Live data from Hacker News

Verizon revives "zombie cookie" device tracking on AOL's ad network

propublica.org

81–90 of 98 posts

Re: Verizon revives "zombie cookie" device tracking on AOL's ad network

#81

Earlier quoted context omitted.

You're making the https://en.wikipedia.org/wiki/Nothing_to_hide_argument except for corporate surveillance instead of state surveillance.

Not making an argument - I'm trying to get real examples of everyone's argument of what they're losing, in terms of actual effect against them. I get that most people have uninteresting data but don't want it collected anyway, but what happens if it is? (Because it is right now). What is it doing to them today? More targeted ads? More spam? More...? That's what I'd like to know.

One thing that appears to be happening is that some companies are selling information about which users are going to medical sites like WebMD and what they're viewing. I'm concerned that my insurance rates will change because I looked up an obscure disease. I can't prove that that the data is being used that way, yet, but it concerns me.

Re: Verizon revives "zombie cookie" device tracking on AOL's ad network

#82
post #67

Earlier quoted context omitted.

We only hear about this in mobile but I presume Comcast, Time Warner and friends do the same thing for broadband users, or is there some regulation that stands in their way? For that matter I've always wondered why the tv industry pays so much for inaccurate Nielson data (sometimes still based on diaries) when presumably the cable providers have much more accurate data for many more users.

Because Nielsen gives them numbers they like. I'm sure the real data proves to advertisers exactly how few people really watch TV ads rather than skip/change channels/mute etc.

If so presumably the cable companies also know the networks are scared of seeing how many people flip channels during commercials and so they would package the data into larger chunks to hide this.

Re: Verizon revives "zombie cookie" device tracking on AOL's ad network

#83

I wrote a small Heroku app a while back for viewing request headers: http://rocky-brook-3183.herokuapp.com/ Source for the site is here if you're interested: https://github.com/wyattjoh/HeadersCheck

That's interesting. I see

   "dnt": "1"
using Firefox, regardless of whether "tell sites I do not want to be tracked" is unchecked or unchecked.

Could be a bug in Firefox, since visiting your site with Safari doesn't send the header at all (which is how it's supposed to work).

Edit: Sorry about the noise. It's not your site, and it's not Firefox. NoScript took it upon itself to set this header!

Re: Verizon revives "zombie cookie" device tracking on AOL's ad network

#84

What exactly is the big aversion to tracking? The vast majority has shown (via actions, not internet noise) that they don't care so what exactly is the big downside? Not arguing for/against, just want to know reasons beyond "i just dont like it".

To all the downvotes - Why? It's sad that asking any opposing questions around here leads to this.

I am sorry to see the down votes happen, but I can tell you that seeing your questions bring up memories of conversations I've had with friends and family about this issue. They, too, were curious about the issues of tracking and cookies, but in my experience nobody's opinion changes beyond their initial gut reaction, and extended discussion on the topic do not result in much listening-- only non-stop talking. So I wonder if the down votes in this thread are a silent attempt to discourage discussion along this route to prevent a flame.

Re: Verizon revives "zombie cookie" device tracking on AOL's ad network

#85
post #32
post #17

Earlier quoted context omitted.

There's a lot of randomness in what gets traction on HN, so sometimes a story needs to be posted a few times before it does. So we don't consider reposts to be duplicates until the story has had significant attention on HN (see https://news.ycombinator.com/newsfaq.html ). One downside is that the original submitter of a story doesn't always end up with the karma for it.

Hey dang, Thanks for getting back to me quickly yesterday and restoring my old hn name. I still seem to be unable to connect from my entire network, and I have gotten a few arbitrary upvotes, but no one has responded to any comment or submission since yesterday. Coupled with connectivity issues, would you mind double checking there is not a ri.ri.cox.net ip address that was banned at a software level, begins with 72…

i somehow am having traffic timeout to most cloudflare severs

I had all sorts of intermittent problems like this about 18 months ago. In my particular case it was

   The web server reported a bad gateway error.
Dan and I went back and forth a few times in email but didn't conclude anything before things cleared up. I haven't seen the problems since.

One thing to try is to set up a Personal Hotspot on a phone, and point your laptop at that. In my case I would still see the same errors.

Good luck.

Edit: this may be nothing but IIRC I had more problems trying to access HN anonymously than if I was logged in. Sounds crazy, but most intermittent problems are exactly that: crazy.

Re: Verizon revives "zombie cookie" device tracking on AOL's ad network

#86

Earlier quoted context omitted.

Since this is tied to an account, it means data that never dies. While currently unlikely, imagine being vetted for a job by the websites you visit. Do you want an employer to be able to purchase your online history? There's more to hide the the usual things like pornography or political sites. Imagine you've visited several competitor employers, including past job listings. One could easily deduce you likely applied…

Makes sense. Isn't this more of an issue of discrimination and what data a company can have access to? Are employers getting access to search data today? I'm not sure that's happening. Most 3rd party tracking isn't that accurate in coming up with interests/segments for the user in the first place and 1st party data is well protected in that it's what gives the holder value. I think privacy is important, but there a l…

> Are employers getting access to search data today?

The more it's used, the cheaper it becomes to collect and sell. The issue is never about how it is used today; always about how it can be used in the future.

You can always find a way to work for yourself and avoid passing an employer background check. I'm more worried about political parties and private eyes -- blackmail, extortion, ugly divorce proceedings, etc. This can have a chilling effect on free speech and curiosity.

The Jacob Applebaum talk explaining linkability.[1]

Anyone who has access to any website where you logged into an account you publicly admit to owning can link your public identity to any private/anonymous persona, given another marketing data source. Verizon "owns the data", but not really. They are the original owner of the data, but eventually Expirion (target of the recent T-Mobile-Experion data theft) and the other credit reporting agencies will have your X-UIDH. Facebook, Twitter, and Google will know as soon as you log in once. They will be able to identify all of your accounts, perhaps even if you use a VPN.

As with any other high tech tracking, the average end-user is either unaware of the zombie cookie or unaware of the full capabilities of the linkability of it.

[1] https://www.youtube.com/watch?v=HHoJ9pQ0cn8

Re: Verizon revives "zombie cookie" device tracking on AOL's ad network

#87
post #84

Earlier quoted context omitted.

To all the downvotes - Why? It's sad that asking any opposing questions around here leads to this.

I am sorry to see the down votes happen, but I can tell you that seeing your questions bring up memories of conversations I've had with friends and family about this issue. They, too, were curious about the issues of tracking and cookies, but in my experience nobody's opinion changes beyond their initial gut reaction, and extended discussion on the topic do not result in much listening-- only non-stop talking. So I w…

Pretty much everything has been discussed to death these days, doesnt mean new conversation or new learnings cant happen.

We'll never if we dont even start that discussion. I just expected HN to not act like reddit or other sites that downvote for disagreement.

Re: Verizon revives "zombie cookie" device tracking on AOL's ad network

#88

Earlier quoted context omitted.

HTTPS is just transit data, they don't need to see that. They can still tell the sites you've visited and really they just want to ID you and optionally make that ID available to others who pay/participate in data syncing.

It's not about Verizon. Of course they know where their users connect to. But by injecting a special HTTP header field, they make it possible for third parties to track the user – for example an ad network that serves ads on sites the user visits. Regular cookies are limited to certain domains, but this header is added to every request, making it cross-domain. HTTPS would prevent Verizon from injecting it.

The HTTP header was really the lowest tech they could've used and feels like more of a stopgap.

Most ISPs will use tracking at a much lower network layer and provide APIs for partners to match up IDs on demand. No need for HTTP headers.

Re: Verizon revives "zombie cookie" device tracking on AOL's ad network

#89
post #60

Earlier quoted context omitted.

It is an http header: X-UIDH added to http requests

It occurs to me that a mischievous person could easily write a Firefox plugin to (over)write that header with random garbage. If enough people used the plugin, it would render Verizon's data useless.

except that the ISP is adding this header. They could (or do already?) just replace your header with their own..

Re: Verizon revives "zombie cookie" device tracking on AOL's ad network

#90
post #27

AOL’s ad network will be able to match millions of Internet users to their real-world details gathered by Verizon, including — “your gender, age range and interests.” ... AOL will also be able to use data from Verizon’s identifier to track the apps that mobile users open, what sites they visit, and for how long. Verizon purchased AOL earlier this year... "I think in some ways it’s more privacy protective because it’s…

I think this happens pretty much everywhere a mobile carrier can profit from selling data about who's doing what. For example, Norwegian company Mobiletech.no has API access to the largest, Nordic mobile carriers' billing gateways and can turn an IP address:port pair from an HTTP/HTTPS connection into a MSISDN, sometimes with additional subscriber details. They're working with advertisers and analytics companies to h…

How is that legal in the European Economic Area?
Post reply on HN