Somebody’s Already Using Verizon’s ID to Track Users
propublica.org
propublica.org
I do not pay and then want to get tracked so that the provider or some other dickheads can data-mine me and make even more money. If I want this, I can choose a free plan (e.g. unlimited 3G, but with tracking).
About time everyone switches over to HTTPS with HSTS (so that no provider can perform a SSL MITM attack using its own trusted certs).
I was expecting the feds to bust their doors in. This is US Postal opening every package and rewrapping it to insert advertisements.
No, because ISPs aren't common carriers. It's a pretty common political position (among those who care) that ISPs should be common carriers.
Because Title II would put an end to all this shit.
The common carrier designation solves an entire slew of problems that were previously experienced with other technologies as well. It addresses privacy, liability for what you are delivering, etc.
>liability for what you are delivering
While I fear further regulation may introduce unforeseen consequences or inhibit innovation, I also fear doing nothing is proving to have problems as well. Regulations need to be written by people with the knowledge to be very precise about how things are done; we don't want mandatory ISP deep packet inspection (I already get letters from my cable company about HBO torrents that I download).
http://www.cisco.com/web/about/ac123/ac147/archived_issues/i...
Effectively, common carriers are protected from liability unless they know that what they carry is not legal.
<comment class="devils-advocate">
Given that logic, wouldn't it mean that an ISP is basically obligated to block traffic to, say, the pirate bay when they become aware of it?Effectively, the only sustainable way to maintain common carrier status is to maintain a deliberate ignorance of the legality — or lack thereof — of any traffic they might carry.
By mail volume the USPS is basically a government subsidized advertising delivery service these days.
This is why, despite being a big fan of NN, I wonder if it's going to be enough. We need more competition in markets, so when ISPs do chickenfuckery such as this, we can all vote with our feet.
https://status.modern.ie/httpstricttransportsecurityhsts?ter...
That's a joke. Android's permission model encourages users to freely give out their device serial number. The permission to read device ID is hidden behind the permission that allows an app to determine if you're on a call. A totally innocuous permission (which should not be a permission) smuggles in a very intrusive one.
Oh, and for a kicker, device ID permission also gives apps access to the number of who you call or calls you. So even security conscious users that check permissions can easily get tricked. "Sure, I want this flashlight app to turn off if I get a call so I don't blind myself trying to answer" - bam, you just gave away your permanent ID and call logs.
This could be a negligent incompetent mistake on Google's part, but it seems unlikely because it's so nonsensical and they've done nothing to rectify it in years.
Google promised at I/O that a permission system with more fine-grain control would come in Lollipop, but it's still nowhere to be seen.
(My Android's ID/serial number is 0123456789ABCDEF, the same as tens of millions others out there, so I'm not so worried about it. One of the perks of owning an unbranded generic Chinese device, along with a new random MAC address whenever I reset the WiFi...)
It's clear that these companies do not have their customer's best interests at heart, though I'm not sure that they ever have.
Google is a search engine and application provider, not a customer profiling service provider. Similar things could be said of Facebook, cable/satellite TV, automobiles, retail stores, government agencies. But all are focusing on collecting information and building profiles.
Wow, I was pretty ambivalent about SPDY/HTTP2 before but now I really hope it catches on.
I'm waiting for the first carrier to perform SSL MITM.
If a certificate is compromised, changing it means all pinned clients will get a huge warning. Either the user ignores the warning (in which case pinning is useless) or he doesn't and the site is harmed. Keeping a compromised certificate is even worse.
For WoT you first need a web of trusted individuals.
Unfortunately key distribution over insecure channels is still an unsolved problem.
Quote from someone working for a satellite internet provider for airlines.
Source: http://www.atis.org/openweballiance/docs/OWAKickoffSlides051... page 27
Nokia, funnily enough, did this on certain dumbphone models. Not a carrier, I know, but still interesting.
Yeah...except the NSA-agent-hiring IETF [1] gave up on that at the last minute.
http://arstechnica.com/security/2014/01/nsa-employee-will-co...
They seem to be deathly afraid of becoming "dumb pipes".
This, my dear friends, is why ISPs need to become regulated, government-owned utilites. Or has anyone seen regulators preventing experiments on self-driving cars and trains in order to keep train conductor's jobs?
Yes? Isn't that the crux of the Uber and AirBnB and Aereo battles?
Taxi regulations exist to prevent Uber's "surge pricing" model, thereby guaranteeing the customer the same price for the same distance, no matter how late at night it is or how drunk the customer is (at least in Germany; the taxi market as a whole seems to be broken in the US so that's another story).
Hotel regulations exist to protect other tenants in a building from the kind of bullshit which has happened multiple times: ever-changing, drunk tenants demolishing stuff, being loud, throwing sex parties, etc.
The only law area being "disrupted" where the existing regulations don't protect any legitimate interests aside from MAFIAA's Big Money is the TV distribution, and I'm sad that Aereo got problems there. But well, that's the area of Big Money, no chance to compete there :(
We also published a follow-up about how AT&T has said they will stop using the header: http://www.propublica.org/article/att-stops-using-undeletabl...
Is there a way to opt out of this?
I remember for a while the only way to change the User Agent header for iOS UIWebViews was to set the user agent header in lowercase, as long as it's after the actual header, PHP will uppercase both and the later one will win (for $_SERVER atleast, obviously this is PHP specific.)
Which may be a way around this. Run a local proxy that does stuff like use line folding, comments in headers, and other things to make their parse code abort. Of course, you then run the risk of breaking compatibility with actual HTTP servers (with good reason-those are bad features and such messages are probably an attack). And of course the ISP can always fix their code.
Make a web service that "coincidentally" uses the same header for something else, or add it as part of a new feature of an existing popular web service. Of course, it should have an app. Tell its users to complain to Verizon when the service breaks for them/the app doesn't work.
push "redirect-gateway" push "dhcp-option DNS 8.8.8.8"
You'd have to do something exceedingly clever like have the VM automatically route VPN traffic into Tor.
While I was definitely getting that header added to my outbound traffic two weeks ago, it is not happening to me now. I noticed that a day or two ago, and it still seems to be the case now.
AT&T's x-acr header, though, seems to be gone, as others have reported. They were about 0.5% of our traffic.
We are the product, indeed.
Currently they inject the header with an ID which changes e.g. daily and charge third parties to associate the ID with a profile. They can only inject in HTTP.
If instead the third party (e.g. an adserver) contacts a Verizon server with the IP (and port number in case of carrier grade NAT) on every request and that server gives back the profile and Verizon charges the adserver for this, then nobody would ever know and there would be not much protection against it (without a third party proxy or vpn to hide the IP).
Edit: apparently this is old and they may have stopped for the moment?
Are you sure you're not using any proxies, VPNs, or local wifi?
I have seen the header disappear for a brief period, only to return a day later. I've seen another user reporting that the header disappeared after they used all web-based opt-outs, and complained by phone... but then reappeared after traveling to a different region.
So there does appear to be some volatility and inconsistency in what Verizon is doing. Also, reportedly, government and some business accounts may be immune.
So keep checking, especially after travel: even if you haven't seen it so far, you might someday.
Update: I turned off Wi-Fi and still didn't find the header. I wonder if business vs personal accounts makes a difference? I'm on a shared business plan.
Update: Perhaps they are identifying identification sites and not tacking it on in those cases? Quite a stretch and tin foil hatish.
Update: Or perhaps someone else on the shared plan already opted out.
The ad-tech industry is targeting mobile advertising as the Next Big Thing, and they're right to do so. Anyone not tracking and optimizing ads toward the permacookie will be left behind.