I do however know two things. 1) That their local software processes almost every key stroke made. 2) And that they do send at least some portion of this data back to their servers.
At this point it would be trivial for them to send my private information TOMORROW if they decided to do so. I don't know that they don't have a subroutine to begin sending all of my SMS back to their servers if they decide to so for profit or under government coercion.
If they have no plans of using my Google searches, they shouldn't process it in the first place.
Your starting point was that they were collecting† data that could jeopardize national security††. You clearly based that argument on the idea that their own recruiter mentioned "10s of gigabytes a day".
Now, in true message board geek fashion, you're going to steadily move the goalposts. What? They're not collecting messages? Well then they're processing messages! They shouldn't be doing that either!
The problem with this tactic --- make a spectacularly unsupported assertion and then back off it in a series of non-concession-concessions --- is that you cease to be credible. Is this what you really think? Or will you re-harden your position if e.g. it becomes clear that they're not even seeing the keycodes of the keypresses, but rather using an API that could conceivably allow them to get them.
† Your word.
†† Ibid.
I don't think there's any goalpost moving here at all: Hundreds of millions of keyloggers -- rootkits, really, as the article states -- are installed and unremovable. Whether they are being abused or not at the moment is irrelevant; it should be outrageous and unacceptable that such a datastream is going through a third-party without any kind of transparency, acceptance, or even tacit acknowledgement.
Likewise, your rhetorical refutation here (very thorough, in the abstract) would be a lot more damning if there wasn't, you know, video evidence of this rootkit collecting exactly this data and sending it back.
Now you're defending/rationalizing whatever disgusting bullshit Carrier IQ is up to.
What's wrong with you?
Just like we didn't have absolute proof that Aaron's indictment was politically motivated, we can't be absolutely sure that Carrier IQ is a company full of shit and devoid of morals.
But it's blindingly obvious that both are very, very likely.
In case you're just blissfully unaware of how full of shit the world actually is, here's a report on your justice system fraudulently, systematically signing away people's homes: http://www.rollingstone.com/politics/news/matt-taibbi-courts...
"Carrier IQ, which in the second quarter of 2011 passed the petabyte milestone in processed analytics data"
If we go by the official letter you've posted and assume conservatively CarrierIQ has only 1 Petabyte of data, and that they've been collecting since 2006 (when they received their Series A), they've been collecting 456 GBs of data per day. Its probably more than that today since the data collection rate has surely accelerated over time.
That's an order of magnitude beyond 10s of GB per day.
A terabyte is 1000GB. Why would they be shouting about terabytes if it were anything over .09 terabytes?
And isn't it likely that some phones are set to transfer more data than others?
An average across 145M users crossing various demographics and phones types is not a good metric to use to determine the possible danger of the data being sent.
I tend to agree with you, but at the same time wonder how they're aggregating the data; they could store each day's raw data in however many GB, then crunch it down later.
The only other potential issue that jumps out at me is bandwidth; I'd find it strange if the data isn't being compressed, but if it is, you could cram quite a lot of useful information into those few hundred bytes ;)
So logging all of everyone's texts is probably still out.
But easily logging their browsing patterns. Probably app installation and use. And certainly they retain the capability to log texts containing keywords without going too far outside that aggregate range of data. Or doing targeted logging of all of selected individuals usage.