Live data from Hacker News

Verizon Wireless injecting tracking UIDs into HTTP requests

news.ycombinator.com

71–80 of 151 posts

Re: Verizon Wireless injecting tracking UIDs into HTTP requests

#71
post #69
post #17

They don't appear to be doing this if you've opted out of "Relevant Mobile Advertising", which is another option [separate from CPNI] on http://verizonwireless.com/myprivacy . Here's the setting you're looking for: http://i.imgur.com/QFJJNV5.png Mods may also want to update the title to include "Wireless" after Verizon; Verizon landline is not doing this anywhere AFAIK.

I'm opted out of everything on that page and I'm still seeing the header sent. Maybe the header isn't being sent for you due to this change possibly being a gradual rollout.

The header is sent if you opt out. It's explicitly stated in the privacy policy, which i've copied into a parent post on this HN thread.

Re: Verizon Wireless injecting tracking UIDs into HTTP requests

#72
post #20

Let's say I want to send some TCP. That TCP happens to kind of look like HTTP, but it's not. It's just some protocol I made up which looks HTTPish enough to trigger this injection. Doesn't that mean that Verizon isn't actually offering TCP/IP (Internet) access, since they corrupt my protocol stream in transit? Shoudln't that mean they should be charged with fraud if they continue to advertise the fact that they provi…

No. Your question may have been serious, but it's also ridiculous, unless you have a much more technically detailed contract with Verizon than I've ever seen.

I wonder if it would be possible to have them sign a contract when you sign up since customer is king.

Re: Verizon Wireless injecting tracking UIDs into HTTP requests

#73

I assume there are similar opt-outs for AT&T, Sprint, T-Moblie, etc. Anyone maintain a page of links for how to access the opt-outs?

Interesting, I just tested my device over AT&T LTE, but there was no UIDH header. Edit: There is an x-acr header, which contains a curiously large amount of encoded data, far too much to be any reasonably sized id. Anyone know what it is?

I see this as well. AT&T LTE with iPhone 5 (running 8.1).

Re: Verizon Wireless injecting tracking UIDs into HTTP requests

#75
post #69
post #17

They don't appear to be doing this if you've opted out of "Relevant Mobile Advertising", which is another option [separate from CPNI] on http://verizonwireless.com/myprivacy . Here's the setting you're looking for: http://i.imgur.com/QFJJNV5.png Mods may also want to update the title to include "Wireless" after Verizon; Verizon landline is not doing this anywhere AFAIK.

I'm opted out of everything on that page and I'm still seeing the header sent. Maybe the header isn't being sent for you due to this change possibly being a gradual rollout.

I am opted out of everything. The header is sent in mobile Chrome and Firefox, with incognito mode, and with DNT enabled.

Re: Verizon Wireless injecting tracking UIDs into HTTP requests

#78
post #13

This has been going on for ages, not sure why people just now noticed it. They were testing it last year, you could clearly see these headers on a large percentage of traffic coming from their gateways. I'm not expressing an opinion one way or another but they clearly felt the UID is not directly identifiable and thus does not become a privacy issue until they share the mapping of the UID to customer data. My guess i…

The news is that they are injecting it even when you have opted out of CNPI. The disturbing part is a unique ID that follows you despite private browsing and across browsers. The worst part is that it goes to every site you visit (not just VZW or selected advertisers). It can be trivially linked to your existing cookies/identity to follow you even after clearing cookies, changing browsers, switching devices, etc.

Yes it's disturbing, again I'm no mind reader, but I guess they assume when you opt-out they just don't map your UID. Meanwhile you're still trackable and just one small data point could be used to reverse everything you visit.

As an example if you sign up for some random blog and they capture UID's they could quickly map your email to your UID and onward into the spiral we go.

IP Addresses are a similar problem for home users, nobody seemed to have noticed that quite some time ago ISP's started making DHCP lease times quite long. Not to put on a tin foil hat, but I assume this was done more strategically then just to reduce load on DHCP servers in their networks.

Re: Verizon Wireless injecting tracking UIDs into HTTP requests

#79

I assume there are similar opt-outs for AT&T, Sprint, T-Moblie, etc. Anyone maintain a page of links for how to access the opt-outs?

Well, I found the AT&T page. Wow, they make this very difficult to opt-out. http://www.att.com/gen/privacy-policy?pid=24339

This is bullshit. You shouldn't have to "opt out" of tracking in the first fucking place.
Post reply on HN