Live data from Hacker News

How Verizon's Advertising Header Works

webpolicy.org

11–20 of 68 posts

Re: How Verizon's Advertising Header Works

#11

Is this even legal? I mean are ISPs, or telecom in general allowed to identify the requester without their permission? But I imagine it will not work on encrypted connections. SSL FTW?!

I looked into these legal questions in some detail in an article I wrote for CNET (before leaving to found http://recent.io/ earlier this year). The short answer is that Verizon has more leeway than it would if it's a cable company, and it's possible that VZ's actions implicate the Wiretap Act, but exact implementation details matter: http://www.cnet.com/news/web-monitoring-for-ads-it-may-be-il...

Here's a related article I wrote about Verizon selling customers' geographical locations, app usage, and Web browsing activities: http://www.cnet.com/news/verizon-draws-fire-for-monitoring-a...

My favorite quote from that story: "We're able to view just everything that they do," Bill Diggins, U.S. chief for the Verizon Wireless marketing initiative, told an industry conference earlier this year. "And that's really where data is going today. Data is the new oil." "We're able to identify what that customer likes not by filling out a form, but by analyzing what they do on a day-to-day basis..."

Re: How Verizon's Advertising Header Works

#14

Is this even legal? I mean are ISPs, or telecom in general allowed to identify the requester without their permission? But I imagine it will not work on encrypted connections. SSL FTW?!

It doesn't work on SSL yet. Although I won't be surprised when in the near future certain carrier-enhanced phones start coming with a Verizon-signed root CA installed that enables them to crack into your SSL stream and do the same thing.

As for its legality, it shouldn't be, but it likely is. After all, it's well established that ISPs may mess around with your TCP and IP packets to enable NAT. So why not with the HTTP stream?

Re: How Verizon's Advertising Header Works

#15
post #10
post #7

This means that they are doing deep packet inspection and re-writing the actual packets sent over the network, right?

I wouldn't call it particularly deep packet inspection—they're just rewriting the http requests.

wouldn't re-writing the HTTP request require inspecting the packets as deeply as it is possible to?

Re: How Verizon's Advertising Header Works

#16
So, I suppose this means that ads that Verizon customers see are potentially targeted by their home address, age, gender, and call/texting patterns.

Holy shit, if I was a customer that would be ending today, even if I was in a contract, I'd say they pretty clearly are in breach of contract over my privacy expectations, by sharing who I am with every website I visit.

Re: How Verizon's Advertising Header Works

#17
Anyone know if....

A. It is possible to request your "advertising profile" from them.

B. Can a customer request that gathered information on them be destroyed?

C. If you opted-out today (like me) does that mean that they stop collecting information and continue to sell "your devices" ad profile? Or do they also stop selling your info?

(sending these to Verizon. I'll post if I get answers)

Re: How Verizon's Advertising Header Works

#18

I haven't had the opportunity to tinker with this, but what if the client sends a X-UIDH: header of it's own? Will VZW overwrite the header, or will it pass it through? If it doesn't clobber it, there's a browser plugin waiting to be written.

Maybe someone should write some browser plugins so desktop browsers can send fake X-UIDH headers to help poison the well, just a little.

Better still have the plugin get a group of known headers and distribute them all over.

Re: How Verizon's Advertising Header Works

#20

Is this even legal? I mean are ISPs, or telecom in general allowed to identify the requester without their permission? But I imagine it will not work on encrypted connections. SSL FTW?!

It doesn't work on SSL yet. Although I won't be surprised when in the near future certain carrier-enhanced phones start coming with a Verizon-signed root CA installed that enables them to crack into your SSL stream and do the same thing. As for its legality, it shouldn't be, but it likely is. After all, it's well established that ISPs may mess around with your TCP and IP packets to enable NAT. So why not with the HTT…

it's a good reason to buy iphones. Apple will let a poisoned ca cert on their phones about the same time hell freezes over. Android can probably only be trusted if it's a nexus phone.
Post reply on HN