.

That seemingly unrelated technical problem gave researchers the clue needed to investigate background audio activity.

It demonstrates how much modern websites can be doing behind the interface we actually see.

Opening a web page today can trigger advertisements, analytics platforms, fraud-detection services, authentication systems, recommendation engines and countless background scripts.

Most of that activity remains invisible unless someone specifically investigates it.

Fingerprinting Raises a Bigger Privacy Question

The controversy surrounding AliExpress is therefore about more than one retailer.

It raises a larger question about how websites should identify devices when users have deliberately restricted traditional tracking mechanisms.

Users increasingly disable third-party cookies because they do not want to be followed around the internet.

If websites simply replace cookies with harder-to-detect fingerprinting techniques, the user's privacy choice becomes less meaningful.

At the same time, completely preventing websites from identifying suspicious devices can make fraud prevention considerably harder.

The answer will probably require browsers, regulators and website operators to distinguish more clearly between legitimate security identification and persistent behavioural tracking.

Transparency will be particularly important.

If a website is collecting unusual device characteristics for security purposes, users should ideally understand that such processing is taking place.

Browser Choice Is Becoming Increasingly Important for Privacy

Stories like this also demonstrate how much privacy protection now depends on the browser itself.

Most users will never inspect JavaScript running on a shopping website or analyse how the Web Audio API is being used.

They rely on their browser and extensions to enforce sensible boundaries automatically.

Browsers such as Brave and Firefox have increasingly positioned fingerprinting protection as an important privacy feature, while extensions such as uBlock Origin provide additional control for users who want more aggressive blocking.

No solution is perfect, however.

Fingerprinting techniques continually evolve because browsers expose many legitimate hardware capabilities that websites genuinely need.

Graphics rendering, audio processing and device information all serve useful purposes.

The challenge is preventing those capabilities from becoming invisible identifiers.

Final Thoughts

The alleged AliExpress audio fingerprinting technique is a good example of how online tracking has evolved beyond ordinary cookies.

According to Brave's investigation, the retailer's website could silently process audio through the Web Audio API and combine the resulting characteristics with signals such as Canvas, WebGL and hardware information to contribute to a device fingerprint.

The scripts may have been connected to legitimate anti-fraud systems, but that does not eliminate the privacy questions surrounding such invisible identification techniques.

More importantly, this is unlikely to be the last unusual fingerprinting method discovered.

As browsers become better at blocking conventional tracking, companies will continue exploring different signals—from GPUs and fonts to graphics rendering and audio behaviour.

For ordinary users, the lesson is straightforward: privacy on the modern web is no longer just about deleting cookies.

What your browser reveals about your hardware can sometimes identify you just as effectively as something stored on your computer.

Malaysia Targets Locally Developed ARM Chips for P...
What Album Covers Can Teach Us About Visual Storyt...

Related Posts

 

Comments 0

Loading latest comments...
Sunday, 23 August 2026

Captcha Image

LEMON VIDEO CHANNELS

Step into a world where web design & development, gaming & retro gaming, and guitar covers & shredding collide! Whether you're looking for expert web development insights, nostalgic arcade action, or electrifying guitar solos, this is the place for you. Now also featuring content on TikTok, we’re bringing creativity, music, and tech straight to your screen. Subscribe and join the ride—because the future is bold, fun, and full of possibilities!

My TikTok Video Collection