Secret app on millions of phones logs key taps
theregister.co.uk
theregister.co.uk
If you're still inclined to give them the benefit of the doubt, just read the CarrierIQ website. Their ENTIRE BUSINESS MODEL is based on collecting data about mobile phone users!! Here's a choice excerptI found on their website after browsing their site for 30 seconds[1]:
Carrier IQ's Mobile Service Intelligence Platform (MSIP)...receives raw data (known as Metrics) from phones and converts them into reliable, repeatable Measures which feed into analytic applications.
Or you can read this comment from a discussion last week where a CarrierIQ recruiter told an HN member that they collect 10s of gigabytes of data PER DAY.[2]
These guys are indeed collecting RAW DATA from actions on your phone. There are tremendous opportunities for abuse here, should CarrierIQ decide to do so. CarrierIQ in blatant violation of privacy norms and could do enormous damage to national security of many countries, conduct corporate espionage, or simply violate the citizens' expectation of privacy when using their phone.
This is dangerous and should be stopped immediately.
1. http://www.carrieriq.com/overview/mobileservice/index.htm 2. http://news.ycombinator.com/item?id=3264264
I do however know two things. 1) That their local software processes almost every key stroke made. 2) And that they do send at least some portion of this data back to their servers.
At this point it would be trivial for them to send my private information TOMORROW if they decided to do so. I don't know that they don't have a subroutine to begin sending all of my SMS back to their servers if they decide to so for profit or under government coercion.
If they have no plans of using my Google searches, they shouldn't process it in the first place.
Your starting point was that they were collecting† data that could jeopardize national security††. You clearly based that argument on the idea that their own recruiter mentioned "10s of gigabytes a day".
Now, in true message board geek fashion, you're going to steadily move the goalposts. What? They're not collecting messages? Well then they're processing messages! They shouldn't be doing that either!
The problem with this tactic --- make a spectacularly unsupported assertion and then back off it in a series of non-concession-concessions --- is that you cease to be credible. Is this what you really think? Or will you re-harden your position if e.g. it becomes clear that they're not even seeing the keycodes of the keypresses, but rather using an API that could conceivably allow them to get them.
† Your word.
†† Ibid.
I don't think there's any goalpost moving here at all: Hundreds of millions of keyloggers -- rootkits, really, as the article states -- are installed and unremovable. Whether they are being abused or not at the moment is irrelevant; it should be outrageous and unacceptable that such a datastream is going through a third-party without any kind of transparency, acceptance, or even tacit acknowledgement.
Likewise, your rhetorical refutation here (very thorough, in the abstract) would be a lot more damning if there wasn't, you know, video evidence of this rootkit collecting exactly this data and sending it back.
Now you're defending/rationalizing whatever disgusting bullshit Carrier IQ is up to.
What's wrong with you?
Just like we didn't have absolute proof that Aaron's indictment was politically motivated, we can't be absolutely sure that Carrier IQ is a company full of shit and devoid of morals.
But it's blindingly obvious that both are very, very likely.
In case you're just blissfully unaware of how full of shit the world actually is, here's a report on your justice system fraudulently, systematically signing away people's homes: http://www.rollingstone.com/politics/news/matt-taibbi-courts...
"Carrier IQ, which in the second quarter of 2011 passed the petabyte milestone in processed analytics data"
If we go by the official letter you've posted and assume conservatively CarrierIQ has only 1 Petabyte of data, and that they've been collecting since 2006 (when they received their Series A), they've been collecting 456 GBs of data per day. Its probably more than that today since the data collection rate has surely accelerated over time.
That's an order of magnitude beyond 10s of GB per day.
A terabyte is 1000GB. Why would they be shouting about terabytes if it were anything over .09 terabytes?
And isn't it likely that some phones are set to transfer more data than others?
An average across 145M users crossing various demographics and phones types is not a good metric to use to determine the possible danger of the data being sent.
I tend to agree with you, but at the same time wonder how they're aggregating the data; they could store each day's raw data in however many GB, then crunch it down later.
The only other potential issue that jumps out at me is bandwidth; I'd find it strange if the data isn't being compressed, but if it is, you could cram quite a lot of useful information into those few hundred bytes ;)
So logging all of everyone's texts is probably still out.
But easily logging their browsing patterns. Probably app installation and use. And certainly they retain the capability to log texts containing keywords without going too far outside that aggregate range of data. Or doing targeted logging of all of selected individuals usage.
There are multiple YC startups that could write the (bad) marketing sentence "we receive raw data (known as metrics) from X and convert them into reliable, repeatable Measures which feed into analytic applications". Personally, I'm inclined to think that when someone writes "we receive raw metrics", they mean "they receive raw metrics". You seem to premise your entire comment on the idea that "raw metrics" means "tremendous opportunities for abuse, damage to national security, corporate espionage".
Those two points --- 10 gigabytes, and "raw metrics" --- seem literally to be the entire basis of your (currently top ranked) comment.
I wish I could be more strident in disagreeing with you (because your tone makes me want to be), but I have to admit that I have no clue what this company is taking off Sprint phones. I'm inclined to believe that nobody could be dumb enough to take the contents of SMS messages from phones --- Sprint doesn't want that data --- but who knows?
I wrote a similarly negative comment yesterday when this story hit HN the first time. Then I read downthread and found John Graham-Cumming thoughtfully picking apart the story. I read his comment, re-read mine, and deleted mine. 'jgc's comments on this story are interesting; ours are less so; his is buried under yours now. Perhaps you could follow my lead.
This fundamental principle is embedded in all the software I use. I consider any software that doesn't adhere to this principle malware. When my PC crashes, Microsoft asks me if I want to share information with them about what led to the crash. I usually say no, but I appreciate them asking. When I use gmail, I do so with the understanding that Google has full access to the contents of my email. They promise me that they won't do any funny stuff and I accept the conditions of this contract in exchange for free email.
I never entered into such an agreement with CarrierIQ. I've never even heard of CarrierIQ until this week. Yet despite this, they are logging everything I type into my phone, and sending some portion of the information that they log.
If I offered you $100 to install a program I wrote that logged every keystroke on your computer and sent some portion of this information to my own server over TCP, without giving you a privacy policy, you know very well you'd never take me up on this offer. So why is it ok with CarrierIQ?
The focus on how much information is in 10GB is beside the point. The point is that CarrierIQ has been demonstrated to have the ability to read and send everything you type into your phone. At this point we're just hoping they're the good guys and won't do anything overtly evil. But what's to stop them from calling the following function on your phone?
if username == 'tptack': sendStoredData()
As 'potatolicious seems fond of saying, "that's not even wrong".
Everyone agrees with you already.
I always forget, is it light or heat that's the one you don't want? You're adding more of the bad one, and none of the good one.
Apart from rebutting your analysis earlier, I'm under no illusion that my comment is helping clear up this ${INSERT_NERD_FREAKOUT_HERE} either, but I'm at least happy to speak up and raise the meta point that we shouldn't be rewarding comments like yours. Also, for obvious reasons, I'm past giving a shit about comment karma, so I can just say what I think.
Principles matter, meta discussions like these matter. The technology we work on don't operate in a social vacuum.
When someone uses a mobile phone, they generally have the assumption that, unless they consent to it, third parties do not have access to their data (the government being a different story I won't go into). When I use GMail, I consent to Google reading my email via automated algorithms, and targeting ads at me through that. If I have anything important, I use email that I host myself or, if it's really top-secret, an anonymous throwaway account through Tor.
However, from what this video demonstrates, CarrierIQ is violating the basic principle of this by capturing and potentially logging your personal data without your knowledge or consent. Furthermore, it's violating the assumption that most people have that their passwords and such are not captured by applications other than the ones that they are entered into.
Now, we don't know for sure whether all this information is sent off to their servers and logged or not. However, in my personal opinion, the fact that this information is CAPTURED AT ALL is a serious problem, when combined with the fact that you are not informed of this!
He's one of the people who has been on HN forever. He's often a bit contrarian, but I don't doubt that he believes what he says, even when I strongly disagree with it. And if you scroll up, you'll see that I've already made clear my disagreements on this one.
http://www.carrieriq.com/overview/IQInsightServiceAnalyzer/i...
I wouldn't care if they were logging non-identifying info, such as the amount of time my phone display is on to analyze battery performance, for instance, or perhaps even the general settings I have on my phone to help HTC deliver more desirable "factory settings." Any of this could add up to that 1% you mention.
Speaking personally though I use a 5 or 6-year-old Blackberry model with no data plan and will happily continue to do so.
Who is to say the carriers are not processing on the upstream? We certainly know that Carnivore was designed to do just this.
Let's just say; there is NO privacy on ANY digital communications. Period.
If you think otherwise, it is likely just being naive.
We know that the US and China have been in an extended cyber war fro more that 10 years now.
You, earlier:
"What percentage of all the SMS messages ... do you think 10 gigabytes is?"
Stop moving the goalposts and maybe we'll get somewhere.
Their own words are not dispositive; I'm not suggesting that they are. But here you're trying to interpret their words in a way that contradicts their own direct statement. Your interpretation is possibly accurate, but implausible.
My best guess (I know just as little about CarrierIQ as everyone else on this thread) is that CarrierIQ is trying to collect very innocuous information (performance statistics and event information to correlate them to), but is doing a slapdash job of generating that information --- for instance, by logging raw details to the Android filesystem.
I wouldn't want it on my phone either, but that doesn't make them Big Brother --- or, obviously, a "rootkit".
http://www.schneier.com/blog/archives/2009/11/leaked_911_tex...
Even so, I wouldn't put it past them to do keyword mining for mobile ads. That just seems like such an obvious potential use.
What do you know about them that makes you trust them?
1. CarrierIQ is a "secret" in the same sense as the network management software that Sprint uses that can also see all your SMS messages is a "secret": (a) nobody at Sprint thinks its relevant to you, and (b) nobody at Sprint thinks its any of your business. Which, if you take a breath, strictly speaking about the performance metrics they're collecting, it isn't your business.
2. CarrierIQ was dumb about threatening this guy like lots of other companies have been identically dumb. Companies have threatened to sue me. I remain cordial with the owners of some of those companies. Welcome to security research; we don't have jackets, but we sure get a lot of press.
Incidentally, put yourself in CarrierIQ's position and assume that this particular researcher is full of shit, meaning, no, CarrierIQ is not snooping on people's keystrokes. What would you do? There's a guy out there claiming that their performance agent is a "rootkit". They got pissed. Surprised?
3. Any piece of systems software the carrier agrees to stick on the phone is capable of snooping. Sprint itself could just backdoor their Android distro.
I think someone once said that sufficiently advanced incompetence is indistinguishable from malice. Whether they're dumb or malicious, I'm just glad their crap isn't on my phone.
I don't know whether some other shoe is about to drop; for instance, someone could actually show that they're transmitting real keycodes and not just metrics data. But in the absence of that shoe dropping, especially given how many people have jumped to a conclusion about CarrierIQ, I'm inclined to believe that what they do is actually benign. If you want to get upset at someone, get upset at the carriers themselves. When you do, remember, they're already recording all your messages without CarrierIQ.
Using 2e12 SMS messages/year, 160 characters/message, and 1 byte/character:
(2e12 * 160) / (365 * (2^30)) = 816.501983 GiB/day
So 10GiB/day is about 1.2% of daily SMS traffic.
EDIT: Too slow.
I think that there are zero people on HN that think CarrierIQ is a good idea.
So if all we're doing here is condemning CarrierIQ, let's just replace this whole thread with "CARRIERIQ BAD", followed by a bulleted list of bad things, vote it up to 1000, and then get back to talking about building things.
We get it, you don't like this thread. You don't need to respond to every comment with a pedantic "fuck you, shut up, and get off my lawn, I have a billion comment karma because people upvote snark so now I'm going to act like a dick " comment of your own.
My feeling is that the same name recognition influence that gets most of my comments modded up 100-200% more than they're actually worth is going to get my -4 comments read even though they're light grey. We'll see!
I asked someone who is quite good with crypto a question about a possible MITM attack on 141 million phones. I didn't condemn CarrierIQ, I avoided dramatic language, I even added qualifiers to avoid stating something as fact if it wasn't yet confirmed.
Doing an SSL MITM from agent software installed by the carrier on a phone seems pretty silly, since the carrier is in a position to see anything you're typing into your phone anyways (in the sense that it controls the OS).
I'm not sure I buy any analysis that suggests CarrierIQ is really "MITM'ing" SSL --- though that's trivial for a software agent to do --- because the same people saying that are also saying that it's obvious that CarrierIQ is capturing and remote-logging message contents.
I'm just curious if that's the way phones will be forever: with the OS controlled by the carrier and with no right to tinker/hack/modify the device you buy & pay huge monthly fees to use.
From your link to the recruiter:
Each handset collects and reports 100's of metrics of device and user behavior in real time.
That's data like phone location, applications used, etc. Very bad yes, keylogger reporting your password, no.
The guy shows `adb logcat` running and showing CarrierIQ logging keystrokes with their ASCII codes.
(edit: I make no claims about the transmission of data. I merely took "collection" and assumed that if the app was recording (even if not persistently) keystrokes on my phone that it counted as collection. Further, the fact that it can is enough to piss me off, especially since it seems like makers of this type of software have piss-poor track records for their app security)
Even if "raw data" are not currently being uploaded, how thin is the line between this being turned off and it being turned on? And who is in control of that decision?
At an absolute minimum, the situation demands transparency.
As for me, I'm a step closer to being firmly in Stallman's camp.
Second, maybe they are selling the information to other parties by letting the other parties grab the information themselves.
All I've seen proof of so far is that it is capable of doing so because of how it is called before everything for anything, but let's not jump to conclusions here.
They're obviously doing bad stuff, but I see no evidence of uploading your keystrokes
com.htc.android.iqagent.action.ui01
actionUI01:49,0
where 49 is the keycode for the "1" key. This means the Carrier IQ code is called to collect and process this event information.We just don't know what the code is doing with this information. Perhaps it is simply updating statistics and discarding it. So I guess your argument with drivebyacct2 is on the definition of "collecting"...
What if the program just collects the aggregate metrics, sends them and then deletes the actual keystrokes?
Not saying it doesn't send keystrokes, but the video is definitely not proof of that and it bears further investigation, not knee jerk reactions.
Meanwhile, there are plenty of pieces of code strewn throughout your system that get access to similar bits of sensitive data. For instance, every BSD system has a BPF device and driver that exists solely to tap your network traffic. Luckily, nobody sells a BPF-for-Android product.
I'm not saying that this is a clinching argument. I'm simply making a point that is germane to the discussion. Distilled, it is: "just because a piece of systems code deals with your private information does not make a violation of your privacy; sometimes it does, sometimes it doesn't".
Besides, the BPF driver in every BSD system is probably open-source and could be reviewed for intent if in doubt. It's not easy, not everybody can do it, but it is possible.
However, you cannot do that for CarrierIQ. Even if such logs aren't getting sent, you don't know that they haven't installed some kind of mechanism to trigger such an upload on demand.
Maybe he did send data, maybe he didn't. But he's also sent you a CnD notice and threatening to sue you if you tell anyone.
I fear this is where we're going in all corners of tech. Even moreso because we're already quickly eroding at any expectation that one should provide privacy to their users. All the while users are ignorant enough about tech in general and have no idea that their privacy can and is flying out the door. Software exists in such a way that the lay user can't ever understand the boundaries or capabilities of software to do things that they are completely unaware of. The numbers of people who do understand what is going on is so small that they are neither a significant portion of the market, nor a "reasonable person" in the eyes of courts.
Privacy will be dead before anyone even notices.
This is bad enough, though. But, let's keep our head about this and calmly demand an explanation from HTC. Why them? Because they signed the binaries with their certificate, presumably at the request of carriers, but HTC is the first in line.
And don't believe the response from CarrierIQ. Just prior to that response, they still had very informative high resolution screenshots of their "Device Analyzer" product which showed a scary level of data mining of end user devices. They were probably great eye candy for their customers (carriers), but creepy for anyone valuing their privacy.
I agree that this information is likely for improved QoS, but what can (has) it been mis-used for? Employees can't be trusted, and the government can't be trusted. An end user can't even opt out of it.
Edit: According to Google Image Search, others are mirroring some of the prior shots. Note that nothing is anonymized in the least (nevermind that anonymizing data is practically a myth).
I'll try and tack the URLs below.
http://androidsecuritytest.com/wp-content/uploads/2011/11/ci...
http://www.xda-developers.com/wp-content/uploads/2011/11/met...
http://androidsecuritytest.com/wp-content/uploads/2011/11/me...
http://androidsecuritytest.com/wp-content/uploads/2011/11/tr...
http://androidsecuritytest.com/wp-content/uploads/2011/11/CI...
http://androidsecuritytest.com/wp-content/uploads/2011/11/si...
http://www.carrieriq.com/overview/IQInsightDeviceAnalyzer/De...
This one doesn't need to be big to get the jist:
http://www.carrieriq.com/overview/IQInsightServiceAnalyzer/i...
"In an interview last week, Carrier IQ VP of Marketing Andrew Coward rejected claims the software posed a privacy threat because it never captured key presses.
“Our technology is not real time,” he said at the time. "It's not constantly reporting back. It's gathering information up and is usually transmitted in small doses.”
Note that last clause there.
Besides: Reading weasel words like 'usually' in corporate statements just makes me shudder.
There's also a third upload reason in that image which has it's own disturbing implications: "SMS_PullRequest_CS".
Even if they never do anything with keystroke data, just the fact that they can is the dangerous part. What is to prevent some switch to start sending the keystrokes in the future? I'll be blunt, this companies implementation of its business model strikes me as being borderline wiretapping.
"Dear Kevin Jacobs,
I understand you would like more information about the Carrier IQ software, or any software of this nature on your device. I understand your concerns about this issue and protecting my privacy is definitely one of my top priorities as well.
We have not had any reports of any kind of software like this on any Windows Phone 7 device. This type of software has been used on Android devices, but since Microsoft developed this operating system I am sure they did not include any software of this kind.
Let me know if I have successfully answered your question, please click here to complete this.
To send a reply to this message, please click here.
Sincerely,
Kathleen
HTC"
While I am a WP7 owner, I find this to be a little presumptuous. Microsoft may not have included _this specific_ software, but how does HTC know they didn't include anything like it? I don't believe Microsoft gives handset makers the source code for the software. I know they don't allow them to customize it. Perhaps HTC has not installed anything like it or been allowed to install anything like it, but how would HTC know if MS did it themselves?
http://blog.jgc.org/2011/11/getting-little-tired-of-security...
There's no evidence that it sends this information to the company and no evidence that it actually logs it. Only that APIs are called containing it.
I think the subtle difference here is that we as consumers have a implicit understanding that the OS and the carriers must store and handle our data in order to provide the services to us that they do. We must trust them if we use their devices and networks.
That trust is given because the data sensitivity is proportional to the disclosure and scrutiny of the providers. The phone, its OS and who provides the network inherently have access to all your data, a huge responsibility, so no attempts are made to hide or obfuscate who those companies are and what they're doing. You know Samsung makes your phone, it runs on android and you use the Verizon network. CarrierIQ seems to have access to all the same data your OS and carrier has, yet their presence is not made transparent/known to the user of the phone.
That said, it's not clear to me what CarrierIQ's integration is like? Is it purely a software framework Android uses to log and store metrics for the carriers? Is it a 3rd party app installed by the carrier to help them store user metrics? How antonymous is CarrierIQ with the data? Do CarrierIQ engineers see your data or is it just for the carriers? Until that's clear, it's anyone's guess.
This is 1000 times worse.
Anything Apple does wrong is blown out of proportion. Yes the Apple collected data wasn't encrypted, but now it is.
What if this data is compromised at this CIQ company? I hope the data is traceable to an IMEI number ONLY which would make it okay, but still! Why do they need to receive text messages coming in to the phone???
this was detected on an android device which is a fairly open platform when compared to the iPhone/Windows phones in terms of software transparency, correct? Is there any way to know for certain that Apple/MS aren't doing this exact same/similar sort of thing?
You can't really ever know things "for certain", but considering the number of jailbroken iOS devices in researcher hands it's likely this would have been discovered.
This has been alarmingly on the rise here on HN these days.
http://lifehacker.com/5863895/carrier-iq-how-the-widespread-...
"Update: Our original article stated that the software also came preinstalled on iPhones and dumphones, which has not been confirmed. That information came from this article at Geeks.com, and we actually believe that to be a typo. Considering it hasn't been mentioned in any other source, and that the iPhone isn't on Eckhart's list of affected devices, we're removing it until other sources say otherwise. Thanks to everyone who pointed this out."
With this finding, if someone got possession of your phone, they could apparently discern...nothing. Instead a subset of data is sent to a company contracted by the carriers (or at least one - Sprint) for the purposes of network monitoring/quality monitoring. Of course the carriers already know your location history through time (just as they know every SMS you sent, picture you sent, data you transmitted, voice call you made, etc), whether you're on a smartphone or dumbphone, and everyone knows and is aware of this.
Is this app sending too much data? I guess we'll find out. Is it "1000 times worse" than a forever location log easily exploitable? Not really.
EDIT (while sitting at -4 while the hysterics have their fit of vapours): Moderation in this story has demonstrated to me once and for all that HN is largely populated by ignorant bottom-feeders now. It is a sad state of affairs, and this site desperately needs a turn off moderation from dipshits option for users to toggle.
To get access to your location data on the iPhone, someone would have to steal your phone or get into your itunes account. This is happening in the background.
Where does anyone say that it is being sent to a third party? This rather noob-ish developer noted that they have a keyboard hook, but in no way does that mean that they send all of your keystrokes to a third party.
Honestly I think I expect too much from HN. The level of discourse on here is absolutely no better than any typical blowhard site.
Directly from the article:
> “Our technology is not real time,” he said at the time. "It's not constantly reporting back. It's gathering information up and is usually transmitted in small doses.”
The issue is, we don't know what this software is gathering and sending. It is not being done with consent.
But you're right, this needs to be looked into before getting the pitchforks out. But certainly, having the presence of a keylogger is bad enough in itself.
The meta is pertinent. I expect the sort of knee-jerk reaction among non-software developers. I don't among a more educated in the realm crowd.
There is little chance this company is recording, much less transmitting, everything you type, every message you receive, etc. I would hazard a guess that they do, however, record basic usage patterns to let the carrier know how people are using their devices ("6975 characters average per day, send 256 messages while receiving 12. Spends an average 37 seconds in the dialer.").
This whole story is that they have system event hooks. That's it. Maybe a real security researcher will find something deeper, but as is it's a nothing story of limited interest. When people like you carry it further than reality you just add ignorance to the conversation.
[1] http://news.ycombinator.com/item?id=3263955 [2] http://news.ycombinator.com/item?id=3273416
* Did they implemented key-logger? Yes/No
* Do they write keys into some local log? Yes/No
* If they have key-logger, then why do they have key-logger? (Company statement - please)
* If they write key strokes to some log file, is that log file related to logs which are send to "mother ship"?
This is rather brash. I am surprised to see this on a such an open platform as Android. Even as some of the comments are suggesting they are not sending the data in non crash situations, keeping it logged is rather brazen.
On the flip side though, I have to wonder how would one determine crash behavior before the phone crashes? It seems to me that the phone would need to preemptively log some behavior that would then be indicative as to what caused the crash.
The problem this thread highlights is poor marketing and transparency. No one at CarrierIQ gives a damn what we text. Breaking those basic privacy tenants would destroy their business, which seems to be going nicely if their software is on >100M devices.
The company just does a crappy job explaining what their technology does and how it helps consumers. Uncertainty around our private information spooks people, which leads to distrust and conspiracy theories. Let this be a valuable lesson for entrepreneurs who touch consumer data, even B2B solutions.
Gmail and Bluekai provide excellent counter-examples of ways to squash these concerns: -Gmail -remember the ruckus about Google reading your email for ads? Google publicly explained this and now no one cares. -Bluekai -the company tracks data for online ads. Touch subject. But they're transparent and lay everything out on their website, including an opt-out: http://bluekai.com/consumers.php
CarrierIQ clearly needs to address these issues. Let's call on them to do that. In the meantime, take a moment to imagine how much more we'd hate carriers if reception was even spottier (cough...AT&T iphone...)
>"The problem this thread highlights is poor marketing and transparency. No one at CarrierIQ gives a damn what we text." Warrantless wiretapping is illegal. I'm not sure what more to say here.
>"Breaking those basic privacy tenants would destroy their business, which seems to be going nicely if their software is on >100M devices." unless you can't [as a non-techie] remove their software or opt out, which you can't.
>"The company just does a crappy job explaining what their technology does and how it helps consumers. Uncertainty around our private information spooks people, which leads to distrust and conspiracy theories." http://www.echelon2.org/wiki/Palantir OK. I don't believe you since there are lots of documented reasons to not trust anyone with data like this. Also, why did they send a CnD letter to the guy and threaten him if they're not doing anything bad?
>"Let this be a valuable lesson for entrepreneurs who touch consumer data, even B2B solutions." Yes, installing rootkits on hundreds of millions of devices without user consent, then trying to gag the security researcher who outs you is pretty damn bad form.
>"CarrierIQ clearly needs to address these issues. Let's call on them to do that. In the meantime, take a moment to imagine how much more we'd hate carriers if reception was even spottier (cough...AT&T iphone...)" No, people already hate carriers, and there is no explanation that will make installing keyloggers on hundreds of millions of cellphones acceptable, ever. As I already said, carriers have had the power to gather the data they need to improve their networks at the infrastructure level (towers record MEIDs / EIDs / IMEIs already and this data would be easier to collect there) for years, and they already do use that to "improve" their networks.
Not to spout conspiracy theories everywhere here, but have you /seen/ the FCC press release about the ATT / T-Mobile merger and how badly ATT misrepresented facts? http://www.theverge.com/2011/11/30/2599466/fcc-report-att-pr... give this a read and then honestly tell me you think that carriers have all the best intentions.
Companies are supposed to make profits for shareholders, not protect your privacy or be nice to you. If they can make money by selling your personal data, they will and they're probably doing just that right now.
A handful of comments are saying that is ok because CarrierIQ is probably not sending all data (probably not in Europe, but probably they do in Saudi Arabia). This is disturbing because people making these kind of comments are entrepreneurs and in general great people. It seems like we are loosing our moral compas in Silly Valley. Fuck. Please please don't do things like this.
I'd like to run wireshark to check out what's really going out of my phone when I'm on the wifi - I'm a bit of a novice in that area (network monitoring), does anyone have any pointers of things to look for?
Alright. So for now I don't see much "phone-home trouble" but I'm far from the security expert around here. There are a few http queries (both GET and POST) made using some plain text OAUTH tokens to the MotoBLUR servers, but as far as I could notice nothing was really sending much information. Then again, the first thing you do when you launch blur for the first time is giving it your twitter/facebook/gmail account login&passwords, so... I'll get what I deserve here :P
The only "tracking/keylogging" queries I could find were done to data.flurry.com, and were only tracking (in plain text) my inputs on the Winamp App, so I call it fair play.
I'm a bit relieved here, thanks again for the tip with Charles. Let's hope someone with a better expertise than me will definitely rule Motorola out of that CarrierIQ logging thing, but so far, so good.
Carrier IQ VP of Marketing Andrew Coward rejected claims the
software posed a privacy threat because it never captured key presses.
“Our technology is not real time,” he said at the time. "It's not constantly reporting back.
It's gathering information up and is usually transmitted in small doses.”
Coward say[s] that Carrier IQ was a diagnostic tool designed to give network carriers and device manufacturers
detailed information about the causes of dropped calls and other performance issues.Accessed yes, logged, well nobody has found the log yet, and sent, nobody has found any network traffic.
It's still bad, but the reports seem to be over-hyped by journalists looking for a scoop.
The issues are:
(1) That a vector is there for an untrusted third party to record and report all keystrokes
(2) It was put there at the insistence of the carriers, and
(3) That there is no way for a user to turn it off without voiding their warranty.
edit:
(4) This has serious implications for the trustworthiness of Android-based platforms as we attempt to move towards using NFC for financial transactions. Who in their right mind would trust Android (or any smartphone, really) as a debit card after this?
http://www.schneier.com/blog/archives/2009/11/leaked_911_tex...
How is stealing the most sensitive of data off my phone without my knowledge/consent ANY different then walking into my house and taking my passport??
MASSIVE CLASS ACTION
Lawyers fire up your infomercials.
No, instead the lawyers responsible for offering the class action will be willing to settle for a) a rather nice profit for them, b) a pittance for the handful of individuals they round up to be plaintiffs, and c) some symbolic genuflecting in the direction of privacy, maybe in the form of a charitable donation to a non-profit.
The sum total cost of a) through c) will be carefully calculated - high, but not too high, or Carrier IQ (and their clients, who will also get sued) will decide to fight back and possibly win. Certainly nothing infomerical-worthy - that's reserved for cases where winning is pretty much guaranteed.
Here are a couple of quotes from Carrier IQ's pending U.S. 20090207749 USER-INITIATED REPORTING OF MOBILE COMMUNICATION SYSTEM ERRORS:
"...This configuration enables the system 200 to dynamically generate and download to a population of wireless devices rule-based data collection profiles. Data collection profiles may be generated manually by a network administrator, a software developer or other personnel involved in the operation of the network (hereinafter referred to as "network administrators"), created offline as a portion of a data analysis solution, or automatically generated based on network parameters or other events. Profiles define what information is to be collected on the devices in response to which conditions and events, as well as the conditions and events that cause the device to upload the collected information.
[0038] Conditions or events include any occurrence in the network or on the device that the device can sense, such as a call dropping or a user pressing a button on the device. Conditions and events also include the passage of time, or a request from a network administrator that the device report information back to the server. Conditions and events which cause a device to collect information or upload the collected information may generally be referred to as "triggers." "
and:
"[0080] In the exemplary embodiment, triggers may be included in the data collection directives of a data collection profile, and their inclusion causes the client to initiate, abort, and terminate data collection activity as appropriate when the associated trigger condition is invoked by the wireless device 400. A trigger invocation that matches the initiating trigger causes data collection activity to begin. A match of the terminating trigger causes the data collection activity to end, and a metrics package is then prepared for uploading. An abort trigger causes data collection activity to cease, and a metrics package is not prepared or is not uploaded. In the example used earlier, launching an application caused the client to be invoked with an "application launched" trigger event, which is matched against triggers in downloaded profiles and causes data collection activity to begin on a user's device. The user's entering of a particular key sequence, pressing of a dedicated button, or selection of a particular menu option while the application is running would cause another trigger to be activated, and the SQC would match the event to a terminating trigger in the profile, cause data collection to stop and a metrics package to be prepared and uploaded. As can be seen, the inclusion of a trigger in a profile effectively selects the condition under which a specific action associated with that profile is to be executed. The trigger is not strictly within the profile, rather it associates specific profile actions (start, stop, abort) with a specific event on the device. "
And the claims from their pending "USING MOBILE DEVICE TO CREATE ACTIVITY RECORD" application No. 20090210516 is quite interesting to browse:
1. In a communication system, a method for creating an activity record, the method comprising: recording data at a device, the data including one or more events and event-related data that describe activities of a user; uploading the data to a server, wherein the server organizes the data based the event related data; and generating an activity record using the data that can be presented to a user, wherein the activity record represents at least a partial log of the activities of the user.
2. The method of claim 1, wherein event-related data comprise one or more of: a time an event occurs; a date the event occurs; a location of the device when the event occurs; a filename of an event object associated with the event; a mobile device number (MDN); and a contact name.
3. The method of claim 2, wherein generating an activity record using the data comprises creating an entry for each of the one or more events describing where and when an event occurred.
4. The method of claim 3, further comprising presenting the activity record on a website, wherein the website is accessed by the device or using another device.
5. The method of claim 3, wherein the one or more events comprise at least one of: making or receiving a phone call; sending or receiving a message; taking a photograph; recording a device location; receiving and playing a broadcast; connecting to an 802.11 or Bluetooth access point; and using a device application.
6. The method of claim 5, wherein the location of the mobile device is recorded periodically and independently of other events. ....
It's not "Android" phones alone, it seems like everything but iPhones and Windows phones. Thus, the title is accurate.
How what works?
I see just as many "Android phones do this naughtiness" headlines as I see "iPhones allow these shenanigans" headlines. The fact that is isn't mentioned in the header lends more credence to the author (and article).
It says iphones and blackberrys are equally affected.
No, it says Blackberries and Nokia phones are equally affected. The application requires 1. carrier-custom ROMs and 2. very low level access to the OS. Both are things iOS does not provide, Apple does not allow carriers to tinker with iOS images and does not allow low-level OS access (unless you jailbreak).
Remember the js code that showed all the places the phone have been using a mere phone backup data?
ios is already worse then all of this
Do you have the slightest evidence for your claim?
> It's just more difficult to see inside a safe.
Anything can be seen on a jailbroken iphone.
> Remember the js code that showed all the places the phone have been using a mere phone backup data?
This was (explained as) a location cache the developer forgot to clean (most phones will cache the last few locations so it does not have to boot the location circuitry if an application only needing a very rough location estimate needs a fix) which mistakenly existed in a backuped location (note that unless users sent them, those backups never left their machine). And the issue was fixed in the next update (both the backuping and the too-greedy cache).
> ios is already worse then all of this
I'll go with no until you provide evidence.
Then there's also the privilege of the apps. which i have no idea how it works on ios.
getting root access is NOT the same as looking at source code. and i don't know anyone reversed the code for IOS besides the small activation parts.
loggers could pretty much do nothing if device is not stock.
what else could be have 'too greedy logging' 'by mistake'? you and me will never know. may be nothing.
No.
> getting root access is NOT the same as looking at source code.
Er... duh? That doesn't matter, the kind of issues we're talking about here is usually discovered via blackbox testing (not whitebox), by tracing syscalls or core API calls (no need for source access for that) as well as network communications (no need for sources either).
> loggers could pretty much do nothing if device is not stock.
And the vast majority of devices are stock.
> what else could be have 'too greedy logging' 'by mistake'? you and me will never know.
Logging has to go somewhere, logging that goes nowhere is pointless. As soon as logging goes somewhere, it can be seen and traced.
Is there a certain level beneath which it is not reasonable to give consumers (optional) access? (Should consumers be prevented from "rooting" devices? Should we allow companies to maintain control over devices, e.g. having them "phone home", after they sell them?)
If yes, why?
Maybe a rootkit should just be viewed just like the crapware that comes pre-installed on a PC. Sure it will help some company and perhaps the consumer herself, if she decides to use it. But it's _optional_.
Maybe they could give consumers an easy way to opt-out.
I want a "blank slate". With the right specs and form factor.