Live data from Hacker News

Verizon Wireless injecting tracking UIDs into HTTP requests

news.ycombinator.com

121–130 of 151 posts

Re: Verizon Wireless injecting tracking UIDs into HTTP requests

#121
post #74

Apparently Verizon has two patents on the process: http://www.faqs.org/patents/app/20130318346 http://www.google.com/patents/US20130318581

Excellent news, that means their competitors are safer to use?

It would make sense for Verizon to license the technology to other carriers.

1) The more widespread the technology is, the more advertisers will be aware of it and will seek it. This means more revenue for Verizon (bigger market for this product).

2) If all carriers do it, then people won't have an incentive to switch from Verizon.

3) Licensing fees.

Re: Verizon Wireless injecting tracking UIDs into HTTP requests

#122
post #67
post #17

They don't appear to be doing this if you've opted out of "Relevant Mobile Advertising", which is another option [separate from CPNI] on http://verizonwireless.com/myprivacy . Here's the setting you're looking for: http://i.imgur.com/QFJJNV5.png Mods may also want to update the title to include "Wireless" after Verizon; Verizon landline is not doing this anywhere AFAIK.

My "Relevant Mobile Advertising" was already long-ago opted-out ("No, I don't want to participate in Relevant Mobile Advertising"). Still, last night, my "Verizon 3G" (iPhone 4s) was definitely adding the header to all plain-HTTP traffic, including that from private/incognito-mode tabs, and from another machine sharing the "personal hotspot". I then changed the other two settings ("Customer Proprietary Network Inform…

And... the header is back again. Haven't made any further changes to privacy preferences (all opt-out).

Re: Verizon Wireless injecting tracking UIDs into HTTP requests

#123
post #69

Earlier quoted context omitted.

I'm opted out of everything on that page and I'm still seeing the header sent. Maybe the header isn't being sent for you due to this change possibly being a gradual rollout.

The header is sent if you opt out . It's explicitly stated in the privacy policy, which i've copied into a parent post on this HN thread.

I don't see how the privacy policy wording can be interpreted that way.

The wording you've clipped does not suggest that the "unique, anonymous identifier" will be sent to every website. (It does suggest there's a customer choice in some way, but that's unclear and so far no one has reported a reliable way to have Verizon suppress the X-UIDH header.)

The note that "many opt-outs are cookie-based" may not be relevant to this tampering. In particular, there's no clear way that cookies to Verizon websites could be consulted when doing the tampering on each HTTP request to other websites: they're not part of the connection. (I suspect this section is boilerplate related to some other opt-out.)

Re: Verizon Wireless injecting tracking UIDs into HTTP requests

#124
post #46
post #14

This makes me rather unhappy. I'm seeing this on Verizon. Can someone with an alternative mobile provider like Sprint or T-Mobile test this, too?

I just tested mine, but the situation is a bit complicated. My service is with T-mobile in the US, but I am currently connecting through Movistar Chile. The response from the website was: > did not receive X-UIDH header. So I presume I can say that Movistar Chile is not inserting that into the header. Not sure about T-Mobile (US) though.

If you are roaming and using the T-Mobile APN, then you're still going through the T-Mobile data infrastructure.

When you're in China and roaming on a foreign operator, you're not affected by the Great Firewall since you're data goes through the APN in your home country.

Re: Verizon Wireless injecting tracking UIDs into HTTP requests

#125
post #86
post #63

Earlier quoted context omitted.

I'm not clear why you think it would be illegal. There may be rules against not allowing people to opt out, I don't know. But when you ask "How can they discriminate like that?", there's nothing illegal about discriminating on the basis of credit or willingness to pay for a more expensive product.

I can understand discriminating on quality or something like that, but we're talking about not being able to opt out of having your personal information sold. It seems like there should be some kind of a law where that has to be made absolutely clear. It doesn't even seem to be buried anywhere in the Terms of Service, which say: "Verizon Wireline consumers and certain business customers may opt-out by calling 1-866-4…

You want to know how to opt out? You cancel your contract. Verizon is under no obligation to provide you with phone and internet access, ad-free or otherwise. They offer a product on the free market, and if you don't like that product, you should not buy it. While I think their policies and attitude toward privacy is despicable, accusing them of doing anything illegal is simply incorrect.

Re: Verizon Wireless injecting tracking UIDs into HTTP requests

#126
post #108
post #63

Earlier quoted context omitted.

I'm not clear why you think it would be illegal. There may be rules against not allowing people to opt out, I don't know. But when you ask "How can they discriminate like that?", there's nothing illegal about discriminating on the basis of credit or willingness to pay for a more expensive product.

>I'm not clear why you think it would be illegal. Consent matters. In Europe it would most certainly be illegal.

What's Europe got to do with this?

Re: Verizon Wireless injecting tracking UIDs into HTTP requests

#127
post #108

Earlier quoted context omitted.

>I'm not clear why you think it would be illegal. Consent matters. In Europe it would most certainly be illegal.

What's Europe got to do with this?

Because somebody seemed surprised that people expected this to be illegal. The fact that it is illegal in a large number of countries is a useful datapoint, and shows that the initial reaction of "shouldn't this be illegal" isn't completely off the wall.

Re: Verizon Wireless injecting tracking UIDs into HTTP requests

#128
post #86

Earlier quoted context omitted.

I can understand discriminating on quality or something like that, but we're talking about not being able to opt out of having your personal information sold. It seems like there should be some kind of a law where that has to be made absolutely clear. It doesn't even seem to be buried anywhere in the Terms of Service, which say: "Verizon Wireline consumers and certain business customers may opt-out by calling 1-866-4…

You want to know how to opt out? You cancel your contract. Verizon is under no obligation to provide you with phone and internet access, ad-free or otherwise. They offer a product on the free market, and if you don't like that product, you should not buy it. While I think their policies and attitude toward privacy is despicable, accusing them of doing anything illegal is simply incorrect.

While what you said may seem logically correct, there are a myriad of privacy protections that corporations are expected to adhere to regarding the information customers entrust to them. One reason for these protections is that the "resolution" you've suggested --- that the customer can simply choose not to use their services --- provides no protections against future-use of information. Say a customer chooses a vendor that sells his information after he ends his service with them. Under your strategy - the customer would have absolutely no recourse since he has no leverage against that vendor. He's already "walked" so to speak - yet they still may have information of value about that customer.

Take another example. A medical facility cannot take customer information about a person with a specific ailment and sell that information to advertisers for the purpose of earning a commission on the sale of those targeted ads. There are laws forbidding how that information is shared.

The following link outlines some of the state and federal laws specific to California, but each state has their own, and the federal laws obviously apply to the entire United States.

http://oag.ca.gov/privacy/privacy-laws

Re: Verizon Wireless injecting tracking UIDs into HTTP requests

#130
post #51

Earlier quoted context omitted.

"Doesn't that mean that Verizon isn't actually offering TCP/IP (Internet) access, since they corrupt my protocol stream in transit?" This is a serious answer: Go back and look at what they actually promise to deliver. Bet it doesn't have the word "TCP" in it anywhere. You can't hit them with contract violation when they aren't in violation of their contract. (Well, you can lodge any lawsuit you like. But it won't go…

If they used the proper noun "Internet" then TCP/IP is implied.

No, it really isn't. Even in our world thinking Internet == TCP/IP is a faux pas, roughly equivalent to thinking Internet == WWW. Legally speaking I suspect the term borders on meaningless. Obviously a company offering "internet access" must do something to discharge their contract but I seriously doubt you could ever nail them on this.

And if you could and did today, in a month the contracts would be rewritten anyhow, making this a completely moot point.

Post reply on HN