There is no way most customers are informed and intentionally consenting to them tampering with the HTTP requests they send to include their customer ID.
The obvious expectation of a customer of an ISP is that it sends the data through unchanged.
There is no way most customers are informed and intentionally consenting to them tampering with the HTTP requests they send to include their customer ID.
The obvious expectation of a customer of an ISP is that it sends the data through unchanged.
There really should be provisions in the telecom bill that data traffic is to remain absolutely untouched.
Just imagine phone calls where mentioning the word "pizza" would trigger an advertisement being injected into it.
If they want to make some possibly non-standard protocol adjustments they mutually understand, they should be able to inject it, too. Researching the protocols/crypto to understand that more and trying to produce a POC are side-projects on my list, maybe some day.
The root of the issue is that your ISP often knows who you are, every site you connect to knows who your ISP is, and they have incentives to trade notes on you and few reasons not to.
Most ISPs will use tracking at a much lower network layer and provide APIs for partners to match up IDs on demand. No need for HTTP headers.
[0]: http://arstechnica.com/security/2015/02/lenovo-pcs-ship-with...
I remember it, because I had it sitting on my desk for a week before I got around to following the instructions.
Not saying good/bad - just how they treat it.