3 ms·
I work in mobile advertising (not in the US), and my company is partnered with a mobile carrier that does something similar, although the "header enrichment" as
by monofonik 12y ago
I work in mobile advertising (not in the US), and my company is partnered with a mobile carrier that does something similar, although the "header enrichment" as it's called is only enabled on specific domains (i.e. requests to our ad server API). I feel that it's unlikely these headers are being set on all web requests. Has anybody verified this claim?
- sehugg 12y agoI've seen a lot of these headers on traffic that has no business having these headers (internal app traffic to a non-public-facing server) EDIT: On the one server I sampled, they're included in approx. 10% of requests (mostly Android/iOS traffic)
- pixl97 12y agoI looked in the logs on my public web server I host different sites on. I only found one UIDH record in my modsec_audit logs, but most worryingly it was it was for a personal injury trial lawyer. Made some records semi-anonymous. --eee7b544-A-- [25/Sep/2014:15:33:19 --0500] VCR8D6wUChkAAG-HuKQAAAAH 70.209.73.XXX 32675 X.X.X.X 80 --eee7b544-B-- GET /wp-content/uploads/2012/07/XXXXXXXXXXX.jpg HTTP/1.1 X-UIDH: MTU4NTI5Mjg3AKafKcbQqnDdCMuP+UbmoCyKvEu8MnDsqV0I+AQ2K/M+ User-Agent: Mozilla/5.0 (Linux; Android 4.4.4; XT1030 Build/SU4.21) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/33.0.0.0 Mobile Safari/537.36 GSA/3.4.16.1149292.arm Host: www.XXXXXXXXX.com Connection: Keep-Alive Accept-Encoding: gzip