Showing posts with label header Insertion. Show all posts
Showing posts with label header Insertion. Show all posts

Monday, February 2, 2015

Verizon: Customers May Opt-out from Header Insertion


Back in October,  Jonathan Mayer,  a computer scientist and lawyer at Stanford, found how Verizon Wireless'  HTTP header insertion works (here, chart below), which naturally raised concerns about customers'  privacy.

In conjunction (?) with the Data Privacy Day (here), Brian X. Chen and Natasha Singer post to the New York Times blog states that "Verizon Wireless, which has been under fire by privacy advocates since late last year, has decided to make a major revision to its mobile ad-targeting program .. In a recent interview, Praveen Atreya, a Verizon director who helped develop the technology behind the mobile marketing program, said the company was considering allowing its subscribers to opt out of being tagged with its undeletable customer codes. On Friday, Verizon confirmed this decision.

Debi Lewis [pictured], a Verizon spokeswoman, issued this statement: 'Verizon takes customer privacy seriously and it is a central consideration as we develop new products and services. As the mobile advertising ecosystem evolves, and our advertising business grows, delivering solutions with best-in-class privacy protections remains our focus.

We listen to our customers and provide them the ability to opt out of our advertising programs. We have begun working to expand the opt-out to include the identifier referred to as the UIDH, and expect that to be available soon. As a reminder, Verizon never shares customer information with third parties as part of our advertising programs'".

See "Verizon Wireless to Allow Complete Opt Out of Mobile ‘Supercookies’" - here.

Sunday, October 26, 2014

Verizon Injects HTTP Header for Advertising


A post by Jonathan Mayer [pictured], a computer scientist and lawyer at Stanford analyzes the recent HTTP header insertion by Verizon (apparently used for behavioral advertising):

"After poring over Verizon’s related patents and marketing materials, here’s my rough understanding of how the header works [see chart below] .. In short, Verizon is packaging and selling subscriber information, acting as a data broker on real-time advertising exchanges. Questionable. By default, the information appears to consist of demographic and geographic segments.2 If a user has opted into “Verizon Selects,” then Verizon also shares behavioral profiles built by deep packet inspection". 

See more at "How Verizon’s Advertising Header Works" - here.

Thursday, January 26, 2012

O2 Uses Openwave to Insert Users' Mobile Numbers into HTTP Requests

     
The press reports that Lewis Peckover, system administrator, Probability, found that O2 inserts customers' mobile number into HTTP headers (x-up-calling-line-id field) sent to web sites. Lewis even set a web page (here) for O2 users (or anyone else) to see that. This is a common mobile proxy gateway, generally known as "header insertion".

According to the following article, x-up-calling-line-id field is generated by Openwave gateways, which are also used by O2. Equipment from other vendors does it as well, of course, see an example for that here. One reason to do that is to identify the user to 3rd parties, for chagrining or other purposes.

Few hours after his discovery, Lewis tweeted that "Looks like @O2 may have just resolved the issue. It has stopped showing my number. Anyone still seeing it?"

See report by Anna Leach for The Register - "O2 leaks 3G users' mobile numbers to every website visited" - here.