Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Carrier IQ: The Sony rootkit all over again

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » General Discussion Donate to DU
 
FarCenter Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Nov-30-11 05:46 PM
Original message
Carrier IQ: The Sony rootkit all over again
Can someone legally record almost everything you do on your phone without telling you? Yes. Meet Carrier IQ, whose software is installed on nearly 142 million handsets

It turns out your phone may be spying on you even more than you thought.

Android developer Trevor Eckhart was tooling around with his HTC smartphone a few weeks ago when he discovered an unfamiliar app on it from a company called Carrier IQ.

That bit of code appeared to be capturing everything his phone did -- all numbers dialed, text entered, websites visited, buttons pressed, and so on, even while he was only using Wi-Fi -- and phoning home with that data.

The software was running in secret, not listed among his other running Android apps, and Eckhart could not force it to quit. In short, it was acting just like a rootkit used to hide malware.

http://www.infoworld.com/t/cringely/carrier-iq-spying-your-cellphone-180425
Printer Friendly | Permalink |  | Top
Earth_First Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Nov-30-11 05:54 PM
Response to Original message
1. Where is 'phoning home' exactly?
Where is all this data being routed?
Printer Friendly | Permalink |  | Top
 
FarCenter Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Nov-30-11 06:03 PM
Response to Reply #1
2. I believe it goes back to CarrierIQ servers
CarrierIQ analyses the data and provides data and/or analyses to the carriers.

But it is possible that one or more of the carriers, e.g. Verizon, AT&T, Sprint or T-Mobile, would run servers and collect the data directly.

Note that the carriers have a lot of data already, since they can read all the signaling messages and all the data and voice traffic. What they wouldn't have is information about failed attempts to use apps, and data that was encrypted by SSL between the handset and a web site.
Printer Friendly | Permalink |  | Top
 
MattBaggins Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Dec-01-11 03:23 PM
Response to Reply #2
7. As far as data on failed apps or crashes
can be taken care of the old fashioned way where a trace is run, data collected and the user is asked if they would like to submit a report.

The SSL recording is not kosher though as it intentionally circumvents the very reason for using that protocol. I can see them claiming that they need data on why a phone locked up after going to a web page with a bad java script or flash widget, but CIQs method is just wrong.
Printer Friendly | Permalink |  | Top
 
MattBaggins Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Dec-01-11 03:15 PM
Response to Reply #1
6. Where the data is going is a work in progress
Edited on Thu Dec-01-11 03:24 PM by MattBaggins
Some techies are "packet sniffing" as it is called to see where it goes.

CIQ states on their websites that they collect the data although some Carriers probably collect data as well.
Printer Friendly | Permalink |  | Top
 
REP Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Dec-01-11 03:32 PM
Response to Reply #6
11. They probably have a super good reason to be able to read all txts sent, too, right?
Per CIQ pres, yes they can.
Printer Friendly | Permalink |  | Top
 
MattBaggins Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Dec-01-11 03:46 PM
Response to Reply #11
14. They could claim it was done at the behest of the Carriers
to enforce message limit contracts.

Devils advocate only. Very very flimsy excuse for why they tried to hide the the software and what it did or why they created it to run as a rootkit.
Printer Friendly | Permalink |  | Top
 
REP Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Nov-30-11 08:08 PM
Response to Original message
3. Yes, but it will perform an abortion, right?
Printer Friendly | Permalink |  | Top
 
saras Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Dec-01-11 10:51 AM
Response to Reply #3
4. Only if you set it on 'vibrate heavy' before you stuff it up there.
Printer Friendly | Permalink |  | Top
 
dreamnightwind Donating Member (863 posts) Send PM | Profile | Ignore Thu Dec-01-11 03:12 PM
Response to Original message
5. K & R
Just read the article, good find. I'm amazed this isn't getting more responses.
Printer Friendly | Permalink |  | Top
 
REP Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Dec-01-11 03:25 PM
Response to Reply #5
8. It's hard to understand, so no attention
Unlike the sexy, sexy Apple non-story about how women's health clinics aren't called "abortion clinics."
Printer Friendly | Permalink |  | Top
 
MattBaggins Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Dec-01-11 03:27 PM
Response to Reply #8
9. Except it was more than that
but easier to dismiss it than examine what people were noticing.
Printer Friendly | Permalink |  | Top
 
REP Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Dec-01-11 03:30 PM
Response to Reply #9
10. I know, right? Look at the fucked up results I got!





Printer Friendly | Permalink |  | Top
 
WillyT Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Dec-01-11 03:34 PM
Response to Original message
12. K & R !!!
:kick:
Printer Friendly | Permalink |  | Top
 
blkmusclmachine Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Dec-01-11 03:35 PM
Response to Original message
13. Spying. Spying. Of everywhere you go. And everything you do.
We'll get there. Bit by bit, you won't even recognize. And then, BAM! :tinfoilhat:
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Fri Apr 19th 2024, 01:20 PM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » General Discussion Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC