This is bad enough, though. But, let's keep our head about this and calmly demand an explanation from HTC. Why them? Because they signed the binaries with their certificate, presumably at the request of carriers, but HTC is the first in line.
And don't believe the response from CarrierIQ. Just prior to that response, they still had very informative high resolution screenshots of their "Device Analyzer" product which showed a scary level of data mining of end user devices. They were probably great eye candy for their customers (carriers), but creepy for anyone valuing their privacy.
I agree that this information is likely for improved QoS, but what can (has) it been mis-used for? Employees can't be trusted, and the government can't be trusted. An end user can't even opt out of it.
Edit: According to Google Image Search, others are mirroring some of the prior shots. Note that nothing is anonymized in the least (nevermind that anonymizing data is practically a myth).
I'll try and tack the URLs below.
http://androidsecuritytest.com/wp-content/uploads/2011/11/ci...
http://www.xda-developers.com/wp-content/uploads/2011/11/met...
http://androidsecuritytest.com/wp-content/uploads/2011/11/me...
http://androidsecuritytest.com/wp-content/uploads/2011/11/tr...
http://androidsecuritytest.com/wp-content/uploads/2011/11/CI...
http://androidsecuritytest.com/wp-content/uploads/2011/11/si...
http://www.carrieriq.com/overview/IQInsightDeviceAnalyzer/De...
This one doesn't need to be big to get the jist:
http://www.carrieriq.com/overview/IQInsightServiceAnalyzer/i...