18 ms·
Verizon Wireless injecting tracking UIDs into HTTP requests
See @KennWhite: https://twitter.com/kennwhite/status/525110471733817344
Verizon Wireless is injecting a UID into all HTTP requests made on the VZW network, regardless of whether or not you've opted out of their Customer Proprietary Network Information (CNPI) options.
It's injected at the network level- So it tracks across browsers and ignores 'private browsing', do-not-track headers, overriding the UIDH in the client/curl, everything. My confirmation showing the headers only appearing in unprotected HTTP requests (disappearing when VPNed):
https://twitter.com/rammic/status/525360201361530880
If you're on the VZW cell network and not using wifi, you can check your own ID here (via @j4cob):
http://uidh.crud.net/
- Floegipoky 12y agoWhere's the class-action lawsuit?
- chatmasta 12y agoI'm on Verizon and got "did not receive X-UIDH header" message from uidh.crud.net. Possibly because it says "1x" at the top of my phone and that means it's on another network?
- Eiriksmal 12y agoCould be 4G only? Just did it from a 4G LTE tablet, got a big ol' X-UIDH string of what appears to be Base64. Edit: Also, on a positive match, the page displays a link to an NBC News article on Verizon's CPNI (Customer Proprietary Network Information). http://www.nbcnews.com/tech/security/why-you-should-check-your-verizon-wireless-privacy-settings-right-f1C6370918 http://www.nbcnews.com/tech/security/why-you-should-check-yo...
- ewzimm 12y agoI get the header injected on 3g.
- deleted 12y ago[deleted]
- sp332 12y agoHow do you opt out of CPNI?
- pillfill 12y agoOlder article, but still works: http://www.nbcnews.com/tech/security/why-you-should-check-your-verizon-wireless-privacy-settings-right-f1C6370918 http://www.nbcnews.com/tech/security/why-you-should-check-yo...
- Eiriksmal 12y agoThe linked NBC News article explains you can do it through Verizon's customer account web interface, but the parent says that won't work. ..."regardless of whether or not you've opted out of their Customer Proprietary Network Information (CNPI) options."
- mfkp 12y agoHmm, confirmed on Verizon 4G LTE network. Can anybody recommend a good VPN service that works on android?
- pillfill 12y agoPrivate internet access. Works great.
- coconutrandom 12y agozenmate
- bobbyi_settv 12y agoIf you use Chrome and enable Google's Data Compression Proxy, all http traffic is proxied via Google's servers and sent to them via spdy (which is encrypted), so Verizon can't tamper with the requests or see what they are: https://developer.chrome.com/multidevice/data-compression https://developer.chrome.com/multidevice/data-compression
- ams6110 12y agoSo you trade Verizon's tracking for Google's?
- teraflop 12y agoAt the very least, it would only be Google that could track you, instead of every website you visit being able to read your Verizon-assigned ID.
- el_duderino 12y agoWhat about DNS queries?
- ams6110 12y agoThey're not http so would guess they don't go through the proxy.
- lpgauth 12y agoThis as been known for a while and it's used by some advertisers...
- pillfill 12y agoThe news is that it's ignoring the opt-out selections (including mine that I set a while ago).
- sbarker 12y agoI'm on Verizon and got "did not receive X-UIDH header". 4G, droid ultra, FL
- kator 12y agoThis has been going on for ages, not sure why people just now noticed it. They were testing it last year, you could clearly see these headers on a large percentage of traffic coming from their gateways. I'm not expressing an opinion one way or another but they clearly felt the UID is not directly identifiable and thus does not become a privacy issue until they share the mapping of the UID to customer data. My guess is in their minds if you opt-out they just do not provide your UID to 3rd parties for targeting. In the ever increasing dream of cross device marketing (think your iPad, iPhone and Laptop) many companies are trying to figure out ways to connect these devices to a single individual or family. IIRC Verizon quietly started rolling out service wide TOS changes to allow this sort of thing a couple years back. That said I'm not sure if their TOS makes it clear how this is implemented and what potential side effects might be caused by the way they've implemented them.
- pillfill 12y agoThe news is that they are injecting it even when you have opted out of CNPI. The disturbing part is a unique ID that follows you despite private browsing and across browsers. The worst part is that it goes to every site you visit (not just VZW or selected advertisers). It can be trivially linked to your existing cookies/identity to follow you even after clearing cookies, changing browsers, switching devices, etc.
- kator 12y agoYes it's disturbing, again I'm no mind reader, but I guess they assume when you opt-out they just don't map your UID. Meanwhile you're still trackable and just one small data point could be used to reverse everything you visit. As an example if you sign up for some random blog and they capture UID's they could quickly map your email to your UID and onward into the spiral we go. IP Addresses are a similar problem for home users, nobody seemed to have noticed that quite some time ago ISP's started making DHCP lease times quite long. Not to put on a tin foil hat, but I assume this was done more strategically then just to reduce load on DHCP servers in their networks.
- CameronNemo 12y ago
- jo_ 12y agoThis makes me rather unhappy. I'm seeing this on Verizon. Can someone with an alternative mobile provider like Sprint or T-Mobile test this, too?
- hackuser 12y ago> This makes me rather unhappy. I'm seeing this on Verizon. Can someone with an alternative mobile provider like Sprint or T-Mobile test this, too? I would guess that voting with your feet would be the most effective response. While many think consumers don't care (or don't understand), we can see many vendors beginning to emphasize confidentiality features.
- jo_ 12y agoI'm not sure if I value my confidentiality more than the unlimited talk/data/text plan on which I'm grandfathered. It's a hard change to make, especially considering I no longer see the tracking data after I disabled it in my settings.
- privong 12y agoI just tested mine, but the situation is a bit complicated. My service is with T-mobile in the US, but I am currently connecting through Movistar Chile. The response from the website was: > did not receive X-UIDH header. So I presume I can say that Movistar Chile is not inserting that into the header. Not sure about T-Mobile (US) though.
- kalleboo 12y agoIf you are roaming and using the T-Mobile APN, then you're still going through the T-Mobile data infrastructure. When you're in China and roaming on a foreign operator, you're not affected by the Great Firewall since you're data goes through the APN in your home country.
- privong 12y agoOkay, thanks for the clarification. I did just check and I have an American geolocated IP, consistent with what you said.
- gergles 12y agoThey don't appear to be doing this if you've opted out of "Relevant Mobile Advertising", which is another option [separate from CPNI] on http://verizonwireless.com/myprivacy http://verizonwireless.com/myprivacy. Here's the setting you're looking for: http://i.imgur.com/QFJJNV5.png http://i.imgur.com/QFJJNV5.png Mods may also want to update the title to include "Wireless" after Verizon; Verizon landline is not doing this anywhere AFAIK.
- ewzimm 12y agoI have a prepaid account, and I'm not allowed to change privacy settings either online or over the phone. The web tells me I am an account member and not owner, and the phone just says prepaid is not eligible to opt out. I can fix it by using a VPN, but isn't it illegal to not even allow me to opt out? Postpaid is significantly more expensive than prepaid and not available to people with bad credit. How can they discriminate like that?
- deleted 12y ago[deleted]
- smeyer 12y agoI'm not clear why you think it would be illegal. There may be rules against not allowing people to opt out, I don't know. But when you ask "How can they discriminate like that?", there's nothing illegal about discriminating on the basis of credit or willingness to pay for a more expensive product.
- ewzimm 12y agoI can understand discriminating on quality or something like that, but we're talking about not being able to opt out of having your personal information sold. It seems like there should be some kind of a law where that has to be made absolutely clear. It doesn't even seem to be buried anywhere in the Terms of Service, which say: "Verizon Wireline consumers and certain business customers may opt-out by calling 1-866-483-9700. Verizon Wireless consumer and certain business customers may call 1-800-333-9956." Only after calling that number are you told you are ineligible because you are prepaid. This is advertised as a prepaid account, not a personal-information-selling subsidized account. It's also not even really competitive with other plans. Verizon gives you up to 1GB/month for $45, only with recurring payments, while Cricket gives you 10GB 4G with unlimited throttled data for $55. Unfortunately, Verizon has a monopoly in most of my area. T-Mobile and Sprint don't operate here, and AT&T is spotty.
- youzer 12y agoLet's say I want to send some TCP. That TCP happens to kind of look like HTTP, but it's not. It's just some protocol I made up which looks HTTPish enough to trigger this injection. Doesn't that mean that Verizon isn't actually offering TCP/IP (Internet) access, since they corrupt my protocol stream in transit? Shoudln't that mean they should be charged with fraud if they continue to advertise the fact that they provide internet access when what they really provide is a broken version of TCP they made up? It's a serious question.
- LamaOfRuin 12y agoNo. Your question may have been serious, but it's also ridiculous, unless you have a much more technically detailed contract with Verizon than I've ever seen.
- josho 12y agoYup in theory. In practice you would call up your legal counsel, and they'd ask you how hard would it be to re-engineer your protocol to not break by Verizon. If the answer is anything less than 1 year and tens to hundreds of thousands of dollars then they'd advise you to just fix your protocol. On the other hand if your spouse is a lawyer and wants to make a name for themself then you'd consider moving forward on failure to deliver service / false advertising / etc.
- jerf 12y ago"Doesn't that mean that Verizon isn't actually offering TCP/IP (Internet) access, since they corrupt my protocol stream in transit?" This is a serious answer: Go back and look at what they actually promise to deliver. Bet it doesn't have the word "TCP" in it anywhere. You can't hit them with contract violation when they aren't in violation of their contract. (Well, you can lodge any lawsuit you like. But it won't go well for you.)
- ArtDev 12y agoThis looks like a job for Tunnelbear VPN! https://www.tunnelbear.com/ https://www.tunnelbear.com/ I am huge fan since I starting using it when traveling Europe. The mobile version works great as well.
- ntw1103 12y agoTunnelbear does work great, except for the fact that it drains the battery in my phone like crazy. I use SSHTunnel to route all traffic through my private server.
- higherpurpose 12y agoWhatever you do, do not uninstall TunnelBear! http://i.imgur.com/1YQfGRN.png http://i.imgur.com/1YQfGRN.png
- ToastyMallows 12y agoTunnelBear probably has the best branding I've seen in the while, very well executed.
- sarciszewski 12y agoTunnelbear VPN - Blowfish with HMAC-SHA1 https://www.tunnelbear.com/development/encryption/ https://www.tunnelbear.com/development/encryption/ Seems like a bit of an odd choice for a ciphersuite. I sure hope it's implemented well.
- leejoramo 12y agoI assume there are similar opt-outs for AT&T, Sprint, T-Moblie, etc. Anyone maintain a page of links for how to access the opt-outs?
- leejoramo 12y agoWell, I found the AT&T page. Wow, they make this very difficult to opt-out. http://www.att.com/gen/privacy-policy?pid=24339 http://www.att.com/gen/privacy-policy?pid=24339
- RexRollman 12y agoThis is bullshit. You shouldn't have to "opt out" of tracking in the first fucking place.
- pdabbadabba 12y agoInteresting, I just tested my device over AT&T LTE, but there was no UIDH header. Edit: There is an x-acr header, which contains a curiously large amount of encoded data, far too much to be any reasonably sized id. Anyone know what it is?
- kyrra 12y agoI see this as well. AT&T LTE with iPhone 5 (running 8.1).
- micah_chatt 12y agoWhen I try to 'withdraw consent' for 'Verizon Selects Participation Status', I get this prompt http://imgur.com/sbVpMhR http://imgur.com/sbVpMhR
- cddotdotslash 12y agoThat's because that program gives you rewards points specifically for sharing your private information [1]. [1] http://time.com/money/3025429/verizon-smart-rewards-loyalty-programs-retail/ http://time.com/money/3025429/verizon-smart-rewards-loyalty-...
- booleanbetrayal 12y agoalso seeing this despite CNPI settings. class-action time?
- ChuckMcM 12y agoBummer, the iPad (LTE version) sends this tracking information and there is no way to turn it off.
- zackify 12y agosetup a vpn with digitalocean like I do, it's about all we can do.
- ChuckMcM 12y agoWell to be clear, on WiFi it does not send the tracking data, only when using the LTE network. That said the only SSL tunnel software I saw was Junos Pulse which is sitting on a ton of bad reviews at the moment because apparently it doesn't work with iOS 8. What VPN software do you use with your iPad?
- codezero 12y agoI use OpenVPN Connect, it's a bit of a pain to set up, but it works well. https://itunes.apple.com/us/app/openvpn-connect/id590379981?mt=8 https://itunes.apple.com/us/app/openvpn-connect/id590379981?...
- paxswill 12y agoiOS has support for some common VPN protocols built-in: http://support.apple.com/kb/HT1288 http://support.apple.com/kb/HT1288
- bndw 12y agoYou can view all of your device's request headers at http://checkyourinfo.com/request http://checkyourinfo.com/request
- pacino 12y agoI just checked my AT&T iPhone and it includes a "X-Acr" HTTP header that has a long GUID? Is this a similar tracking ID?
- acdha 12y agoCurious, I don't see this but if that's the same acronym used here it's a tracking ID: http://www.gsma.com/oneapi/anonymous-customer-reference-beta/ http://www.gsma.com/oneapi/anonymous-customer-reference-beta...
- pillfill 12y agoJust confirmed that the UID follows the SIM, so even swapping phones won't save you.
- peterwwillis 12y agohttps://www.verizonwireless.com/b2c/support/customer-agreement https://www.verizonwireless.com/b2c/support/customer-agreeme... "We collect personal information about you. We gather some information through our relationship with you, such as information about the quantity, technical configuration, type, destination and amount of your use of our telecommunications services. You can find out how we use, share and protect the information we collect about you in the Verizon Privacy Policy, available at verizon.com/privacy. By entering this Agreement, you consent to our data collection, use and sharing practices described in our Privacy Policy. We provide you with choices to limit, in certain circumstances, our use of the data we have about you. You can review these choices at verizon.com/privacy#limits. If there are additional specific advertising and marketing practices for which your consent is necessary, we will seek your consent (such as through the privacy–related notices you receive when you purchase or use products and services) before engaging in those practices. [..] DISCLAIMER OF WARRANTIES We make no representations or warranties, express or implied, including, to the extent permitted by applicable law, any implied warranty of merchantability or fitness for a particular purpose, about your Service, your wireless device, or any applications you access through your wireless device." https://www.verizon.com/about/privacy/policy/ https://www.verizon.com/about/privacy/policy/ "We collect information about your use of our products, services and sites. Information such as call records, websites visited, wireless location, application and feature usage, network traffic data, product and device-specific information and identifiers, service options you choose, mobile and device numbers, video streaming and video packages and usage, movie rental and purchase data, FiOS TV viewership, and other similar information may be used for billing purposes, to deliver and maintain products and services, or to help you with service-related issues or questions. In addition, this information may be used for purposes such as providing you with information about product or service enhancements, determining your eligibility for new products and services, and marketing to you. This information may also be used to manage and protect our networks, services and users from fraudulent, abusive, or unlawful uses; and help us improve our services, research and develop new products, and offer promotions and other services. [..] When you register on our sites, we may assign an anonymous, unique identifier. This may allow select advertising entities to use information they have about your web browsing on a desktop computer to deliver marketing messages to mobile devices on our network. We do not share any information that identifies you personally outside of Verizon as part of this program. You have a choice about whether to participate, and you can you can visit our relevant mobile advertising page (link to www.vzw.com/myprivacy) to learn more or advise us of your choice. Customer Proprietary Network Information (CPNI): [..] Verizon Wireline consumers and certain business customers may opt-out by calling 1-866-483-9700. Verizon Wireless consumer and certain business customers may call 1-800-333-9956. Other customers may decline to provide or withdraw CPNI consent by following the instructions in the Verizon notice seeking consent. For additional information, you can read examples of common consumer CPNI notices for Verizon Wireline and Verizon Wireless. Please note that many opt-outs are cookie-based. If you buy a new computer, change web browsers or delete the cookies on your computer, you will need to opt-out again. Please also note that some wireless devices, portals and websites have limited ability to use and store cookies. As a result, advertising entities may have a limited ability to use cookies in the manner described above or to respect cookie-based opt out preferences. However, ads may still be tailored using other techniques such as publisher, device or browser-enabled targeting. You should check the privacy policies of the products, sites and services you use to learn more about any such techniques and your options. If you do not want information to be collected for marketing purposes from services such as the Verizon Wireless Mobile Internet services, you should not use those particular services."
- edallme 12y agoApparently Verizon has two patents on the process: http://www.faqs.org/patents/app/20130318346 http://www.faqs.org/patents/app/20130318346 http://www.google.com/patents/US20130318581 http://www.google.com/patents/US20130318581
- rockdoe 12y agoExcellent news, that means their competitors are safer to use?
- blumkvist 12y agoIt would make sense for Verizon to license the technology to other carriers. 1) The more widespread the technology is, the more advertisers will be aware of it and will seek it. This means more revenue for Verizon (bigger market for this product). 2) If all carriers do it, then people won't have an incentive to switch from Verizon. 3) Licensing fees.
- tedks 12y agoDoesn't examining/modifying data exempt you from the DMCA safe harbor protections?
- jimktrains2 12y agoVZW doesn't use SIMs except in some new 4G tech.
- tedks 12y agoUm, how is this relevant? IANAL, but the DMCA seems to protect you from liability only if you don't examine and modify traffic. If they're looking at the protocol to see if it's HTTP and therefore modifiable, they could look at the host to see if it's going to the pirate bay and block it. This means that when someone goes to the pirate bay on the Verizon Wireless network, Verizon is liable for their actions under the DMCA. This is like YouTube reviewing videos before they're uploaded. If they were reviewing videos, they could catch copyright violations from the start and thus should. There's probably legal trickery they could use to get out of it but it seems like a valid point.
- kator 12y agoJust checked my Verizon 4G LTE MiFi and the headers are not there, I've not done anything special to my account settings. On ATT I see the X-Acr thing but not clear if it's UID like or not in nature, would need to see more of them.
- 13throwaway 12y agoI just checked my AT&T phone and I have an X-Acr header too.
- kngspook 12y agoHow're you checking?
- 13throwaway 12y agoGo to this page over a cellular connection. (Turn off your wifi) http://checkyourinfo.com/request http://checkyourinfo.com/request Then look for a long number.
- tehwebguy 12y agoSame, I've opted out here and I still get it: http://www.att.com/gen/privacy-policy?pid=24339 http://www.att.com/gen/privacy-policy?pid=24339
- wittymebee1 12y agoJust checked my phone and I have "do not track" turned on and x-acr is tracking. Who/what is it? Why? How do I stop it?
- wittymebee1 12y agoChecked over data not WiFi
- kator 12y agoChecked my Wife's Verizon iPad on LTE and no UID header.
- dzhiurgis 12y agoHow is this UID different to an IP address?
- ericlitman 12y agoUseful to note that the UIDH changes every 7 days.
- 13throwaway 12y agoHere's a scary thought: How do we know every ISP isn't doing this, it would be undetectable if they only injected these on certain domains e.g. facebook, google. However I don't see how much more tracking ability that would grant over IP tracking.
- SwearWord 12y agoNote, the ID rotates every week. However they do allow select companies to retrieve a history of IDs
- srj 12y agoAs this requires reassembling the HTTP request to add the additional header, this probably introduces extra latency too. Fortunately https is becoming more pervasive which bypasses this and any other transparent proxies.
- tedd4u 12y agoThe carriers are working to subvert this -- see the IETF draft for "HTTP/2.0 Explicit Trusted Proxy" or read this article: http://www.theregister.co.uk/2014/02/25/evil_or_benign_trusted_proxy_draft_debate_rages_on/ http://www.theregister.co.uk/2014/02/25/evil_or_benign_trust...
- tedchs 12y agoOn my Verizon Moto X (Android), the header is not visible if I use the Chrome feature "Reduce data usage", but it is visible if I disable that feature or, ironically, use Incognito mode. This feature causes non-SSL, non-Incognito traffic to be proxied through Google's servers, using the SPDY protocol. Some info on how this works: https://developer.chrome.com/multidevice/data-compression https://developer.chrome.com/multidevice/data-compression
- Spooky23 12y agoVZW does all sorts of weird traffic management. They proxy everything and will throttle applications deemed to chatty as well.
- scintill76 12y agoSeems similar to Apple's Spotlight phone-home thing: unsolicited extra data being sent, a somewhat buried disclosure that it's happening, people having difficulty getting their opt-out preference honored (possibly caused by several confusingly-similar options to disable.) It does sound like Verizon's is more a case of simply not honoring the option, though, unless some commenters here have just not found the magic checkbox yet.
- arca_vorago 12y agoWhat about LTE modems on Verizon? I am testing them and was planning a fairly big rollout to replace some services that previously relied on Sat internet.
- signifiers 12y agoYes, modems, access points, LTE tablets included. Consumer and Enterprise users (including me) are seeing it. Eg: https://twitter.com/innismir/status/525279100907560961 https://twitter.com/innismir/status/525279100907560961
- mgamache 12y agoAs a prepaid account I don't have access to the privacy settings. I spent an 1:15 on the phone with Verizon with no luck (no one had any idea what I was talking about). This has huge potential to be abused. It won't take long for companies to link your real name to web traffic and know exactly everything you look at on your phone. Wait until the cable/DSL companies realize the untapped revenue potential.
- abhishekmdb 12y agoVerizon Wireless tracking on its customers browsing habits, but why? http://www.techworm.net/2014/10/verizon-wireless-tracking-on-its-customers.html http://www.techworm.net/2014/10/verizon-wireless-tracking-on...
- mbelshe 12y agoKinda makes you wish the IETF had adopted all-TLS-all-the-time in HTTP/2.0. We need HTTP/3.0 to be SSL all the time and nix the CAs so we can avoid MITM from VZ.
- danyork 12y agoIt seems that http://uidh.crud.net/ http://uidh.crud.net/ is not working right now (gives a 502). However the UIDH header can be seen here: http://lessonslearned.org/sniff http://lessonslearned.org/sniff Also http://verizon-uidh.tk/ http://verizon-uidh.tk/ gives a yes/no if you have the UIDH header (and shows you the header if you do)