Vodafone and Deutsche Telekom to introduce persistent user tracking
blog.simpleanalytics.com
blog.simpleanalytics.com
Fuck the ad-tech industry. Seriously. Is there any line they won't cross?
Now what are the communist reasonings behind Vodafone and Deutsch Telecom?
I think the ultimate sign a person is no smarter than a dog is their inability extend reason beyond their personal circumstances.
Singularity theory was probably wrong about a convergence of technology and information to form a super-intelligence. We're just converging on a super-efficient stupidity. Collectively we're like a flame that will burn out.
Do your goddamn job.
Literally the same, but probably very different: also in middle of Europe they have recently put me in a prepaid plan with free internet, and I find myself mindlessly scrolling when I have to do other things.
It's easy to not to distract myself when I have to pay for it, but for free it's much harder.
Counter-point: I get decent Vodafone (ex-Unitymedia) service.
Chatting about individual experiences with their service is probably a welcome distraction for them.
However, the tools which are offered by the official institution (Bundesnetzagentur), which should hold watch over ISPs and their service, do not even measure package loss. All they measure is throughput and ping. That alone is not sufficient for proper gaming. Also an average ping does not suffice, if there are short ping spikes, which average out over the measuring period. Basically I know more than the tool checks and the things the tool checks are often not the problem. Furthermore I have to go through a process of measuring so and so many times on a schedule. Add to that, that the ping spikes are sporadic, so that I would have to be lucky, to actually record any.
It is quite telling, that the official tool for measuring a connection offers so little statistics, that it is basically useless for people, who just need a _stable_ connection (no package loss, low ping, no ping spikes, OK-ish throughput). The official tool does not allow me to "prove it".
Basically, I could live with half my speed, if the connection was super solid. Throughput is not everything, unless you watch 4k videos all day, where there is lots of buffering happening anyway. Instead, they promise everyone (mostly people, who don't know much about IT) "high speed", at the cost of reliability.
I swore to never be a customer of them, after they screwed me over with a contract, then they eventually bought the major cable providers in Germany.
Now there is no way around Vodafone if you are in a region where cable is a better option than ADSL.
This can be and is easily disabled by a network or mobile configuration. Vodafone and Deutsche Telekom will just do the same. https://developer.apple.com/support/prepare-your-network-for...
The EU already has a lot of regulations in place that particularly hurt EU companies. GDPR for example is good for citizens but requires extra effort by companies. Small US companies can ignore it until they are big enough to expand into the EU market but small EU companies need to follow the law from the start.
It’s much easier starting everything with the law in mind than it is trying to retroactively apply it.
Another example - roaming charges dropped, this directly hurt all telcos big time.
The core of complying with GDPR are that you can provide a customer with a view of what data you hold on them, that you can delete it on request, that that data is accurate (and resolve if not), and if you’re doing anything non-obvious with it then you ask permission.
Designing for all of that from the start is relatively simple, particularly if you don’t go and integrate with every analytics/tracking SaaS under the sun.
I mean nothing stops even small US companies from planning for GDPR if they want to expand to Europe. There's no advantage for European companies here.
Vodafone and Deutsche Telekom have already filed a complaint to the European Commission to stop Apple from doing this.
To me, the is the master level of being an asshole Company. Not only your are abusing your customers, but you even sue to ensure they can't use their rights...Really no one with common sense should use one of these providers.
And I just imagine the senior manager there that decided or approved that. I hope so much that they are religious so that they know that they will go to hell directly!
The state actively protects them, with telecoms they can even setup their own rules and bylaws.
Some info here : - https://mobile.twitter.com/Chronotope/status/151390041563242...
It does, but if you read carefully you'll see there's no source saying that's how that's being implemented. It's all speculation on the author's part. In fact, one of the sources linked (wired.com) says the opposite, claiming that it's "based on a user’s IP address", which wouldn't require any HTTP header injection.
I already stopped trusting my ISP after it was announced that one of the three UK LTE internet providers had implemented the "log absolutely everything" clause in the snoopers charter... I guess now the cats out of the bag, Vodafone is likely the provider, since they can probably build upon what they have already implemented and sell it to 3rd parties. Pretty gross.
If I had to guess, they probably have a process similar to a cookie sync to obtain this id.
Sending just the IP would be useless, as the publisher already has the IP address (and sends it to bidstream, although it is truncated for privacy) so there would be little incentive to pay for the carrier data.
I worked in adtech for a while, and designed a system similar to this for a large UK carrier, although it never ended up being implemented as carrier was worried about optics.
The mobile providers use public spectrum that they license from governments.
Make it a condition of the license that they are only allowed to provide dumb pipes and PTSN services. It will reduce the value of the licenses, but not by much, because this is a service that they haven't introduced until now, so was not priced in to the original auctions.
Note that while using VPNs will assist, the telcos have your IMEI/PSTN numbers and assign the underlying IP connection (whether CGNAT or otherwise). So they can track the traffic at the L2/L3 level.
Then they can introduce a "merchant's service" that takes that traffic and maps it to an identifier that's provided to the websites/advertisers. Even if the L4 traffic is encrypted, the packets themselves could be extended to include the information they need before it exits their network.
In almost every discussion about VPNs people say something along the lines of: “you can’t trust the VPN provider more than your ISP”. This has always been a dumb argument and this completely proves it.
ISPs are the worst. There is now only one in the Netherlands that I might trust (Freedom), but even they are using the network of another untrustworthy one (KPN) so I doubt they’d be able to do anything about it if the network owner would start something like this.
A permanent VPN connection is becoming more and more logical as long as you trust the provider more than your ISP. I use Mullvad.
Please let’s stop perpetuating the “now you are just moving the trust from ISP to VPN-provider” as a counter argument to using a VPN and start using it as a main reason to use VPN. Sad maybe, but necessary.
Make data collection transparent, force companies to have opt-in for it and fine non-conforming companies.
Dt. Telekom and Vodafone recently lost their zero rating business (StreamOn or what it was called), they're in constant search for new sources of revenue.
Which was always in violation of net neutrality, by the way.
They'll do anything we'll let them get away with, no matter how shady. And I think the DT CEO would admit that.
Take the hit for once and do the right thing.
If this is your provider, give them the message.
This is the opinion of every German I've ever met, but as an outsider who formed their opinion before hearing the public's opinion, O2 gives me consistently better signal than my work phone where my boss decided to go with Telekom for some reason I have yet to ask after (but, knowing germans, I have a suspicion). This is in NRW mostly (both cities and forested area), can't remember if it was different in Frankfurt or Stuttgart, so at least not noticeably worse I guess.
The fairly recent (like, after people formed this opinion) merger with E+ probably helped, if I remember this provider's history correctly.
... maybe I should check whether they're doing this stuff too. My experience with them makes me believe "absolutely" (they're annoying to deal with, but hey, they're following the law).
In any case, multiplexing wouldn't stop the tracking, and they might as well figure out just as much about you.
Worked for a year then woke up day to have no phone number anymore and a completely rude support rep.
So, no. This isn't an option.
> Until now, these network operators did not interfere in the transmission and merely forwarded the data.
As it should be!
[0]https://www.zdnet.com/article/new-details-releasedsection-70...
Also. I don’t blame gpdr for shitty popups. I blame adtech. You can easily do websites without popups, they just don’t because they don’t respect their users.
Are there any other known cases, just not made such fuss about in other countries?
I know that the Croatian branch of the German Telekom is often used as a testbed for new developments, like their IPTV service or fiber overland, so I wouldn't be surprised if that already was reality in Croatia or other branches of one of those corps, just kept under the rug.
Https and DoH don't protect you in any way from the site operator wanting to serve you ads, and Vodafone will always know what IP:port they assigned you personally (well, your phone).
Tor, VPN and proxy services can protect from this, since they decouple your original request from what the server receives. Of course, the latter two can also sell your information instead of Vodafone.
This is a good point. However it's also worth pointing out that it's not a fruitless endeavour. There are very limited ISP options and none of them are transparent about logging but it's well known to happen. However with a VPN there are comparably limitless options.
They just need to be chosen carefully, and while you can never be sure it's better than the guaranteed invasion of privacy by your ISP.
Size of packets. Number of packets. Size of response. If the site content is static, that could give a good idea which page was loaded. Packet frequency. Enough to say if it's probably a page load or a realtime chat or a download, etc.
There are probably enough details in the handshake endpoints to tell them whether you visited Facebook in a browser or opened the Facebook app, for example.
What time you went to the site, how often you go there, how long you stayed. Vodafone mobile would know which cell tower(s) you are connected to. They can probably narrow in on whether you work and roughly where you work (cell towers you connect to during the day vs. at night) and from the land use in those areas they could guess roughly what you do. They know your home address for billing, so how expensive your home is and how desirable the area is, they could also guess at that from which cell towers you connect to.
What times you visit sites, whether you usually busy on a Friday evening or using your phone, whether you are regularly on gambling sites or regularly on crypto sites or healthcare sites.
Yes they can't see that you typed "glasses" into a Google search, but they can see you visiting google.com then visiting zennioptical.com. They can see you visiting Reddit and then whether you load a lot of imgur pictures or a lot of video traffic or load some fashion blogs and inferr what kind of things you're interested in.
Now ISP can simply read the data of active mappings from GCNAT. That is which user has which IP:Port pair in use and provide it for a price to anyone asking like the web server where user has connected.
(There is also the web servers IP:Port 443 involved. But that makes things more fine grained.
(But if the visited site is colluding with VF, your traffic is no longer protected from VF observation anyway)
1. The site that wants visitor information makes a CORS/third party request to https://vodafone.example/api/GetSubscriberInfo, which then fetches the associated account information and returns it to the site
2. The site notes the IP + port + timestamp that was used for the HTTP connection, and then asks vodafone for the information.
[1] https://assets.simpleanalytics.com/blog/2022-Trustpid/vodafo...
Simpleanalytics is Netherlands based, so guess this is EU focussed.
> Vodafone Group is currently conducting a test involving other European telecommunication providers including Deutsche Telekom and a few advertisers and publishers to investigate the benefits of a new technical solution to facilitate digital advertising and marketing.
Something additional will be required to stop this tracking. As it stands right now some European countries have started forcing ISPs to save logs, that’s actually worse. We must make sure that it’s well understood that the public does not want these policies. The public must also deny any party their vote if fixing this is not in their agenda. Politicians are getting away with slowly eroding our freedoms without many people noticing or speaking about it, that has to change. We need to let them know that they have zero support from us if they decide to continue in this trajectory.
I thought the GDPR didn't allow signing away of privacy? Because if it does, then it's utterly useless - every webpage comes with a 100-page terms of service these days.
> As it stands right now some European countries have started forcing ISPs to save logs, that’s actually worse.
In fact the European Court of Justice declared that illegal [1], yet many countries simply ignored that ruling. You would think this would result in a large media assault about "subverting the rule of law", but I guess that's only a concern when they dislike the one doing the subverting.
[1] https://www.reuters.com/article/us-eu-court-privacy-idUSKBN1...
If that was the case Europeans wouldn’t have been able to use services like Facebook or iCloud.
> In fact the European Court of Justice declared that illegal
For example, Sweden did it shortly after an ISP Bahnhof advertised to its customers that it would not save logs. What seemed at the time to have fuelled this whole thing was mostly entertainment companies pushing these policies against European countries to crack down on piracy. Obviously an unsuccessful project. Many of our politicians traded our freedoms for the sake of the entertainment industry not losing money (supposedly). It didn’t serve its purpose, rather it just gave the government(s) more power over the people.
I would assume the EU would act much faster than the US to add regulation against this behavior.
Telcos are not giving anything except the IP address. If you go to other websites and don't provide your data to them, all they will have is an identifier about the IP. It is that data that can be managed under GDPR, but IP in isolation means nothing.
I stand by what I said: IP addresses, by themselves, are not PII. To become PII, it needs to come with the data from the person visiting the website.
I suggest you let go with the pedantic posturing, and if you really think that GDPR has any way to actually stop these new actions from the EU telcos, go ahead and initiate legal action against them.
> GDPR has nothing to do with it.
This is false: if they use the IP address to match the website visitor with the ISP customer, GDPR is very much relevant as GDPR restricts the use of personal data (including IP addresses) like this.
The networks are in the clear.
Also, as far as I know, PII is a US concept and appears nowhere in the GDPR.
Another way that I can argue for this interpretation is simple: if you want connect to a hotspot in Germany, no one asks you if you opt-in to sharing your IP addresses. These, by itself, are considered "required information to appropriate service" (or something equivalent in legalese).
The third argument I can give is a bit circular: if GDPR had any way to rule this illegal, it would already have been met by huge outcry from the proper privacy NGOs. If it has gotten to the point where the companies are announcing tryouts, it means that the networks are confident enough that they are (at least in regards to GDPR) legally in the clear.
All in all, I hope that people crying for regulations and government intervention could understand once and for all that the laws that get approved are never going to do what they wished it did. I already got into plenty of arguments here with people that believe that GDPR is effective to protect users, but this is just yet-another example of regulatory capture.
1. Courts and legal teams don't always agree. Also, privacy scenarios are nuanced: when something falls under GDPR, it's not automatically illegal and you don't necessarily need to ask for consent either or even list it in your privacy policy. You need to read what the GDPR says and see whether you are within the lines or if you need to adapt your business model, processes, tech and/or disclaimers.
2. Connecting to a hotspot does not automatically mean collecting or sharing your IP address: Yes, a hotspot needs to store the DHCP lease while it's active and the MAC address while there's traffic, but GDPR often allows such processing that is limited to what is technically necessary and obvious. It would be different if the hotspot stored the data for longer time, shared it with third parties and/or used it for other purposes. Selling data without user consent is typically illegal.
3. We don't know enough about these tryouts to assess how they plan to align with GDPR: perhaps they'll ask for consent, perhaps they don't use IP addresses, perhaps they plan to bargain a deal with the governments or pay the fines.
4. We need effective laws and luckily some laws are effective. Privacy laws and GDPR are somewhat unsettled and the ultimate effects remain to be seen, but EU courts have already ordered some significant fines in cases that have made sense so I'm still optimistic.