I think that there are zero people on HN that think CarrierIQ is a good idea.
So if all we're doing here is condemning CarrierIQ, let's just replace this whole thread with "CARRIERIQ BAD", followed by a bulleted list of bad things, vote it up to 1000, and then get back to talking about building things.
We get it, you don't like this thread. You don't need to respond to every comment with a pedantic "fuck you, shut up, and get off my lawn, I have a billion comment karma because people upvote snark so now I'm going to act like a dick " comment of your own.
My feeling is that the same name recognition influence that gets most of my comments modded up 100-200% more than they're actually worth is going to get my -4 comments read even though they're light grey. We'll see!
I asked someone who is quite good with crypto a question about a possible MITM attack on 141 million phones. I didn't condemn CarrierIQ, I avoided dramatic language, I even added qualifiers to avoid stating something as fact if it wasn't yet confirmed.
Doing an SSL MITM from agent software installed by the carrier on a phone seems pretty silly, since the carrier is in a position to see anything you're typing into your phone anyways (in the sense that it controls the OS).
I'm not sure I buy any analysis that suggests CarrierIQ is really "MITM'ing" SSL --- though that's trivial for a software agent to do --- because the same people saying that are also saying that it's obvious that CarrierIQ is capturing and remote-logging message contents.
I'm just curious if that's the way phones will be forever: with the OS controlled by the carrier and with no right to tinker/hack/modify the device you buy & pay huge monthly fees to use.