Overview
- In late August a developer found that having an AliExpress tab open stopped his multipoint Bluetooth headphones from switching, which led to discovery of zero-volume Web Audio graphs running in the page.
- The page loaded two obfuscated scripts named collina.js and fireyejs.js that generated inaudible waveforms, read frequency data from the Web Audio graph, and kept the browser’s audio path active even with tab mute.
- Investigators say those audio measurements were combined with canvas, WebGL, display, WebRTC, device and interaction signals to create a multi-signal device profile that can persist without cookies.
- Brave said it blocks the specific AliExpress scripts and has long offered audio-fingerprinting protections, and Mozilla pointed to Firefox’s existing Web Audio defenses introduced in 2023.
- The episode highlights a trade-off where fingerprinting helps fight fraud and bots but can run invisibly to users, and users can reduce exposure with privacy browsers or content blockers at the cost of potentially breaking site security features.