Earlier quoted context omitted.
The original research checked the Turn / NAI / DAA opt out. According to Mayer, it does't respawn. This part of Turn's response is a lie.
They claim the opt-out is stored on their servers and associated with the uid (implying that the optout=1 cookie isn't necessary)
How Verizon and Turn Defeat Browser Privacy Protections
91–100 of 176 posts
Re: How Verizon and Turn Defeat Browser Privacy Protections
#92Earlier quoted context omitted.
> What the fuck, Turn? You got a different explanation for what the fuck "Do Not Track" means? Easy there. IE10 defaults to Do Not Track enabled. So sending the header is not explicitly representative of the user's wishes. Convenient, isn't it?
> IE10 defaults to Do Not Track enabled. So sending the header is not explicitly representative of the user's wishes. > Convenient, isn't it? That might be an excuse, but it's not the reason. They easily could read the DNT header and the user agent, and trust DNT headers from non-IE10 browsers.
http://www.cnet.com/news/apache-web-software-overrides-ie10-...
https://github.com/apache/httpd/commit/a381ff35fa4d50a5f7b9f...
but, ironically, it was soon disabled by default:
https://github.com/apache/httpd/commit/3dd6fb6882ae2b453c90d...
Re: How Verizon and Turn Defeat Browser Privacy Protections
#93It's strange to read this and then simultaneously read people complaining about HTTP2 requiring SSL. It'd surely be nice if law protected us from bad actors but SSL protects from this in a way that (hopefully) can't be circumvented.
SSL can't really stop it, I think. Here's a thread where I've speculated on a way to inject metadata into SSL handshakes[0] just like they're doing with HTTP headers. If that doesn't work (I'd be interested to hear why), someone else suggested using TCP-IP source/destination metadata queried from the ISP to resolve to a customer. [0] https://news.ycombinator.com/item?id=8506492
I'm specifically on the lookout for sneaky ways to (GCHQ call it) "stain" traffic like that, and try to remove them. ("Kleptography" is similar, but the endpoint is complicit - there's not a lot can be done when the endpoint is complicit, but more deterministic primitives help both.)
These can be rather subtle - with temporal differentiation as well, even 1 bit allows for a basic binary search/partitioning attack, so anonymity networks like Tor, I2P etc have to be particularly careful about that.
(You shouldn't really be using TLS 1.0/1.1 anymore, and definitely not SSL.)
Re: How Verizon and Turn Defeat Browser Privacy Protections
#94Earlier quoted context omitted.
Tor is free and much easier than a VPN. Tor Browser bundle on Win/Mac/Linux: https://www.torproject.org/download/download-easy.html.en Orweb on Android: https://play.google.com/store/apps/details?id=info.guardianp... OnionBrowser on iOS: https://itunes.apple.com/us/app/onion-browser/id519296448?mt...
Tor is so slow as to be unusable for everyday browsing.
I2P is also a lot faster than when I last looked, even though i2pd isn't done.
Re: How Verizon and Turn Defeat Browser Privacy Protections
#95Earlier quoted context omitted.
> IE10 defaults to Do Not Track enabled. So sending the header is not explicitly representative of the user's wishes. "By signing up for [insert service here], you agree to the privacy policy." How many times did you actually agree with the privacy policy? Devil's advocate, I know, but it's a sobering reminder that pretty much anything you use gives information that is sold. Open a bank account? If so, notice any new…
To play another devil's advocate, shouldn't that also imply that IE10 users sending Do Not Track are in fact explicitly representing their desire not to be tracked? I mean by that same argument the user, by using Windows/IE10 did in fact choose the default settings of the browser, per the terms and conditions agreed to upon installing/purchasing Windows/IE. Live by the T&C, die by the T&C - unless you can hide your s…
Re: How Verizon and Turn Defeat Browser Privacy Protections
#96Earlier quoted context omitted.
Tor is so slow as to be unusable for everyday browsing.
I don't find Tor that slow. Unless you're talking watching videos or something.
Re: How Verizon and Turn Defeat Browser Privacy Protections
#97Firstly, there are already privacy laws yet it doesn't look as if they apply and that Verizon thinks that even in the case of a law suit Verizon will be able to benefit more than this law suit will cost.
Secondly, even if a court determines that the conduct of Verizon in this case is not legal, the verdict will still be special enough to not be applicable in a loop hole case. So I see protection provided by law as limited.
Thirdly, enforcement is rather difficult and not as obvious as, e.g., a daylight robbery, especially for non-technical observers which I presume to be the vast majority of law enforcement personnel.
And finally, (and rather an opinion) I think government is rather delighted to know who does what on the internet, so I don't see a real motive for them to move decisively apart from some half-* voter appeasement.
Re: How Verizon and Turn Defeat Browser Privacy Protections
#98“It is unnecessary to determine the extent to which the right of privacy is protected as a constitutional matter without the benefit of statute.” Beaney, The Constitutional Right to Privacy in the Supreme Court in 1962 The Supreme Court Review 212 (Kurland ed. 1962); Olmstead v. United States, 277 U.S. 438, 478, 48 S.Ct. 564, 72 L.Ed. 944 (1928) (dissenting opinion of Brandeis, J.); “Dykstra, The Right Most Valued by Civilized Man”, 6 Utah L.Rev. 305 (1959); Pound, The Fourteenth Amendment and the Right of Privacy, 13 W.Res.L.Rev. 34 (1961). '[I]t is sufficient to hold that the invasion of the plaintiffs' solitude or seclusion, as alleged in the pleadings, was a violation of their right of privacy and constituted a tort for which the plaintiffs may recover damages to the extent that they can prove them. ‘Certainly, no right deserves greater protection…’' Ezer, Intrusion on Solitude: Herein of Civil Rights and Civil Wrongs, 21 Law in Transition 63, 75 (1961).
To make an intrusion on seclusion claim, a plaintiff must generally establish 4 elements:
First, that the defendant, without authorization, must have intentionally invaded the private affairs of the plaintiff;
Second, the invasion must be offensive to a reasonable person;
Third, the matter that the defendant intruded upon must involve a private matter; and
Finally, the intrusion must have caused mental anguish or suffering to the plaintiff.
h/t Lisa Borel on G+
https://plus.google.com/113175636916099066477/posts/PBi3NECR...
More at Wikipedia:
http://en.wikipedia.org/wiki/Privacy_laws_of_the_United_Stat...
Intrusion of solitude occurs where one person intrudes upon the private affairs of another.
Intrusion upon seclusion occurs when a perpetrator intentionally intrudes, physically, electronically, or otherwise, upon the private space, solitude, or seclusion of a person, or the private affairs or concerns of a person, by use of the perpetrator's physical senses or by electronic device or devices to oversee or overhear the person's private affairs, or by some other form of investigation, examination, or observation intrude upon a person's private matters if the intrusion would be highly offensive to a reasonable person.
h/t paul beard on G+
https://plus.google.com/u/0/104092656004159577193/posts/5XKX...
Google, as guardian of Android, should look hard at ensuring user protections from this sort of behavior. Ubiquitous HTTPS might be an option (I haven't looked yet to see if the UIDH header can be defeated via that).
Re: How Verizon and Turn Defeat Browser Privacy Protections
#99If the users really care about this issue, that's what would happen on a functioning market anyway...
Re: How Verizon and Turn Defeat Browser Privacy Protections
#100If yes, then people could publish their UIDH and have other people use it as well. If many do this, the unique identification aspect of UIDH is lost.
Something like using a random UIDH from a list of published ones every request.