Zombie Cookies Slated to Be Killed
propublica.org
propublica.org
A company truly "committed to privacy" would have been insulted by Verizon's header manipulation and not have touched it in the first place.
And, as they have shown that they feel this type of method is OK, then what's to say they're not just making a slicker system behind the scenes? Verizon knows each subscriber->TCP tuple and can easily expose such an API for companies like Turn. Their actions show they are not opposed to such data sharing.
Asking the industry to self regulate, by ignoring verizons cookie or adhering to "do not track", distracts from the real problems that we need to solve technically.
Then they use Javascript to either read the tracking data directly and embed it into each request manually, or issue you a new cookie immediately if their tracking cookie is missing but the data is still accessible.
The main problem with these types of tracking is that for the most part browser manufacturers have no reason to restrict the use of such tracking techniques because it will affect their business models.
Other techniques abuse unforeseen uses of new standards such as HTML5 and WebSQL however as the W3C is your usual comity it takes years for any meaningful stance to be taken, and even then they still have quite a bit of conflicting interests.
The problem is that people want a free web, both as in free speech, and as in free beer and these world views tend to collide when pretty much everything out there is commercial. With how little revenue actually comes from web ads these days due to the constant devaluation of "ad clicks" companies go out of there way to squeeze every penny from each visitor. What you end up is with tracking, tailored advertisement and your habits being sold for data mining.
But hey the cat videos are still free!
If they change it to say `encrypt(tracking number + nonce)`, then it will be effectively the same cookie, but you wont be able to tell from the client perspective.
Now if only Verizon had shame.