Hmm, confirmed on Verizon 4G LTE network. Can anybody recommend a good VPN service that works on android?
If you use Chrome and enable Google's Data Compression Proxy, all http traffic is proxied via Google's servers and sent to them via spdy (which is encrypted), so Verizon can't tamper with the requests or see what they are: https://developer.chrome.com/multidevice/data-compression
Verizon Wireless injecting tracking UIDs into HTTP requests
21–30 of 151 posts
Re: Verizon Wireless injecting tracking UIDs into HTTP requests
#22Earlier quoted context omitted.
If you use Chrome and enable Google's Data Compression Proxy, all http traffic is proxied via Google's servers and sent to them via spdy (which is encrypted), so Verizon can't tamper with the requests or see what they are: https://developer.chrome.com/multidevice/data-compression
So you trade Verizon's tracking for Google's?
Re: Verizon Wireless injecting tracking UIDs into HTTP requests
#23They don't appear to be doing this if you've opted out of "Relevant Mobile Advertising", which is another option [separate from CPNI] on http://verizonwireless.com/myprivacy . Here's the setting you're looking for: http://i.imgur.com/QFJJNV5.png Mods may also want to update the title to include "Wireless" after Verizon; Verizon landline is not doing this anywhere AFAIK.
Re: Verizon Wireless injecting tracking UIDs into HTTP requests
#24Let's say I want to send some TCP. That TCP happens to kind of look like HTTP, but it's not. It's just some protocol I made up which looks HTTPish enough to trigger this injection. Doesn't that mean that Verizon isn't actually offering TCP/IP (Internet) access, since they corrupt my protocol stream in transit? Shoudln't that mean they should be charged with fraud if they continue to advertise the fact that they provi…
Your question may have been serious, but it's also ridiculous, unless you have a much more technically detailed contract with Verizon than I've ever seen.
Re: Verizon Wireless injecting tracking UIDs into HTTP requests
#25This has been going on for ages, not sure why people just now noticed it. They were testing it last year, you could clearly see these headers on a large percentage of traffic coming from their gateways. I'm not expressing an opinion one way or another but they clearly felt the UID is not directly identifiable and thus does not become a privacy issue until they share the mapping of the UID to customer data. My guess i…
The disturbing part is a unique ID that follows you despite private browsing and across browsers. The worst part is that it goes to every site you visit (not just VZW or selected advertisers). It can be trivially linked to your existing cookies/identity to follow you even after clearing cookies, changing browsers, switching devices, etc.
Re: Verizon Wireless injecting tracking UIDs into HTTP requests
#26They don't appear to be doing this if you've opted out of "Relevant Mobile Advertising", which is another option [separate from CPNI] on http://verizonwireless.com/myprivacy . Here's the setting you're looking for: http://i.imgur.com/QFJJNV5.png Mods may also want to update the title to include "Wireless" after Verizon; Verizon landline is not doing this anywhere AFAIK.
Re: Verizon Wireless injecting tracking UIDs into HTTP requests
#27They don't appear to be doing this if you've opted out of "Relevant Mobile Advertising", which is another option [separate from CPNI] on http://verizonwireless.com/myprivacy . Here's the setting you're looking for: http://i.imgur.com/QFJJNV5.png Mods may also want to update the title to include "Wireless" after Verizon; Verizon landline is not doing this anywhere AFAIK.
They're ignoring it for me. See: https://twitter.com/kennwhite/status/525374343074029568 Can you confirm you connected over cellular when testing?
Re: Verizon Wireless injecting tracking UIDs into HTTP requests
#28I'm on Verizon and got "did not receive X-UIDH header" message from uidh.crud.net. Possibly because it says "1x" at the top of my phone and that means it's on another network?
Could be 4G only? Just did it from a 4G LTE tablet, got a big ol' X-UIDH string of what appears to be Base64. Edit: Also, on a positive match, the page displays a link to an NBC News article on Verizon's CPNI (Customer Proprietary Network Information). http://www.nbcnews.com/tech/security/why-you-should-check-yo...
Re: Verizon Wireless injecting tracking UIDs into HTTP requests
#29I am huge fan since I starting using it when traveling Europe. The mobile version works great as well.
Re: Verizon Wireless injecting tracking UIDs into HTTP requests
#30Earlier quoted context omitted.
They're ignoring it for me. See: https://twitter.com/kennwhite/status/525374343074029568 Can you confirm you connected over cellular when testing?
Yep, over LTE on an iPhone 6, in NYC. The only thing unique is I have Safari configured to send the DNT header. It would be amusing (in a good way) if that made VZ's infrastructure not tag all my traffic.