Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

True, but an enterprising individual could write an extension to cause non-Verizon users to start feeding fake unique identifiers into their own streams. Heck, you may even be able to hijack a website login using it.


> True, but an enterprising individual could write an extension to cause non-Verizon users to start feeding fake unique identifiers into their own streams.

nl (https://news.ycombinator.com/item?id=8890677) addressed this:

> If you aren't on their network then they can check IP address and ignore values not from the Verizon subnets.



Exactly. But instead of using it to try to change your UIDH within Verizon, it should encourage non-Verizon customers to just pollute the space with random UIDH values from all over the place.


And (as I previously noted) all Verizon has to do is *check the IP address of the client(!). They know the IPs they own.

Assuming that your adversary is dumb as well as malicious is a mistake.


True, but this header is presented to all sites visited. This wouldn't pollute Verizon's tracking (they could do this without the header). This may instead pollute the third parties which are taking advantage.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: