← Back

AliExpress Caught Playing Silent Audio to Secretly Fingerprint Your Hardware

Original version ·

Forget sneaky cookies: Alibaba found a way to snoop on your PC hardware by pumping inaudible sound into your headphones just to tag you across the web.

A cybersecurity researcher noticed that multi-point Bluetooth headphones stubbornly refused to switch back to a smartphone whenever an AliExpress tab was open. It turned out the storefront was secretly keeping the computer's audio channel active by generating inaudible sound waves to build a persistent hardware fingerprint.

Instead of recording through the microphone or asking for invasive browser permissions, two heavily obfuscated security scripts from Alibaba create hidden WebAudio graphs right on the homepage. These scripts generate a synthetic sawtooth audio wave, run it through the system, and route it to an output node with zero volume. While the human ear hears dead silence, the machine processes every minuscule processing anomaly.

Every combination of CPU, sound card, and browser engine renders that zero-volume audio wave with tiny, unique variations. AliExpress measures these exact micro-differences to identify the device, bundling the audio profile with screen dimensions, installed fonts, WebGL data, and mouse movements into a permanent digital fingerprint that survives even when cookies are wiped clean.

Standard browser tab muting does nothing against this trick because no standard HTML5 media player is running. The tracking scripts, identified as collina.js and fireyejs.js, can only be stopped in their tracks by manually blocking the underlying asset domains using content blockers like uBlock Origin.

Web stores have evolved from simply selling cheap cables to running diagnostic audio benchmarks on user silicon without consent. The entire modern web ecosystem has degraded into an aggressive surveillance pipeline where even absolute silence is weaponized for tracking metrics.

Source: LaserPhile

Comments

This is where the magic happens: AI reads your discussion and rewrites the article based on the most interesting comments. Each strong comment adds points to the meter below. Once the meter is full, the article updates live — no page reload needed.

10/24
  1. Refactored Rootkit
    all of that just to recommend me the exact same 3 dollar phone case i already bought
    +3 funnyThe pinnacle of modern surveillance technology is being used to sell you garbage you already own
  2. Dockerized GPU
    webaudio api needs to be locked behind user permissions yesterday. why can any random shopping tab ping my soundcard like this??
    +4 solidA rare moment of sanity where someone actually suggests fixing the browser instead of just complaining
  3. Sandboxed Compiler
    insane catch tbh. imagine finding out because your multipoint headphones got hijacked lmao
    +2 emotionalNothing says 'privacy nightmare' quite like your headphones having a nervous breakdown
  4. Rate-Limited Neckbeard
    and people still laugh at me for running noscript on everything
    +1 jokeThe smug satisfaction of the tinfoil hat crowd is the only thing more reliable than the tracking itself