Silent Tracking Campaign Exposes Device Fingerprinting Tactics
The Chinese e-commerce platform AliExpress has been caught running inaudible audio through users’ web browsers to fingerprint and track devices without their knowledge or consent. Security researchers discovered the technique, which exemplifies increasingly sophisticated tracking methods deployed across the internet to monitor consumer behavior and identify individual users.

The discovery centers on ultrasonic audio—frequencies above the range of human hearing—embedded in AliExpress web pages. These silent signals are designed to identify individual devices and associate browsing activity with specific users, even across different platforms and browsers, creating persistent tracking profiles that survive standard privacy protections.
How Audio Fingerprinting Works
Device fingerprinting is a tracking technique that creates a unique identifier for each device based on a combination of characteristics: browser type, operating system, screen resolution, installed fonts, and hardware capabilities. Unlike cookies, which users can delete or block, fingerprints are harder to detect and persist across browsing sessions indefinitely.
Audio fingerprinting takes this approach a step further. By playing ultrasonic tones—typically in the 18 kHz to 20 kHz range, completely inaudible to human ears—through a user’s speakers and recording the response through their microphone, companies can create an additional layer of identification. The characteristics of how a device reproduces and captures sound are unique enough to serve as a fingerprint, providing tracking data that’s difficult to remove or block.
Why Inaudible Audio?
The appeal to companies like AliExpress is straightforward: it’s invisible to users. While someone might notice and block a cookie, disable tracking pixels, or clear browsing history, inaudible audio runs silently in the background without any notification or visible warning. No technical expertise is required to identify it, and ordinary users would have no way to know they’re being acoustically tracked.
AliExpress and Broader Tracking Practices
AliExpress is not alone in deploying device fingerprinting. The practice has become standard across e-commerce platforms and advertising networks. Companies including Amazon, eBay, and numerous ad-tech firms use variations of fingerprinting to track users across the web and build comprehensive profiles of browsing behavior. What sets AliExpress apart is the deployment of inaudible audio—a technique that crosses into territory many privacy advocates consider particularly invasive.
The platform likely deployed this technology to combat fraud and prevent users from manipulating prices, exploiting promotional codes, or gaming loyalty programs. E-commerce platforms lose billions annually to fraudulent transactions and systematic abuse of discounts. From AliExpress’s operational perspective, audio fingerprinting is a security tool. From a user privacy standpoint, it represents indiscriminate monitoring of every visitor to catch a small fraction engaging in misconduct.
The Privacy Implications
The implications extend far beyond typical tracking. By running audio through devices, AliExpress gains insights into microphone capabilities and acoustic properties of users’ hardware. In scenarios where users have granted microphone permissions to the website, the technology could theoretically create opportunities for more invasive monitoring, though no evidence suggests AliExpress exploited this vulnerability.
The technique also raises fundamental questions about browser security and the assumptions users make about their devices. When a website can trigger audio playback and potentially access microphone input, it creates potential vectors for more invasive surveillance than traditional tracking cookies ever enabled.
How Researchers Discovered the Tracking
Security researchers uncovered the practice through careful analysis of network traffic and browser behavior while visiting AliExpress properties. They identified ultrasonic frequencies embedded in page code and meticulously documented how the signals persisted across different sessions, browsers, and devices. The discovery was published on technology forums and security-focused social media platforms, prompting broader scrutiny of the platform’s tracking infrastructure.
User Reactions and Regulatory Questions
News of AliExpress’s audio fingerprinting sparked genuine outrage among privacy advocates and everyday users. The technique felt particularly invasive precisely because it operated entirely invisibly and inaudibly—a digital fingerprint taken without any human awareness. Comments across social media and technology communities expressed deep concerns about consent, transparency, and whether users had any meaningful control over their own data.
Regulators have not yet directly addressed audio fingerprinting, but the practice likely violates existing privacy frameworks. The European Union’s General Data Protection Regulation requires explicit consent for certain data collection and processing. Many U.S. state privacy laws also mandate transparency and user choice. Audio fingerprinting deployed without notice arguably violates both foundational principles.
The Bigger Picture on Browser Tracking
AliExpress’s audio fingerprinting represents just one component of a much larger ecosystem of tracking technologies that operate below the surface of everyday browsing. Most users have no clear idea how extensively they’re being monitored, what precise data is being collected, or how companies ultimately use that information.
As third-party cookies face phase-out across major browsers due to privacy concerns, technology companies are actively turning to fingerprinting techniques to maintain tracking capabilities. Audio fingerprinting, canvas fingerprinting, and other methods are becoming increasingly common precisely because they’re harder to block than traditional cookies and leave fewer digital traces.
What Users Can Do
Protecting yourself from audio fingerprinting remains difficult but not impossible. Some practical steps include:
- Disable audio autoplay: Modern browsers allow you to disable automatic audio playback, which can block many forms of audio fingerprinting before they occur.
- Review microphone permissions: Regularly check which websites have microphone access and revoke permissions for sites that don’t require it.
- Use privacy-focused browsers: Browsers like Firefox offer stronger privacy protections and allow more granular control over tracking technologies.
- Deploy tracking blockers: Browser extensions designed to block tracking can catch some fingerprinting attempts, though no solution blocks everything.
- Limit site permissions: Be cautious about granting microphone, camera, or location access to any website.
The Path Forward
The AliExpress discovery should prompt broader conversations about tracking transparency and regulatory reform. Users deserve to know what data is being collected and how it’s being used. Companies deploying fingerprinting should be required to disclose the practice clearly and obtain genuine consent—not buried in lengthy terms of service documents.
As tracking methods become increasingly sophisticated, stronger regulatory frameworks and browser-level protections will become necessary to meaningfully protect privacy in the digital age.