Researcher’s Video Shows Software on Millions of Phones Logging Everything
wired.com
wired.com
All it shows is that a phone monitoring agent is informed about events that might be important while debugging - receiveing text, making calls, opening websites, pressing buttons. And that its hard to kill this agent without rooting the device.
What is important is: 1. Is the data logged on the device? (I guess that should be easy on a rooted device), 2. Is there any data sent even if the 'htc quality agent' is not activated? (route it through a linux box, tcpdump) 3. Is the data really anonymized if the 'htc quality agent' is enabled?
The entire purpose of the application is ostensibly to send user activity to a corporation called Carrier IQ. I think the burden of proof is on the application whose purpose is to send user activity to Carrier IQ as to whether or not collected user activity including keystrokes is being sent to Carrier IQ. The fact that the software is able to gain keystroke events and SMS communications at all is a security breach.
I'm sure the problem of determining what confidential information is leaving the device is being worked on right now.
Given their denials so far it's possible they have years of logs... logs containing every password ever typed into 'most modern' Android, Blackberry, and Nokia phones.
> *Handsets currently deployed: 141,275,xxx
I've used xxx because the number just counts up.
http://blog.jgc.org/2011/11/getting-little-tired-of-security...
It seems pretty clear the software doesn't actually transmit the data that it accesses, for a start receiving the volumes of data supposedly involved would require a data center the size of the moon.
CarrierIQ does lots of stuff I don't like, but it's not sending my banking passwords to a server in the USA.
For scale, lets assume that each user sends, oh, 100 megabytes of data over a year. Roughly equivalent to 100 million characters, or (going with a 5mb ascii version of the bible I just googled) 20 bibles worth of text, or 1 million URLs at 100 characters long (that's roughly one URL every 30 seconds), so this is likely an overestimate, possibly substantially. And they have all 141 million users for the full year. Punch in the numbers, and you get 141 terabytes of data. Without compression.
That's microscopic. I can buy hard drives for that off the shelf for not too much money. Here, Backblaze sells that much for $7.4k in a single box, which is absolute pennies to a company with 141 million customers: http://blog.backblaze.com/2011/07/20/petabytes-on-a-budget-v...
Meanwhile, Amazon has pricing tiers going into the petabytes for S3, and very likely receives far more than our theoretical 141TB in a single day. And they're not the size of the moon.
Feel free to prove me wrong though...
Looks like a serious breach of data protection directives:
http://en.wikipedia.org/wiki/Data_Protection_Directive
Personally identifiable, highly personal information gathered by a third party without permission, let alone notification.
What would be good to have is a sure fire way of checking if it's running, and a clear list of which phones have this and which don't. I hope someone is gearing up to sue the f- out of Carrier IQ, but if not, I'd like to have the information publicly available so we can all invoke those old free market principals of customer choice and choose not to buy any phones with this on.
Hence the word 'secret' in the title and the word rootkit multiple times in the article.
It was shown also working on WiFi. How can we tell if this is also on Android tablets?
Are we yet sure this is not in iOS at all?
There's probably plenty more like them that us plebes don't know about.
What would we do without EFF?
This is preposterous. Next thing you know, they'll be using this information to send you a bill at the end of the month based on who you call and how much bandwidth you've used!
And every keystroke that you enter in "secure" connections, and everything you do offline.
That's much, much, more than you expect your ISP to have access to. It's essentially a keylogger running on a computer (your phone) that you own.
But, just because something like this was able to sneak it's way onto there, it does give the Microsoft (WP7) and Apple model of strict control some validity that it might be beneficial to users. I wouldn't expect to see something like this on WP7, where carriers get only a separate category in the Marketplace and for manufacturers, (I believe) only Nokia can add applications. (Same for iOS, where it's all Apple, but WP7 proves that the secure model could possibly work for a more distributed ecosystem like Android.)
1) their software logs all keystrokes. 2) their software sends all keystrokes to their servers. 3) they denied it did so.
Those don't add up to reasonable doubt any way I can see it. If they were using that information for understanding crashes, dropped calls, etc, then they would have seen that it was recording everything, and would have seen it many many many times. It can't have slipped past their notice unless it was totally un-used, and then they should've raised an eyebrow at the massive numbers of signals being sent to their domains.
Is it possible that this is simply a tool to allow for USB debugging of the UI? Otherwise, are there details (how often, what) is getting sent back to the carriers or to this company?
>From there, the data — including the content of text messages — is sent to Carrier IQ’s servers, in secret.
Not that I fully trust the accuracy of journalists, I'd just hope Wired would be mostly accurate at least.
I'm surprised he didn't do that too, would love to try it myself, can't for a week or so though, someone will have done it by then.
(Please? :-)