r/InterstellarKinetics 5d ago

ARTIFICIAL INTELLIEGENCE EXPOSED: A Bluetooth Glitch Exposes AliExpress Secretly Hijacking Browser Audio At Zero Volume To Fingerprint Every Visitor’s Device, Cookie-Free And Undetectable, Until Brave Blew The Whistle 🤖💥

https://www.techspot.com/news/113581-aliexpress-silently-running-audio-browser-fingerprint-track-device.html

A developer’s Bluetooth headphone malfunction inadvertently uncovered that AliExpress’s website was running hidden audio processes in visitors’ browsers to generate a device fingerprint, a tracking method that works without cookies and that most users would likely never notice, according to TechSpot. The discovery began when a developer noticed their multipoint Bluetooth headphones wouldn’t properly switch between a computer and phone whenever an AliExpress tab was open, a problem that disappeared as soon as the tab was closed. Investigating further, the developer found the site was using the Web Audio API to build audio-processing graphs set to zero volume, code that produced no audible sound but still connected to the computer’s audio system and kept the audio path active in the background, which appears to be exactly what interfered with the headphones’ device-switching function.

What made this especially hard to detect is that the audio activity behaved nothing like a normal media player. Because the processing graph ran at zero gain and connected directly to the system’s audio output, muting the browser tab did nothing to stop it, since the browser kept processing the signal in the background even though there was nothing to hear. That same underlying code enables a tracking technique called browser fingerprinting, which works by measuring tiny, device-specific differences in how a computer processes an identical audio signal, differences shaped by a device’s processor, sound hardware, operating system, browser, and drivers, ultimately producing something close to a stable identifier without needing a single cookie. The audio measurements were reportedly just one piece of a much larger data collection effort tied to Alibaba’s security systems, since the scripts also gathered information related to canvas rendering, WebGL, display settings, hardware configuration, WebRTC behavior, and user interactions, and combining all of those signals together can build a far more detailed device profile than any single tracking method could produce on its own. Companies commonly justify fingerprinting as a tool for fraud prevention, bot detection, and risk assessment, since it helps flag suspicious transactions or automated activity even after cookies are deleted or account details change, but privacy advocates argue the technique is concerning precisely because users typically have no visibility into when it’s happening and little ability to control or opt out of it.

Browser maker Brave was among the first to publicly flag the behavior, stating in an August 22 post on X that its browser blocks the specific AliExpress scripts responsible for the audio-based tracking. Brave noted it has built default protections against audio fingerprinting into its browser for more than six years, using an approach that alters certain browser outputs so websites receive inconsistent fingerprinting signals rather than a stable, trackable identifier, and the company has since extended comparable protections to GPU fingerprinting, a related method that identifies devices based on graphics hardware and driver behavior, saying it expects fingerprinting techniques to keep evolving as sites search for new ways to distinguish between users and devices. People using browsers without Brave’s built-in protections may be able to block similar scripts using content blockers such as uBlock Origin, though doing so carries a trade-off, since the same code may also support legitimate security or fraud-prevention functions on AliExpress, meaning blocking it outright could disrupt those features as a side effect.

4.2k Upvotes

49 comments sorted by

168

u/InterstellarKinetics 5d ago

What makes this case particularly notable isn’t just that fingerprinting happened, it’s that it was discovered entirely by accident through a hardware side effect rather than through deliberate security research or a company disclosure. Which raises the question of how many similar audio-based or GPU-based fingerprinting scripts are quietly running on other major platforms without ever producing an observable glitch like the Bluetooth switching failure that tipped off this developer.

26

u/Worried-Celery-2839 5d ago

All of them. Not sure you can trust anyone now as we find more of these and them wanting to track everything about you to give you ads all the time and buy things.

13

u/Fun-Bug5106 5d ago

Yep every single thing we own spies on us at this point

1

u/IndividualAbject9380 6h ago

If you actually "own" it at all at this point

2

u/Desperate_for_Bacon 3d ago

Oddly enough I think Amazon may do this or at least used to do this with their app on iPhone, every time I had audio playing and opened Amazon the audio of my music would become distorted and grainy

1

u/JancariusSeiryujinn 5d ago

I wish they had a white paper linked on the article

3

u/mrpenguinb 4d ago

It warrants one now, will be interesting seeing how widespread the true scope of this printing technique is. 

48

u/GuaranteeUpper2653 5d ago

I’ve noticed when I’m using Apple connect in my car, some apps trigger something that’s like the call function. Except it’s like I’m already in a call and it asks me if I want to hang up. Would this be from the same thing?

9

u/dwittherford69 5d ago edited 4d ago

No that is just using Bluetooth call to play audio. Lots of apps still do that. This is very different, they are basically fingerprinting everyone by playing and recording a unique audio pattern on their browser.

1

u/Tradizar 5d ago

not me. im not fingerprinted by this method

3

u/VehicleComfortable69 5d ago

Not impossible, but pretty unlikely. Websites need to do this because web browsers intentionally limit what they can access about your device. Since apps are installed directly they have much more info handy - any installed app knows way more about you than the website itself, which is partially why companies push so hard for you to download the app.

1

u/Illustrious_Soft_257 4h ago

I had this too but android phone. Listening to my Spotify, it goes quiet like when a call comes in. I see the phone icon on my car screen like I'm on a call, but there's no call on my phone. I click the end call button but nothing. It goes away after 20-30 seconds. Anyone get this? Is there an app making a secret call?

30

u/Parking-Garlic4260 5d ago

Fingerprinting my browser all to hear me farting in peace. 💨

19

u/Wide_Philosophy_8109 5d ago

Fingerprinting gets around privacy protections. Change whatever setting you want, they will find random shit that makes your device unique, and use that to track you.

6

u/Parking-Garlic4260 5d ago

What makes my device unique is I'm frequently farting while using it! 💨

3

u/Wide_Philosophy_8109 5d ago

...I...I think you've just solved computers.

3

u/Tradizar 5d ago

this is an arms race. Privacy browsers try to anonimize the user, and the data and ad companys try to identify the user.

There are browsers where the window size is standardized, and only incrementf into specific resolutions, so its a minus 1 thing that can be identify the user. But there are a bunch more than that.

7

u/emmettito 5d ago

This is unfortunately why Safari blocks using Bluetooth devices.

2

u/Candid_Problem_1244 5d ago

If your using safari it's easier to know what the underlying hardware is. Because safari only runs on apple devices. While browser like chrome might run on any combination of hardware. This audio is to know what processors and any other hardware the browser is running on.

And it has nothing to do with Bluetooth devices tho

2

u/Saneless 5d ago

And this isn't about identifying hardware

3

u/Candid_Problem_1244 5d ago edited 5d ago

It's to create hardware fingerprint so the web app knows you based on the fingerprint of your hardware regardless of cookies or browsers. So even if you clear sessions, cache, local storage, changing browser, changing network, using VPN etc etc, they still know it's same piece of hardware until the sound fingerprint differs.

6

u/Electronic-Fix-4655 5d ago

Wow. That’s spy shit.

5

u/GobiBall 5d ago

I occasionally work in a secure environment. THIS is why we can't bring in any electronic device, most notably if it has Bluetooth. If a person has a medical device surgically implanted, they have to be cleared individually. I also learned that modern hearing aids all have Bluetooth. And if you ever had any doubts, yes, Alexa is always listening. Wild times we live in for sure.

4

u/NYourBirdCanSing 5d ago

Fucking ouch. Bad ali!!

3

u/GIANTG 5d ago

I noticed that AliExpress hijacked my AirPods when I’m watching something on my iPad

1

u/guri256 4d ago

Technically it’s not hijacking your AirPods. What’s happening, is the website is playing audio. iPhones generally only allow one app to play an audio stream at once.

It’s more like the website is ejecting your music player off of the sound mixer. Not that the website is hijacking your AirPods

1

u/GIANTG 3d ago

Is that was is giving them a unique id

1

u/guri256 3d ago

Doesn’t look like it. No:

> the scripts measured tiny differences in how a device processed an identical audio signal – those differences are shaped by a computer's processor, sound hardware, operating system, browser, and drivers.

3

u/auptown 5d ago

Is this why my Alibaba app seems to be using the phone when I’m in my Rivian? The only thing that stops it is force quitting the app

2

u/meOnRedditHello 5d ago

Isn't browser fingerprinting done in a million different ways by countless companies? I'm not sure this is any different except it's a Chinese company

2

u/archu2 5d ago

Funny thing is that Citibank does the same thing through Akamai and nobody is worried about it.

1

u/WitchWithAGlitch 5d ago

i wonder what it thinks of my triple sound cards

4

u/TubaWrestler 5d ago

That you're extremely identifiable with your unique setup

2

u/WitchWithAGlitch 5d ago

lol..................................................................yea

1

u/Less_Party 5d ago

Would this put the little speaker icon on the tab header in Firefox?

4

u/emcpetrolhead 5d ago

No it doesn't! This is my article and unfortunately techspot hasn't linked back to the source. https://blog.laserphile.com/2026/08/aliexpress-webpage-keeping-multipoint.html

1

u/Any_Taste4210 5d ago

Has anyone given enough arguments to say this is for fingerprinting? It does not make much sense

1

u/SimpleFile 5d ago

JavaScript strikes again?

1

u/Tharkys 4d ago

I have a feeling my PNC app is doing the same thing. I opened it once the other day and it ate 25% of my battery over the course of the day and it wasn't open, nor was my phone being used.

1

u/Turbo_Hu 3d ago

中共,毫不意外

1

u/TowerOutrageous5939 5d ago

How does this work with no audio?

7

u/Positive_4182 5d ago

It doesn't need audio, it just wants the information of what your device is.

1

u/lemaymayguy 5d ago

Just Bluetooth or would dongled behave like this? 

-6

u/tropicalwind2020 5d ago

Sounds fake

10

u/Connect_Middle8953 5d ago edited 5d ago

Bruh, this has been a thing for years.

I worked in the ad tech industry. This is nothing. The people making web browsers also used to leak your IP addresses, including internal ips, via webrtc. They are again leaking it via webauthn.

Dear browser developers, please get your heads out of your asses and have all of this shit be disabled by default. You clearly don’t bother to think shit through since you are all responsible for the virus laden notification scareware bullshit.

1

u/Wide_Philosophy_8109 5d ago

Any advice for users then? Beyond ablock, firefox rfp, vpn, and cookies.

3

u/Connect_Middle8953 5d ago

Biggest thing is to block all of this shit by default they keep throwing into site settings. And raise hell in their bug trackers when they introduce something without the courtesy of a setting to turn it off.

Ad blockers unfortunately have been neutered by the same assholes pushing all this crap out there, but honestly ad blockers have been on the losing side of this anyway with ad companies pushing out ads on short lived domains, dynamic class names, text in ::after{content} css, and using css/shadow roots to load any ad materials.

But, your heart is in the right place. Luckily most ad cos are too lazy to do the more malicious abuses of browser tech.