• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

Verizon supercookie uses http header injection to track users

Aquinus

Resident Wat-man
Joined
Jan 28, 2012
Messages
13,147 (2.94/day)
Location
Concord, NH, USA
System Name Apollo
Processor Intel Core i9 9880H
Motherboard Some proprietary Apple thing.
Memory 64GB DDR4-2667
Video Card(s) AMD Radeon Pro 5600M, 8GB HBM2
Storage 1TB Apple NVMe, 4TB External
Display(s) Laptop @ 3072x1920 + 2x LG 5k Ultrafine TB3 displays
Case MacBook Pro (16", 2019)
Audio Device(s) AirPods Pro, Sennheiser HD 380s w/ FIIO Alpen 2, or Logitech 2.1 Speakers
Power Supply 96w Power Adapter
Mouse Logitech MX Master 3
Keyboard Logitech G915, GL Clicky
Software MacOS 12.1
Yeah, no denying that. But it's only paranoia if they're NOT really out to get you. :D ;)
I think you're over exaggerating how much "people" (namely companies and the government,) are tracking you. They don't need a little unique ID to learn everything about you. If some organization really wanted to "get you" they wouldn't need a stupid HTTP header like this to do it. But statements like that prove you have an attribution bias on the subject at hand. Fear is a powerful tool and succumbing to it doesn't make you right. :)
 
Joined
Mar 4, 2005
Messages
3,612 (0.52/day)
System Name TheReactor / HTPC
Processor AMD 7800x3d 5050Mhz / Intel 10700kf (5.1ghz All Core)
Motherboard ASrock x670e Taichi / ROG Strix z490-e gaming
Cooling HeatKiller VI CPU/GPU Block -2xBlackIce GTX 360 Radiators - Swiftech MCP655 Pump
Memory 32GB G.Skill 6000Mhz DDR5 / 32GB G.Skill 3400Mhz DDR4
Video Card(s) Nvidia 3090ti / Nvidia 2080ti
Storage Crucial T700 2TB Gen 5 / Samsung Evo 2Tb
Display(s) Acer Predator xb271hu - 2560x1440 @144hz
Case Corsiar 550
Audio Device(s) on board
Power Supply Antec Quattro 1000W
Mouse Logitech G502
Keyboard Corsair Gaming k70
Software Windows 10 Pro 64bit
Here is the basic code used to extract your carrier from the header...This is all it does.

if headers['MSISDN'] then -- TMO
provider = 'TMO'
acr = crypt.hash(headers['MSISDN']);
elseif headers['X-UIDH'] then -- VZN
provider = 'VZW'
acr = headers['X-UIDH'];
elseif headers['x-up-subno'] then -- ATT
provider = 'ATT'
acr = headers['x-up-subno']
elseif testmode then
if not etag and headers['FAIL'] == 'true' then
ngx.exit(ngx.HTTP_NOT_FOUND)
end
end

So other then detecting the device you are on it doesn't do much else, just looking at that code it is almost not worth discussing. It is basically the same as Browser or Device detection such as Mobile/PC/Tablet. This just extracts what carrier the device uses.
 
Joined
Oct 6, 2014
Messages
1,424 (0.41/day)
System Name octo1
Processor dual Xeon 2687W ES
Motherboard Supermicro
Cooling dual Noctua NH-D14
Memory generic ECC reg
Video Card(s) 2 HD7950
Storage generic
Case Rosewill Thor
I think you're over exaggerating how much "people" (namely companies and the government,) are tracking you. They don't need a little unique ID to learn everything about you. If some organization really wanted to "get you" they wouldn't need a stupid HTTP header like this to do it. But statements like that prove you have an attribution bias on the subject at hand. Fear is a powerful tool and succumbing to it doesn't make you right. :)
You need to work on your sense of humor.
 

Mindweaver

Moderato®™
Staff member
Joined
Apr 16, 2009
Messages
8,194 (1.49/day)
Location
Charleston, SC
System Name Tower of Power / Sechs
Processor i7 14700K / i7 5820k @ 4.5ghz
Motherboard ASUS ROG Strix Z690-A Gaming WiFi D4 / X99S GAMING 7
Cooling CM MasterLiquid ML360 Mirror ARGB Close-Loop AIO / CORSAIR Hydro Series H100i Extreme
Memory CORSAIR Vengeance LPX 32GB (2 x 16GB) DDR4 3600 / G.Skill DDR4 2800 16GB 4x4GB
Video Card(s) ASUS TUF Gaming GeForce RTX 4070 Ti / ASUS TUF Gaming GeForce RTX 3070 V2 OC Edition
Storage 4x Samsung 980 Pro 1TB M.2, 2x Crucial 1TB SSD / Samsung 870 PRO 500GB M.2
Display(s) Samsung 32" Odyssy G5 Gaming 144hz 1440p, ViewSonic 32" 72hz 1440p / 2x ViewSonic 32" 72hz 1440p
Case Phantek "400A" / Phanteks “Enthoo Pro series”
Audio Device(s) Realtek ALC4080 / Azalia Realtek ALC1150
Power Supply Corsair RM Series RM750 / Corsair CXM CX600M
Mouse Glorious Gaming Model D Wireless / Razer DeathAdder Chroma
Keyboard Glorious GMMK with box-white switches / Keychron K6 pro with blue swithes
VR HMD Quest 3 (128gb) + Rift S + HTC Vive + DK1
Software Windows 11 Pro x64 / Windows 10 Pro x64
Benchmark Scores Yes
I'm for data collection... Please, hurry up and figure me out, and only show me what I like to buy, and what stores have it close to me... ;)
 
Joined
Oct 6, 2014
Messages
1,424 (0.41/day)
System Name octo1
Processor dual Xeon 2687W ES
Motherboard Supermicro
Cooling dual Noctua NH-D14
Memory generic ECC reg
Video Card(s) 2 HD7950
Storage generic
Case Rosewill Thor
For those that didn't believe this is an important issue, read this article - http://www.extremetech.com/mobile/1...ies-refuses-to-honor-its-own-opt-out-requests

Let’s say you visit a website that employs this method without the Verizon header. As detailed at Webpolicy.org, the system simply installs a standard tracking cookie. If you visit it with a Verizon header, the system sets a cookie ID that corresponds to the Verizon header. Remove the tracking cookie, and the system promptly reinstates it with the Verizon header. That’s why it’s being called a “zombie” cookie — it comes back once deleted.

No, the advertiser doesn’t know that UID=123456789 is John Doe from Maryland, but the advertising network can track everywhere that John Doe goes, every website he visits, and every page he touches. If you delete the tracking cookie it’s promptly reconstituted and reassociated with your profile. Full details are available at Mayer’s website, but the collateral damage is significant. Laptops tethered to cell phones on Verizon’s network, for example, can be infected by this process.
 

qubit

Overclocked quantum bit
Joined
Dec 6, 2007
Messages
17,865 (2.99/day)
Location
Quantum Well UK
System Name Quantumville™
Processor Intel Core i7-2700K @ 4GHz
Motherboard Asus P8Z68-V PRO/GEN3
Cooling Noctua NH-D14
Memory 16GB (2 x 8GB Corsair Vengeance Black DDR3 PC3-12800 C9 1600MHz)
Video Card(s) MSI RTX 2080 SUPER Gaming X Trio
Storage Samsung 850 Pro 256GB | WD Black 4TB | WD Blue 6TB
Display(s) ASUS ROG Strix XG27UQR (4K, 144Hz, G-SYNC compatible) | Asus MG28UQ (4K, 60Hz, FreeSync compatible)
Case Cooler Master HAF 922
Audio Device(s) Creative Sound Blaster X-Fi Fatal1ty PCIe
Power Supply Corsair AX1600i
Mouse Microsoft Intellimouse Pro - Black Shadow
Keyboard Yes
Software Windows 10 Pro 64-bit
This reminds me of Intel's processor serial number scandal with the P3 all those years ago. Somehow it doesn't surprise me that these big companies will find any and all ways to track what you do.

People shouldn't be so blase about it.
 
Top