Live data from Hacker News

How Verizon and Turn Defeat Browser Privacy Protections

eff.org

61–70 of 176 posts

Re: How Verizon and Turn Defeat Browser Privacy Protections

#61
post #40

Earlier quoted context omitted.

You can't feed them garbage. Verizon operates at the network layer - if you are on their network presumably they will copy the real value over your garbage value. If you aren't on their network then they can check IP address and ignore values not from the Verizon subnets. There are a couple of other solutions you haven't mentions: VPNs: Annoying and currently too hard for most people. Perhaps it is time for device (P…

VPN is insanely easy today. IMO Everyone should use it by default. Too bad it causes an additional load on the internet for the encrypted tunnel traffic. Another option is a blanket law about internet traffic that states no tracking can be made at all unless given express permission.

VPN is insanely easy today

How do I install a VPN on my SmartTV exactly? How do I make it actually work, even using VPN-on-a-router, given the importance CDNs have and how they use the location of your DNS resolver to attempt to give you nearest copies?

How do I explain to the hypothetical 68 yo grandmother why she has to disable the VPN to use (Australian geoblocked catch-up TV Service) iView and then reenable it to browse, but she won't be able to buy Kindle books when it is enabled unless she had it enabled when she first setup an Amazon account and her credit card also has a US address, and...

How is a user supposed to move the keys from their mobile device to their PC when most users can't even get photos off their phones.

Re: How Verizon and Turn Defeat Browser Privacy Protections

#62
post #31

Earlier quoted context omitted.

>"It is Turn’s policy to always honor the consumer opt-out as enacted through either the Turn website or the NAI or DAA." What does this actually mean, and how can I do it?

The original research checked the Turn / NAI / DAA opt out. According to Mayer, it does't respawn. This part of Turn's response is a lie.

They claim the opt-out is stored on their servers and associated with the uid (implying that the optout=1 cookie isn't necessary)

Re: How Verizon and Turn Defeat Browser Privacy Protections

#63

Earlier quoted context omitted.

Tor is free and much easier than a VPN. Tor Browser bundle on Win/Mac/Linux: https://www.torproject.org/download/download-easy.html.en Orweb on Android: https://play.google.com/store/apps/details?id=info.guardianp... OnionBrowser on iOS: https://itunes.apple.com/us/app/onion-browser/id519296448?mt...

Tor is so slow as to be unusable for everyday browsing.

Tor Browser is perfectly suitable for everyday browsing. When's the last time you used it for any significant period of time? It's plenty speedy and very stable.

Please, instead of bemoaning your complete lack of privacy online, do something about it for a change. Download Tor Browser right now.

Tor Browser bundle on Win/Mac/Linux: https://www.torproject.org/download/download-easy.html.en

Orweb on Android: https://play.google.com/store/apps/details?id=info.guardianp....

OnionBrowser on iOS: https://itunes.apple.com/us/app/onion-browser/id519296448?mt....

Re: How Verizon and Turn Defeat Browser Privacy Protections

#64
post #12

Earlier quoted context omitted.

> What the fuck, Turn? You got a different explanation for what the fuck "Do Not Track" means? Easy there. IE10 defaults to Do Not Track enabled. So sending the header is not explicitly representative of the user's wishes. Convenient, isn't it?

> IE10 defaults to Do Not Track enabled. So sending the header is not explicitly representative of the user's wishes. > Convenient, isn't it? That might be an excuse, but it's not the reason. They easily could read the DNT header and the user agent, and trust DNT headers from non-IE10 browsers.

Absolutely. They're interpreting the situation with strict literality because it is in their benefit to do so.

They have a perfectly valid reason for what they do: it's strongly beneficial to their business model to operate in a scummy but probably-legal way. They are hardly unique in this.

Since we have little market recourse (Verizon is often the only option, and we are not customers of Turn), and we have no legal recourse (again, scummy but almost certainly legal in almost all circumstances)...what is left?

Well, there are technical solutions to the problem. TLS is a good start. Browsers can be smarter about third party cookies. The Verizon Overcookie can be stripped by a proxy. VPN can solve many problems... This glommed on tracking junk is fragile.

I strongly resent being drawn into the arms race, but it is winnable.

It will take something dramatic (and who knows how long) for our outrage to be shared by a critical mass of customers/voters, so for now, I think technology is the solution.

But I donate to EFF too.

Re: How Verizon and Turn Defeat Browser Privacy Protections

#65
post #40
post #27

There are two solutions I see. 1) Regulation. Maybe it'll happen, I don't have much hope of it being done intelligently. 2) Feed them garbage data. We just need a database of live UIDH numbers and a browser extension to inject a random UIDH number from that list into the header.

You can't feed them garbage. Verizon operates at the network layer - if you are on their network presumably they will copy the real value over your garbage value. If you aren't on their network then they can check IP address and ignore values not from the Verizon subnets. There are a couple of other solutions you haven't mentions: VPNs: Annoying and currently too hard for most people. Perhaps it is time for device (P…

True, but an enterprising individual could write an extension to cause non-Verizon users to start feeding fake unique identifiers into their own streams. Heck, you may even be able to hijack a website login using it.

Re: How Verizon and Turn Defeat Browser Privacy Protections

#67

Someone who understands this well needs to write a very short 'elevator' explanation for non-technical end-users that we all can copy and paste. That small act would be invaluable to spreading awareness, which is necessary for any progress. I was going to send the EFF article to some Verizon customers I know but I realized they would have no idea what it meant. I don't have time to read it thoroughly and write an acc…

When you click a button on your mobile web browser, if you're a Verizon customer, advertisers see a special tag assigned to you by Verizon. Since Verizon assigned you the tag, they can give you the same tag on every website. Advertisers have ads on many websites, so they can see the tag and match your browsing history to their logs. In effect, because of the tracking tag Verizon assigns to you, any advertisement you see can track who you are and where you've been.

Re: How Verizon and Turn Defeat Browser Privacy Protections

#68
post #49
post #32

Earlier quoted context omitted.

NAI and DAA are industry trade groups; they have cross company opt-out pages via cookies / beaconing http://www.networkadvertising.org/choices/ http://www.aboutads.info/choices/

Their opt out program relies on using 3rd party cookies and only blocks the display of ads (not the collection or other use of the data). Anyone who is doing this should just install an ad blocker.

Oh absolutely; I was just answering the parent's question, not endorsing.

Re: How Verizon and Turn Defeat Browser Privacy Protections

#69

If you were an author (of any sort) could you claim that the transmissions of your material (text) that are under copyright were circumvented (DMCA) via a permacookie under your "moral rights" as an author to publish anonymously?

This gave me an interesting related idea...

It may or may not work depending on the legal status of, among other things, the HTTP standards, but could you claim copyright on transmitted HTTP requests, at least if they contained sufficiently interesting contents?

If you could, then presumably one would have to say that ISPs have implied license to transmit those (implicitly) copyrighted requests to a third party, namely, the server. However, that implied license would presumably not allow the ISP to transmit a derived work to the third party, i.e., the original request augmented with the tracking header.

To argue this one would have to argue that the entire request, headers and all was copyrightable, but I suppose if one did something creative with the headers it could work; e.g., using the HTTP headers as a kind of poem. But of course there's ways to have creative content in something without it being art, just as long as the other side couldn't argue that the headers couldn't be copyrighted because the usual ones are largely predetermined by the standards.

Basically this is just the same idea you had, except instead of invoking the moral right to anonymity, it's invoking the easier-to-digest moral right to the content itself.

I'd say this was all baloney, but the DMCA is so ridiculously broad that it just might work. Of course, this is all pretending that the DMCA is meant to apply to corporations and not just us small folk.

Post reply on HN