Live data from Hacker News

How Verizon and Turn Defeat Browser Privacy Protections

eff.org

21–30 of 176 posts

Re: How Verizon and Turn Defeat Browser Privacy Protections

#21
Some additional research that came out today, with more details of the various things Verizon is doing / plans to do with UIDH: https://freedom-to-tinker.com/blog/englehardt/verizons-track...

(We collaborated with Mayer on this research.)

Code and data that you can play with to verify these results / do other similar experiments, using our web privacy measurement tool OpenWPM: https://github.com/englehardt/verizon-uidh / https://github.com/citp/OpenWPM

Re: How Verizon and Turn Defeat Browser Privacy Protections

#22

If you were an author (of any sort) could you claim that the transmissions of your material (text) that are under copyright were circumvented (DMCA) via a permacookie under your "moral rights" as an author to publish anonymously?

If you are a content provider you may choose not to serve ads on your content.

Re: How Verizon and Turn Defeat Browser Privacy Protections

#23

It's frustrating, the internet has become such a creepy "you are the product" medium. The more of this I see, I start to feel like I don't want to be a part of it anymore.

That would be OK if my cellphone usage was "free". But it's not. I'm paying Verizon hundreds of dollars a month for me and my family. I wonder if an MVNO would be less creepy than Verizon? Probably not, I'd bet they're even sleazier.

Well, do you care enough to take your business elsewhere? That's really the last-ditch way for you to have any voice on this.

For whatever it's worth, I left them recently for this very reason (your choice is yours, mine is mine, no preaching or judgement here either) – I ended up having a few minute conversation with the confused (but nice) call rep who didn't understand what they were doing but seemed to empathize as I explained it. Ultimately, will my explanation matter? Probably not, but it was all the power I felt I had, beyond cutting them off from my monthly payments.

While still not trustworthy in my book, t-mobile is definitely an upgrade, at least in this regard.

Re: How Verizon and Turn Defeat Browser Privacy Protections

#24

> In fact, Turn has told EFF that they do not believe that either Do Not Track or a user deleting their cookies is a signal that the user wishes to opt out from tracking. What the fuck, Turn? You got a different explanation for what the fuck "Do Not Track" means? Are they for fucking real right now? I mean, I've seen my share of grade-A corporate double-speak, but this takes the goddamn cake. Holy fucking shit. Thank…

I get that this falls in line with the accepted local opinion but I thought HN aspired to be better than pandering garbage filled with vulgarity.

Re: How Verizon and Turn Defeat Browser Privacy Protections

#25
post #22

If you were an author (of any sort) could you claim that the transmissions of your material (text) that are under copyright were circumvented (DMCA) via a permacookie under your "moral rights" as an author to publish anonymously?

If you are a content provider you may choose not to serve ads on your content.

hmm, not talking about the content provider. I am saying if I am an author who was publishing something under anonymity and I assumed I was anonymous because I "cleared my cookies/Enabled Do Not Track settings" during the publication of the material - only to discover that my cookies had been circumvented via permacookie by a commercial entity - is my "moral right" of anonymity is now gone? could I claim the permacookie method was a circumvention under the DMCA?

Re: How Verizon and Turn Defeat Browser Privacy Protections

#26
Classic soulless PR-drone reply here:

http://www.turn.com/blog/in-response-to-propublica

"Clearing cookies is not a reliable way for a user to express their desire not to receive tailored advertising,..." Okay, but is it a reliable way for me to express my desire for you not to track me? I assume you ignore the DNT header, and I already block your ads, but still...

"Turn fully supports enabling consumers to express their choice and consent in regards to data use for digital advertising." Choke on a bag of dicks, you sleazy, lying scum.

Re: How Verizon and Turn Defeat Browser Privacy Protections

#27
There are two solutions I see.

1) Regulation. Maybe it'll happen, I don't have much hope of it being done intelligently.

2) Feed them garbage data.

We just need a database of live UIDH numbers and a browser extension to inject a random UIDH number from that list into the header.

Re: How Verizon and Turn Defeat Browser Privacy Protections

#28
post #15

My guess is that the "entrepreneurial" solution here would be a combination of: - A browser that doesn't support cookies and provides the server with a client controlled session-id (perhaps a user-id also). - Only uses SSL sessions to avoid middle-box injection of HTML headers (this still leaves the provider with the ability to inject data as IP options / TCP headers). - A micropayment solution that allows content pr…

| A micropayment solution that allows content providers to get revenue from content rather than ads.

Even if this were popular, you'd still be tracked because it makes money. Really, so few people care about this deeply I don't think it will be solved. Sure, everyone hates it, but no one will switch carriers over it.

Re: How Verizon and Turn Defeat Browser Privacy Protections

#29
post #27

There are two solutions I see. 1) Regulation. Maybe it'll happen, I don't have much hope of it being done intelligently. 2) Feed them garbage data. We just need a database of live UIDH numbers and a browser extension to inject a random UIDH number from that list into the header.

This is fantastic and I'd install it in a heartbeat

Re: How Verizon and Turn Defeat Browser Privacy Protections

#30

Some additional research that came out today, with more details of the various things Verizon is doing / plans to do with UIDH: https://freedom-to-tinker.com/blog/englehardt/verizons-track... (We collaborated with Mayer on this research.) Code and data that you can play with to verify these results / do other similar experiments, using our web privacy measurement tool OpenWPM: https://github.com/englehardt/verizon-ui…

quantcast was sued for resuscitating browser cookies when flash LSOs persisted [1], ie taking the cookie value from the LSO and recookie-ing the browser. quantcast and clearspring settled for $2.5m [2]. The crux of the matter seemed to be that users didn't know such data was in flash cookies or associated with quantcast, making it hard to opt-out, though I'm not sure if this is illegal; and violated quantcast and the 3rd party sites' privacy agreements, which appears to be illegal. A lawsuit outline for one plaintiff is here [3] and the full text of the initial filing here [4]. I naively assume there is a clear parallel to this case, though perhaps verizon and turn have thoroughly privacy policied their way out, somewhere in 30 pages of legalese.

According to Jonathan Mayer,

   Commercial supercookies, fingerprinting, and zombie cookies are tolerated 
   (if not permitted) under current United States law. [...] Any associated 
   consumer deception, however, is a violation of the Federal Trade Commission 
   Act and parallel state statutes. [5]
   
[1] http://www.wired.com/2010/07/zombie-cookies-lawsuit/

[2] http://www.lexology.com/library/detail.aspx?g=bc3a4358-6692-...

[3] https://www.privaworks.com/Details/AlertReference/PrintPrevi...

[4] http://www.wired.com/images_blogs/threatlevel/2010/07/CV10-5...

[5] http://webpolicy.org/2015/01/14/turn-verizon-zombie-cookie/

Post reply on HN