Live data from Hacker News

Verizon revives "zombie cookie" device tracking on AOL's ad network

propublica.org

31–40 of 98 posts

Re: Verizon revives "zombie cookie" device tracking on AOL's ad network

#31
post #2

The article just below it indicates users can opt-out but mobile tracking is such a big business I sm sure that if it actually is possible, it is not easy. Anyone have good privacy resources for mobile/iOS. My phone security is nowhere near where it should be.

You can visit http://checkyourinfo.com to see all of the HTTP headers your device is sending in requests, including any your ISP may tack on.

Disclosure: I maintain the site

Re: Verizon revives "zombie cookie" device tracking on AOL's ad network

#32
post #17
post #10

Previously: https://news.ycombinator.com/item?id=10354692

There's a lot of randomness in what gets traction on HN, so sometimes a story needs to be posted a few times before it does. So we don't consider reposts to be duplicates until the story has had significant attention on HN (see https://news.ycombinator.com/newsfaq.html ). One downside is that the original submitter of a story doesn't always end up with the karma for it.

Hey dang,

Thanks for getting back to me quickly yesterday and restoring my old hn name. I still seem to be unable to connect from my entire network, and I have gotten a few arbitrary upvotes, but no one has responded to any comment or submission since yesterday. Coupled with connectivity issues, would you mind double checking there is not a ri.ri.cox.net ip address that was banned at a software level, begins with 72 and ends with 48. Sorry to reply here, just trying to confirm if i am visible. Thanks for the reply yesterday, cheers.

======================

Edit

====•==================

i somehow am having traffic timeout to most cloudflare severs. Sorry to bother you again, you were super helpful. Going to try and figure this out or find a direct ip if it exists. Super fast, really pleasant response yesterday. Thanks again. I am def. visible.

Re: Verizon revives "zombie cookie" device tracking on AOL's ad network

#33

Earlier quoted context omitted.

HTTPS is just transit data, they don't need to see that. They can still tell the sites you've visited and really they just want to ID you and optionally make that ID available to others who pay/participate in data syncing.

It's not about Verizon. Of course they know where their users connect to. But by injecting a special HTTP header field, they make it possible for third parties to track the user – for example an ad network that serves ads on sites the user visits. Regular cookies are limited to certain domains, but this header is added to every request, making it cross-domain. HTTPS would prevent Verizon from injecting it.

I'm sure the three letter agencies also love it. But as we know now, the agencies don't have to rely on extracting cookies from intercepted traffic in this particular case: Verizon will happily go above and beyond the call of duty and betray the trust the customers put into them.

Re: Verizon revives "zombie cookie" device tracking on AOL's ad network

#34
post #12
post #5

Earlier quoted context omitted.

Tor as an OS-level feature may not spark the best reaction. It's been given a bad name ("deep web," silk road, etc) in mass media and many people don't understand it enough to think of it as anything other than bad. I think that it'd be cool to have, but I don't think that Apple would ever implement it.

I never dreamed Apple would in any way officially support, or even acknowledge the existence of, ad blocking.

It's an aggressive strategy.

Apple is only blocking internet ads, not in-app ads, which makes it obvious that they're targeting content creators to push them to either Apple newsstand or iOS apps, where Apple gets a cut of the ads.

It's disappointing because Apple is using their mobile marketshare to attack and fragment the open web. Users either don't understand or don't care because they have cognitive bias towards ads to begin with - e.g. people only attribute negative ad experiences to ads, never good experiences (w/ few exceptions like the superbowl).

Re: Verizon revives "zombie cookie" device tracking on AOL's ad network

#35
post #26

I've left Verizon when the story first broke. The coverage I get from T-Mobile is not quite as good as Verizon was - but it is a small price to pay ... ... if indeed I'm getting any privacy in return. Which I'm not at all sure about.

Good call! That's the only way of making them change their ways. It doesn't hurt to complain and sue them, either.

Re: Verizon revives "zombie cookie" device tracking on AOL's ad network

#36
post #2

The article just below it indicates users can opt-out but mobile tracking is such a big business I sm sure that if it actually is possible, it is not easy. Anyone have good privacy resources for mobile/iOS. My phone security is nowhere near where it should be.

I use http://lessonslearned.org/sniff . I check it reflexively every so often, as Verizon has at least once re-enabled the super cookie after I had disabled it. That site checks for cookies from other carriers as well.

Re: Verizon revives "zombie cookie" device tracking on AOL's ad network

#37
post #6

They should be sued for that. There is no way most customers are informed and intentionally consenting to them tampering with the HTTP requests they send to include their customer ID. The obvious expectation of a customer of an ISP is that it sends the data through unchanged.

It's things like this that drive people to want HTTPS everywhere, but even that is subject to subterfuge when the provider inserts their own "trusted" certificates to proxy that traffic. There really should be provisions in the telecom bill that data traffic is to remain absolutely untouched. Just imagine phone calls where mentioning the word "pizza" would trigger an advertisement being injected into it.

I don't know of any ISPs that are currently MITMing HTTPS. That seems like something that would be big news and get a CA revoked. Do you have a source for that?

Re: Verizon revives "zombie cookie" device tracking on AOL's ad network

#38
post #15

Earlier quoted context omitted.

Zombie cookies in particular are insidious -- while you are actively trying to conceal your identity by proactively deleting cookies or using incognito mode, your ISP re-adds them without your consent. This kind of aggressive and underhanded behavior should be shamed as it violates the trust that users have in their ISPs.

A lot of this came about because of the "war" on the 3rd party cookie which was unfairly demonized. I get why zombie cookies are bad as it takes control away, but what is the issue surrounding plain tracking of behaviours? So what if a company knows the history of sites you've visited - what does this do against you?

It's not just "a company", it's many companies. They're injecting this header into every request you make which is visible to the servers you connect to.

It makes any positive steps you've taken to protect your privacy utterly meaningless.

Re: Verizon revives "zombie cookie" device tracking on AOL's ad network

#39
post #2

The article just below it indicates users can opt-out but mobile tracking is such a big business I sm sure that if it actually is possible, it is not easy. Anyone have good privacy resources for mobile/iOS. My phone security is nowhere near where it should be.

I use http://lessonslearned.org/sniff . I check it reflexively every so often, as Verizon has at least once re-enabled the super cookie after I had disabled it. That site checks for cookies from other carriers as well.

Super cool thanks. Still can't figure out why I can't connect to HN, but no tracking beacons which is nice.

Re: Verizon revives "zombie cookie" device tracking on AOL's ad network

#40
So I have a VPN I use already on my iPhone for sensitive things. Seems like I should use it all the time.

Is it possible to make a VPN connection mandatory on a consumer iPhone? It's really a pain having to reconnect manually after I haven't used it for a few minutes.

Post reply on HN