Live data from Hacker News

Verizon revives "zombie cookie" device tracking on AOL's ad network

propublica.org

71–80 of 98 posts

Re: Verizon revives "zombie cookie" device tracking on AOL's ad network

#71

What exactly is the big aversion to tracking? The vast majority has shown (via actions, not internet noise) that they don't care so what exactly is the big downside? Not arguing for/against, just want to know reasons beyond "i just dont like it".

To all the downvotes - Why? It's sad that asking any opposing questions around here leads to this.

Re: Verizon revives "zombie cookie" device tracking on AOL's ad network

#72

Earlier quoted context omitted.

A lot of this came about because of the "war" on the 3rd party cookie which was unfairly demonized. I get why zombie cookies are bad as it takes control away, but what is the issue surrounding plain tracking of behaviours? So what if a company knows the history of sites you've visited - what does this do against you?

You're making the https://en.wikipedia.org/wiki/Nothing_to_hide_argument except for corporate surveillance instead of state surveillance.

Not making an argument - I'm trying to get real examples of everyone's argument of what they're losing, in terms of actual effect against them.

I get that most people have uninteresting data but don't want it collected anyway, but what happens if it is? (Because it is right now). What is it doing to them today? More targeted ads? More spam? More...? That's what I'd like to know.

Re: Verizon revives "zombie cookie" device tracking on AOL's ad network

#73
post #30

What exactly is the big aversion to tracking? The vast majority has shown (via actions, not internet noise) that they don't care so what exactly is the big downside? Not arguing for/against, just want to know reasons beyond "i just dont like it".

The "vast majority" aren't even CLOSE to being INFORMED , so saying they don't care is complete bull-shit. The "internet noise" is everyone who actually understands what's going on, and is rightfully upset.

What does informed mean? If it's articles and news stories, haven't there been countless of those?

Just last week there was a local primetime news story about internet history collection. But it hasn't at all stopped the usage of Google, Facebook or the hundreds of services that collect data. The issue with surveys is people will always say one thing but will do something else. Thoughts/words != actions.

At what point and how do we measure education vs apathy and decide which is true?

Re: Verizon revives "zombie cookie" device tracking on AOL's ad network

#74
post #60
post #56

If your ISP really wants to provide customer/household level tracking to advertisers/partners, they could easily provide an API to them like getCustomerId(IPAddress, Timestamp). It's not entirely clear from the article whether it's "Set-Cookie" being injected in to replies, or the "Cookie" header in to requests, or both. Interesting times nonetheless.

It is an http header: X-UIDH added to http requests

It occurs to me that a mischievous person could easily write a Firefox plugin to (over)write that header with random garbage. If enough people used the plugin, it would render Verizon's data useless.

Re: Verizon revives "zombie cookie" device tracking on AOL's ad network

#75
Lovely. https://www.verizonwireless.com/support/unique-identifier-he...

"Verizon Wireless will stop inserting the UIDH after a customer opts out of the Relevant Mobile Advertising program or activates a line that is ineligible for the advertising program. GOVERNMENT AND ENTERPRISE LINES ARE EXAMPLES OF INELIGIBLE LINES. The UIDH will still appear for a short period of time after a customer opts out of the Relevant Mobile."

Emphasis mine. This sort of clause is indicative that anyone with bargaining power would not put up with this. Business users are probably even more valuable to have data on, but the individuals just deal.

Re: Verizon revives "zombie cookie" device tracking on AOL's ad network

#76
post #34
post #12

Earlier quoted context omitted.

I never dreamed Apple would in any way officially support, or even acknowledge the existence of, ad blocking.

It's an aggressive strategy. Apple is only blocking internet ads, not in-app ads, which makes it obvious that they're targeting content creators to push them to either Apple newsstand or iOS apps, where Apple gets a cut of the ads. It's disappointing because Apple is using their mobile marketshare to attack and fragment the open web. Users either don't understand or don't care because they have cognitive bias towards…

To be clear, Apple is not blocking any ads. They are providing browser hooks to let people create ad blockers, just like (say) Google does on desktop Chrome. The difference is important.

Re: Verizon revives "zombie cookie" device tracking on AOL's ad network

#77

Earlier quoted context omitted.

You're making the https://en.wikipedia.org/wiki/Nothing_to_hide_argument except for corporate surveillance instead of state surveillance.

Not making an argument - I'm trying to get real examples of everyone's argument of what they're losing, in terms of actual effect against them. I get that most people have uninteresting data but don't want it collected anyway, but what happens if it is? (Because it is right now). What is it doing to them today? More targeted ads? More spam? More...? That's what I'd like to know.

They're losing trust, control, and piece of mind. Like if a bully comes up to you and pretends to punch you in the face every day: you can't just say "oh, I'm not hitting you" and think what you're doing is ok. It forces people to be cynical and defensive, and people don't want to be cynical and defensive.

Re: Verizon revives "zombie cookie" device tracking on AOL's ad network

#78
post #67

Earlier quoted context omitted.

I think this happens pretty much everywhere a mobile carrier can profit from selling data about who's doing what. For example, Norwegian company Mobiletech.no has API access to the largest, Nordic mobile carriers' billing gateways and can turn an IP address:port pair from an HTTP/HTTPS connection into a MSISDN, sometimes with additional subscriber details. They're working with advertisers and analytics companies to h…

We only hear about this in mobile but I presume Comcast, Time Warner and friends do the same thing for broadband users, or is there some regulation that stands in their way? For that matter I've always wondered why the tv industry pays so much for inaccurate Nielson data (sometimes still based on diaries) when presumably the cable providers have much more accurate data for many more users.

Because Nielsen gives them numbers they like. I'm sure the real data proves to advertisers exactly how few people really watch TV ads rather than skip/change channels/mute etc.

Re: Verizon revives "zombie cookie" device tracking on AOL's ad network

#79
post #6

They should be sued for that. There is no way most customers are informed and intentionally consenting to them tampering with the HTTP requests they send to include their customer ID. The obvious expectation of a customer of an ISP is that it sends the data through unchanged.

It's things like this that drive people to want HTTPS everywhere, but even that is subject to subterfuge when the provider inserts their own "trusted" certificates to proxy that traffic. There really should be provisions in the telecom bill that data traffic is to remain absolutely untouched. Just imagine phone calls where mentioning the word "pizza" would trigger an advertisement being injected into it.

[deleted]

Re: Verizon revives "zombie cookie" device tracking on AOL's ad network

#80

Earlier quoted context omitted.

HTTPS is just transit data, they don't need to see that. They can still tell the sites you've visited and really they just want to ID you and optionally make that ID available to others who pay/participate in data syncing.

It's not about Verizon. Of course they know where their users connect to. But by injecting a special HTTP header field, they make it possible for third parties to track the user – for example an ad network that serves ads on sites the user visits. Regular cookies are limited to certain domains, but this header is added to every request, making it cross-domain. HTTPS would prevent Verizon from injecting it.

They may not be able to inject HTTPS, but they can offer an API that will map IPaddress:port to identity (as one mentioned here[1]), for only a bit more overhead than tampering with HTTP headers and without breaking TLS.

If they want to make some possibly non-standard protocol adjustments they mutually understand, they should be able to inject it, too. Researching the protocols/crypto to understand that more and trying to produce a POC are side-projects on my list, maybe some day.

The root of the issue is that your ISP often knows who you are, every site you connect to knows who your ISP is, and they have incentives to trade notes on you and few reasons not to.

[1] https://news.ycombinator.com/item?id=10357583

Post reply on HN