Stories
Slash Boxes
Comments

SoylentNews is people

SoylentNews is powered by your submissions, so send in your scoop. Only 19 submissions in the queue.
posted by LaminatorX on Friday October 31 2014, @05:43PM   Printer-friendly
from the wildlife-tags dept.

Wired and Forbes reported earlier this week that the two largest cellphone carriers in the United States, Verizon and AT&T, are adding a tracking number to their subscribers' Internet activity, even when users opt out.

The data can be used by any site — even those with no relationship to the telecoms — to build a dossier about a person's behavior on mobile devices — including which apps they use, what sites they visit and for how long.

ProPublica reports that MoPub ("the world's largest mobile ad exchange"), acquired by Twitter in 2013, uses Verizon's tag to track and target cellphone users for ads and that AT&T and Vodaphone are also testing the waters with similar tracking IDs.

Related Stories

ProPublica Launches a Tor Hidden News Site 17 comments

Wired and others report that ProPublica has become the first "major" news outlet to launch a version of the site using Tor:

On Wednesday, ProPublica became the first known major media outlet to launch a version of its site that runs as a "hidden service" on the Tor network, the anonymity system that powers the thousands of untraceable websites that are sometimes known as the darknet or dark web. The move, ProPublica says, is designed to offer the best possible privacy protections for its visitors seeking to read the site's news with their anonymity fully intact. Unlike mere SSL encryption, which hides the content of the site a web visitor is accessing, the Tor hidden service would ensure that even the fact that the reader visited ProPublica's website would be hidden from an eavesdropper or Internet service provider.

"Everyone should have the ability to decide what types of metadata they leave behind," says Mike Tigas, ProPublica's developer who worked on the Tor hidden service. "We don't want anyone to know that you came to us or what you read."

ProPublica accepts news tips using a SecureDrop hidden service. The recent move to include a Tor hidden site was motivated by concerns that Chinese readers could be put at risk by reading reports about the country's Web censorship.

The site can be reached at: propub3r6espa33w.onion

ProPublica often collaborates with The New York Times, NPR, PBS, The Intercept and others to publish stories. Here are a few ProPublica stories that have made it to our front page:

Somebody's Already Using Verizon's ID to Track Users
Fines Remain Rare as Health Data Breaches Multiply
NSA Monitors Americans' International Internet Traffic to Hunt Hackers for FBI
Fairview: AT&T's Collaborative Relationship with NSA Revealed
Psychology Practice Revealed Patients' Mental Disorders in Debt Lawsuits


Original Submission

This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 1) by zzw30 on Friday October 31 2014, @05:49PM

    by zzw30 (4576) on Friday October 31 2014, @05:49PM (#111963)

    Is there anything that can be done about this outside of not using AT&T/Verizon services? For myself, and I assume many others, boycotting is not an option; in my case I just re-upped a 2 year contract.

    • (Score: 2) by Nerdfest on Friday October 31 2014, @06:08PM

      by Nerdfest (80) on Friday October 31 2014, @06:08PM (#111970)

      In Canada we have a Privacy Commissioner. Is there something similar in the US? If so, file a complaint.

      • (Score: 2) by Snow on Friday October 31 2014, @06:20PM

        by Snow (1601) on Friday October 31 2014, @06:20PM (#111978) Journal

        Just make sure you fill out the form in triplicate, on legal sized paper. Have it notorized, signed by the lieutenant governor, and initialed by the Queen. Then wait the manditory 4-6 months. They'll contact you if they need anything else.

        • (Score: 2) by Nerdfest on Friday October 31 2014, @06:42PM

          by Nerdfest (80) on Friday October 31 2014, @06:42PM (#111993)

          It may not be that bad. I filed a CRTC complaint against Rogers Communications, and it was followed up on, just from filling in an online form. I think too many people think the processes are too onerous. If nobody complains these weasels get away with their unscrupulous behaviour for way too long.

          • (Score: 1) by Buck Feta on Friday October 31 2014, @06:45PM

            by Buck Feta (958) on Friday October 31 2014, @06:45PM (#111994) Journal

            > Rogers Communications

            Apparently rogers is a verb.

            --
            - fractious political commentary goes here -
            • (Score: 2) by Nerdfest on Friday October 31 2014, @09:09PM

              by Nerdfest (80) on Friday October 31 2014, @09:09PM (#112056)

              That's certainly their opinion.

        • (Score: 2) by FatPhil on Saturday November 01 2014, @12:48PM

          by FatPhil (863) <{pc-soylent} {at} {asdf.fi}> on Saturday November 01 2014, @12:48PM (#112180) Homepage
          Don't forget to ensure all 10 fingerprints are clear, and enclose a recent photograph of yourself. Please also make sure that the blood and urine samples are securely closed.
          --
          Great minds discuss ideas; average minds discuss events; small minds discuss people; the smallest discuss themselves
      • (Score: 1) by art guerrilla on Friday October 31 2014, @07:27PM

        by art guerrilla (3082) on Friday October 31 2014, @07:27PM (#112018)

        oh sure, we have a 'privacy commissioner' too, he's called 'Director of the NSA'...
        just type your complaint into your computer, and he'll see it...

        • (Score: 0) by Anonymous Coward on Friday October 31 2014, @07:59PM

          by Anonymous Coward on Friday October 31 2014, @07:59PM (#112033)

          Yawn.

          Do you always have to be "on"?

          • (Score: 2) by tangomargarine on Tuesday November 04 2014, @07:58PM

            by tangomargarine (667) on Tuesday November 04 2014, @07:58PM (#113034)

            Evil never sleeps ;)

            --
            "Is that really true?" "I just spent the last hour telling you to think for yourself! Didn't you hear anything I said?"
    • (Score: 1) by ddtmm on Friday October 31 2014, @06:14PM

      by ddtmm (4849) on Friday October 31 2014, @06:14PM (#111975)

      I am curious to know if using a vpn on your cell device would be an effective work-around. I have a vyprvpn account and it works well in the iPhone. Anyone know if that circumvents the ID thing?

      • (Score: 3, Interesting) by Snow on Friday October 31 2014, @06:24PM

        by Snow (1601) on Friday October 31 2014, @06:24PM (#111980) Journal

        Interesting question, futher to that, would https connections also be immune, or would they be MITMing the connection with forged certs to insert the ID. Or is the ID embedded into the phone, and it's the phone that adds the ID, and not verizon directly. I coudn't find any technical details in the article.

      • (Score: 1, Informative) by Anonymous Coward on Friday October 31 2014, @06:29PM

        by Anonymous Coward on Friday October 31 2014, @06:29PM (#111983)

        Just loaded the test site (http://lessonslearned.org/sniff) on my AT&T phone with VPN enabled and I'm pleased to report that that circumvents the UID broadcast (I tested earlier without VPN and a UID was present). I'd just recently signed up with FrootVPN (https://www.frootvpn.com/) when I saw the Wired article. Kinda wishing I'd done it sooner, now.

        • (Score: 1) by ddtmm on Friday October 31 2014, @06:31PM

          by ddtmm (4849) on Friday October 31 2014, @06:31PM (#111985)

          awesome. thx

        • (Score: 2) by urza9814 on Tuesday November 04 2014, @02:00PM

          by urza9814 (3954) on Tuesday November 04 2014, @02:00PM (#112947) Journal

          Tor (Orbot on Andoid) blocks it too if anyone is wondering.

    • (Score: 1) by WillAdams on Friday October 31 2014, @06:32PM

      by WillAdams (1424) on Friday October 31 2014, @06:32PM (#111987)

      Change your useragent so that it's a contract enforcing a charge for tracking and take anyone you find doing so to small claims court?

      • (Score: 3, Interesting) by edIII on Friday October 31 2014, @08:09PM

        by edIII (791) on Friday October 31 2014, @08:09PM (#112040)

        I like the cut of your jib. Unfortunately that will never work.

        The useragent is from the client. It's the server that is contacted and dictates the legal terms of the interaction with TOS or policy messages, that are also governed by any applicable state laws and constraints.

        You propose to surreptitiously amend an existing relationship with another contract. Quite likely it would also eliminate legal language beneficial to the other side. I'm 99% sure that is prohibited by most contract law as the principle is that neither side has unilateral control over amendments. Since you initiated the contact, you always had the option of not going to the website. In order for you to proceed you need to consider the legal language in the contracts between two or more parties, out all of those involved. Verizon is making money of this with advertising revenue, so some of the websites are certainly covered by that TOS. According to the article though, it's data leakage on a massive scale, meaning that it's also quite likely that other major ad networks already had that tracking place for free both legally and financially.

        A lawyer could correct me. I think a financing analogy is that equity loan you lent is 6th in line, and not worth a dime.

        What's sad is that you shouldn't need to sue anyone with such tactics. It should be a violation of your civil rights when a corporation removes privacy that could be reasonably argued to be expected. Don't know about you, but I was not expecting Verizon to be using DPI and hijacking for all web requests, and then completely remove your privacy utterly from the biggest actors in the whole privacy game.

        The tracking is intended to be anonymous, but it also fails with that as well. The largest offenders out there only need a single identifying data point to permanently associate an ostensibly anonymous tracking number, with an actual connection to profile information. Probably from one of the major providers like Lexus Nexus or others.

        So the reality is that Verizon created a massive database of all of your activities, visit durations, etc. and then effectively anonymized it with a single identifier. Great. Well, it only needs to be cracked once and then the major players now know all the stuff you do. Nice. I can pay a few thousand dollars, fake some crap, and then in addition to a full credit report, background check, and god knows what else, I get a full listing of all the websites you visited from your phone or Verizon Wireless enabled device.

        Now a prospective employer knows I spent 43 minutes on Young Asian Cheerleaders With Tight Asses at Pornhub on a Wednesday at 11am while I probably should have been "servicing the shareholder's penis instead".

        Maybe Verizon should have said something when their actions effectively acted to unilaterally amend an existing contract with their subscribers in such a way as to be obscured and hidden, while also likely being highly objectionable when adequately explained.

        Verizon cannot claim ignorance of the objectionable amendment either, as they are self-proclaimed to be in the "Internet Advertising Business" as well as an ISP. They full well have sophisticated knowledge of consumer preferences and habits, as well as usage on many advertising blocking Apps and plugins.

        I would initiate a class action lawsuit against Verizon Wireless arguing they violated your reasonable rights and expectation to privacy, they are in breach of contract, unreasonably interfered with likely attempts by plaintiffs to secure privacy through other paid for services acting to interfere in those contracts, and that plaintiffs are deserving of remedy including punitive damages.

        Then when Verizon fights, we end up getting them to stop and give all affected people complementary VPN service from participating providers. After 4 years while their program is still running. Which is because we are talking a legal defense which is quite like a fly trying to kill a lion at this point.

        Best we can do is to force Verizon Wireless into being a dumb pipe. Just get a VPN. If they try and stop that, then just stop paying them for it . With the way everything is going anyways, you have to assume all of your packets are monitored and progressively interfered with for tracking and advertising purposes.

    • (Score: 2) by pendorbound on Friday October 31 2014, @07:01PM

      by pendorbound (2688) on Friday October 31 2014, @07:01PM (#112002) Homepage

      1) Use SSL.
      2) VPN your traffic somewhere sane.

      They can’t inject in SSL connections, so that’s a partial fix. I also run OpenVPN back to my router at home from ALL of my devices (phone, tablet, laptop), so that works at least until TimeWarner gets stupid. After that, third party VPN service so I look like a complete drug dealer….

    • (Score: 0) by Anonymous Coward on Friday October 31 2014, @07:07PM

      by Anonymous Coward on Friday October 31 2014, @07:07PM (#112005)

      Use Tor? It's available on Android.

    • (Score: 2) by Fnord666 on Saturday November 01 2014, @04:09AM

      by Fnord666 (652) on Saturday November 01 2014, @04:09AM (#112116) Homepage

      Is there anything that can be done about this outside of not using AT&T/Verizon services? For myself, and I assume many others, boycotting is not an option; in my case I just re-upped a 2 year contract.

      Use a VPN for all traffic to and from your phone.

  • (Score: 2) by Kromagv0 on Friday October 31 2014, @07:25PM

    by Kromagv0 (1825) on Friday October 31 2014, @07:25PM (#112015) Homepage

    Another win for having a dumb phone.

    --
    T-Shirts and bumper stickers [zazzle.com] to offend someone
    • (Score: 3, Interesting) by c0lo on Friday October 31 2014, @08:34PM

      by c0lo (156) Subscriber Badge on Friday October 31 2014, @08:34PM (#112052) Journal
      I don't get it... Just how having a dumbphone protects you against smartphone tracking? You use it as some sort of charm or amulet?
      (ducks for cover)
      --
      https://www.youtube.com/watch?v=aoFiw2jMy-0 https://soylentnews.org/~MichaelDavidCrawford
      • (Score: 0) by Anonymous Coward on Friday October 31 2014, @09:44PM

        by Anonymous Coward on Friday October 31 2014, @09:44PM (#112068)

        The cell company tracks you instead of some anonymous website?

        I have seen the radius feeds. They have everything in them to track exactly what you do. I watched one dude work out where his phone was down to about 50 feet, without gps. You can usually 'see' 2-3 towers and they record it all. GPS makes it simple for you to know where you are at. The phone company already knows. It has to, so it can do the tower handoff.

    • (Score: 0) by Anonymous Coward on Saturday November 01 2014, @07:01AM

      by Anonymous Coward on Saturday November 01 2014, @07:01AM (#112140)

      Or you could just turn the GPS off when you're not using it, and not install software on that forces tracking, like Facebook's app, instead visiting their website from Firefox mobile w/ Ghostery, etc. And not use shitty, expensive, stalker carriers like Verizon and ATT in the first place, which is the only way to not be at risk of being tracked by them through the methods mentioned in this article.

      The only reason people's smartphones get used for tracking is because the users enable all the options that allow them to be tracked. You can't be tracked via GPS if you don't leave it on all the time, and location-by-tower works exactly the same with dumbphones.