Live data from Hacker News

Verizon revives "zombie cookie" device tracking on AOL's ad network

propublica.org

1–10 of 98 posts

Re: Verizon revives "zombie cookie" device tracking on AOL's ad network

#3
Apple's already shown they don't like this behaviour with their randomised MAC addresses in iOS 8+. Obviously what this article references is done at the carrier level, not on open wifi networks.

I expect them to do something about this carrier-level behaviour next iOS. From a technical perspective, what could they do to prevent this?

Re: Verizon revives "zombie cookie" device tracking on AOL's ad network

#4
post #3

Apple's already shown they don't like this behaviour with their randomised MAC addresses in iOS 8+. Obviously what this article references is done at the carrier level, not on open wifi networks. I expect them to do something about this carrier-level behaviour next iOS. From a technical perspective, what could they do to prevent this?

Run everything from the phone through a VPN over iCloud servers, so all traffic from every iPhone in the world hits the internet as if it comes out of Cupertino? Install Tor as an OS-level feature?

Re: Verizon revives "zombie cookie" device tracking on AOL's ad network

#5
post #3

Apple's already shown they don't like this behaviour with their randomised MAC addresses in iOS 8+. Obviously what this article references is done at the carrier level, not on open wifi networks. I expect them to do something about this carrier-level behaviour next iOS. From a technical perspective, what could they do to prevent this?

Run everything from the phone through a VPN over iCloud servers, so all traffic from every iPhone in the world hits the internet as if it comes out of Cupertino? Install Tor as an OS-level feature?

Tor as an OS-level feature may not spark the best reaction. It's been given a bad name ("deep web," silk road, etc) in mass media and many people don't understand it enough to think of it as anything other than bad.

I think that it'd be cool to have, but I don't think that Apple would ever implement it.

Re: Verizon revives "zombie cookie" device tracking on AOL's ad network

#6
They should be sued for that.

There is no way most customers are informed and intentionally consenting to them tampering with the HTTP requests they send to include their customer ID.

The obvious expectation of a customer of an ISP is that it sends the data through unchanged.

Re: Verizon revives "zombie cookie" device tracking on AOL's ad network

#7
post #6

They should be sued for that. There is no way most customers are informed and intentionally consenting to them tampering with the HTTP requests they send to include their customer ID. The obvious expectation of a customer of an ISP is that it sends the data through unchanged.

It's things like this that drive people to want HTTPS everywhere, but even that is subject to subterfuge when the provider inserts their own "trusted" certificates to proxy that traffic.

There really should be provisions in the telecom bill that data traffic is to remain absolutely untouched.

Just imagine phone calls where mentioning the word "pizza" would trigger an advertisement being injected into it.

Re: Verizon revives "zombie cookie" device tracking on AOL's ad network

#8
post #6

They should be sued for that. There is no way most customers are informed and intentionally consenting to them tampering with the HTTP requests they send to include their customer ID. The obvious expectation of a customer of an ISP is that it sends the data through unchanged.

The data is unchanged. Most ISPs have internal tracking for each request to see how network data flows. You can just think of this as Verizon leaving those tags on - and in this case it owns AOL so it's sharing within the same entity.

Not saying good/bad - just how they treat it.

Re: Verizon revives "zombie cookie" device tracking on AOL's ad network

#9
post #6

They should be sued for that. There is no way most customers are informed and intentionally consenting to them tampering with the HTTP requests they send to include their customer ID. The obvious expectation of a customer of an ISP is that it sends the data through unchanged.

It's things like this that drive people to want HTTPS everywhere, but even that is subject to subterfuge when the provider inserts their own "trusted" certificates to proxy that traffic. There really should be provisions in the telecom bill that data traffic is to remain absolutely untouched. Just imagine phone calls where mentioning the word "pizza" would trigger an advertisement being injected into it.

HTTPS is just transit data, they don't need to see that. They can still tell the sites you've visited and really they just want to ID you and optionally make that ID available to others who pay/participate in data syncing.
Post reply on HN