5 ms·
The article mentions they are injecting a http header, so shouldn't https be enough to prevent tampering?
by moehm 4y ago
The article mentions they are injecting a http header, so shouldn't https be enough to prevent tampering?
- turtleman1338 4y agoYes, you can not just inject a http header when using SSL without breaking it.
- lakomen 4y agoThat's what I wonder, how will they actually do it?
- tsimionescu 4y agoThat's only about how Verizon did it back in the day. They don't explain how Vodafone and DT are planning to technically achieve it, but it could simply be related to IP or similar lower level protocol addresses from 4/5G. As network operators, they have access to the Account:IP mapping, they don't necessarily need to inject anything special in the packets.
- tomxor 4y agoYup, there is no way to hide basic packet information from your ISP without some kind of tunnelling like Wiregaurd or TOR. I already stopped trusting my ISP after it was announced that one of the three UK LTE internet providers had implemented the "log absolutely everything" clause in the snoopers charter... I guess now the cats out of the bag, Vodafone is likely the provider, since they can probably build upon what they have already implemented and sell it to 3rd parties. Pretty gross.
- mpeg 4y agoThat wouldn’t work as they almost certainly use CGNAT so an IP address is shared with thousands of subscribers. If I had to guess, they probably have a process similar to a cookie sync to obtain this id.
- tsimionescu 4y agoThey're the carrier: they know exactly at every time what IP:port belongs to each phone, otherwise they couldn't send the response packets back to the phone.
- mpeg 4y agoBut they have to communicate this to the advertisers in the RTB bidstream, in a way that advertisers can decode to a unique subscriber identifier (or at least unique enough) Sending just the IP would be useless, as the publisher already has the IP address (and sends it to bidstream, although it is truncated for privacy) so there would be little incentive to pay for the carrier data. I worked in adtech for a while, and designed a system similar to this for a large UK carrier, although it never ended up being implemented as carrier was worried about optics.
- gruez 4y ago>The article mentions they are injecting a http header It does, but if you read carefully you'll see there's no source saying that's how that's being implemented. It's all speculation on the author's part. In fact, one of the sources linked (wired.com) says the opposite, claiming that it's "based on a user’s IP address", which wouldn't require any HTTP header injection.
- cedricgle 4y agoIt looks to me that Vodafone attach an id to a flow by using the device network id (sim, imsi or maybe the MAIDs). Then the website, when generating the html page, can ask Vodafone this id and include a targeted ad. Some info here : - https://mobile.twitter.com/Chronotope/status/1513900415632429062 https://mobile.twitter.com/Chronotope/status/151390041563242...