Verizon Injects Unique IDs Into HTTP Traffic
An anonymous reader writes: Verizon Wireless, the nation's largest wireless carrier, is now also a real-time data broker. According to a security researcher at Stanford, Big Red has been adding a unique identifier to web traffic. The purpose of the identifier is advertisement targeting, which is bad enough. But the design of the system also functions as a 'supercookie' for any website that a subscriber visits. "Any website can easily track a user, regardless of cookie blocking and other privacy protections. No relationship with Verizon is required. ...while Verizon offers privacy settings, they don’t prevent sending the X-UIDH header. All they do, seemingly, is prevent Verizon from selling information about a user."
Just like they said they would.
This should be illegal. People have a right to try and avoid being tracked. There has to be a way to prevent this. I'm a sysadmin, not a network guru, so I will defer to those smarter than me here...
Will tell them to go fuck themselves on this, and make them stop...
They should offer this to the user as an option, where the user has to pay less when tracking is enabled. Otherwise this is abuse of market power to make users agree to being tracked.
They can't inject into secure traffic. HTTPS solves this problem too.
I'm on fios and just checked headers, nothing like this (yet).
I wonder... if we wrote addons for popular browsers that would inject bogus X-UIDH headers into every request, whether we could make this kind of inappropriate privacy intrusion prohibitively expensive. If it works as he surmises, maybe we can overwhelm Verizon's ad exchange platform with meaningless data.
If it does load, that doesn't mean the NSA isn't still spying on you...
God. it's like you people don't even appreciate the value added service they are *GIVING* away here. Who wouldn't want to see more perfectly tailored and targeted ads -- some of which even include *VIDEO* again, completely for free.
You have to pay for cable right? The same thing applies, you're getting the service you paid for (TV shows, home shopping channels) with the added bonus of free to view advertisements.
In both cases they're simply giving away high quality, hopefully relevant audio and video. I think that's super generous of them.
And for no charge! And yet, you people still bitch. Absolutely shameful.
Don't want your carrier messing with your traffic?
Use HTTPS.
It's safer for a supermodel to walk down MLK in your favorite large city naked than a homely woman to walk from one end of Fort Hood to the other, wearing ACUs after dark. When soldiering becomes less of a duty and more of a way to delay starting out your life of dismal poverty, you start making the wrong kind of army.
I have come to the conclusion that anything the geek says about women, rape or the military needs to be fact-checked.
A cash-strapped female soldier told a Fort Hood hearing board Tuesday about how a noncommissioned sexual assault prevention officer on base forced her into a prostitution ring so she could buy groceries for her child.
The private testified against Sgt. 1st Class Gregory McQueen during a proceeding similar to a grand jury hearing. McQueen could face some 21 criminal charges if he is slapped with a military court-martial.
''Basically, it was having sex with higher ranking officers for money," the woman told the board.
The private, who was 20 and struggling as a single mother of a 3-year-old child at the time of the alleged prostitution, was granted immunity in return for her testimony. She told the board how McQueen snapped pics of her naked to distribute to potential clients. The two also had sex so McQueen could see how she would ''act out'' with clients.
McQueen, who has since been relieved from his sexual assault prevention duties, faces charges of pandering, conspiracy, adultery and sexual assault.
Another female private claims McQueen sexually assaulted her when he tried to recruit her into the military sex ring.
That woman told investigators that McQueen ''preys on young females who are in bad financial situations and that he keeps their pictures on his cell phone,'' the Austin American-Statesman reported in December.
Fort Hood sexual assault prevention officer ran on-base prostitution ring: witness [June 3, 2014]
Where did you check from? You don't see the headers on your end; they're only added at the ISP gateway. Unless you were able to bounce a request off an external web server and see the headers that it *received* - which don't have to be the ones you sent - then you don't know. Oh, and don't use HTTPS for the test, since they obviously can't modify those requests.
There's no place I could be, since I've found Serenity...
And lose access to several websites. Slashdot, for example, redirects HTTPS hits to HTTP for non-subscribers because ad networks have been slow to implement HTTPS. And a lot of shared web hosts don't support HTTPS because their policies haven't been updated in the six months since the last major Server Name Indication-ignorant desktop web browser (IE on Windows XP) reached end of support in April. But HTTPS support is the second biggest reason I stopped going to TV Tropes in favor of All The Tropes (after licensing).
I just checked using http://centralops.net/co/ over my Verizon mobile phone and sure enough there is the X-UIDH header. Well, this cements my plan to switch carriers in a month when my contract expires. Any tips on moving to a pay-as-you-go plan that lets me keep my phone number?
This posting is provided 'AS IS' without warranty of any kind, implied or otherwise.
In order to stop being a Verizon customer, someone who requires home or mobile Internet access for his way of life might have to move his family away from territory serviced by Verizon, either as the DSL ILEC or as the only wireless carrier with acceptable coverage. Consensus in comments to previous Slashdot articles is that almost nobody is willing to spend the time and money to move just to change ISPs.
For all users other than subscribers and karma-capped users who have checked "Disable Advertising", Slashdot is funded by advertisements. Using an HTTP ad network from an HTTPS site would be blocked as mixed content, and HTTPS support among ad networks is very new. AdSense, for example, didn't support HTTPS until September of last year.