Verizon fined $1.3M for supercookie header injection [pdf]
transition.fcc.gov
transition.fcc.gov
Interestingly it doesn't directly fix the problem either (although it wrecks the current free-profit model, yay!), "To settle this matter, Verizon Wireless will pay a fine of $1,350,000 and implement a compliance plan that requires it to obtain customer opt-in consent prior to sharing a customer’s UIDH with a third party to deliver targeted advertising"
But lest anyone think this is a UIDH prohibition, the next line goes on to say customers must at least have the ability to opt-out from internal Verizon usage, meaning the UIDH will be there (unless the customer opts out) and that a persistent, unique identifier that follows the user wherever they go is permitted. This ruling is primarily about Verizon sharing the targeting information: Verizon is still permitted a persistent attack on their users, but they are now only permitted to sell customer data on an opt-in basis. Ad-networks will have to do their own tracking themselves for everyone else.
Hopefully Verizon's profits from this schtick are shorn from this shift, to a degree where they give up this disgraceful corpoate panopticon they've been going to the bank on.
Supercookies makes this a big deal.
You made my point even stronger.
Now I know why everyone was staring at me when I was on my way in from the airport...
Let's say it was only 1 million, so not even $1.50 each. Cup of coffee for same one person, nearly 200x more.
I'm not making a value judgement on whether that's good or not. I'm just making a factual statement about the way the US justice system works.
Came here to say exactly this — except that it's even worse than your numbers suggest: some form of the UIDH has been in play since at least 2012. If you amortize the fine across the lifetime of the program, a mere $1.3m is an obscenely paltry penalty.
These "fines" will never deter bad behavior until they have some teeth. When VZW takes in more in the time it takes for me to let a call go to voicemail than they were fined for this crap, I think the take-away has to be that the regulatory bodies are pretty much, "That's nice, son. You run along and play now" over it.
That number would be way higher than 1.3m.
Verizon's profits for 2015 were $4.22bn. That makes it a 0.03% fine.
But that's still not close enough, because this infraction was in "Verizon Wireless", not the entire company. So to really get a sense of its relevance, you need to figure out what the profit of that arm of the business was.
I can't find that number anywhere. Anybody got a hint?
All I know is when I'm fined, there's a possibility that it might be the last straw. The last straw to homelessness.
When a rich man, or remotely successful corporation is fined it's just someting to talk about.
It seems to violate one of those admendments that people seem to forget about--the 8th? It doesn't matter because nothing will change.
But with the usual limitation of a maximum of 360 days and the min/max limits being 5/30'000 EUR the absolute amount of a maximum 360-day fine can vary between EUR 1'800 and EUR 10'800'000.
Such systems can be made, they can work and I think they can be made loophole free.
If you do propose to hold the entire company accountable for any action taken in its name, then consider what you are enforcing: this would mean companies would be immediately obliged to disempower their entire staff from making decisions at any level, and require review and approval for all actions, to make sure that nobody ever makes a mistake that could be punitively expensive.
Neither of these is going to turn out to be a simple solution to a complex problem.
Worse, you can't even use a simple rule here, because what do you do about companies that aren't making a profit? Do they effectively have carte blanche to violate the law in order to improve their situation? That's probably not what you want, so you'd end up with some complicated mix of both systems.
Deciding this number is beyond my economics skills -- and quite beyond my point -- because I want to say that it is more reasonable to base the fine on the actual violation and not the business as a whole.
Of course.
this would mean companies would be immediately obliged to disempower their entire staff
No.
Their entire staff is already "disempowered" to make decisions that could put the company in legal trouble. Also this is intended, not merely reckless. Do you really believe this was some nobody's idea? Come on!
Please, someone with real legal knowledge could you explain why this is not like Volkswagen.
I suspect that privacy violations are not quantified or else a "class action" would dry any and all the profits.
How about every line of code that you write being reviewed by legal to make sure it was within the bounds of the law?
There's plenty of scope here for a far more defensive position on ensuring compliance. That is what you would expect and desire from any attempt to massively increase the liability of errors, no?
OK then.
I don't know why I thought it was about a deal of hundred of thousands or maybe millions of dollars affecting customers' privacy :->
To be serious, I think you're making an arbitrary destinction.
I realize it may emotionally feel good to demand larger fines, but I'm not sure it would have all that great an effect above and beyond what it already has. And the HN gestalt would be among the first to complain about what happens to the workers of Verizon if a fine that actually did greatly hurt them was issued, so "much larger fines" could well go to a negative value to the HN gestalt if a full accounting is done.
Compared to cartel price-fixing, Verizon's UIDH insertion is actually much easier to detect. In fact, anyone can do so just by looking at their access logs. I think that, more than fine size, will be the primary reason that they won't try this again. That's not to say they won't play other games, however.
Anyhow, if you really want to change a particular behavior, class action suits offer a much more attractive option where they're possible. They don't really benefit the class members financially (they're not supposed to), but they are one hell of a big stick. And historically, a very effective one at that. Even when companies prevail, they tend to take notice and often change the behavior in question.
If you only fine for directly provable damages you encourage cheats who find new hidden areas, and if you don't punish all offenders a certain base amount you encourage those who cheat for indirect gain (hard to quantify at trial) such as market share.
And to actually change behavior, attack the leaders directly. Corporate fines mean nothing! They're usually not even relevant to the directors and officers compensation. Prove conspiracy, force the company to withdraw legal aid, and attack their personal assets.
http://finance.yahoo.com/q/is?s=VZ&annual
The best numbers I can locate indicate Verizon Wireless is generating well over $20 billion per year in operating income.
Out of their nearly $18b in net income the last four quarters, wireless would pretty much have to be 75%-90% of that. The numbers before the Vodafone / VZ Wireless sale, indicated the wireless division was a huge share of their income.
I would say, to my defense- if a company is in the red, would a violation mean they get a negative penalty? So is there a linear fee = rate * profit + base penalty, or is it not a linear fee structure you are supposing?
I don't see why a violation would be tied to performance, frankly, but I also would not try and argue that you are "wrong" either, it's just not how I would figure it. I'd also tend towards thinking the choice of a 0.0010% revenue fee, if we want to be accurate about it, rather indicates that it was indeed picked against revenue, rather than merely coincidence, but again I wouldn't claim to be right or that people who wanted to figure it differently were wrong.
That seems silly - it'd be a huge incentive to misstate profits. A "growth" company would claim zero profit - and probably a net loss. (Negative fine?)
Imagine if someone robbed a bank but argued they should only be forced to pay back a little because they spent most of it on the getaway car which was destroyed in the escape attempt, negating most of the profit.
The correct way to do it is to remove all the gross-profits that the company improperly collected - negate all benefits they got and then add a hefty fine on top.
And as for which piece of the business did the crime - image if I could blame just my hands for picking the lock, thus claiming my body should only be fined lightly... Obviously the fine should go all the way up the chain, multiplied at every level, because there's an expectation of due-diligence and if that's being intentionally ignored it's an affront to the state and the protections granted to legal corporations.
The fine should probably be quintupled at every level because the indiscretion was by a subsidiary and wasn't caught directly or in oversight.
1. What about if the benefit/income from the evil is expected to arrive after being caught and fined, rather than before?
2. What if the purpose is actually harm done to a competitor's long-term-growth, to indirectly increase future market-share?
It's interesting to look at it in political terms. A modern presidential campaign costs about a billion, i.e. less than one day per election. That's $7.50 for each voter in the last election, or likely more than $750 for each "undecided" voter in a competitive state.
And then you learn that lesser politicians provide as much as 40x returns...
http://abcnews.go.com/Politics/story?id=1667009I'm very glad to be wrong here. :) Thank you all for your support, and I'm sorry to have spread misinformation so far; it was not my intent!
Always using a VPN (or SSH tunnel) solves most of the problems.
$ ssh me@example.com -4ND 127.0.0.1:1080
But you'll need to make sure ppp(8) ignores the HLDC errors they inject
into long standing sessions. It will work if your settings and chat
script are correct.Lastly, check your contract; you might be one of the lucky ones who have the clause stating VPN traffic is not counted towards your bandwidth cap and/or rate limit.
[0] https://www.eff.org/deeplinks/2016/01/eff-confirms-t-mobiles...
http://www.spectrumgateway.com/t-mobile-700a-spectrum
Band 12 is rolling out pretty quickly and is spectrum that allegedly helps with a lot of issues caused by buildings / dense urban environments / long range / etc. I can't confirm personally since I don't own a device that supports LTE band 12 (purchased before TMo bought this spectrum....) but reports seem to be very positive.
If the streaming service doesn't do this, you just get a terrible experience (buffering... buffering... buffering...).
Buffering is a terrible experience everywhere.
On my desktop, I'd rather wait to get the best quality video that I can get. On mobile though, I probably prefer for video to start NOW at a lower bitrate if need be. It will save bandwidth, and battery, and time and the quality is probably good enough.
But anyway, why not download to desktop, and then transfer to mobile device? Destroys spontaneity, I know.
It's exactly that. I'm sitting in a waiting room or the departure gate at the airport flipping through Twitter or Instagram and a click on a video. I don't need that 6 second video to play in 4K. That it runs instantly is the most important quality, IMHO.
In contrast, the super-cookies were only discovered by people noticing unexpected headers in the requests their servers were receiving. There was no pre-announcement and it took publicity to get opt-out instructions.
VerizonWireless, whether via a "smart" phone or a dongle (i.e. 3G EVDO or 4G LTE via USB usually, or PCMCIA historically) operates as a plain old modem connected to a serial port. To connect with a UNIX system, you need ppp, either in kernel or in userland. You also need a "chat script" which is the AT Commands needed to set up the connection.
Once the connection is up, create a SOCKS proxy bound to localhost with ssh(1) by using the '-D host:port' flag. You could use another type of secured connection like OpenVPN or IPSec tunnels, but ssh(1) is by far the easiest.
The one thing I've never figured out is the exact AT Commands necessary to update the PRL (Preferred Roaming List), but that only needs to be done every few years if you don't move around the globe too much. The cell tower leases are usually 20 to 30 years, so they stick around for a long time. Unfortunately, if your PRL gets too far out of date, VerizonWireless can prevent connections, so occasionally you need the verizon software to update it.
* * *.
https://news.ycombinator.com/formatdoc
You can write a single asterisk in "code" format with two leading spaces on a line.
*22898
That should work.> 16. Termination of Investigation. In express reliance on the covenants and representations in this Consent Decree and to avoid further expenditure of public resources, the Bureau agrees to terminate the Investigation. In consideration for the termination of the Investigation, Verizon Wireless agrees to the terms, conditions, and procedures contained herein.
Verizon has agreed to pay $1.35M and will likely notify the FTC by mail if it makes a change. It has agreed to abide by the law. If you put this in perspective, this is way more than a slap on the wrist. If we assume a gb costs ~$10 and an average user uses ~6gb then:
($1,350,000 fine / $10/gb) / (6gb/user * 12months) = 1875
This is almost very nearly 1900 people! A huge number. Obviously this is back of a napkin, and the actual size of headers is pretty negligible so there isn't any sense in backing that out of the calculation, because the users already paid for the bandwith.
Plus, verizon is literally the only company out of hundreds of providers doing this. Surely between the weight of this fine and the competition the company will go bankrupt soon.
Big win! Say what you want about the FTC but they closed down the investigation saving an untold number to the US tax payer, Verizon is forced to break the bank, and the response time was rapid, 4 years open shut.
The FTC has been super sharp on policing the industry, by allowing the Governement to subsidize huge swathes of infrastructure costs and selling a finite amount of bandwith, they have been able to keep companies on their toes, not allowing any one company to own telephone, wireless, and internet capabilities.
I hope they can keep this up because Verizon is the only bad actor in the entire space, so it is pretty much all taken care of now.
We must leave some space for wit and ambiguity in our discourse.
Since they broke that agreement, they had to pay. 10b is a big risk to take, and 1.3M is likely to panic the market. So while I am happy to see them go bankrupt, I could only imageine the chaos that would ensue if taxpayers had to try and resell that to someone.
If you asked those 190million people whether they would rather have $60 to sell the bandwith or have the country pay to build them an entire wireless network, legislate on their behalf, and limit most of their future profits tax burden, while allowing them to make a profit, and then inject and sell adverts, no brainer, $60 up front.
They are just a Unicorn company anyway, lets see if selling a core service you got for free into an impenatrable market is a good business. Can't wait to see these guys on http://ourincrediblejourney.tumblr.com
[0]http://www.fiercewireless.com/story/verizon-aws-3-we-have-le...
Computers are really the thing that make aggregate petty injustice a workable business model, because doing any computation millions of times with humans would cost far too much. This is one reason why dealing with the problem is actually a hacker/programmer moral imperative.
The last piece of the puzzle is why the FTC, SEC, etc. are so ineffective. These are the police of big business. Why are the police of individuals so harsh and powerful, but the police of business so weak and ineffective? I think it has to do with the politics of ignorance. There is no political pressure on the FTC to do it's job; it's too far removed from any elected official. No-one is going to pick the next president based on who they appoint as FTC chairman. One of the reasons is that the country is divided on regulation itself, which means that a large fraction of people, even the victims of petty injustice, would prefer that Verizon simply get away with it. These are the same people who would interpret a harsher penalty as an "anti-business" Obama/Democrat move, instead of simple enforcement of the law.
It's the 21st century and I think it's time that we enumerated some new rights in the face of unprecedented assaults on our freedoms. There needs to be the equivalent of a "fiduciary responsibility" for communications companies. People should not be allowed to give away their legal rights (the right to file class-action lawsuits). The justice system needs to be reformed, with technology and simplifying policies, to make it much faster and much much cheaper. (Not quite related to this case, but our personal devices that represent a very real extension of our minds should be absolutely protected from intrusion.)
The only recourse available within the given legal system. It is the legal system which limits our recourse against aggregated petty injustice, and so if people cared enough, the system could be changed or bypassed. The bigger problem is people just don't care about the many small problems... they really don't care about most big problems either. Some days I look at the apathy and wonder if I should just sign up alongside the likes of Verizon and try to profit off the apathy.
That's a very succinct and clear way of putting it. I wonder if there is an essay or other origin for the particular term you are using?
"Overall, Verizon reported a profit of $4.22 billion" reported by forbes for the 2015 operating year. That is profit, not revenue.
So, 1,300,000 / 4,220,000,000 = .000308 ouch..
[1] http://www.clarkhoward.com/how-opt-out-verizons-super-cookie...
Amusingly, they don't do it for "government or enterprise" accounts.
Is there any reason why Verizon would even bother to comply??
Just wait and see what happens if you get another suit that penalize you 0.01%, then comply.
I'm being sarcastic of course.
Analytics and ad operators, social media firms, and other data exchanges can identify you using this, and they can use this information for tracking what you say and do online.
Verizon has been in business with these companies to sell your identity to them -- Verizon is effectively including your name, address, Facebook account, and email address with every HTTP request you make. Again, this applies across all browsers and devices, and you cannot opt-out.
In some sense it's a bug in client software, that allows information to be stored for eventual inclusion in future requests (i.e., like a regular browser cookie), but outside the ability of the user to monitor or delete (unlike a regular cookie). For some time people mostly blamed this on Flash, but there are probably other ways for old and/or strangely-configured clients to screw up like this.
Besides that, ignorantia iuris nocet. Governments don't have problems with fining individuals unaware of arcane and complex laws. Why would we feel sorry for unscrupulous corporations?
the guy who was forced to write the code didn't speak to their managers about potential implications
That isn't really the way things work in an agency/Fortune 500 relationship. What really happens is something like:
-> the development manager attempts to translate the implications of said software to an account manager who is directly responsible for client communication -> the account manager has little idea of what the development manager is talking about, which does not stop them from attempting to translate in turn to the client's marketing team -> the one tech representative from the client company listens to the translation in abject horror, knowing that any questions they ask will never be adequately answered -> everyone goes out for drinks on the agency's tab
This isn't a raging critique of the process, it's just what normally happens.
That said, Verizon got fined for a good reason.