Earlier quoted context omitted.
Step 1: Site operators install backend library to detect uid cookies and send them via API to a central database Step 2: Privacy-minded activists install a browser extension that reads the uids from central database and spoofs HTTP headers with them. Extension could even cycle through uids on a daily basis to cause more mayhem. Result: with just a few big sites running this, a few thousand people with the extension c…
Step 3: Turn ignores UIDH headers originating from non-Verizon IPs and Verizon replaces any user-generated UIDH header. Your solution is not going to fool anyone.
(Interestingly unless they take extra precautions, this exposes them to a CSP sandboxing vulnerability)
Turn needs to handle these headers basically in realtime, and while I'm not saying it would be impossible to do IP filtering on a header, it would be expensive.
If outsmarting them became a cat and mouse game and people stay ahead of them at any point, that would be good enough to make third party companies that rely on Turn's zombie cookies to lose confidence. Unless turn publishes more info about how they circumvent the circumvention, and this would implicate them further politically and legally.
What they are doing is immoral and probably illegal.