Live data from Hacker News

Verizon revives "zombie cookie" device tracking on AOL's ad network

propublica.org

21–30 of 98 posts

Re: Verizon revives "zombie cookie" device tracking on AOL's ad network

#21
post #6

They should be sued for that. There is no way most customers are informed and intentionally consenting to them tampering with the HTTP requests they send to include their customer ID. The obvious expectation of a customer of an ISP is that it sends the data through unchanged.

[deleted]

Re: Verizon revives "zombie cookie" device tracking on AOL's ad network

#22
post #15

Earlier quoted context omitted.

Zombie cookies in particular are insidious -- while you are actively trying to conceal your identity by proactively deleting cookies or using incognito mode, your ISP re-adds them without your consent. This kind of aggressive and underhanded behavior should be shamed as it violates the trust that users have in their ISPs.

A lot of this came about because of the "war" on the 3rd party cookie which was unfairly demonized. I get why zombie cookies are bad as it takes control away, but what is the issue surrounding plain tracking of behaviours? So what if a company knows the history of sites you've visited - what does this do against you?

Since this is tied to an account, it means data that never dies. While currently unlikely, imagine being vetted for a job by the websites you visit. Do you want an employer to be able to purchase your online history? There's more to hide the the usual things like pornography or political sites. Imagine you've visited several competitor employers, including past job listings. One could easily deduce you likely applied and failed if the job listings no longer exist and you're applying for this new job. Perhaps this makes for a lower offer on the new employers behalf.

I could invent many hypotheticals in this vain but privacy is something worth protecting.

Re: Verizon revives "zombie cookie" device tracking on AOL's ad network

#23
post #15

Earlier quoted context omitted.

Zombie cookies in particular are insidious -- while you are actively trying to conceal your identity by proactively deleting cookies or using incognito mode, your ISP re-adds them without your consent. This kind of aggressive and underhanded behavior should be shamed as it violates the trust that users have in their ISPs.

A lot of this came about because of the "war" on the 3rd party cookie which was unfairly demonized. I get why zombie cookies are bad as it takes control away, but what is the issue surrounding plain tracking of behaviours? So what if a company knows the history of sites you've visited - what does this do against you?

Please, publish your browser history on Pastebin and let's see what we can figure out about you.

Re: Verizon revives "zombie cookie" device tracking on AOL's ad network

#24
post #15

Earlier quoted context omitted.

Zombie cookies in particular are insidious -- while you are actively trying to conceal your identity by proactively deleting cookies or using incognito mode, your ISP re-adds them without your consent. This kind of aggressive and underhanded behavior should be shamed as it violates the trust that users have in their ISPs.

A lot of this came about because of the "war" on the 3rd party cookie which was unfairly demonized. I get why zombie cookies are bad as it takes control away, but what is the issue surrounding plain tracking of behaviours? So what if a company knows the history of sites you've visited - what does this do against you?

You're making the https://en.wikipedia.org/wiki/Nothing_to_hide_argument except for corporate surveillance instead of state surveillance.

Re: Verizon revives "zombie cookie" device tracking on AOL's ad network

#25
post #3

Apple's already shown they don't like this behaviour with their randomised MAC addresses in iOS 8+. Obviously what this article references is done at the carrier level, not on open wifi networks. I expect them to do something about this carrier-level behaviour next iOS. From a technical perspective, what could they do to prevent this?

They could encourage developers to support and prefer HTTPS – which is exactly what they are doing: https://developer.apple.com/library/prerelease/ios/technotes...

Re: Verizon revives "zombie cookie" device tracking on AOL's ad network

#27
AOL’s ad network will be able to match millions of Internet users to their real-world details gathered by Verizon, including — “your gender, age range and interests.” ... AOL will also be able to use data from Verizon’s identifier to track the apps that mobile users open, what sites they visit, and for how long. Verizon purchased AOL earlier this year...

"I think in some ways it’s more privacy protective because it’s all within one company,” said Verizon’s (chief privacy officer) Zacharia"

Good to know she's looking out for our interests.

Re: Verizon revives "zombie cookie" device tracking on AOL's ad network

#28

What exactly is the big aversion to tracking? The vast majority has shown (via actions, not internet noise) that they don't care so what exactly is the big downside? Not arguing for/against, just want to know reasons beyond "i just dont like it".

Well, imagine a world where every site you visit, every purchase you make, etc. is tracked and a score is assigned to you. Imagine that the activity your friends undertake also affects this score.

Now, imagine that it's happening in China.

You don't have to. They're actively building it.

Advertisers in the US would kill to get that kind of an individualized profile. So would insurance companies, credit card issuers, etc.

How long before you employer demands access? Because guaranteed that someone in Congress would agree that it's a good idea.

How long before Homeland Security becomes interested?

Re: Verizon revives "zombie cookie" device tracking on AOL's ad network

#29

Earlier quoted context omitted.

It's things like this that drive people to want HTTPS everywhere, but even that is subject to subterfuge when the provider inserts their own "trusted" certificates to proxy that traffic. There really should be provisions in the telecom bill that data traffic is to remain absolutely untouched. Just imagine phone calls where mentioning the word "pizza" would trigger an advertisement being injected into it.

HTTPS is just transit data, they don't need to see that. They can still tell the sites you've visited and really they just want to ID you and optionally make that ID available to others who pay/participate in data syncing.

It's not about Verizon. Of course they know where their users connect to. But by injecting a special HTTP header field, they make it possible for third parties to track the user – for example an ad network that serves ads on sites the user visits. Regular cookies are limited to certain domains, but this header is added to every request, making it cross-domain. HTTPS would prevent Verizon from injecting it.

Re: Verizon revives "zombie cookie" device tracking on AOL's ad network

#30

What exactly is the big aversion to tracking? The vast majority has shown (via actions, not internet noise) that they don't care so what exactly is the big downside? Not arguing for/against, just want to know reasons beyond "i just dont like it".

The "vast majority" aren't even CLOSE to being INFORMED, so saying they don't care is complete bull-shit.

The "internet noise" is everyone who actually understands what's going on, and is rightfully upset.

Post reply on HN