Live data from Hacker News

Verizon Wireless injecting tracking UIDs into HTTP requests

news.ycombinator.com

1–10 of 151 posts

Verizon Wireless injecting tracking UIDs into HTTP requests

#1
See @KennWhite: https://twitter.com/kennwhite/status/525110471733817344

Verizon Wireless is injecting a UID into all HTTP requests made on the VZW network, regardless of whether or not you've opted out of their Customer Proprietary Network Information (CNPI) options.

It's injected at the network level- So it tracks across browsers and ignores 'private browsing', do-not-track headers, overriding the UIDH in the client/curl, everything. My confirmation showing the headers only appearing in unprotected HTTP requests (disappearing when VPNed):

https://twitter.com/rammic/status/525360201361530880

If you're on the VZW cell network and not using wifi, you can check your own ID here (via @j4cob):

http://uidh.crud.net/

Re: Verizon Wireless injecting tracking UIDs into HTTP requests

#4

I'm on Verizon and got "did not receive X-UIDH header" message from uidh.crud.net. Possibly because it says "1x" at the top of my phone and that means it's on another network?

Could be 4G only? Just did it from a 4G LTE tablet, got a big ol' X-UIDH string of what appears to be Base64.

Edit: Also, on a positive match, the page displays a link to an NBC News article on Verizon's CPNI (Customer Proprietary Network Information).

http://www.nbcnews.com/tech/security/why-you-should-check-yo...

Post reply on HN