Live data from Hacker News

Secret app on millions of phones logs key taps

theregister.co.uk

11–20 of 193 posts

Re: Secret app on millions of phones logs key taps

#11
post #9

Earlier quoted context omitted.

The location data concern was that if anyone got possession of your phone or a copy of your backup, they could discern your entire location history. With this finding, if someone got possession of your phone, they could apparently discern...nothing. Instead a subset of data is sent to a company contracted by the carriers (or at least one - Sprint) for the purposes of network monitoring/quality monitoring. Of course t…

I think it is certainly a lot worse. All user data (since it is a keylogger?) being logged and sent to a third party without user knowledge or consent, how is that not worse than just logging user information on the device? To get access to your location data on the iPhone, someone would have to steal your phone or get into your itunes account. This is happening in the background.

>All user data (since it is a keylogger?) being logged and sent to a third party without user knowledge or consent

Where does anyone say that it is being sent to a third party? This rather noob-ish developer noted that they have a keyboard hook, but in no way does that mean that they send all of your keystrokes to a third party.

Honestly I think I expect too much from HN. The level of discourse on here is absolutely no better than any typical blowhard site.

Re: Secret app on millions of phones logs key taps

#13
I am surprised the internet took this long to respond, considering that the HN discussion on this was started almost a week ago[1][2]. That said, after watching the video I'm all kinds of sceptical about the dude's claim.

[1] http://news.ycombinator.com/item?id=3263955 [2] http://news.ycombinator.com/item?id=3273416

Re: Secret app on millions of phones logs key taps

#14
post #2

Remember when people were up in arms about how much location data iPhones stored locally? This is 1000 times worse.

The location data concern was that if anyone got possession of your phone or a copy of your backup, they could discern your entire location history. With this finding, if someone got possession of your phone, they could apparently discern...nothing. Instead a subset of data is sent to a company contracted by the carriers (or at least one - Sprint) for the purposes of network monitoring/quality monitoring. Of course t…

If someone got your phone, they could get all the passwords you typed in. Its certainly not 'nothing' that they could discern.

Re: Secret app on millions of phones logs key taps

#16
post #8

It should be noted that there's no evidence (yet) of what is sent to other entities, only what is captured by the software on the device. This is bad enough, though. But, let's keep our head about this and calmly demand an explanation from HTC. Why them? Because they signed the binaries with their certificate, presumably at the request of carriers, but HTC is the first in line. And don't believe the response from Car…

To be fair, the response from CarrierIQ implies that this is the case:

"In an interview last week, Carrier IQ VP of Marketing Andrew Coward rejected claims the software posed a privacy threat because it never captured key presses.

“Our technology is not real time,” he said at the time. "It's not constantly reporting back. It's gathering information up and is usually transmitted in small doses.”

Note that last clause there.

Re: Secret app on millions of phones logs key taps

#18

Earlier quoted context omitted.

The location data concern was that if anyone got possession of your phone or a copy of your backup, they could discern your entire location history. With this finding, if someone got possession of your phone, they could apparently discern...nothing. Instead a subset of data is sent to a company contracted by the carriers (or at least one - Sprint) for the purposes of network monitoring/quality monitoring. Of course t…

If someone got your phone, they could get all the passwords you typed in. Its certainly not 'nothing' that they could discern.

??? Really, how so. How are they going to get all of the passwords you typed in? Can you point out where anyone has noted any log on the device of this data?

This whole story is that they have system event hooks. That's it. Maybe a real security researcher will find something deeper, but as is it's a nothing story of limited interest. When people like you carry it further than reality you just add ignorance to the conversation.

Re: Secret app on millions of phones logs key taps

#19
post #9

Earlier quoted context omitted.

I think it is certainly a lot worse. All user data (since it is a keylogger?) being logged and sent to a third party without user knowledge or consent, how is that not worse than just logging user information on the device? To get access to your location data on the iPhone, someone would have to steal your phone or get into your itunes account. This is happening in the background.

>All user data (since it is a keylogger?) being logged and sent to a third party without user knowledge or consent Where does anyone say that it is being sent to a third party? This rather noob-ish developer noted that they have a keyboard hook, but in no way does that mean that they send all of your keystrokes to a third party. Honestly I think I expect too much from HN. The level of discourse on here is absolutely…

I dont see how meta comments on HN help the discussion?

Directly from the article:

> “Our technology is not real time,” he said at the time. "It's not constantly reporting back. It's gathering information up and is usually transmitted in small doses.”

The issue is, we don't know what this software is gathering and sending. It is not being done with consent.

But you're right, this needs to be looked into before getting the pitchforks out. But certainly, having the presence of a keylogger is bad enough in itself.

Re: Secret app on millions of phones logs key taps

#20
post #17

Before reading, I guessed that "millions of phones" meant millions of Android phones. Because if this was happening on iPhones, that would merit mention in the headline. Funny how that works.

>Funny how that works

How what works?

I see just as many "Android phones do this naughtiness" headlines as I see "iPhones allow these shenanigans" headlines. The fact that is isn't mentioned in the header lends more credence to the author (and article).

Post reply on HN