Live data from Hacker News

Secret app on millions of phones logs key taps

theregister.co.uk

151–160 of 193 posts

Re: Secret app on millions of phones logs key taps

#151

Earlier quoted context omitted.

You are militantly missing my point. There is no evidence that they are seeing message contents. All we are going on in this thread is the supposition that because they're getting "10 gigabytes a day", it must be message contents.

They themselves use the phrase "raw data" to describe what they collect (as "metrics"). Metrics are not comprised of raw data, but of measurements, so unless they're being hinky with word choice, a plain reading of their own materials would suggest that they do indeed receive user content.

They've said repeatedly that they do not collect that data. This is a common attitude on HN threads: the idea that the only facts for us to discuss are the ones in the article itself or in other comments on the thread. There are more facts just a Google search away for you.

Their own words are not dispositive; I'm not suggesting that they are. But here you're trying to interpret their words in a way that contradicts their own direct statement. Your interpretation is possibly accurate, but implausible.

Re: Secret app on millions of phones logs key taps

#152

three words. MASSIVE CLASS ACTION Lawyers fire up your infomercials.

The usual suspects are almost certainly going to file a class-action lawsuit or two over this, but it won't be 'massive' since this isn't a clear and easy win. (The hardest part about this type of suit is showing real, concrete harm to actual people - and not just hypothetical potential harm. So Carrier IQ knows you play Angry Birds - so what? How'd that demonstrably hurt you?) No, instead the lawyers responsible for…

Since their business model is based around selling data collected without user knowledge/consent, I feel like digging into their financial would reveal a pretty strong case against them.

Re: Secret app on millions of phones logs key taps

#153

Earlier quoted context omitted.

If Sprint wanted to do that, it doesn't need agent software to get the messages.

This is an important point that I think some people are forgetting. I use Verizon. They already have access to all of my text messages. I send my text messages to Verizon , who then forwards them on to the person I'm talking to. Just as Google first gets my email.

It is unfortunately a point that the contradicts the thread narrative that casts a hapless, poorly-marketed analytics company as Big Brother incarnate, so nobody's going to pay attention to it.

Re: Secret app on millions of phones logs key taps

#154
post #31

Earlier quoted context omitted.

They say they are installed on > 148.3M phones. If we imagine that they are gathering 10GB per day then that's about 76 bytes per phone, if it's 90GB (the upper limit before the recruiter would have been shouting about terabytes) then it's 680 bytes. It's more likely to be in the middle (because otherwise the recruiter would have rounded up) so you are talking 100s of bytes per phone per day. I don't think it's reali…

Whether they are sending a full log report of my actions TODAY is beside the main point. I do however know two things. 1) That their local software processes almost every key stroke made. 2) And that they do send at least some portion of this data back to their servers. At this point it would be trivial for them to send my private information TOMORROW if they decided to do so. I don't know that they don't have a subr…

This is, of course, an attitude that is going to "deftly" shoot down any new fact or analysis brought into the discussion.

Your starting point was that they were collecting† data that could jeopardize national security††. You clearly based that argument on the idea that their own recruiter mentioned "10s of gigabytes a day".

Now, in true message board geek fashion, you're going to steadily move the goalposts. What? They're not collecting messages? Well then they're processing messages! They shouldn't be doing that either!

The problem with this tactic --- make a spectacularly unsupported assertion and then back off it in a series of non-concession-concessions --- is that you cease to be credible. Is this what you really think? Or will you re-harden your position if e.g. it becomes clear that they're not even seeing the keycodes of the keypresses, but rather using an API that could conceivably allow them to get them.

Your word.

†† Ibid.

Re: Secret app on millions of phones logs key taps

#155

Earlier quoted context omitted.

I think that the facts matter. I think that there are zero people on HN that think CarrierIQ is a good idea. So if all we're doing here is condemning CarrierIQ, let's just replace this whole thread with "CARRIERIQ BAD", followed by a bulleted list of bad things, vote it up to 1000, and then get back to talking about building things.

Or how about if you don't think that this thread is contributing anything to what you think HN should be, you stop yelling at everyone posting in it and go back to "building things"? We get it, you don't like this thread. You don't need to respond to every comment with a pedantic "fuck you, shut up, and get off my lawn, I have a billion comment karma because people upvote snark so now I'm going to act like a dick " c…

No. Tried that. Now trying the other way. These threads are dragging HN down, and I've decided to be noisier about it.

My feeling is that the same name recognition influence that gets most of my comments modded up 100-200% more than they're actually worth is going to get my -4 comments read even though they're light grey. We'll see!

Re: Secret app on millions of phones logs key taps

#156
post #80

Earlier quoted context omitted.

By that logic we should all be very angry at our TTY drivers.

I'm not even sure what I should say to explain the difference here. It should be obvious...

You're implying the difference is intent. I'm saying, their intent isn't known. Their own statement is that they don't want the raw characters, just the stats.

Meanwhile, there are plenty of pieces of code strewn throughout your system that get access to similar bits of sensitive data. For instance, every BSD system has a BPF device and driver that exists solely to tap your network traffic. Luckily, nobody sells a BPF-for-Android product.

I'm not saying that this is a clinching argument. I'm simply making a point that is germane to the discussion. Distilled, it is: "just because a piece of systems code deals with your private information does not make a violation of your privacy; sometimes it does, sometimes it doesn't".

Re: Secret app on millions of phones logs key taps

#157
post #126

Earlier quoted context omitted.

Why does this have to be made into an iPhone vs. Android oneupmanship game? This has been alarmingly on the rise here on HN these days.

Well, for one, because the legion of fandroids would be here raving about the "evil Apple empire" if this story were about Apple, as it is about Android these same fandroids are saying that Apple are just as bad, if not worse.

I was going to post a comment mentioning how I heard it was installed on the iPhone but I was wrong it seems.

http://lifehacker.com/5863895/carrier-iq-how-the-widespread-...

"Update: Our original article stated that the software also came preinstalled on iPhones and dumphones, which has not been confirmed. That information came from this article at Geeks.com, and we actually believe that to be a typo. Considering it hasn't been mentioned in any other source, and that the iPhone isn't on Eckhart's list of affected devices, we're removing it until other sources say otherwise. Thanks to everyone who pointed this out."

Re: Secret app on millions of phones logs key taps

#158
post #25
post #24

There are a handful of comments here giving CarrierIQ the benefit of the doubt, because the video did not show CarrierIQ sending the logged data over the network. If you're still inclined to give them the benefit of the doubt, just read the CarrierIQ website. Their ENTIRE BUSINESS MODEL is based on collecting data about mobile phone users!! Here's a choice excerptI found on their website after browsing their site for…

They are collecting data, but I'm pretty sure it's not keystroke data - that kind of volume would be 10s of TB per day, not GB. From your link to the recruiter: Each handset collects and reports 100's of metrics of device and user behavior in real time. That's data like phone location, applications used, etc. Very bad yes, keylogger reporting your password, no.

People aren't writing novels on their SmartPhones. The typed input from a normal volume of text messages, e-mails, and URLs is actually pretty minute when you think about it. Certainly it would be compressed before being uploaded to their servers. IIRC they cite 140 million active devices so if you figure 3kB per day, which is probably on the high side, that's only 400GB before compression. You can compress text down by about 90% these days. That works out to only 44GB of data uploaded per day.

Re: Secret app on millions of phones logs key taps

#159

Earlier quoted context omitted.

I'm not even sure what I should say to explain the difference here. It should be obvious...

You're implying the difference is intent. I'm saying, their intent isn't known. Their own statement is that they don't want the raw characters, just the stats. Meanwhile, there are plenty of pieces of code strewn throughout your system that get access to similar bits of sensitive data. For instance, every BSD system has a BPF device and driver that exists solely to tap your network traffic. Luckily, nobody sells a BP…

There is a hell of a lot more wrong with your analogy than a mere "difference in intent".

Re: Secret app on millions of phones logs key taps

#160

Earlier quoted context omitted.

You're implying the difference is intent. I'm saying, their intent isn't known. Their own statement is that they don't want the raw characters, just the stats. Meanwhile, there are plenty of pieces of code strewn throughout your system that get access to similar bits of sensitive data. For instance, every BSD system has a BPF device and driver that exists solely to tap your network traffic. Luckily, nobody sells a BP…

There is a hell of a lot more wrong with your analogy than a mere "difference in intent".

I'm interested in why you think that. I wrote the comment in good faith. I'm asking you to clarify also in good faith.
Post reply on HN