Carrier IQ Speaks Out: We ignore extraneous user Data
allthingsd.com
allthingsd.com
[1] http://www.carrieriq.com/company/careers.htm#ExtAnalyticsArc...
It's a nice try to include software to do this in the background with no way to opt out, but with the cat out of the bag, the carriers are going to have to figure something else out. (I use Cyanogen Mod so I doubt this affects me at all. But it's annoying to discover that the reason behind closed bootloaders and firmwares is to spy on me behind my back without permission. Good thing they employ shitty developers to write that code!)
(a) Because the carriers don't want you to, if only because it would increase support costs to have to walk users through turning it back on, but probably mostly because normal people don't really care about the stuff CIQ is intended to do.
(b) Because the feature for disabling CIQ with cell service disabled makes zero money for any party involved and therefore has slipped every MRD given to its engineering team.
That's easy; they can't reliably tell between disabled cellular service and broken cellular service, and the carriers really want to know about the latter. Well, they probably could figure out whether service is supposed to be disabled, but the mechanisms that control whether service is enabled are, themselves, one of the things that CarrierIQ would be used to detect problems with.
"If during a support call a technician asks a customer to enter a short code, CIQ will be listening for it; when it’s entered, CIQ will relay the appropriate diagnostic information to the carrier. Any keystrokes beyond that are ignored."
Their explanation then, for monitoring keystrokes, is that they are waiting for a diagnostic code to be entered by the user. Presumably this can be done from anywhere within the phone, on any platform, without regards to running applications.
"During a support call a technician asks a customer to enter a short code, CIQ will be listening for it"
Without knowing a ton more, maybe there's a _much_ better way to do this..like having the user explicitly launch a program rather than having something always running and always listening. No argument there. But if you're thinking they should abstract away some "code_entered" event, ultimately something lower-level is going to be listening to each keypress and looking at sequences to raise those events.
Some of this stuff happens at a lower level than a lot of us might be use to programming nowadays. I'm not sure that there's necessarily a pretty error event they can hook into. Something about all of this reminds me of using stuf like Spy++ on Windows and you see just how much raw data is available at the lowest levels
My money is on Carrier IQ providing a valuable service in a somewhat sub-optimal way with regards to privacy, and carriers probably doing a really shoddy job of integrating it into the phones they distribute.
I suspect laws would be broken if any of this data was actually being reported _off_ of the device.
Given that the carriers already have all your SMS data and phone usage history, I think you're probably wrong on the legal front, too.
CarrierIQ brought some of this on themselves by reacting terribly to a security researcher's claims regarding their software. Trevor Eckhart claimed CIQ was a "rootkit", and they freaked out and threatened to sue him.
Naturally, everyone now assumes that CarrierIQ is evil, since suing security researchers is almost invariably an evil thing to do.
People are paying less attention to the fact that CarrierIQ subsequently issued a formal apology to Trevor (from experience: companies stung by security researchers virtually never do this; they just back off quietly), and that nobody has really refuted CIQ's claims about what their software does.
The "there's this evil big brother company nobody has ever heard of that a security researcher found out and got sued over" narrative is a lot more fun than the banal reality, so that's what we're all going to run with.
It's also a little amusing to see people wigging out over the privacy of their SMS messages. Their SMS messages have no privacy. The carriers see and log all of them. Lord only knows what other tools they have on their network explicitly for the purpose of mining data out of those messages.
If anyone is really all that outraged, what concrete steps have they taken to make sure this crap gets sorted out?
Oh and BTW, do you have a link confirming the _formal apology_ ? Couldn't find it with a simple DDG search. Maybe my search vector was wrong.
As I understand it, they are logging information relevant to communication quality, and using that to improve the network. If you give people the opportunity to opt-out of providing data, many of them will, which means you have much less data to analyze in order to improve services.
Presumably the carriers could request any data, not simply diagnostics.
It certainly sounds like CIQ is prepared to deliver whatever a carrier might ask for: CIQ's rootkit can capture everything.