5 ms·
Step 3: Turn ignores UIDH headers originating from non-Verizon IPs and Verizon replaces any user-generated UIDH header. Your solution is not going to fool anyo
by No1 12y ago
Step 3: Turn ignores UIDH headers originating from non-Verizon IPs and Verizon replaces any user-generated UIDH header.
Your solution is not going to fool anyone.
- rubbingalcohol 12y agoReading through the original report, I'd doesn't seem that Turn's handling of the header is very sophisticated, in fact they just dumbly accept whatever header you give them. (Interestingly unless they take extra precautions, this exposes them to a CSP sandboxing vulnerability) Turn needs to handle these headers basically in realtime, and while I'm not saying it would be impossible to do IP filtering on a header, it would be expensive. If outsmarting them became a cat and mouse game and people stay ahead of them at any point, that would be good enough to make third party companies that rely on Turn's zombie cookies to lose confidence. Unless turn publishes more info about how they circumvent the circumvention, and this would implicate them further politically and legally. What they are doing is immoral and probably illegal.
- richardwhiuk 12y agoIP filtering compared to checking a HTTP header is trivial - it isn't going to be expensive.
- MichaelGG 12y agoThere's no cat and mouse. IP filtering is trivial. Say Verizon has 50M IPs, and let's pretend each is a /22. That's 50K * 22-bit entries, but we'll be inefficient and round to 4 bytes. That's a 200KB lookup table. BFD, and that's an inefficient estimate. HTTP is a terrible text-based format that's very inefficient to parse. The overheard of another IP lookup per request is negligible. Your heart's in the right place, but your technical proposal simply doesn't accomplish anything. And, if you could get traction on people installing plugins or whatever, you could just get them to install adblock.