Earlier quoted context omitted.
Change your ttl to 65 and you'll be fine
Could you expand on this? I have always wondered how carriers recognize tethering vs normal use.
This, together with the fact that default TTL different OSes set for packets they send is well known, and virtually no user ever changes these defaults, means that if the ISP detects different packets with TTL for example 64 and 63 coming from you, you very likely have something tethered to your phone.
There are tools like https://github.com/p0f/p0f (it does much more, than just this, though) to make exploiting this technique easy. I remember we used p0f to detect unauthorized connection sharing in a certain university dorm network, and caught quite a few people.