Apple: We Don’t Use Carrier IQ… In Most Of Our Products… Anymore.
techcrunch.com
techcrunch.com
It seems obvious to me that carriers or manufacturers can collect that data if the user explicitly agrees to it (by actually flipping a switch without being forced or tricked into doing so).
Carrier IQ is only a problem if it is turned on by default and if it collects more data than is explicitly said∆.
—
† If the Diagnostics & Usage switch indeed controls Carrier IQ then we already know that the last two conditions are met.
∆ This is only the minimum viable evilness. Worse kinds of evil are imaginable, like not telling users anywhere that data is being or collected or making it hard for users to turn the collection of data off.
> Carrier IQ is only a problem if it is turned on
The problem being that having it installed is just another attack vector that houses potential vulnerabilities on your device."With any diagnostic data sent to Apple, customers must actively opt-in to share this information..."
As I understand it, Carrier IQ is about sending data to carriers. Apple only denied that data was silently sent to Apple. That's completely different than saying no data has been transmitted at all.
I think the more logical interpretation is that if they (Apple) don't receive any data then no other party receive any data.
This has more information: http://blog.chpwn.com/post/13572216737
[..] To help Apple’s partners and third-party developers improve their apps, products and services designed for use with Apple products, Apple may provide such partners or developers with a subset of diagnostic information that is relevant to that partner’s or developer’s app, product or service, as long as the diagnostic information is aggregated or in a form that does not personally identify you.
http://daringfireball.net/misc/2011/12/ios-5-diagnostics-pri...
Why on earth would they be doing keylogging? What data can they get that doesn't violate my privacy? If they aren't using that data, then why the fuck is that code there tracking the keys pressed?
As such I feel like this is being blown out of proportion, Apple's use of carrier IQ has never been anything to worry about. A user can optionally choose to participate. (I.e it's not an opt-out scenario) and the information it sends is benign and not personally identifiable.
The issue has been that some vendors have been adding full-capability CarrierIQ to android handsets which then have been shown to be reporting more than what can be considered reasonable, including allegations of key logging. This is obviously wrong and should be corrected. (Or simply removed.)
Funny how you first lament that the issue is being blown out of proportion wrt Apple and then blow it out of proportion yourself. Nobody has shown what data is being reported or indeed, evidence that any data is being reported at all.
They primary issue at this point seems to be that the temporary local logging of the data represents a security risk on these devices even if it is never reported.
Can someone please explain why the rage is not directed at phone manufacturers who asked for, and put this software in the phones they sold to customers?
People gave up their privacy on the web (hey, you don't get mad at Google for sites having Google Analytics tracking code all over the web do you), now it'll slowly transfer to other platforms.
Because every single statement from phone manufacturers have indicated that it was the carriers that demanded this be put on the handsets (or did it themselves in cases of operator modifications).
The only carrier I've heard say very clearly that they are not using Carrier IQ is Verizon.
Aww. Poor vulnerable and naive billion dollar phone manufacturers! </sarcasm>
How does that exonerate the phone manufacturers? At the very least they should have disclosed this to the people they sold phones to.
Even at that why is the rage not directed at the carriers? In addition, I doubt the carriers can make such modifications without the active participation of the phone manufacturers.
[1] http://www.theverge.com/2011/11/22/2581952/xda-developers-me...
Now, that is an entirely different matter. Thanks for bringing this perspective.
That's still an awful lot of places.
I'm not at all surprised that Apple isn't violating users privacy.
In this case they're coincidentally a bit ahead of the ball, so there's no need to wait and formulate a plan.
They are a hardware company that sells the hardware it makes direct to consumer. They are perfectly positioned and quite capable of writing their own "rootkits".
Of course, when they do everything possible to prevent you from "rooting" the phone you purchase from them it's a tad more difficult to check for such things.
For the average non-technical iPhone customer it would seem next to impossible.
Either way, ugh. Bad Apple.
That doesn’t contradict what you are saying at all.
Apple acknowledges that some references to Carrier IQ are still in iOS 5, but the limited functionality has been completely disabled. The next step is to remove all the deactivated references. Doesn't seem to be anything inconsistent with their statements there.
And from all indications (the researcher vs. what Apple states) is that you can explicitly turn it off.
You're anyone, why don't you do it?