Live data from Hacker News

How Verizon and Turn Defeat Browser Privacy Protections

eff.org

111–120 of 176 posts

Re: How Verizon and Turn Defeat Browser Privacy Protections

#111
post #85

Earlier quoted context omitted.

Step 1: Site operators install backend library to detect uid cookies and send them via API to a central database Step 2: Privacy-minded activists install a browser extension that reads the uids from central database and spoofs HTTP headers with them. Extension could even cycle through uids on a daily basis to cause more mayhem. Result: with just a few big sites running this, a few thousand people with the extension c…

Step 3: Turn ignores UIDH headers originating from non-Verizon IPs and Verizon replaces any user-generated UIDH header. Your solution is not going to fool anyone.

Reading through the original report, I'd doesn't seem that Turn's handling of the header is very sophisticated, in fact they just dumbly accept whatever header you give them.

(Interestingly unless they take extra precautions, this exposes them to a CSP sandboxing vulnerability)

Turn needs to handle these headers basically in realtime, and while I'm not saying it would be impossible to do IP filtering on a header, it would be expensive.

If outsmarting them became a cat and mouse game and people stay ahead of them at any point, that would be good enough to make third party companies that rely on Turn's zombie cookies to lose confidence. Unless turn publishes more info about how they circumvent the circumvention, and this would implicate them further politically and legally.

What they are doing is immoral and probably illegal.

Re: How Verizon and Turn Defeat Browser Privacy Protections

#112

Someone who understands this well needs to write a very short 'elevator' explanation for non-technical end-users that we all can copy and paste. That small act would be invaluable to spreading awareness, which is necessary for any progress. I was going to send the EFF article to some Verizon customers I know but I realized they would have no idea what it meant. I don't have time to read it thoroughly and write an acc…

How about: Because your mobile device really belongs to the carrier and not to you, whenever you browse the web with it, they know who you are no matter what. They are now refusing to keep that information secret even if you want them to, instead selling it to advertisers without your consent (even despite your obvious non-consent). They do this by sabotaging your mobile browser so it can't really delete certain cook…

Naive follow up question: Can doing something like routing through a VPN help with this? I assume not, since a forced cookie on your browser will make you always identifiable to the person on the other end, correct?

Re: How Verizon and Turn Defeat Browser Privacy Protections

#113
post #42

It's strange to read this and then simultaneously read people complaining about HTTP2 requiring SSL. It'd surely be nice if law protected us from bad actors but SSL protects from this in a way that (hopefully) can't be circumvented.

SSL can't really stop it, I think. Here's a thread where I've speculated on a way to inject metadata into SSL handshakes[0] just like they're doing with HTTP headers. If that doesn't work (I'd be interested to hear why), someone else suggested using TCP-IP source/destination metadata queried from the ISP to resolve to a customer. [0] https://news.ycombinator.com/item?id=8506492

[deleted]

Re: How Verizon and Turn Defeat Browser Privacy Protections

#114

Someone who understands this well needs to write a very short 'elevator' explanation for non-technical end-users that we all can copy and paste. That small act would be invaluable to spreading awareness, which is necessary for any progress. I was going to send the EFF article to some Verizon customers I know but I realized they would have no idea what it meant. I don't have time to read it thoroughly and write an acc…

How about: Because your mobile device really belongs to the carrier and not to you, whenever you browse the web with it, they know who you are no matter what. They are now refusing to keep that information secret even if you want them to, instead selling it to advertisers without your consent (even despite your obvious non-consent). They do this by sabotaging your mobile browser so it can't really delete certain cook…

That's a terrible synopsis. It doesn't have anything to do with the device at all, and that's the whole point!

No matter what you do to attempt to avoid this you can't if you use the Verizon communication layer. The only way around it is to use counter measures to avoid the Verizon software seeing your connection (ie, a VPN).

Re: How Verizon and Turn Defeat Browser Privacy Protections

#115
post #31

Earlier quoted context omitted.

>"It is Turn’s policy to always honor the consumer opt-out as enacted through either the Turn website or the NAI or DAA." What does this actually mean, and how can I do it?

The original research checked the Turn / NAI / DAA opt out. According to Mayer, it does't respawn. This part of Turn's response is a lie.

So what you're saying is that we need everyone on the planet to install an app that automatically accesses Turn's website every few seconds ... just to be sure that they know we don't want tracking!

;0)

Re: How Verizon and Turn Defeat Browser Privacy Protections

#116
post #62

Earlier quoted context omitted.

They claim the opt-out is stored on their servers and associated with the uid (implying that the optout=1 cookie isn't necessary)

It's convenient for them that their server-side opt-out code cannot be audited. It would have been easier for them to just set an anonymous, client-side opt-out cookie.

A client-side cookie is not sufficient, you'd have to set it in every browser you ever use. Practically speaking it needs to be server-side, but should be (but never would be) opt-in rather than opt-out.

The other option is respecting DNT, but that is never going to happen as a default behaviour for all companies.

Re: How Verizon and Turn Defeat Browser Privacy Protections

#117
If someone chooses to work for a sleazy company, say one that aggressively violates a person's expressed desire to not be tracked, I would not want to hire them or otherwise associate with them.

Should the engineers who enable companies like Turn be shunned by other engineers?

Re: How Verizon and Turn Defeat Browser Privacy Protections

#118

Earlier quoted context omitted.

How about: Because your mobile device really belongs to the carrier and not to you, whenever you browse the web with it, they know who you are no matter what. They are now refusing to keep that information secret even if you want them to, instead selling it to advertisers without your consent (even despite your obvious non-consent). They do this by sabotaging your mobile browser so it can't really delete certain cook…

Naive follow up question: Can doing something like routing through a VPN help with this? I assume not, since a forced cookie on your browser will make you always identifiable to the person on the other end, correct?

Using a VPN would encrypt your traffic, preventing Verizon from injecting a UIDH header. You could then clear your cookies and websites would not be able to re-add them via the UIDH header since it isn't being sent.

This isn't to say that the websites can't identify you via some other means, just that they no longer have the guaranteed UIDH header to identify you.

Re: How Verizon and Turn Defeat Browser Privacy Protections

#119
post #117

If someone chooses to work for a sleazy company, say one that aggressively violates a person's expressed desire to not be tracked, I would not want to hire them or otherwise associate with them. Should the engineers who enable companies like Turn be shunned by other engineers?

Should engineers who invent new rifle shells, or atomic bombs, or armed drones, or work at the NSA, or Tinder, or Uber, or Groupon, or Zynga be shunned? All of their employers are perceived by some as some as scumbags.

If your job that you liked came to you with a challenge like "I want you to invent a brand new way to track our users that nobody has thought of before", would you turn it down?

edit: or Facebook, or Google, etc? These companies are in the business of tracking their users' behavior to be sold to advertisers. I'm not really sure how that's different at the macro level than what Verizon/Turn is doing, and we're shunning an awful lot of engineers at this point.

Re: How Verizon and Turn Defeat Browser Privacy Protections

#120
post #117

If someone chooses to work for a sleazy company, say one that aggressively violates a person's expressed desire to not be tracked, I would not want to hire them or otherwise associate with them. Should the engineers who enable companies like Turn be shunned by other engineers?

Not everyone has the luxury to be able to refuse or quit a paying job. It'd be harsh to judge like this. It would of course do to shun the firms which do this - ultimately we want to eliminate the behaviour - not the people.
Post reply on HN