They need to be publicly attacked for doing this. Only massive embarrassment will change the behavior. Maybe get some politicians involved if there are any they haven't bought yet.
How Verizon's Advertising Header Works
51–60 of 68 posts
Re: How Verizon's Advertising Header Works
#52The largest network in the UK, O2 (and therefore Three and Tesco), were sending your mobile number as a HTTP header to every site you visited [1]. Didn't last long. ISP's have also tried this in the past - I remember a few in the UK trying to set up an ad-injection model, but can't seem to find them now, other than NebuAd [2]. [1] - http://www.theregister.co.uk/2012/01/25/o2_hands_out_phone_n... [2] http://en.wikiped…
To get around this a number of companies provide services that anonymise the MSISDN, so you can get a unique ID for end users the same as the Verizon header works. I don't know whether this is used by an advertising network or for cross promotion, but I would be highly surprised if it wasn't. Given one of the main proponents of mobile billing are the adult entertainment and gambling industries, I wouldn't put it past them to not have shady business practices like this.
Also Three and O2 are completely separate companies, O2 has a number of MVNOs of which Tesco is one.
(I used to work for a telecom services company in the UK)
Re: How Verizon's Advertising Header Works
#53Oh, oh, I know, this is the moment where smart people on here tell us that more regulation by the FCC would be a bad thing ! Because you know, a telecommunications provider that manipulates the content of your telecommunication is just screaming out for being an overregulated area of business.
If we're going to make fun of a political-theory-cum-religion, we might as well do it right: Oh, oh, I know, this is when the Free Marketeers will tell us all that it would be so easy to build out a massive continent-spanning cell phone network to compete with Verizon if only the FCC Nanny State weren't in the way. And that new network would certainly beat a network which has been entrenched for decades, because "Reg…
Re: How Verizon's Advertising Header Works
#54The largest network in the UK, O2 (and therefore Three and Tesco), were sending your mobile number as a HTTP header to every site you visited [1]. Didn't last long. ISP's have also tried this in the past - I remember a few in the UK trying to set up an ad-injection model, but can't seem to find them now, other than NebuAd [2]. [1] - http://www.theregister.co.uk/2012/01/25/o2_hands_out_phone_n... [2] http://en.wikiped…
An article on the subject, from the same source: http://www.theregister.co.uk/2012/01/25/o2_number_sharing/
Re: How Verizon's Advertising Header Works
#55Earlier quoted context omitted.
It doesn't work on SSL yet. Although I won't be surprised when in the near future certain carrier-enhanced phones start coming with a Verizon-signed root CA installed that enables them to crack into your SSL stream and do the same thing. As for its legality, it shouldn't be, but it likely is. After all, it's well established that ISPs may mess around with your TCP and IP packets to enable NAT. So why not with the HTT…
it's a good reason to buy iphones. Apple will let a poisoned ca cert on their phones about the same time hell freezes over. Android can probably only be trusted if it's a nexus phone.
Re: How Verizon's Advertising Header Works
#56Earlier quoted context omitted.
It reportedly overwrites a header sent by the client: https://twitter.com/kennwhite/status/525338284029775872
Given the ordering of the process, that makes sense. I'm not a Verizon customer but I would be gone yesterday if I were after reading about this. As I understand it, they offer an "opt out" that doesn't actually opt you out of this. Truly gross behavior, though.
And where would you go? AT&T? Is that really a better option?
Sprint and TMo just don't have the reception everywhere I go (or didn't last time I checked).
Re: How Verizon's Advertising Header Works
#57So, I suppose this means that ads that Verizon customers see are potentially targeted by their home address, age, gender, and call/texting patterns. Holy shit, if I was a customer that would be ending today, even if I was in a contract, I'd say they pretty clearly are in breach of contract over my privacy expectations, by sharing who I am with every website I visit.
I am sure there lawyers wear $5000 suits and made damn sure the contract is confusing as hell and lawsuit proof.
Re: How Verizon's Advertising Header Works
#58Re: How Verizon's Advertising Header Works
#59I happen to be in the process of patenting an opt-in system for authenticating and recording requests from users. One of my design goals was to prevent anyone from piggybacking on the scheme to track the users across multiple requests. It occurs to me that if I'd been suffering from a less overdeveloped sense of decency, I could've filed sooner with something like this and hit Verizon with a lawsuit.
Re: How Verizon's Advertising Header Works
#60I work in mobile advertising (not in the US), and my company is partnered with a mobile carrier that does something similar, although the "header enrichment" as it's called is only enabled on specific domains (i.e. requests to our ad server API). I feel that it's unlikely these headers are being set on all web requests. Has anybody verified this claim?
EDIT: On the one server I sampled, they're included in approx. 10% of requests (mostly Android/iOS traffic)