AliExpress Tracked You Without Cookies — Using Sound

AliExpress was caught using silent audio signals to build a unique fingerprint of each visitor's browser — no cookies needed. This technique is nearly invisible and hard to block, raising serious privacy concerns for anyone browsing the web.

Your Browser Has a Fingerprint — and It Doesn’t Need Cookies

Most people have heard of cookies — small files websites store on your computer to track you across sessions. Block the cookies, stay private. Simple enough. Except it isn’t, because there are other ways to identify you, and one of them just got caught in the wild on one of the world’s biggest shopping platforms.

Researchers discovered that AliExpress, the massive online retail marketplace, was running a silent audio trick in the background of its website. The site used your browser’s audio processing hardware to generate a tiny, inaudible signal — one you’d never hear or see — and then measured how your specific device processed that signal. Because every combination of operating system, browser, sound drivers, and hardware handles audio slightly differently, the result is a number that’s nearly unique to your machine. No cookies. No login required. Just your device doing what it always does, giving itself away.

What Is Browser Fingerprinting?

Browser fingerprinting is a technique where a website collects small details about your browser and device — screen size, installed fonts, graphics card behaviour, and now audio processing — and combines them into a profile. Alone, each detail is harmless. Together, they create something close to a unique ID for your device. Unlike a cookie, there’s nothing stored on your computer, so clearing your browser history does nothing to help.

The audio version of this trick — sometimes called AudioContext fingerprinting — has been known in security research for years. What makes this discovery notable is catching a major commercial platform actively using it, quietly, buried in the page code where most users would never look.

Why Should Website Owners Care?

If you run a website or an online store, there’s a lesson here beyond privacy rights. Your visitors are increasingly aware of tracking, and regulators in Europe and elsewhere are watching closely. Techniques like this, even if technically legal in some regions, can damage user trust fast when exposed. The story went public, and the backlash was immediate.

For everyday users and site operators alike, this is a reminder that standard privacy tools — ad blockers, cookie banners, private browsing mode — don’t stop fingerprinting. Extensions like Canvas Blocker or browsers with built-in anti-fingerprinting features (Firefox, Brave) offer more protection, but nothing is a complete shield.

What Comes Next

As cookie-based tracking gets squeezed out by browser changes and new privacy laws, fingerprinting is quietly filling the gap. Expect more platforms to experiment with techniques like this, and expect regulators to catch up eventually — but slowly. For now, the most useful thing you can do is use a browser that actively fights fingerprinting, and treat any large commercial website as a place that wants to know exactly who you are.