So, if I recall correctly, that "tracking supercookie" they're mentining in that account has to be injected in the headers of any request / response, right? Doesn't this mean it's easily defeated by HTTPS? Or am I misunderstanding how that works?
But one can still infer actual page a user is visiting by means of looking at some leakage of data. See https://security.stackexchange.com/questions/4388/are-urls-v....
It isn't easy but I am sure some people have done it.
One thing ISP has been doing for years is with DNS. If you are at home and you entered some wrong domain name, your ISP will likely present you with its custom search page. This is enough to understand what you are looking for. Furthermore, Google & Facebook aren't relying on cookies as the only way to mine your interest anymore, instead they focus on building profile for you when you use single sign on. For example, when you sign up for Stackoverflow and chooses to login with your Google account, Google may be able to learn you are using Stackoverflow.
Verizon in particular has been in the ads business for years, especially with their acquisition of AOL and on-going acuqisiton of Yahoo, Verizon has a big plan to make use of all the data they have, likely to provide a Google search or new portal for their users, much like AOL back in the days in the 90s and early 2000s.