At least nine telecommunications companies around the world are using so-called super cookies to secretly monitor their customers' online behavior, according to a new study.

Super cookies enforce a unique token for each subscriber that is injected into every HTTP request made over a telecommunications company's mobile phone networks.
It cannot be removed by the user: it allows ad networks and media publishers to track users across the Internet, even if they delete their cookies.
Super Cookies allow networks to create profiles that include users' habits, so they can serve targeted ads, while phone companies take their cut.
A six-month investigation by digital rights group Access has shown that overseas phone companies are using super-cookie techniques.
The activist group Access even created a website called Amibeingtracked.com, and by tracking visits from 180,000 internet users, the group found that 15.3% of visitors had tracking headers installed on their phones from vendors in Canada, China, India, Mexico, Morocco, the Netherlands, Peru, Spain, the US, and Venezuela.
Verizon, AT&T, Bell Canada, Bharti Airtel, Cricket, Telefonica de España, Viettel Peru Sac, Vodafone NL, and Vodafone Spain all used Super Cookies technology.
The samples collected from the website showed a wide degree of variation in what data is collected and transmitted using the technique. Some phone companies encrypt the header information, but some still send the data in plain text. In some cases, the user's phone number is even included.
“Not all providers track their users, and those that respect privacy deserve our support,” the study states [PDF].
The only way to stop this data leak is to limit your internet browsing to only websites that use HTTPS, which is currently impossible.
Source: secnewsgr.kinsta.cloud
