Carrier IQ Tries to Censor Research With Baseless Legal Threat
eff.org
eff.org
"Verizon has publicly came forward with a statement regarding their usage on Carrier IQ statistics and give users a way to stop them from selling the information outside of Verizon"
Wow. No surprise that they would like to suppress that information, but they should've known better than to be so heavy-handed with the lawyering. They might have been able to spin it a little more positive with some decent PR, but now it just screams that they're being evil.
Is it possible, then, that carriers have in their databases the passwords of every server that every system admin has connected to over ssh from their smartphone?
With such a large number of potential victims, it would be difficult to determine if a wave of thefts from a particular institution were the result of the institution's security being compromised or if a CarrierIQ database was compromised.
I develop some on Android and have been aware of this product for many months now but I have no idea what data it collects and transmits. Just what it is capable of. So this may be a non-issue. For now, at least.
Or, to put it more bluntly, what did they expect to accomplish with this C&D letter? Did they seriously believe that he would just do whatever they said to?
Bad press. Lots of bad press.
The worst that can happen as a result of this C&D is 1) The Streisand Effect 2) Major news organizations smell blood in the water and decide to ramp up coverage 3) Lawsuits and Senate hearings
If the WSJ picks this up like they did the UDID, you can say goodbye to Carrier and all of the data they collect.
Understanding whether Eckhart was peddling 'inaccuracies' hinges, I think, on at least some technical proficiency. I'm not a legal expert, and even if there were inaccuracies I don't know if that establishes the plaintiff's claim or whatever.
As more and more legal complaints involve more and more complicated tech, how can we expect even a brilliant legal scholar with no technical expertise to determine facts in complicated cases?
I'm just wondering whether you can be a good judge without understanding the technical details as well as the legal ones, or at the very least be an exceptionally fast learner. At the same time, few people are both technically and legally proficient - even most patent lawyers don't need to fully understand the tech they're dealing with to write cease and desist letters, or advise their clients to settle, etc.
But maybe the judges do, and as tech progresses even more, how can we reasonably expect judges to know enough of both? I'm not trying to make the obvious point of "gee, shouldn't judges know how an iPhone works before ruling on it" but asking whether it's even possible to understand both technical and legal sides well enough.
Did he actually infringe on anything or does the First Amendment apply here?
Saying "do these things immediately and all claims will be fully released" is usually a sign of weakness to begin with - pretty much any company lawyer is going to open by overplaying his hand.
This is only an overplay of a weak hand.
Oh wait, lawyers are paid to send letters, not to minimize the reputation damage to their clients. Now I know why this comes up all the time.
[snip; about recruiter]
We sell software to tier 1 mobile network operators. Our software is running
on over 150mm handsets in the US. Each handset collects and reports 100's of
metrics of device and user behavior in real time. These metrics comprise 10's
of gigs of data per day resulting in Petabytes of data stored to date.
With our intelligence solutions, the Mobile Operator can for the first time,
analyze system, device and user behavior from every enabled smart phone
handset/device on their network. From this insight, the MNO can meaningfully
improve CAP/OPEX and customer satisfaction.
We need to hire someone to lead our data analysis effort for our ground breaking
solutions. This role would report to our VP of engineering.
[snip -- describing the company]
key phrase: " Our software is running on over 150mm handsets in the US. Each handset collects and reports 100's of metrics of device and user behavior in real time. These metrics comprise 10's of gigs of data per day resulting in Petabytes of data stored to date."50GB spread over 150 million users comes out as ~333 bytes per user and day.
Of course, the transmission of that data is likely more bursty, but even if it transmits all the data in one go, that's only 10K per month.
So your argument about the limit doesn't really fly because even if they did charge for for that data (which they probably do), considering a limit of 1GB per month, those 10k would be 0.001% of your monthly allowance, so it's probably not even detectable by their overcharge detection algorithm.
Now. Don't get me wrong: This kind of malware is really bad and shouldn't be on these phones, or if it is, it should be opt-in for the purpose of remote support.
It's just important that we hate it for the right reasons (security, privacy).
The "150m devices" claim is rather vague too. It will no doubt include devices that are no longer in use, like when a dating site claims to have X million members without mentioning the fact that all but a few thousand of them haven't logged in for many months - they can truthfully claim such devices have the software installed but that will skew the average bytes/device/day taken from the released figures downwards.
A rule of marketing (which includes selling the company to prospective employees if they are looking for them on linkedin): Never lie when you can selectively use honest statistics instead.
Research is one thing but making the research known to a wider audience who generally do not read research papers, maybe that's another.
So given the choice between a handset with CarrierIQ and packed with "features" or one without all that but which works as it's supposed to, would all informed consumers continue to choose the one with the features?
Before cell phones, pen registers and wiretaps used to require a warrant. Would anyone need a warrant to get a postive response from a wireless carrier if they asked for some CarrierIQ data? They'd probably get a price quote.
Will this type of technology be used only to catch criminals, or might it someday be used to study consumer behavior? The argument it's used to improve wireless service and therefore a justified invasion of privacy just doesn't fly.