Live data from Hacker News

How Verizon and Turn Defeat Browser Privacy Protections

eff.org

161–170 of 176 posts

Re: How Verizon and Turn Defeat Browser Privacy Protections

#161

Earlier quoted context omitted.

VPN is insanely easy today. IMO Everyone should use it by default. Too bad it causes an additional load on the internet for the encrypted tunnel traffic. Another option is a blanket law about internet traffic that states no tracking can be made at all unless given express permission.

The recent European cookie law was close to that and got laughed at by tech people. Poor Europeans are constantly being asked for permission "Can we store a cookie on your computer?" whenever they visit a major website. Also, how do you stop people tracking you by IP? Every web server's log does this by default. How do you allow sessions even? It's not easy to define tracking so it's different from essential operatio…

> Poor Europeans are constantly being asked for permission "Can we store a cookie on your computer?" whenever they visit a major website.

As a non-European who visits the BBC, my impression is that it's even less useful than that (you can get that kind of annoying prompt just by setting cookie permissions on your browser to 'always ask'!). Instead of a prompt, you get an intrusive notice that they are setting cookies, and that your remedy if you don't want them to do it is to go away.

Re: How Verizon and Turn Defeat Browser Privacy Protections

#162
post #27

There are two solutions I see. 1) Regulation. Maybe it'll happen, I don't have much hope of it being done intelligently. 2) Feed them garbage data. We just need a database of live UIDH numbers and a browser extension to inject a random UIDH number from that list into the header.

> 1) Regulation. Maybe it'll happen, I don't have much hope of it being done intelligently Why so hopeless? My water is clean, airplanes and roads are safe, retail banks don't lose their customer's savings, etc. Not all regulation works, but this one is pretty straightforward.

> Why so hopeless?

Because the current US political climate is not in favour of regulations. It is true that we have all the regulations you describe, but each was fought tooth and nail when introduced!

EDIT: Original post had slightly more pointed political language.

Re: How Verizon and Turn Defeat Browser Privacy Protections

#163
post #45
post #15

My guess is that the "entrepreneurial" solution here would be a combination of: - A browser that doesn't support cookies and provides the server with a client controlled session-id (perhaps a user-id also). - Only uses SSL sessions to avoid middle-box injection of HTML headers (this still leaves the provider with the ability to inject data as IP options / TCP headers). - A micropayment solution that allows content pr…

> A browser that doesn't support cookies We are working on a browser ( https://gngr.info ) that supports cookies but doesn't enable them by default for all websites. We also don't enable JavaScript by default. User needs to enable these on a per-site basis. Enabling for all sites at once is also possible if the user so wishes. In the near future, we also want to support https only sessions (opt-in to begin with and o…

Why was this downvoted? It seems like a productive contribution to the conversation—in fact, it's a direct response to another user's question. I can imagine plenty of technical objections, but it seems that they should be made via responses, not downvotes.

Re: How Verizon and Turn Defeat Browser Privacy Protections

#164
post #117

If someone chooses to work for a sleazy company, say one that aggressively violates a person's expressed desire to not be tracked, I would not want to hire them or otherwise associate with them. Should the engineers who enable companies like Turn be shunned by other engineers?

In addition to the other replies you've got, this kind of judgement is, I think, beyond most people's capability to make. Should everyone who works at Turn be shunned, or just those who work on this project specifically? If a previously honourable company starts doing dishonourable work, how long a window does an engineer working there have to find another job before he or she is shunned? What does it mean to 'enable' Turn? That is, could a third-party indirectly enable them? How do we make the judgement when this has happened? For example, should W3C be shunned for making a standard that can be abused in this way?

Re: How Verizon and Turn Defeat Browser Privacy Protections

#165
post #129
post #124

Earlier quoted context omitted.

> I think it's important that you always be free to come to your own conclusions on such matters as well. I completely agree, but it's equally important not to be too dogmatic about it. For example, to what government do you pay taxes?

Not trying to be sarcastic, but is "too dogmatic" a different way of saying "too principled?" I pay taxes to several entities, including the government of the United States of America and the state of Washington. These taxes are non-voluntary and coerced from me under threat of force.

> These taxes are non-voluntary and coerced from me under threat of force.

One could say equally well that, for many of the engineers working on them, these reprehensible projects are non-voluntary and coerced under threat of economic ruin.

(To "you can always quit"—well, you can always renounce your US citizenship, too. To "then I'll just wind up paying taxes to some other repressive government"—someone contemplating quitting his or her job could also despair that he or she will just have to take another morally questionable job.)

EDIT: Oops, dcole2929 (https://news.ycombinator.com/item?id=8895200) made many of these points before I did.

Re: How Verizon and Turn Defeat Browser Privacy Protections

#166
post #164
post #117

If someone chooses to work for a sleazy company, say one that aggressively violates a person's expressed desire to not be tracked, I would not want to hire them or otherwise associate with them. Should the engineers who enable companies like Turn be shunned by other engineers?

In addition to the other replies you've got, this kind of judgement is, I think, beyond most people's capability to make. Should everyone who works at Turn be shunned, or just those who work on this project specifically? If a previously honourable company starts doing dishonourable work, how long a window does an engineer working there have to find another job before he or she is shunned? What does it mean to 'enable…

I appreciate your comment.

For me, it's a matter of the degree to which the person sees the ramifications of what they are doing, and the degree to which they directly contribute to the bad actions.

For example, the management team that has built a business around tracking people who clearly do not wish to be tracked is highly suspect, in my view.

The sysadmin that runs the servers, less so. But if she/he knows what the company is all about, I'd urge him/her to either try to change the mindset within the company (likely, impossible) or start looking for another gig.

I would not ask anyone to sacrifice themselves, but neither should they be facilitating unhelpful behaviors.

Verizon, of course, is enabling Turn (as I understand the situation.) Companies that are customers of Turn are also enabling them, in my view.

How do you see it?

Re: How Verizon and Turn Defeat Browser Privacy Protections

#167

Earlier quoted context omitted.

something like this? https://github.com/lightswitch05/Bogus_X-UIDH

Exactly. But instead of using it to try to change your UIDH within Verizon, it should encourage non-Verizon customers to just pollute the space with random UIDH values from all over the place.

And (as I previously noted) all Verizon has to do is *check the IP address of the client(!). They know the IPs they own.

Assuming that your adversary is dumb as well as malicious is a mistake.

Re: How Verizon and Turn Defeat Browser Privacy Protections

#168
post #149

Does anyone know how flash cookies are handled on cell phones? Is there any way to block or clear them? https://en.wikipedia.org/wiki/Local_shared_object This add on is good for clearing them using firefox: https://addons.mozilla.org/en-US/firefox/addon/betterprivacy...

Considering phones haven't had Flash (easily installable, that is) for a considerable amount of time, I doubt you're affected.

Re: How Verizon and Turn Defeat Browser Privacy Protections

#169

Earlier quoted context omitted.

Another question? Would FF+Adblock Plus+Ghostery stop this UIDH header injection without a VPN?

No the header injection happens after the request leaves your browser. However, adblock can prevent the request going to Turn and other ad sites in the first place. But then the website owner (eg Facebook) can work with the ad network to pass your info to them on the server side, although I'm not sure how widespread this is.

How about if I wanted to actively subvert the header? Would there be a way to beat Verizon's network to the punch by injecting the same header myself and populating it with garbage data?

Re: How Verizon and Turn Defeat Browser Privacy Protections

#170
post #46

Earlier quoted context omitted.

OP here, I'd be OK with swapping in Mayer's blog post. Will let the mods decide. If you haven't seen it before, this guy's stuff is absurdly good. Encyclopedic knowledge of privacy tech and law.

Yeah, that was main reason why I wanted to share his original post – the EFF (or ProPublica) stories aren't bad but he's done a great job writing about many things of interest to the HN community.

Didn't see this yesterday, and I'm sorry we didn't, because we would have switched out the URL. HN prefers original sources, and it's always nicer to give credit (and traffic) to the original creator or researcher.

Unfortunately, it's too late to make a difference now, so we'll just leave things as they were. However: if you (or anyone) notice something like this in the future, the best way to alert us is to email hn@ycombinator.com. We can't read all the threads but we do see all those emails, and usually pretty quickly.

Post reply on HN