Slashdot Mirror


Verizon Injects Unique IDs Into HTTP Traffic

An anonymous reader writes: Verizon Wireless, the nation's largest wireless carrier, is now also a real-time data broker. According to a security researcher at Stanford, Big Red has been adding a unique identifier to web traffic. The purpose of the identifier is advertisement targeting, which is bad enough. But the design of the system also functions as a 'supercookie' for any website that a subscriber visits. "Any website can easily track a user, regardless of cookie blocking and other privacy protections. No relationship with Verizon is required. ...while Verizon offers privacy settings, they don’t prevent sending the X-UIDH header. All they do, seemingly, is prevent Verizon from selling information about a user." Just like they said they would.

206 comments

  1. Is there a way to prevent this? by Anonymous Coward · · Score: 5, Interesting

    This should be illegal. People have a right to try and avoid being tracked. There has to be a way to prevent this. I'm a sysadmin, not a network guru, so I will defer to those smarter than me here...

    1. Re:Is there a way to prevent this? by Anonymous Coward · · Score: 2, Interesting

      third party VPN paid for by a cash card

    2. Re: Is there a way to prevent this? by Anonymous Coward · · Score: 3, Interesting

      Or just browse https only

    3. Re:Is there a way to prevent this? by Anonymous Coward · · Score: 0

      The internet was not made for porn... it was made for tracking. So no, you can't prevent it.

    4. Re:Is there a way to prevent this? by 0dugo0 · · Score: 2

      Rig as many webservers as possible to give users with that header a nag screen

    5. Re:Is there a way to prevent this? by slinches · · Score: 1, Insightful

      Don't use Verizon as your ISP?

      --
      Knowledge Brings Fear
    6. Re:Is there a way to prevent this? by Anonymous Coward · · Score: 0

      clone random headers all over the place so that unique ID isn't reliable.

    7. Re: Is there a way to prevent this? by Anonymous Coward · · Score: 3, Interesting

      To be honest, I don't think this does anything. I think a VPN might be the only current way to avoid this, as your traffic in a VPN tunnel is theoretically not seen by the routers that pass it. I'm not sure if deep packet inspection tools could add the unique ID. I'm not a network engineer, so I don't know for sure. I do know that VPNs of today are rapidly becoming easier to circumvent by those who would do so.

    8. Re:Is there a way to prevent this? by Anonymous Coward · · Score: 0

      I think I heard Comcast rub its hands with glee...

    9. Re:Is there a way to prevent this? by Charliemopps · · Score: 3, Informative

      Don't use Verizon as your ISP?

      Personally, I use Verizon and have no other choice for a wireless provider. AT&T has plans to build another tower here in 2021, and it's not like their the champions of my privacy either.

    10. Re:Is there a way to prevent this? by Anonymous Coward · · Score: 4, Interesting

      Unacceptable. Verizon licensed the spectrum from citizens, and therefore has certain obligations.

      This is what should occur. Make use of any spectrum contingent upon a series of consumer friendly policies. Failure to comply requires turning the spectrum and any technology that uses it or assists in its use over to auction. Then establish a rule that prohibits anyone over a pay grade access to any industry that uses spectrum for a predetermined duration.

      If you set the concequesnces high enough than ideas like this get shot down in the board room.

    11. Re: Is there a way to prevent this? by Anonymous Coward · · Score: 0

      Hmm, I think it should. The encryption is done at a level above HTTP, so the HTTP headers including URL etc should all be encrypted over HTTPS, meaning they can't inject headers.

      Well, they could put a proxy between but you'd get warnings about bad certificates. They could tell you to add theirs as a trusted cert, but at that some point nobody can stop someone else from putting a gun to their own head and pulling the trigger if they are that intent on bypassing the SSL security.

    12. Re:Is there a way to prevent this? by CaptainDork · · Score: 1, Insightful

      So your theory is that, now that women have been "integrated" in the military, male soldier's sexual needs have been met?

      --
      It little behooves the best of us to comment on the rest of us.
    13. Re:Is there a way to prevent this? by whoever57 · · Score: 4, Insightful

      There has to be a way to prevent this

      As a sysadmin, you should know that it is easy and cheap to rent a VPS (Virtual Private Server). Then, run squid on the server, or do some fancy routing to send all your web traffic out via a VPN to your VPS. Since most VPS services offer a minimum of 1TB of monthy data, there should not be any excess data usage charges.

      --
      The real "Libtards" are the Libertarians!
    14. Re:Is there a way to prevent this? by Anonymous Coward · · Score: 0

      "Unacceptable. Verizon licensed the spectrum from citizens, and therefore has certain obligations"

      Bwahahahahahahahahahahahah *Breath*

      BWahahahahahahahahahahaha.

      Nice one! They don't you or I shit. They bought the spectrum, and they have numerous bullshit laws in place to ensure that they can and will do whatever they damned well please.

    15. Re: Is there a way to prevent this? by Anonymous Coward · · Score: 3, Informative

      TLS from end to end ...

    16. Re:Is there a way to prevent this? by Nethemas+the+Great · · Score: 1, Insightful

      Judging by the sexual harassment reports, I'm guessing no. They must be cutting back on cycling soldiers through SE Asia.

      --
      Two of my imaginary friends reproduced once ... with negative results.
    17. Re:Is there a way to prevent this? by Anonymous Coward · · Score: 0

      For like $5 a month you could get a cheap VPS and install OpenVPN on it.

    18. Re:Is there a way to prevent this? by DamnOregonian · · Score: 3, Insightful

      Not just sexual harassment. It's safer for a supermodel to walk down MLK in your favorite large city naked than a homely woman to walk from one end of Fort Hood to the other, wearing ACUs after dark.
      When soldiering becomes less of a duty and more of a way to delay starting out your life of dismal poverty, you start making the wrong kind of army.

    19. Re:Is there a way to prevent this? by Anonymous Coward · · Score: 0

      Failure to comply requires turning the spectrum and any technology that uses it or assists in its use over to auction.

      If the citizens truly own this spectrum, then you should be able to prevent them from tracking us or auctioning it to someone else, otherwise ownership is just an illusion and a sham.

    20. Re:Is there a way to prevent this? by mmell · · Score: 1, Insightful

      ...the internet was indeed created for porn and online casinos.

      .

      FTFY.

    21. Re:Is there a way to prevent this? by gbjbaanb · · Score: 0

      sure, but covertly serving gays have been there since.. well, shortly after the Greek empire ended.

    22. Re:Is there a way to prevent this? by gbjbaanb · · Score: 1

      bullshit. They bought it from the government, whose representation of its citizens occurs roughly every 5 years for a fortnight. Apart from that time, they do what they like. And even in that fortnight they just tell you what you wanted to hear anyway.

    23. Re:Is there a way to prevent this? by dgatwood · · Score: 1

      So you're saying they made a new network for blackjack and hookers? You know what, forget the network. And the hookers.

      --

      Check out my sci-fi/humor trilogy at PatriotsBooks.

    24. Re:Is there a way to prevent this? by slinches · · Score: 1

      That's the problem with monopolies (natural or otherwise). Still, there is an option to sign up for just the phone plans without wireless data and use wired or satellite ISPs for internet access.

      You could also go the route of circumventing the problem (using the methods others have already suggested) with a bit of added effort/cost, but in that case there's no disincentive to help persuade Verizon to stop the program.

      --
      Knowledge Brings Fear
    25. Re:Is there a way to prevent this? by Anonymous Coward · · Score: 0

      A VPS usually has a static IP address (or in case of IPv6, a static prefix). That's not going to help.

    26. Re:Is there a way to prevent this? by Dishevel · · Score: 1
      You still have the right.

      You just need to decide to not be a Verizon customer.

      --
      Why is it so hard to only have politicians for a few years, then have them go away?
    27. Re:Is there a way to prevent this? by slashdime · · Score: 0

      What the GP offered was a way to easily bypass the questional practices in TFA, Verizon injecting a http header, not a way for you to have real ultimate anonymity everywhere and forever.

      By using a VPN between your VPS and yourself, Verizon would not be able to inject a http header into encrypted packets.

      Of course, this is assuming your VPS is hosted by a provider who also doesn't do any funny business to your packets.

    28. Re:Is there a way to prevent this? by cbhacking · · Score: 1

      USA, so more like every two years for the federal government (this is an election year for congress, though not for the presidency) and it lasts a lot longer than a fortnight (which, it should be mentioned, is a word only very rarely used on this side of the pond) due to the degree of campaigning that people do here (though it's definitely a bigger deal on the presidential years).

      No argument on the "tell you what you wanted to hear anyway" part, though! Something so far removed from the few very carefully controlled Major Issues as corporate misuse of licensed bandwidth is going to be completely ignored by both sides (and there *are* only two sides; the media won't even report on any other parties or permit them at the debates). Occasionally some congressthing ("critter" isn't sufficiently derogatory for them) will make some statement (and maybe actually introduce / support some legislation) about such topics, but generally only when pandering to local interests in their districts.

      --
      There's no place I could be, since I've found Serenity...
    29. Re: Is there a way to prevent this? by TheGratefulNet · · Score: 1

      I don't think you could modify packets that are in an ssl stream and not have ssl detect it and reject the 'broken' packets.

      https is mostly secure (other than MitM attacks on certs) and vpn's are also very secure.

      I have a vpn and while I use it mostly at home, there is an android client (even for my ancient 2.x android o/s) for the vpn provider I have and so I could get as complete privacy as possible on my phone, while doing inet things.

      --

      --
      "It is now safe to switch off your computer."
    30. Re:Is there a way to prevent this? by CaptainDork · · Score: 1

      Interesting connective theory.

      Noted, as well, is that chemtrails began to appear only after the invention of radio.

      --
      It little behooves the best of us to comment on the rest of us.
    31. Re:Is there a way to prevent this? by Anonymous Coward · · Score: 1

      > There has to be a way to prevent this.

      Does anyone know if you configure your broswer to send it's own X-UIDH header will verizon overwrite it with their version or let it pass unmolested?

      If you can send your own then a simple plugin should be able to randomize it for every page access.

    32. Re:Is there a way to prevent this? by Bob9113 · · Score: 1

      When soldiering becomes less of a duty and more of a way to delay starting out your life of dismal poverty, you start making the wrong kind of army.

      Wait, we can do worse; how about making enlistment an alternative to a prison sentence for newly convicted criminals? (actually, that sounds so awful, I'm surprised it isn't already in place)

    33. Re:Is there a way to prevent this? by nazsco · · Score: 2

      > Don't use Verizon as your ISP?

      How quaint. A foreigner.

      well lad, in the US of A, you have the freedom of choosing the ISP that was selected to monopolize your burrough.

      Or you can use the one mobile provider that has good coverage in your city instead, if you don't want to use that pre-selected ISP.

    34. Re: Is there a way to prevent this? by Anonymous Coward · · Score: 1, Insightful

      Well, they could put a proxy between but you'd get warnings about bad certificates. They could tell you to add theirs as a trusted cert, but at that some point nobody can stop someone else from putting a gun to their own head and pulling the trigger if they are that intent on bypassing the SSL security.

      Worse yet, they could preload that cert into the phone's ROM image and not let you remove it.

    35. Re:Is there a way to prevent this? by SuricouRaven · · Score: 1

      The US military currently has too many and too few recruits. Lots of people want in, because when the economy tanks the military is one of the few options left. But most of them fail the entry qualifications, so the number of qualifying recruits is still too low.

    36. Re:Is there a way to prevent this? by Anonymous Coward · · Score: 0

      I get that. My point is that using a VPS proxy to evade being tracked through Verizon's tagging is hardly fit for purpose, as you replace one unique identifier with another. If your goal is to stick it to Verizon, go ahead. If your goal is to avoid tracking, this is not the way to do it.

    37. Re: Is there a way to prevent this? by Anonymous Coward · · Score: 0

      Nope.
      What is happening is essentially a "man in the middle" attack; the xUIDH header is put on by VzW by the proxy device connecting at the DataCenter.
      The device is made by Flash Networks - http://www.flashnetworks.com/Monetization-Overview

      The clever box does several things, the proxy design reduces the number of over the air connections, a webpage has many connections (to ad servers, to discrete image servers, etc) and the box sends a single image over the air to the device.
      It also reduces the image resolution so that you aren't sending pixels and then tossing them out to display it on a tiny screen.
      It also has TCP+, a varient that uses different assumptions to speed up the transfer.

    38. Re: Is there a way to prevent this? by Anonymous Coward · · Score: 1

      Nope.
      What is happening is essentially a "man in the middle" attack; the xUIDH header is put on by VzW by the proxy device connecting at the DataCenter.
      The proxy is IP transparent, it adds the xUIDH to the outgoing http stream, before the certificate request.
      The device is made by Flash Networks - http://www.flashnetworks.com/Monetization-Overview

      The clever box does several things, the proxy design reduces the number of over the air connections, a webpage has many connections (to ad servers, to discrete image servers, etc) and the box sends a single image over the air to the device.
      It also reduces the image resolution so that you aren't sending pixels and then tossing them out to display it on a tiny screen.
      It also has TCP+, a varient that uses different assumptions to speed up the transfer.

    39. Re: Is there a way to prevent this? by allo · · Score: 2

      So, and why wouldn't TLS help there?

    40. Re:Is there a way to prevent this? by jandar · · Score: 2

      In my jurisdiction is altering data (stored or transmitted) without censent a felony. The action of Verizon is hacking and would here be punishable as such.

    41. Re: Is there a way to prevent this? by Anonymous Coward · · Score: 0

      The payload doesn't need to be modified. Just the header.

    42. Re:Is there a way to prevent this? by Zontar+The+Mindless · · Score: 1

      It's been done. I've a friend who got busted at age 19 for selling heroin. The judge gave him the option of enlisting and volunteering for combat duty, or doing hard time in the state pen. He chose the former--which in those days, was effectively getting a ticket to Vietnam.

      There's a photo somewhere showing one of the last US helicopters to take off from Saigon in April 1975. In the photo you can a soldier dangling from one of the landing skids. That's my friend.

      --
      Il n'y a pas de Planet B.
    43. Re:Is there a way to prevent this? by tepples · · Score: 1

      Still, there is an option to sign up for just the phone plans without wireless data

      Are you sure Verizon will even activate voice-only service on a smartphone? AT&T sure won't.

      and use wired or satellite ISPs for internet access.

      And if the DSL ILEC for your area is also Verizon, too bad.

    44. Re:Is there a way to prevent this? by Stan92057 · · Score: 1

      "walk down MLK"
      Please ..share.

      --
      Jack of all trades,master of none
    45. Re: Is there a way to prevent this? by Anonymous Coward · · Score: 0

      So, and why wouldn't TLS help there?

      Because it would, and he doesn't understand protocol layering or where SSL/TLS fits in the scheme?

      I've had to deal with external partners who had the same misapprehensions. After calm, rational explanations didn't work and they continued to insist that SSL would leak URLs and headers in the clear, I had to resort to mocking reductio ad absurdum. "So, you believe the protocol has a separate side channel to send headers and URIs in the clear while everything else is encrypted? Why?"

      Cluehammer applied.

    46. Re: Is there a way to prevent this? by Anonymous Coward · · Score: 0

      The adversary is the TLS-using site itself, which is trying to track you in spite of your clearing cookies. They can ping an http site they control.

    47. Re: Is there a way to prevent this? by Anonymous Coward · · Score: 0

      Try TorBrowser, see what happens.

      (ironic captcha: legally)

    48. Re: Is there a way to prevent this? by allo · · Score: 1

      hmm, true. But maybe they will trigger an "unsafe elements" alert in the browser.

    49. Re: Is there a way to prevent this? by allo · · Score: 1

      nope, he's right. Your adversary is the site, not verizon. And the site can make you request non-http stuff, where verizon (which is not the main enemy) injects an id, which can then be read by the site. There is not much protection without using extreme measures like requestpolicy (and not allowing anything using http).

    50. Re: Is there a way to prevent this? by Anonymous Coward · · Score: 0

      And that can't happen in a pure ssl/tls connection. VZW can't interfere with that request/response cycle unless they are actively MITM ssl proxy via invalid certificates.

      The sideloading attack is irrelevant to my point, as is the rest of your argument.

    51. Re: Is there a way to prevent this? by allo · · Score: 1

      you're still not getting the szenario, just as i did not in my first post.

      VZW does not want to interfere for this szenario. They interfere with http adding an id and ignore https. The website wants your identification. So they generate a token on the https-site and load image.jpg?token from a http(without s) site. Then they know a token vzw correlation and can assign the same token on your next visit.

      Hello supercookies.

    52. Re: Is there a way to prevent this? by Anonymous Coward · · Score: 0

      MLK refers to Martin Luther King which is commonly the name of a major street in historically black areas of many urban areas in American cities.

  2. Let me be one of the first... by Anonymous Coward · · Score: 1, Insightful

    Fucking scumbags.

  3. Nothing new by Anonymous Coward · · Score: 0

    Carriers have done this for years. Most carriers require a white-listed relationship with the destination.

  4. What about Tor? by Anonymous Coward · · Score: 0

    Does this header remain intact if one uses Tor? I don't know enough about it offhand.

    1. Re:What about Tor? by NotInHere · · Score: 1

      No, unless the exit node uses verizon wireless, too.

    2. Re:What about Tor? by watermark · · Score: 1

      The first tor hop is encrypted, so no. Technically, if the exit node is on verizon wireless, then it would have the code of exit node, not yours.

    3. Re:What about Tor? by GNious · · Score: 1

      Run a Tor exit-node on your Verizon network?
      That should allow SnR to effectively mask you against tracking.

  5. Maybe the FCC... by Anonymous Coward · · Score: 3, Funny

    Will tell them to go fuck themselves on this, and make them stop...

    1. Re:Maybe the FCC... by Overzeetop · · Score: 1

      If there ever was a +6 Funny, this is the one.

      --
      Is it just my observation, or are there way too many stupid people in the world?
  6. Free market? by NotInHere · · Score: 4, Insightful

    They should offer this to the user as an option, where the user has to pay less when tracking is enabled. Otherwise this is abuse of market power to make users agree to being tracked.

    1. Re:Free market? by fox171171 · · Score: 3, Insightful

      They should offer this to the user as an option, where the user has to pay less when tracking is enabled. Otherwise this is abuse of market power to make users agree to being tracked.

      Except it will be the other way around. Pay more to not be tracked.

    2. Re:Free market? by Anonymous Coward · · Score: 4, Insightful

      I think the free market solution would simply be having enough ISPs so that if one pulls stuff like this you can just switch to another. Some sort of "competition". I suggest we find out why there is only one fast ISP per area, and fix that problem.

    3. Re:Free market? by Charliemopps · · Score: 4, Insightful

      They should offer this to the user as an option, where the user has to pay less when tracking is enabled. Otherwise this is abuse of market power to make users agree to being tracked.

      No because they'll quickly value this service at $50 a month to force you into it.

      They should not be altering my HTTP requests. It's wiretapping, plane and simple.

    4. Re:Free market? by Anonymous Coward · · Score: 0

      Well, you are already paying less when tracking is enabled.

    5. Re:Free market? by Anonymous Coward · · Score: 0

      Except I don't believe you'll be ever able to pay enough for corps to stop doing this.

      Anything they earn on top of normal service pricing will be more than not earning it.
      As such I very much doubt that non-tracking will ever be offered.

      All sorts of other premium-upsellery? Sure.
      And the tracking info of expensive premium users should then again fetch a nice premium itself.

    6. Re:Free market? by Anonymous Coward · · Score: 0

      Maybe you as a user could offer this information to Verizon? Sell them some traffic logs. Then it's your information. If they try to hand that information to someone else it should be copyright infringement, right? Then sue them.

    7. Re:Free market? by Bob9113 · · Score: 1

      I suggest we find out why there is only one fast ISP per area,

      Here's a hint: It's the same reason there is only one electricity provider in most areas. Generally, it is not cost efficient to run multiple sets of wires, but everyone wants electricity.

      and fix that problem.

      The solution is the same as with electricity. We've tried all the other solutions, many, many, many times over, and we keep coming back to the same small set of best answers; all over the world, in all kinds of cultures and every shade of Western economics.

    8. Re:Free market? by nazsco · · Score: 1

      last time i heard about US ISP/mobile provider shenanigans there was a debate on net neutrality (which the tel cos were wining) arguing that they were not common carriers.

      well, that just goes to prove that they are not common carriers. they can even monetize on the service they are already selling you. they don't consider your communication protected in any way.

      it is like opening a restaurant and selling your scraps to feed cows. except that they are the only restaurant in town. and after 12sec they take away your plate and consider what is left scrap. oh, and dog bags are forbiden on the contract.

      i wonder if the FSF pays verizon to get the IDs from the senate to advertise to them... how would they like it? probably would jail everyone shouting commie. or is that terrorist nowadays?

    9. Re:Free market? by SuricouRaven · · Score: 1

      It's called a natural monopoly. It occurs when the capital cost of entering a market is so high as to render doing to prohibitive for all but the first entry.

      Verizon or another of the major ISPs comes first. That means they pay for laying cables, renting mast space, installing equipment and lobbying local government for the appropriate rights. It costs them a fortune, but they can be assured of a return because they'll have 100% of the market - there's no other option for potential customers.

      When another ISP comes along, they'd have to pay just as much for cables, equipment and such - but they wouldn't get 100% of the market. They'd have to poach customers from an existing provider, which is a great deal harder than getting unaffiliated customers. There's no realistic way they would turn a profit as a second-comer, so they stay out of that area.

      Thus one ISP gets a monopoly.

    10. Re:Free market? by Anonymous Coward · · Score: 0

      As these two have said, you really can't have a free market for something that requires wires coming to your house.

      There is an alternative to a corporate monopoly. A public utility.

    11. Re:Free market? by cgimusic · · Score: 1

      But that's the same thing as paying less when you are being tracked.

  7. What did you expect? by koan · · Score: 1

    Everyone was targeting mobile use because that's what the average slob uses, remember Facebook's panic because they couldn't find the right model for mobile?
    How many other methods are in use? Who else is using this method? (ATT?)
    Are agencies like the NSA doing something similar?

    --
    "If any question why we died, Tell them because our fathers lied."
  8. which Verizon services by Anonymous Coward · · Score: 0

    This mentions Verizon wireless does that mean just wireless or also dsl and fios?

    1. Re:which Verizon services by watermark · · Score: 3, Interesting

      I'm on fios and just checked headers, nothing like this (yet).

    2. Re:which Verizon services by cbhacking · · Score: 2

      Where did you check from? You don't see the headers on your end; they're only added at the ISP gateway. Unless you were able to bounce a request off an external web server and see the headers that it *received* - which don't have to be the ones you sent - then you don't know. Oh, and don't use HTTPS for the test, since they obviously can't modify those requests.

      --
      There's no place I could be, since I've found Serenity...
    3. Re:which Verizon services by jbmartin6 · · Score: 3, Informative

      I just checked using http://centralops.net/co/ over my Verizon mobile phone and sure enough there is the X-UIDH header. Well, this cements my plan to switch carriers in a month when my contract expires. Any tips on moving to a pay-as-you-go plan that lets me keep my phone number?

      --
      This posting is provided 'AS IS' without warranty of any kind, implied or otherwise.
    4. Re:which Verizon services by Anonymous Coward · · Score: 0

      I don't know about other major carriers, but T-Mobile made it pretty easy for me. All I had to do was mention to the rep (I was in person, also buying a new phone) that I wanted to use my old number during the sign-up process. A couple days later, I got a call from a rep to certify the number transfer, and that was it. I think I had to reset my phone to get it to pick up the changes? Don't really remember because it was such a non-issue. Oh, you'll need to know your SIM number, IMEI, and any PINs for them.

      I also vaguely recall hearing a rumor that phone companies are required to let you keep your number when transferring service, but I never bothered to fact-check it.

    5. Re:which Verizon services by Anonymous Coward · · Score: 0

      Ting (http://ting.com) shrank my bill from ~100 to 30. I'm still on Sprint network but save a bundle each month. I tested with my daughters phone for a while and then switched myself. Going from paying over $200/mth to about $60 is nice.

      Ting is basically one of those who buy bulk and then resell at a great discount. They charge you independently for Data, Voice and Texts. Minimum charge I think is $6.

    6. Re:which Verizon services by nazsco · · Score: 1

      > Any tips on moving to a pay-as-you-go plan that lets me keep my phone number?

      DO NOT cancel your account!

      call the new company, say you want to port your number.

      the system is F*up... you will have to give the new co your account number AND PASSWORD for the old one. so if it is your SSN as it is by default, change it before if you care (or stop believing that SSN is secret, you are a grow up).

      anyway, i cancelled ATT and then ported to TMOBILE. ATT was obliged by law to reactivate my account to complete the transfer... but that didn't hold them against mailing for a NEW 2yr contract and cancelation because i "hired" the service again... costed me a couple calls to short it out since they can't charge you.

      anyway, the system sucks. read online and follow the steps. i had lots of headache for not following the dumb non-sense crap.

      be a happy sheep. and good luck.

    7. Re:which Verizon services by Anonymous Coward · · Score: 0

      It's Verizon Wireless. Reading comprehension not your strong point?

    8. Re:which Verizon services by Anonymous Coward · · Score: 0

      Where did you check from? You don't see the headers on your end; they're only added at the ISP gateway. Unless you were able to bounce a request off an external web server and see the headers that it *received* - which don't have to be the ones you sent - then you don't know. Oh, and don't use HTTPS for the test, since they obviously can't modify those requests.

      I usually do that here:
      http://simplesniff.com

      Disclaimer: I own that site. I'm thinking of doing an HTTPS version as well, but only with a self-signed cert.

    9. Re:which Verizon services by watermark · · Score: 1

      I'm aware. I used some random site I found on google that displays my sent headers.

    10. Re:which Verizon services by JesseMcDonald · · Score: 1

      I just checked using over my Verizon mobile phone and sure enough there is the X-UIDH header.

      I just checked with my AT&T mobile phone and found an "x-acr" header which seems to serve much the same purpose, so switching away from Verizon might not help. (The header is not present when accessing the site through a VPN, so it wasn't sent by the browser.)

      The content seems to be based on the Anonymous Customer Reference concept promoted by the GSM Alliance.

      --
      "The state is that great fiction by which everyone tries to live at the expense of everyone else." - Bastiat
    11. Re:which Verizon services by jbmartin6 · · Score: 1

      T-Mobile doesn't, at least as far as I could tell. Not yet at least.

      --
      This posting is provided 'AS IS' without warranty of any kind, implied or otherwise.
    12. Re:which Verizon services by Anonymous Coward · · Score: 0

      Verizon *Wireless* is doing this.

      Not suggesting they aren't going to move this practice to wireline services also, but as yet, according to Ars anyway this is just on mobile.

  9. Verizon Fios by gurps_npc · · Score: 1
    Does it only apply to Verizon Wireless?

    Does anyone know if FIOS internet uses the same system? I don't have a Verizon Wireless account.

    --
    excitingthingstodo.blogspot.com
    1. Re:Verizon Fios by Lawrence_Bird · · Score: 0

      I just ran a test in wireshark and could not find that header

    2. Re:Verizon Fios by cbhacking · · Score: 1

      Of course not. It's added to your requests when they reach the ISP gateway. Why would you expect to be able to see them on anything between you and that gateway?

      --
      There's no place I could be, since I've found Serenity...
    3. Re:Verizon Fios by Anonymous Coward · · Score: 0

      Woohoo, I can use Wireshark but otherwise, I have no fucking clue.

      FTFY.

    4. Re:Verizon Fios by Lawrence_Bird · · Score: 1

      Thanks for the pointer. I should have read the hacker news linked in TFA as it was not clear to me whether the header was one way or on both ends of the connection.

    5. Re:Verizon Fios by Anonymous Coward · · Score: 0

      try http://centralops.net/co/
      The xUIDH will only show up from a mobile phone , not from a land connection.
      That's because the device is part of a proxy on their mobile to wired gateway.
      http://www.flashnetworks.com/Layer8

  10. HTTPS Everywhere by watermark · · Score: 4, Insightful

    They can't inject into secure traffic. HTTPS solves this problem too.

    1. Re:HTTPS everywhere by XanC · · Score: 1

      The slashdot objection is that slashdot itself isn't on HTTPS. Come on, guys! Does whoever posted this article not see the need??

    2. Re:HTTPS Everywhere by Burz · · Score: 1

      I intend to use a proxy in addition to HTTPS-E.

    3. Re:HTTPS Everywhere by Charliemopps · · Score: 3, Insightful

      They can't inject into secure traffic. HTTPS solves this problem too.

      Good idea, I just need to figure out what the http address for slashdot is...

    4. Re:HTTPS Everywhere by cbhacking · · Score: 4, Insightful

      Slashdot actually supports HTTPS just fine. They simply redirect you back to HTTP immediately! Try it yourself: https://slashdot.org/ - 302, Location: http://slashdot.org/index2.pl - 302, Location: http://slashdot.org/

      I wish I was joking...

      --
      There's no place I could be, since I've found Serenity...
    5. Re:HTTPS everywhere by cbhacking · · Score: 1

      No, it's actually much worse than that. Slashdot supports HTTPS just fine. They simply force you back to HTTP (using a redirect *out* of HTTPS whenever you request an HTTPS page)! Total bullshit; there's no legitimate reason for such behavior. Even without dedicated TLS hardware, the overhead of HTTPS is pretty trivial for modern servers.

      --
      There's no place I could be, since I've found Serenity...
    6. Re:HTTPS Everywhere by DoofusOfDeath · · Score: 1

      Slashdot actually supports HTTPS just fine. They simply redirect you back to HTTP immediately! Try it yourself: https://slashdot.org/ - 302, Location: http://slashdot.org/index2.pl - 302, Location: http://slashdot.org/

      I wish I was joking...

      Any idea why they do this? Of all the sites to not to https...

    7. Re:HTTPS Everywhere by Anonymous Coward · · Score: 0

      They can't inject into secure traffic. HTTPS solves this problem too.

      Install CGIproxy on your webhost with an SSL cert (Free from StartSSL) and use it for all your web browsing cover ISP spying on non-https supporting websites (such as slashdot)

      If you don't mind your ISP knowing the domain of the https sites you visit, you can still go to them directly.

      If your webhost is your own server however there is no additional risks routing everything through CGIproxy.
      Shared webhost space is an additional risk, since they would have the ability to see your unencrypted traffic if they desired.

      Of course there is no encryption between the webhost and the non-ssl websites you visit, but since that is/was true when visiting them directly anyways this only turns a very sucky situation into a slightly less sucky one - a net improvement over all.

      But all the ISP will see is that 100% of your web traffic is to a single IP and fully encrypted, and you apparently don't use the rest of the internet in your web browser.

    8. Re:HTTPS Everywhere by Anonymous Coward · · Score: 0

      If they want to, they can just send a UDP packet from your IP address with your UID in it to any server you connect to. If your ISP wants to rat you out, they can, unless you hide the destination IPs from them, for example by using a VPN to tunnel out.

    9. Re:HTTPS Everywhere by Charliemopps · · Score: 1

      Educated guess?
      The sites made up of custom code written before HTTPS was really all that common. It's such a mess that adding it now would require just as much work as just flat out rewriting the whole site. Last time they tried a site redesigned all the neck beards on here started shooting rocksalt at them and screaming "GET OFF MY LAW!!!"

      I suspect this site barely pays for itself. I do not anticipate any large site redesigns ever.

    10. Re:HTTPS Everywhere by gman003 · · Score: 1

      Soylent News runs on Slashcode (although a fork of an earlier version, I think). HTTPS works just fine, as does Unicode and probably a few other things broken on Slashdot. No IPv6 yet but I'm sure it's coming. It's all on Github so it would be fairly trivial to merge it in to Slashdot.

    11. Re:HTTPS Everywhere by cbhacking · · Score: 2

      TLS (or lack thereof) is, or at least should be, completely transparent to the Perl-based web application powering the site. In fact, the HTTP request itself doesn't even specify anything about the protocol. The request line has the path and stuff after it, and the Host header has the domain name, but doesn't mention the protocol. The absolute minimum they should do would be to return *exactly* the same content over HTTPS that they do over HTTP for a given request (remember, the HTTP traffic is the same whether it's tunneled through TLS or not).

      In fact, I just checked: the site already uses protocol-agnostic URLs. For example:
      <a title="" class="read-more" href="//hardware.slashdot.org/story/14/10/24/2320227/microsoft-now-makes-money-from-surface-line-q1-sales-reach-almost-1-billion"><span>Read More</span> </a> (random link off the home page, note the href="//hardware.slashdot..." URL, which doesn't specify HTTP or HTTPS). Your browser handles such URLs by using whatever protocol the page itself was served over.

      They wouldn't have to change a damn thing except to remove the stupid rule that redirects users out of HTTPS. That's a pretty damn minor change.

      --
      There's no place I could be, since I've found Serenity...
    12. Re:HTTPS Everywhere by Anonymous Coward · · Score: 0

      Educated guess?
      The sites made up of custom code written before HTTPS was really all that common. It's such a mess that adding it now would require just as much work as just flat out rewriting the whole site. Last time they tried a site redesigned all the neck beards on here started shooting rocksalt at them and screaming "GET OFF MY LAW!!!"

      I suspect this site barely pays for itself. I do not anticipate any large site redesigns ever.

      Guess again! All the beta crap is relatively new as is most of what they shove at you when you use the nobeta option: http://slashdot.org/index2.pl?...\
      Old slashcode was much better in function then current, IMO. If you would like to further your "education" then you might want to visit https://soylentnews.org/ which is encoded in older, but with some modification slashcode. If you will notice it works just fine with https and you can leave javascript off there and browse very nicely without it, unlike the broken anti-AC visitor slashcode here at slashdot. For even further education I am sure some simple searches will turn up some variations on the source code that you can download and compare if you are that interested in it.

      Slashdot has basically crapped out since the Dice started rolling it over.

      Darn and I seem to be out of flame proof underwear.

    13. Re:HTTPS Everywhere by TimTucker · · Score: 1

      They can't inject into secure traffic. HTTPS solves this problem too.

      For cellular at least, Verizon keeps pretty tight control over what devices they allow on their network. All they would need to do is to start shipping phones with a Verizon root cert installed that can't be removed. Phone trusts the cert, Verizon proxy performs MITM on SSL traffic...

    14. Re:HTTPS Everywhere by TheGratefulNet · · Score: 3, Interesting

      quite a valid point!

      just like you can NEVER trust a windows (or mac or even linux box) that was not setup by you, especially if its a corporate box that was given to you pre-installed.

      almost every company of mid-size or larger preinstalled MitM certs for their spying firewalls. they don't tell employees that, but netadmins and sysadmins pretty much all know this.

      I work at a large networking company and they didn't tell me WHAT they do or HOW they'd spy on me, but I found out via a friend (in germany) exactly what they are doing. in .de, you have to disclose to the employees a lot more than the US requires you to do, and he relayed the info to me about how our corp laptops come preinstalled with corp spyware. ability to active mic, camera, screen caps, all that bullshit in addition to traffic logging.

      I'm a network mgmt guy and when I was out interviewing for jobs (the last few years) almost all of them involved DPI and MitM attacks, even though they tried to explain it away as 'troubleshooting information' and 'for the users benefit'. quite bullshitty but they said it with a straight face, like they believe their own BS.

      you guys have to start realizing that corp america is all about privacy invasion; of customers and employees, alike. if you have a corp laptop, do NOT login to your home email systems and keep your work laptops entirely clean of anything personal and home related. yeah, even if you see the lock icon on the browser, it means nothing anymore, in a corp LAN.

      --

      --
      "It is now safe to switch off your computer."
    15. Re:HTTPS Everywhere by Anonymous Coward · · Score: 0

      > Good idea, I just need to figure out what the http address for slashdot is...

      https://solynetnews.org/

      They've even got a it accessible as a TOR hidden service at:

      http://7rmath4ro2of2a42.onion/

    16. Re:HTTPS Everywhere by Harodotus · · Score: 1

      Well I have a free (albeit older) Slashdot account and it doesn't redirect me to http when i follow the https link above.

      I think they're just limiting non-logged in access to http, not subscriber (paid) only access.

      -Harodotus

      --
      Its not users who are broken, it's systems not taking account their likely behaviour and fixing it technically.
    17. Re:HTTPS Everywhere by _merlin · · Score: 2

      Any idea why they do this? Of all the sites to not to https...

      CPU load. SSL/TLS greatly increases CPU demands on the server(s). For a high-traffic site that costs real money.

    18. Re:HTTPS Everywhere by Coniptor · · Score: 0

      They want you to pay to use https.
      If you subscribe and login you can browse with https urls for as long as your session cookie is remembered/hasn't expired.

    19. Re:HTTPS Everywhere by Zontar+The+Mindless · · Score: 1

      And people wonder why I buy my own hardware for work, don't use a company-supplied laptop or phone, and always connect to the corporate net using a VM and never from the host OS...

      --
      Il n'y a pas de Planet B.
    20. Re:HTTPS Everywhere by watermark · · Score: 1

      There are tons of reports (just google them) of the server side cpu load being minimal to encrypt traffic. My guess is either the load balancing setup they have doesn't support SSL or their 3rd party ad network doesn't.

      In general, I think sites don't support https because of a) the extra cost of a cert, b) they don't care, c) the extra cost of a dedicated IP (SNI isn't supported on IE on XP). You can say "screw XP" all you want, but a good 20% still (of at least my traffic) comes from IE on XP.

    21. Re:HTTPS Everywhere by Anonymous Coward · · Score: 0

      Not true.
      The injection is done by a proxy box connecting the mobile user to the network.
      Https is not a problem, the xUIDH header is added after the device and before the https server, acting as a 'man in the middle'.
      The actual device in use is http://www.flashnetworks.com/Layer8

    22. Re:HTTPS Everywhere by Cederic · · Score: 1

      Soylent News can't even email a password to me. If I want to use their site, it's anonymous or not at all. Fuck 'em.

    23. Re:HTTPS Everywhere by Anonymous Coward · · Score: 0

      A solution is HTTPS-E addon should tell the browser to ignore security downgrade Redirects.

    24. Re:HTTPS Everywhere by cbhacking · · Score: 1

      a) is already taken care of; they have a signed cert in place and set up.
      b) is probably the main reason, but you would think that they would be more wise to what their user demographic wants. (But then, there's beta, so...)
      c) is not a valid reason. Leaving aside the fact that IE6 traffic has got to be absolutely miniscule on this site - which serves HTML and CSS than IE6 has no idea how to handle - those people could just go on using HTTP. We're not asking them to mandate HTTPS, just to allow it.

      As you say, the server load is pretty trivial. Even if you aren't using the new CPUs with hardware accelerated crypto, the vast majority of the CPU time to serve a web application over HTTPS is spent parsing requests and building pages, not doing crypto... and unless you have really excellent caching, the I/O time to do things like database access dwarfs the CPU time altogether. Using TLS typically imposes less than 5% overhead, often much less.

      --
      There's no place I could be, since I've found Serenity...
    25. Re:HTTPS Everywhere by cbhacking · · Score: 1

      Wow, really? That's several kinds of BS, that right there. Neither security nor privacy should cost money.

      Also, that's not mentioned on the FAQ under subscriber perks. In fact, the string "https" doesn't occur anywhere on the FAQ at all. Is it documented somewhere else that I just didn't see?

      --
      There's no place I could be, since I've found Serenity...
    26. Re:HTTPS Everywhere by cbhacking · · Score: 1

      I'm signed in, have an account that's nearly ten years old (not *as* old as yours, but still six digits), have Excellent karma (and have for years), have tried multiple browsers, and still get redirected every time. I'm not a subscriber, (on any accounts; I only have the one) but if that's the difference, I am pissed.

      --
      There's no place I could be, since I've found Serenity...
    27. Re:HTTPS Everywhere by Burz · · Score: 1

      Any idea why they do this? Of all the sites to not to https...

      CPU load. SSL/TLS greatly increases CPU demands on the server(s). For a high-traffic site that costs real money.

      This is 2014 not 2004; Most servers have CPU's with built-in AES acceleration. Unless the site gets lots of very short-term use from many different users, the impact of server load should be negligible because most of the crypto will be AES and not the initial public key stuff.

    28. Re:HTTPS Everywhere by Burz · · Score: 1

      Then you may like this... http://www.qubes-os.org/

    29. Re: HTTPS Everywhere by Harodotus · · Score: 1

      Hmm interesting. I was a subscriber many years ago before ad and script blocking technology. Maybe my browser (Chrome) and its plug-ins is the cause or perhaps it's something about the legacy status of my account.

      --
      Its not users who are broken, it's systems not taking account their likely behaviour and fixing it technically.
    30. Re:HTTPS Everywhere by Coniptor · · Score: 0

      You are correct that they do not come right out and say that in the faq. I'm not sure if they did in the past.
      However in the FAQ at:
      https://slashdot.org/faq
      At section Subscriptions with question:
      Why subscribe to Slashdot? Can't I read for free?
      You find the link:
      https://slashdot.org/faq#subsc...
      That takes you further down the page with more details where as you said it does not mention this.
      *It is an unmentioned plum.*

      While you are logged into your account observe on the upper right where I expect you have your Slashbox.
      If you don't then go enable it.
      With that enabled you have the default content that goes in your Slashbox and it lists your current Karma.
      Mine has been Bad since I think about 2007. Haven't seen a mod point sense.
      Below Karma you have three links:
      Journal Subscription Account

      Subscription is this link:
      https://slashdot.org/subscribe...

      Where in you read:
      Absolutely nothing about this!?
      Hrm. I could have sworn I read about this and didn't just figure it out on my own.

      Okay they either covered this before and removed it. Not sure and don't know why they would do that.
      Or I read this in a post several years ago and just assumed everyone I've been reading complain about this just didn't want to subscribe.
      I subscribed a few years ago and wanted encryption and also had trouble with this feature due to redirects.
      I resolved this by putting
      *slashdot.org*
      in my forced HTTPS NoScript settings and then added
      slashdot.org/my/login
      into the whitelist for the never force https list.
      Anytime my session/cookie expires I put in slashdot.org/my/login and then get redirected to a https slashdot url.
      Hope that helps you and many others and that they don't degrade this for some reason!?

  11. HTTPS everywhere by Anonymous Coward · · Score: 1

    Every person browsing the web today should be using the HTTPS everywhere extension.

    To forestall the typical slashdot objection: No, it's not perfect. That doesn't mean it isn't damned useful.

  12. Step #6 image is all wrong by HappyDrgn · · Score: 1

    Step #6 image should have been this instead:

    https://doodleaday.files.wordpress.com/2012/03/doodle-1016-money-bags.jpg

    I think it illustrates whats happening more appropriately...

    1. Re:Step #6 image is all wrong by Charliemopps · · Score: 1

      Step #6 image should have been this instead:

      https://doodleaday.files.wordpress.com/2012/03/doodle-1016-money-bags.jpg

      I think it illustrates whats happening more appropriately...

      Except, it's more like pennies. That's what's hilarious about all this privacy invading nonsense we've been subjected to. It's not valuable. They do not make more money with it. Sure, at first it sounds like a great idea. But the mountains of data it generates quickly become completely useless and you just end up sitting on it all and doing nothing with it. I've dealt with marketing people and seen them install their huge data tracking software packages that they paid fortunes for. Several years later and they just stare at the wall of text the software created blankly.

      What I've learned from the data? Most of the sites people visit are by mistake. Out of 10 links visited, 9 were closed within seconds without following another link and the last link was the page with our phone number on it. But all that generated about 100 rows in the table. Multiply that by thousands of customers a day and what do you have? A lot of useless data, that's what. You've no idea which pages they found interesting, dwelled on... were interested in.

    2. Re:Step #6 image is all wrong by BadPirate · · Score: 1

      Appropriate that you share the link HTTPS :)

      --
      - Holy crap, I've got MOD points! Who thought that was a good idea.
  13. How can I set Safari to default to HTTPS? by Anonymous Coward · · Score: 0

    Just wondering. Thanks!

    1. Re:How can I set Safari to default to HTTPS? by Anonymous Coward · · Score: 0

      You have to put https:// in front of all the website addresses you go to. If it doesn't load, that means the NSA is spying on you.

    2. Re:How can I set Safari to default to HTTPS? by jimmifett · · Score: 2

      If it does load, that doesn't mean the NSA isn't still spying on you...

  14. Wonder if a chaff approach would help by chefmonkey · · Score: 5, Insightful

    I wonder... if we wrote addons for popular browsers that would inject bogus X-UIDH headers into every request, whether we could make this kind of inappropriate privacy intrusion prohibitively expensive. If it works as he surmises, maybe we can overwhelm Verizon's ad exchange platform with meaningless data.

    1. Re:Wonder if a chaff approach would help by cbhacking · · Score: 3, Interesting

      This plan. I like this plan! Put a random value in the header on every request. If you're not on Verizon, it'll look like you are (but as a different person every time). If you *are* on Verizon, you may just confuse the software that is adding those headers, or that is logging them. Poison their tracking data with meaningless garbage, and make it *cost* Verizon money to try and track us.

      Well, that and use HTTPS everywhere possible, of course. But that requires that the sites you use allow people to do so (*AHEM* Slashdot, looking at you...)

      Oh, and don't use Verizon. That's the best way to hit them in the pocketbook, by far. I like the idea of sending the header even when you don't use Verizon though, as a general-purpose "fuck you!" to them.

      --
      There's no place I could be, since I've found Serenity...
    2. Re:Wonder if a chaff approach would help by Anonymous Coward · · Score: 1

      It's not going to matter. 1. Hardware is cheap and telcos have been working on scalability during the last century, since way before computing. 2. X-UIDH is only considered valid when coming from Verizon IP range.

    3. Re:Wonder if a chaff approach would help by Mr.+Sanity · · Score: 3, Interesting

      Since they're the ones adding the header, the client setting the header is futile. Verizon's version will clobber it.

      However, if you happen to run some intermediary servers that handle traffic once a backbone layer is crossed, then you can clobber their value.

    4. Re:Wonder if a chaff approach would help by Burz · · Score: 2

      No, not this plan! Since the modified tag is only transmitted from Verizon to advertising sites, Verizon could very easily just strip out all X-UIDH headers coming from you before adding their own.

    5. Re:Wonder if a chaff approach would help by Rich0 · · Score: 1

      However, if you happen to run some intermediary servers that handle traffic once a backbone layer is crossed, then you can clobber their value.

      I suspect that the only folks who care to do deep packet inspection at that level are the privacy-loving folks at the NSA. :)

  15. how much time it costs to make a truth by Anonymous Coward · · Score: 0

    I mean, truth as bolean is true, world revolves around spending time to find what is real when you are truthfull to it, but what computers do is basicly differently human nature itself, so internet also can't be taken as whole asimilation, of course, only if you want it to be like that, you basicly are not making websytes with more than expectation of what is truth.

  16. Spoof it by Anonymous Coward · · Score: 1

    Insert 10 random X-UIDH headers in the same place verizon will, randomize them seeded based on the date and device-id (not the time), what could they do?

    1. Re:Spoof it by Anonymous Coward · · Score: 0

      Depending on how the injection is being done the real header may be in a predictable place in the header.

    2. Re:Spoof it by Anonymous Coward · · Score: 0

      Right, so you have to find that, and put your headers there adjacent to it, or before and after if that's feasibly. I suppose they could always make it right before a specific field, so you know the last one before that field is the real one.

    3. Re:Spoof it by Anonymous Coward · · Score: 1

      what could they do?

      Log the one that stays the same. Duh.

      I prefer chefmonkey's idea.

  17. Could be worse by pushing-robot · · Score: 1, Interesting

    My router injects a unique identifier into every packet it sends. The manufacturer claims they can't turn it off. Yeah, probably under pressure from the government. But I'm building my own open source router that blanks out everything—MAC, IP, you name it. I'll be invisible to everyone. Take that, Orwellian bastards!

    --
    How can I believe you when you tell me what I don't want to hear?
    1. Re:Could be worse by Anonymous Coward · · Score: 0

      Blank out the router's NAT IP too, and I'm in.

    2. Re:Could be worse by CaptainDork · · Score: 1

      You'll be easily recognizable as the only surfer without fingerprints.

      --
      It little behooves the best of us to comment on the rest of us.
    3. Re:Could be worse by cbhacking · · Score: 1

      Does that unique identifier get passed down all the way to the server you're trying to connect to, even if you go through a proxy server or reset your router? This is significantly worse than MAC or IP addresses.

      --
      There's no place I could be, since I've found Serenity...
    4. Re:Could be worse by Anonymous Coward · · Score: 0

      Can't turn it off, huh? Time to turn *it* off, and ensure that you and nobody you know buys from them again.

    5. Re:Could be worse by SeaFox · · Score: 1

      I always find it interesting when people post thing like this and never mention the brand/model of the product so the rest of us can avoid it. It's like we've gotten so worked about lawsuits we censor ourselves now.

  18. Millenicom (Verizon Tower Reseller) Does Not by Anonymous Coward · · Score: 0

    I use Millenicom, which resells 20GB Verizon Wireless bandwidth in blocks. X-UIDH header is not set under their platform.

    1. Re:Millenicom (Verizon Tower Reseller) Does Not by Anonymous Coward · · Score: 0

      sadly you won't have millenicom for long: http://www.dslreports.com/show...

  19. As good a reason as any to switch by Anonymous Coward · · Score: 0

    My contract is up. Time to pick up an unlocked Nexus and find a MVNO I like.

  20. Filthy Ingrates by rogoshen1 · · Score: 5, Funny

    God. it's like you people don't even appreciate the value added service they are *GIVING* away here. Who wouldn't want to see more perfectly tailored and targeted ads -- some of which even include *VIDEO* again, completely for free.

    You have to pay for cable right? The same thing applies, you're getting the service you paid for (TV shows, home shopping channels) with the added bonus of free to view advertisements.

    In both cases they're simply giving away high quality, hopefully relevant audio and video. I think that's super generous of them.

    And for no charge! And yet, you people still bitch. Absolutely shameful.

    1. Re:Filthy Ingrates by sconeu · · Score: 1

      +1.

      The sad part is that some idiots will not see the implied <SARCASM> tags.

      --
      General Relativity: Space-time tells matter where to go; Matter tells space-time what shape to be.
    2. Re:Filthy Ingrates by oodaloop · · Score: 2

      My browser doesn't render sarcasm tags properly. It's really annoying.

      --
      Tic-Tac-Toe, Global Thermonuclear War, and relationships all have the same winning move.
    3. Re:Filthy Ingrates by cbhacking · · Score: 1

      ... I have this sudden urge to write a browser extension. I'm not sure *how* I want it to render <sarcasm> tags, but I think I do want it to do so. Just in case.

      --
      There's no place I could be, since I've found Serenity...
    4. Re:Filthy Ingrates by Anonymous Coward · · Score: 0

      sarcasm { font-family: "Comic Sans MS"; color: purple; text-decoration: blink; }

    5. Re:Filthy Ingrates by Anonymous Coward · · Score: 0

      Easy, just make the font use the sarcastic option. You know like bold, italic, underline, sarcastic.

    6. Re:Filthy Ingrates by Anonymous Coward · · Score: 0

      Make it blink so that when the reader double checks what the text said it disappears. It should be easy to wrap blink tags around any sarcasm section...

    7. Re:Filthy Ingrates by Anonymous Coward · · Score: 0

      http://www.flashnetworks.com/Layer8 is the device in use
      The intent is to have a second page on your phone that offers 'special offers' based on your location and interests.

  21. Just verizon wireless? by Anonymous Coward · · Score: 0

    Has anyone determined whether they are only doing this to their wireless customers, or are they doing this to fios customers as well?

  22. Assholes. by Anonymous Coward · · Score: 0

    Verizon is a bunch of assholes.

  23. Yes, use HTTPS by Anonymous Coward · · Score: 0

    Just install HTTPS Everywhere from the EFF : https://www.eff.org/HTTPS-EVERYWHERE

    It makes your browser try to encrypt all traffic, some sites break, but all good sites work.

    Also : Dump Verizon. LOL

  24. Don't use HTTP. Use HTTPS. by jtara · · Score: 2

    Don't want your carrier messing with your traffic?

    Use HTTPS.

    1. Re:Don't use HTTP. Use HTTPS. by Anonymous Coward · · Score: 0

      Verizon controls the devices allowed on their network, they could easily ship devices with a Verizon root cert that is trusted and proxy HTTPS connections transparently.

    2. Re:Don't use HTTP. Use HTTPS. by Anonymous Coward · · Score: 0

      Yeah, that's great. Shame almost no one bothers to run HTTPS on their servicers, and certainly not ad farms - which is what this is all about at the end of the day. Try to engage your brain next time.

  25. Hello Vodafone by wabrandsma · · Score: 5, Informative
    From: Using Browser Properties for Fingerprinting Purposes.

    Vodafone injects the X-VF-ACR header: 'Vodafone Anonymous Customer Recognition'. It is unclear what this header exactly does; all headers that have been seen start with the string "204004DYNMVFNLACR", followed by 16 X's, and are followed by a BASE64-encoded 256-byte cyphertext, which we were unable to decrypt. It has been suggested that this string might contain the SIM-card identifier (IMSI) or other personal information, as was found in a research conducted by Mulliner in 2010 [14]. Vodafone did not respond to requests of explaining this header. Nevertheless, the presence of this header, certainly identifies customers of Vodafone as being customers of Vodafone.

    1. Re:Hello Vodafone by Pikoro · · Score: 1

      Just checked. AT&T does this as well with an x-acr header

      --
      "Freedom in the USA is not the ability to do what you want. It is the ability to stop others from doing what THEY want"
  26. Who's the NVP now, huh? by Anonymous Coward · · Score: 0

    So Verizon, tell me, who's the narcissistic vulnerability pimp now?

  27. seriously... by Anonymous Coward · · Score: 0

    Google knows way more about you than Verizon ever will. Get over it, who gives a crap.

  28. RUN TOR by Anonymous Coward · · Score: 0

    that will cure the disease.

    1. Re:RUN TOR by Zontar+The+Mindless · · Score: 1

      that will cure the disease by killing the patient.

      TFTFY.

      --
      Il n'y a pas de Planet B.
  29. Wonder if a chaff approach would help by Anonymous Coward · · Score: 0

    The header is signed so the boundary of their system can reject it with a simple computation. They have not implemented well, but if they did random did would do little.

  30. Switch carriers by Ritz_Just_Ritz · · Score: 1

    Just another reason not to spend your money with Verizon.

  31. Telling The Story Backwards and Upside Down. by westlake · · Score: 3, Informative

    It's safer for a supermodel to walk down MLK in your favorite large city naked than a homely woman to walk from one end of Fort Hood to the other, wearing ACUs after dark. When soldiering becomes less of a duty and more of a way to delay starting out your life of dismal poverty, you start making the wrong kind of army.

    I have come to the conclusion that anything the geek says about women, rape or the military needs to be fact-checked.

    A cash-strapped female soldier told a Fort Hood hearing board Tuesday about how a noncommissioned sexual assault prevention officer on base forced her into a prostitution ring so she could buy groceries for her child.

    The private testified against Sgt. 1st Class Gregory McQueen during a proceeding similar to a grand jury hearing. McQueen could face some 21 criminal charges if he is slapped with a military court-martial.

    ''Basically, it was having sex with higher ranking officers for money," the woman told the board.

    The private, who was 20 and struggling as a single mother of a 3-year-old child at the time of the alleged prostitution, was granted immunity in return for her testimony. She told the board how McQueen snapped pics of her naked to distribute to potential clients. The two also had sex so McQueen could see how she would ''act out'' with clients.

    McQueen, who has since been relieved from his sexual assault prevention duties, faces charges of pandering, conspiracy, adultery and sexual assault.

    Another female private claims McQueen sexually assaulted her when he tried to recruit her into the military sex ring.

    That woman told investigators that McQueen ''preys on young females who are in bad financial situations and that he keeps their pictures on his cell phone,'' the Austin American-Statesman reported in December.

    Fort Hood sexual assault prevention officer ran on-base prostitution ring: witness [June 3, 2014]

    1. Re:Telling The Story Backwards and Upside Down. by DamnOregonian · · Score: 4, Informative

      I have a good friend there right now. There have been 2 attempts on her where she had to physically fight someone off of her, and the first 2 days of reception were sexual assault awareness classes where they're instructed to stay out of the dark and not go anywhere on-base that they're not familiar with or get into any cars they're not familiar with. No shit. On a US army base.

    2. Re:Telling The Story Backwards and Upside Down. by Anonymous Coward · · Score: 1

      Congratulation You have become the Colonial Redcoats ie. your army is scum but they are YOUR scum.

      Keep on worshiping them as heroes.

  32. Easy to kill this one by keyvin · · Score: 1

    This one is easy, easy, easy to kill. Your headers to the webserver are a copyrighted creative work if you customize them at all. Verizon is creating an unlicensed derivative work. Any legal eagles willing to run with this?

    1. Re:Easy to kill this one by Harodotus · · Score: 1

      Not really. Even if your derivative work idea was valid and could be used to stop Verizon, they would just update their Terms of Service (TOS) to explicitly have you grant them this right and waive any claims.

      Frankly, while i haven't checked, is very likely that their existing TOS grants them the right to make any change to your traffic they see fit, so it's likely that any derivative work would fail on it's face based on your existing contract.

      --
      Its not users who are broken, it's systems not taking account their likely behaviour and fixing it technically.
  33. Not all web sites offer HTTPS by tepples · · Score: 4, Insightful

    And lose access to several websites. Slashdot, for example, redirects HTTPS hits to HTTP for non-subscribers because ad networks have been slow to implement HTTPS. And a lot of shared web hosts don't support HTTPS because their policies haven't been updated in the six months since the last major Server Name Indication-ignorant desktop web browser (IE on Windows XP) reached end of support in April. But HTTPS support is the second biggest reason I stopped going to TV Tropes in favor of All The Tropes (after licensing).

    1. Re:Not all web sites offer HTTPS by Hypotensive · · Score: 1

      Just use Tor for those sites.

  34. Re:Is there a way to prevent this? YES by Anonymous Coward · · Score: 0

    Stop using Verizon.

  35. Class Action Lawsuit Time by Anonymous Coward · · Score: 0

    Every Verizon Wireless customer join in and sue them for the invasion of privacy that this is.

    Sue them out of existence.

  36. Chaf by Anonymous Coward · · Score: 0

    A technique of dumping crumpled bits of aluminum foil from B-29 aircraft while bombing sites in Germany during WW!! .

  37. Spoof it by flux · · Score: 1

    They could remove your headers and add their own.

  38. Just check "Do Not Track" checkbox in browser by TrollstonButterbeans · · Score: 1

    Then problem goes away!

    --
    Priest: "Universe from nothing, no laws of physics, sped up time"+ huge discrepancies. Creationism? No. Big Bang Theory
  39. Too low for what? by Anonymous Coward · · Score: 0

    Usually when people discuss military spending (or military resources in general) it is either "it should be higher" or "it should be lower" without specifying what's the current or the desired level.

    I had to look up the numbers and it seems that USA has 1.4 million active frontline personnel and another 900k of active reserve. That puts USA at 2.3 million men before having to resort to drafts. I understand that large portition of that is some sort of supporting staff but to me, as a layman, that still seems like quite a few men.

    So could you, for the sake of discussion, specify what is the 2.3 million qualified men too low for? Let's say that we make the qualifications a bit more difficult than they are now and weed out the people that, based on some psychological evaluation, are most likely to rape fellow soldiers (While accepting that there will be false negatives and false positives). Maybe that reduces the manpower over time to a mere 2.2 million qualified men? It stills seems like an adequate size for a military?

    The thing is, this isn't just about rape. Raping fellow soldiers is so obviously wrong and so widely judged that if the military can't police that, it makes me very uneasy about the way crimes against foreing civilian population, etc. are being policed.

  40. HTTP should be killed long live HTTPS by PeteBennett · · Score: 1

    Even though https isn't perfect as heartbleed and the various TLS bugs have demonstrated, it certainly would help. Perhaps slashdot should consider HTTPS!

    1. Re:HTTP should be killed long live HTTPS by Anonymous Coward · · Score: 0

      Your threat model is wrong. Using secure protocols cannot stop the ISP from collaborating with web sites to track users more aggressively.

  41. Slashdot redirects HTTPS to HTTP by tepples · · Score: 1
    Anonymous Coward wrote:

    Just install HTTPS Everywhere [...] all good sites work.

    You appear to call Slashdot not a good site. It redirects all HTTPS hits from non-subscribers to HTTP.

  42. Time and money to move to change ISPs by tepples · · Score: 2

    In order to stop being a Verizon customer, someone who requires home or mobile Internet access for his way of life might have to move his family away from territory serviced by Verizon, either as the DSL ILEC or as the only wireless carrier with acceptable coverage. Consensus in comments to previous Slashdot articles is that almost nobody is willing to spend the time and money to move just to change ISPs.

  43. Bury conduit and blow wires later by tepples · · Score: 1

    Ultimately, utility monopolies arise from cities' ownership of their roads. The solution is for a city to bury empty conduits when it repairs the roads, and then competing ISPs can blow their wires through those conduits.

  44. Ads would be mixed content by tepples · · Score: 3, Insightful

    For all users other than subscribers and karma-capped users who have checked "Disable Advertising", Slashdot is funded by advertisements. Using an HTTP ad network from an HTTPS site would be blocked as mixed content, and HTTPS support among ad networks is very new. AdSense, for example, didn't support HTTPS until September of last year.

    1. Re:Ads would be mixed content by cbhacking · · Score: 1

      While that's at least an understandable argument, I still don't buy it.
      1) People who want to block ads - a significant portion of the site - just block them. I don't imagine the intersection of "people bothered by /. being unsecured and
      would also block mixed content" and "people who aren't subscribers, Excellent karma, or just using an ad blocker anyhow" is that big.
      2) I have Excellent karma and disabled ads. I still can't use HTTPS. That's a really easy thing for them to check, if they wanted to support HTTPS at all (and this was their reason not to).
      3) Some ad networks don't support HTTPS (or at least, don't have a valid cert for their domain name because their content all comes from Akamai or similar), but some (as you point out yourself) do.

      There really aren't any valid excuses.

      --
      There's no place I could be, since I've found Serenity...
  45. HTTP-only ad network by tepples · · Score: 1

    Tell that to the operators of ad networks. If the ad network is HTTP while the rest of the page is HTTPS, it gets blocked as mixed content. That's probably why Slashdot redirects non-subscribers' page views to HTTP.

  46. A little information... by Anonymous Coward · · Score: 0

    First, so far as I know (and I know, since my company uses the X-UIDH header) the process to get access to the translation of this ID (which is an encryption generated by Verizon and translated through calls to an internal API) is about a 4 year contract negotiation.

    Secondly, the UIDH does rotate every week. In other words, it's useless as a tracking cookie unless you have the aforementioned contract with Verizon.

    Thirdly, the X-UIDH is supposed to be sent only to white-listed IP addresses, namely the IP address of companies with a contract. Verizon is having issues with this due to how they implemented X-UIDH and are currently doing tests where they've turned it on for whole markets on every call as a stop-gap.

    Finally, using this code for advertising is specifically forbidden by that contract.

    Yes, I'm posting AC as I don't want to endanger said contract negotiations for my company.

  47. Very clever of them to create new PII by laughingskeptic · · Score: 1

    Now under the law I believe they are required to protect this information. If the state of California has decided that a Zip code is PII, then this identifier certainly is. Roll the plaintiff's attorneys.

  48. Who does this & how do we find out? by JIDatiT4C · · Score: 1

    I am not a HTTP expert. My protocols are so old you probably won't know them!
    - How do I determine if my ISP is doing this? Will Firebug do the job or do I need a protocol sniffer?
    - How can we determine which ISPs are doing this?
    - How can I challenge my own or possible future ISPs?
    It strikes me that the first step is to document this. Will some kind (and expert) soul do this? Perhaps a Wikipedia page? If you don't grok Wikipedia then I (and may others, I am sure) can do the formatting if we have the information - with references.

  49. AT&T does the very same thing by Anonymous Coward · · Score: 0

    Go to http://www.xhaus.com/headers from your at&t device - disable wifi and your vpn ;) - you'll see two header fields Via, which emits your location and X-Acr which will never ever change (check back after a phone restart or go to a different header reporting site to check). According to AT&T customer support you cannot opt out of this.

  50. Is there a way to prevent this? by Anonymous Coward · · Score: 0

    There is a way to spoil it - a firefox plugin called trackmenot automatically takes random phrases from the ny times web site and others and searches for them on google, bing, and others thereby filling the search engines data with random crap. I am sure it wouldn't be hard for someone to come up with a plugin that goes to random web sites and clicks around a little to fill the Verizon ad caches with garbage.

  51. Wonder if a chaff approach would help by Anonymous Coward · · Score: 0

    Someone could make a plugin to do this. The firefox plugin trackmenot that issues random search queries to search engines to spoil their profiling. A couple of random web sites visited per hour and a few clicks to simulate someone browsing would poison their ad cache.