Live data from Hacker News

How Verizon and Turn Defeat Browser Privacy Protections

eff.org

81–90 of 176 posts

Re: How Verizon and Turn Defeat Browser Privacy Protections

#81

Earlier quoted context omitted.

That would be OK if my cellphone usage was "free". But it's not. I'm paying Verizon hundreds of dollars a month for me and my family. I wonder if an MVNO would be less creepy than Verizon? Probably not, I'd bet they're even sleazier.

Well, it seems that Verizon is the only one doing it. The article mentioned that AT&T ran a pilot program and decided not to do it. So presumably any other US provider would be better than Verizon.

yeah, but people will justify it with a hard-on for verizon's network. where somehow in a large city, not a single other provider gets acceptable signal...

Re: How Verizon and Turn Defeat Browser Privacy Protections

#82
post #62

Earlier quoted context omitted.

The original research checked the Turn / NAI / DAA opt out. According to Mayer, it does't respawn. This part of Turn's response is a lie.

They claim the opt-out is stored on their servers and associated with the uid (implying that the optout=1 cookie isn't necessary)

Not just missing a cookie. The original post has screenshots of status checkers showing no opt out.

Re: How Verizon and Turn Defeat Browser Privacy Protections

#85
post #27

There are two solutions I see. 1) Regulation. Maybe it'll happen, I don't have much hope of it being done intelligently. 2) Feed them garbage data. We just need a database of live UIDH numbers and a browser extension to inject a random UIDH number from that list into the header.

Step 1: Site operators install backend library to detect uid cookies and send them via API to a central database Step 2: Privacy-minded activists install a browser extension that reads the uids from central database and spoofs HTTP headers with them. Extension could even cycle through uids on a daily basis to cause more mayhem. Result: with just a few big sites running this, a few thousand people with the extension c…

Step 3: Turn ignores UIDH headers originating from non-Verizon IPs and Verizon replaces any user-generated UIDH header.

Your solution is not going to fool anyone.

Re: How Verizon and Turn Defeat Browser Privacy Protections

#86
post #27

There are two solutions I see. 1) Regulation. Maybe it'll happen, I don't have much hope of it being done intelligently. 2) Feed them garbage data. We just need a database of live UIDH numbers and a browser extension to inject a random UIDH number from that list into the header.

Hmm... garbage doesn't work beause they override the UIDH as a MitM. So maybe this fact could be exploited in the opposite direction:

Start using the X-UIDH: header for some prominent but non-mission-critical feature in a format that is obviously not related to this tracking number. When Verizon rewrites the header, that feature breaks, and you can make a fuss about it in the media or sue Verizon for breaking your webpage.

(it sounds good on paper; this may not work in practice)

Re: How Verizon and Turn Defeat Browser Privacy Protections

#87
post #80

I feel like injecting headers is only the start of something far more pernicious; even SSL/TLS can't stop an ISP from determining and tagging where your traffic goes (and consequently, passing that information onto third parties) - all your traffic goes through equipment on their network, after all. As long as your connection to the Internet is tied to your identity in some way (and there is basically no way a non-fr…

How would ISPs tag requests going over HTTPS as being from a particular subscriber?

OK, I can think of a few ways they might do this (DNS tricks and per-user IPv6 addresses, => user mapping). These all seem significantly more complex than HTTP header injection though.

Re: How Verizon and Turn Defeat Browser Privacy Protections

#88
post #61

Earlier quoted context omitted.

VPN is insanely easy today. IMO Everyone should use it by default. Too bad it causes an additional load on the internet for the encrypted tunnel traffic. Another option is a blanket law about internet traffic that states no tracking can be made at all unless given express permission.

VPN is insanely easy today How do I install a VPN on my SmartTV exactly? How do I make it actually work , even using VPN-on-a-router, given the importance CDNs have and how they use the location of your DNS resolver to attempt to give you nearest copies? How do I explain to the hypothetical 68 yo grandmother why she has to disable the VPN to use (Australian geoblocked catch-up TV Service) iView and then reenable it t…

Why are you even letting your SmartTV connect to the internet at all? Those things are horribly insecure and just spy on you anyway.

Re: How Verizon and Turn Defeat Browser Privacy Protections

#89

It's frustrating, the internet has become such a creepy "you are the product" medium. The more of this I see, I start to feel like I don't want to be a part of it anymore.

That was the first thing that came to mind when I read the name "Turn" - as in, "We Turn users into products."

What about a browser extension and a website that tracked Turn's advertising clients? The website and extension are there to help users boycott Turn's customers.

Can anyone think of a way to automate the collection of those ads and linked clients? Crowd-sourcing maybe?

Post reply on HN