Live data from Hacker News

Verizon Wireless injecting tracking UIDs into HTTP requests

news.ycombinator.com

41–50 of 151 posts

Re: Verizon Wireless injecting tracking UIDs into HTTP requests

#42
post #20

Let's say I want to send some TCP. That TCP happens to kind of look like HTTP, but it's not. It's just some protocol I made up which looks HTTPish enough to trigger this injection. Doesn't that mean that Verizon isn't actually offering TCP/IP (Internet) access, since they corrupt my protocol stream in transit? Shoudln't that mean they should be charged with fraud if they continue to advertise the fact that they provi…

Yup in theory. In practice you would call up your legal counsel, and they'd ask you how hard would it be to re-engineer your protocol to not break by Verizon. If the answer is anything less than 1 year and tens to hundreds of thousands of dollars then they'd advise you to just fix your protocol.

On the other hand if your spouse is a lawyer and wants to make a name for themself then you'd consider moving forward on failure to deliver service / false advertising / etc.

Re: Verizon Wireless injecting tracking UIDs into HTTP requests

#43
post #17

They don't appear to be doing this if you've opted out of "Relevant Mobile Advertising", which is another option [separate from CPNI] on http://verizonwireless.com/myprivacy . Here's the setting you're looking for: http://i.imgur.com/QFJJNV5.png Mods may also want to update the title to include "Wireless" after Verizon; Verizon landline is not doing this anywhere AFAIK.

That setting doesn't exist on my version of the page.. I get a link to "more information" on "Verizon Selects", but none of my lines are listed there.

I'm going to make a few phone calls...

Re: Verizon Wireless injecting tracking UIDs into HTTP requests

#44
post #17

They don't appear to be doing this if you've opted out of "Relevant Mobile Advertising", which is another option [separate from CPNI] on http://verizonwireless.com/myprivacy . Here's the setting you're looking for: http://i.imgur.com/QFJJNV5.png Mods may also want to update the title to include "Wireless" after Verizon; Verizon landline is not doing this anywhere AFAIK.

That setting doesn't exist on my version of the page.. I get a link to "more information" on "Verizon Selects", but none of my lines are listed there. I'm going to make a few phone calls...

Using and ad blocker? I disabled mine and that section showed up.

Re: Verizon Wireless injecting tracking UIDs into HTTP requests

#45
post #44

Earlier quoted context omitted.

That setting doesn't exist on my version of the page.. I get a link to "more information" on "Verizon Selects", but none of my lines are listed there. I'm going to make a few phone calls...

Using and ad blocker? I disabled mine and that section showed up.

I can confirm that disabling adblock allows these settings to show up.

Re: Verizon Wireless injecting tracking UIDs into HTTP requests

#46
post #14

This makes me rather unhappy. I'm seeing this on Verizon. Can someone with an alternative mobile provider like Sprint or T-Mobile test this, too?

I just tested mine, but the situation is a bit complicated. My service is with T-mobile in the US, but I am currently connecting through Movistar Chile. The response from the website was:

> did not receive X-UIDH header.

So I presume I can say that Movistar Chile is not inserting that into the header. Not sure about T-Mobile (US) though.

Re: Verizon Wireless injecting tracking UIDs into HTTP requests

#48
post #17

They don't appear to be doing this if you've opted out of "Relevant Mobile Advertising", which is another option [separate from CPNI] on http://verizonwireless.com/myprivacy . Here's the setting you're looking for: http://i.imgur.com/QFJJNV5.png Mods may also want to update the title to include "Wireless" after Verizon; Verizon landline is not doing this anywhere AFAIK.

My account has had this disabled for months, the header still shows

Re: Verizon Wireless injecting tracking UIDs into HTTP requests

#50
post #29

This looks like a job for Tunnelbear VPN! https://www.tunnelbear.com/ I am huge fan since I starting using it when traveling Europe. The mobile version works great as well.

Tunnelbear VPN - Blowfish with HMAC-SHA1

https://www.tunnelbear.com/development/encryption/

Seems like a bit of an odd choice for a ciphersuite. I sure hope it's implemented well.

Post reply on HN