Live data from Hacker News

Secret app on millions of phones logs key taps

theregister.co.uk

141–150 of 193 posts

Re: Secret app on millions of phones logs key taps

#141

I think this is a good case study in support of "never trust an internet-connected electronic device directly from a vendor". There should be a universal policy to unlock, root, or blow away any software that exists and replace it with "known good" software, like CyanogenMod, Ubuntu, or a new copy of Windows.

Two out of three ain't bad.

Re: Secret app on millions of phones logs key taps

#142
post #46
post #2

Remember when people were up in arms about how much location data iPhones stored locally? This is 1000 times worse.

I have a horribly naive and defiantly uninformed question: this was detected on an android device which is a fairly open platform when compared to the iPhone/Windows phones in terms of software transparency, correct? Is there any way to know for certain that Apple/MS aren't doing this exact same/similar sort of thing?

Microsoft has in fact done the same sort of thing in Windows Update, though it denied it. Certainly nothing as brazen as a keylogger, but in 2003 it was caught phoning home a list of all installed software, and hardware identifiers, in an SSL connection.

Re: Secret app on millions of phones logs key taps

#143
Can somebody clarify this story for me? What are the facts here?

* Did they implemented key-logger? Yes/No

* Do they write keys into some local log? Yes/No

* If they have key-logger, then why do they have key-logger? (Company statement - please)

* If they write key strokes to some log file, is that log file related to logs which are send to "mother ship"?

Re: Secret app on millions of phones logs key taps

#144
post #118

Earlier quoted context omitted.

"The point isn't how many texts they're getting ... " You, earlier: "What percentage of all the SMS messages ... do you think 10 gigabytes is?" Stop moving the goalposts and maybe we'll get somewhere.

You are militantly missing my point. There is no evidence that they are seeing message contents. All we are going on in this thread is the supposition that because they're getting "10 gigabytes a day", it must be message contents.

They themselves use the phrase "raw data" to describe what they collect (as "metrics"). Metrics are not comprised of raw data, but of measurements, so unless they're being hinky with word choice, a plain reading of their own materials would suggest that they do indeed receive user content.

Re: Secret app on millions of phones logs key taps

#145
post #2

Remember when people were up in arms about how much location data iPhones stored locally? This is 1000 times worse.

Yes this is much worse and should get 10x the attention. The reason comparatively minor iPhone scandal gets so big is because everything Apple related gets now over-hyped in the media. You could say Jobs has marketed the Apple brand very well.

Re: Secret app on millions of phones logs key taps

#146
post #2

Remember when people were up in arms about how much location data iPhones stored locally? This is 1000 times worse.

Yes this is much worse and should get 10x the attention. Reason for me to be suspicious of every Android phone I'll get (I assume there are ways to remove it and that it's not shipped on non-contract Nexus). The reason a comparatively minor iPhone scandal gets so big is because everything Apple related gets now over-hyped in the media. You could say Jobs has marketed the Apple brand very well.

Re: Secret app on millions of phones logs key taps

#148
post #76
post #67

Earlier quoted context omitted.

There is a video camera in your bathroom secretly recording you. If the perpetrator never stops by to pick up the tape, is a crime committed?

How did the perpetrator plant such a device in the first place? Did he have permission? If not, perhaps a different crime was committed.

To use a situation analogous to the situation with CarrierIQ, he did not have permission and you never even knew he was there or that the camera was there. However, the camera is digital, it is connected to your power outlet with a battery-backed UPS, and it has an active wireless modem attached to it.

Maybe he did send data, maybe he didn't. But he's also sent you a CnD notice and threatening to sue you if you tell anyone.

Re: Secret app on millions of phones logs key taps

#149
post #138

CarrierIQ provides a valuable service for all us. They relay data that optimizes carrier networks, so that we can call, text, get data, etc more reliably. The problem this thread highlights is poor marketing and transparency. No one at CarrierIQ gives a damn what we text. Breaking those basic privacy tenants would destroy their business, which seems to be going nicely if their software is on >100M devices. The compan…

>"CarrierIQ provides a valuable service for all us. They relay data that optimizes carrier networks, so that we can call, text, get data, etc more reliably." Considering how crappy call quality and SMS (which was designed to be used to send control messages to phones) reliability are and how expensive data is, it seems like they're doing a pretty bad job of it. Also, there is no reason to do this client-side since this can all be done at the carrier infrastructure level -- and already is.

>"The problem this thread highlights is poor marketing and transparency. No one at CarrierIQ gives a damn what we text." Warrantless wiretapping is illegal. I'm not sure what more to say here.

>"Breaking those basic privacy tenants would destroy their business, which seems to be going nicely if their software is on >100M devices." unless you can't [as a non-techie] remove their software or opt out, which you can't.

>"The company just does a crappy job explaining what their technology does and how it helps consumers. Uncertainty around our private information spooks people, which leads to distrust and conspiracy theories." http://www.echelon2.org/wiki/Palantir OK. I don't believe you since there are lots of documented reasons to not trust anyone with data like this. Also, why did they send a CnD letter to the guy and threaten him if they're not doing anything bad?

>"Let this be a valuable lesson for entrepreneurs who touch consumer data, even B2B solutions." Yes, installing rootkits on hundreds of millions of devices without user consent, then trying to gag the security researcher who outs you is pretty damn bad form.

>"CarrierIQ clearly needs to address these issues. Let's call on them to do that. In the meantime, take a moment to imagine how much more we'd hate carriers if reception was even spottier (cough...AT&T iphone...)" No, people already hate carriers, and there is no explanation that will make installing keyloggers on hundreds of millions of cellphones acceptable, ever. As I already said, carriers have had the power to gather the data they need to improve their networks at the infrastructure level (towers record MEIDs / EIDs / IMEIs already and this data would be easier to collect there) for years, and they already do use that to "improve" their networks.

Not to spout conspiracy theories everywhere here, but have you /seen/ the FCC press release about the ATT / T-Mobile merger and how badly ATT misrepresented facts? http://www.theverge.com/2011/11/30/2599466/fcc-report-att-pr... give this a read and then honestly tell me you think that carriers have all the best intentions.

Companies are supposed to make profits for shareholders, not protect your privacy or be nice to you. If they can make money by selling your personal data, they will and they're probably doing just that right now.

Re: Secret app on millions of phones logs key taps

#150
post #72

Earlier quoted context omitted.

The fact that it has hooks to even know of the keystrokes is the real issue here. Even without recording or logging them afterwards, the fact that it has the ability means its a possible attack vector for things like worms/etc... Even if they never do anything with keystroke data, just the fact that they can is the dangerous part. What is to prevent some switch to start sending the keystrokes in the future? I'll be b…

I don't think you read my comment correctly -- or you meant to reply to someone else.

Yep sorry wrong reply, i'll nuke my comment sorry, dont' think its adding much where it is to be honest.
Post reply on HN