Earlier quoted context omitted.
Here's a thread full of you vehemently defending/rationalizing police state -like behaviour: http://news.ycombinator.com/item?id=2802917 Now you're defending/rationalizing whatever disgusting bullshit Carrier IQ is up to. What's wrong with you? Just like we didn't have absolute proof that Aaron's indictment was politically motivated, we can't be absolutely sure that Carrier IQ is a company full of shit and devoid of…
Government contracts can have that effect.
Secret app on millions of phones logs key taps
181–190 of 193 posts
Re: Secret app on millions of phones logs key taps
#182Earlier quoted context omitted.
You're implying the difference is intent. I'm saying, their intent isn't known. Their own statement is that they don't want the raw characters, just the stats. Meanwhile, there are plenty of pieces of code strewn throughout your system that get access to similar bits of sensitive data. For instance, every BSD system has a BPF device and driver that exists solely to tap your network traffic. Luckily, nobody sells a BP…
Yeah, but key logging? What could you possibly do with that data? Besides, the BPF driver in every BSD system is probably open-source and could be reviewed for intent if in doubt. It's not easy, not everybody can do it, but it is possible. However, you cannot do that for CarrierIQ. Even if such logs aren't getting sent, you don't know that they haven't installed some kind of mechanism to trigger such an upload on dem…
Re: Secret app on millions of phones logs key taps
#183Earlier quoted context omitted.
It is unfortunately a point that the contradicts the thread narrative that casts a hapless, poorly-marketed analytics company as Big Brother incarnate, so nobody's going to pay attention to it.
They put backdoors on basically every phone in secret, threatened the guy who outed them with a lawsuit and are perfectly capable of snooping on everything, whether they do so or not. What do you know about them that makes you trust them?
1. CarrierIQ is a "secret" in the same sense as the network management software that Sprint uses that can also see all your SMS messages is a "secret": (a) nobody at Sprint thinks its relevant to you, and (b) nobody at Sprint thinks its any of your business. Which, if you take a breath, strictly speaking about the performance metrics they're collecting, it isn't your business.
2. CarrierIQ was dumb about threatening this guy like lots of other companies have been identically dumb. Companies have threatened to sue me. I remain cordial with the owners of some of those companies. Welcome to security research; we don't have jackets, but we sure get a lot of press.
Incidentally, put yourself in CarrierIQ's position and assume that this particular researcher is full of shit, meaning, no, CarrierIQ is not snooping on people's keystrokes. What would you do? There's a guy out there claiming that their performance agent is a "rootkit". They got pissed. Surprised?
3. Any piece of systems software the carrier agrees to stick on the phone is capable of snooping. Sprint itself could just backdoor their Android distro.
Re: Secret app on millions of phones logs key taps
#184Re: Secret app on millions of phones logs key taps
#185Earlier quoted context omitted.
Government contracts can have that effect.
I wouldn't know. But the idea that you can't even fathom how someone might have a different point of view from you and not be bought off by the government is telling.
Re: Secret app on millions of phones logs key taps
#186Earlier quoted context omitted.
Sorry. You're right. I let the ultra dumbness of this whole thread bring me down a bit. Doing an SSL MITM from agent software installed by the carrier on a phone seems pretty silly, since the carrier is in a position to see anything you're typing into your phone anyways (in the sense that it controls the OS). I'm not sure I buy any analysis that suggests CarrierIQ is really "MITM'ing" SSL --- though that's trivial fo…
real question here: Should it be obvious that the carrier controls the OS? Second question: is that acceptable? I mean, that assumption underpins your dismissal of an MITM as "pretty silly", which also seems totally correct. I'm just curious if that's the way phones will be forever: with the OS controlled by the carrier and with no right to tinker/hack/modify the device you buy & pay huge monthly fees to use.
Re: Secret app on millions of phones logs key taps
#187Earlier quoted context omitted.
They put backdoors on basically every phone in secret, threatened the guy who outed them with a lawsuit and are perfectly capable of snooping on everything, whether they do so or not. What do you know about them that makes you trust them?
Nothing. There's just a likely innocent explanation for all three of those things: 1. CarrierIQ is a "secret" in the same sense as the network management software that Sprint uses that can also see all your SMS messages is a "secret": (a) nobody at Sprint thinks its relevant to you, and (b) nobody at Sprint thinks its any of your business. Which, if you take a breath, strictly speaking about the performance metrics t…
I think someone once said that sufficiently advanced incompetence is indistinguishable from malice. Whether they're dumb or malicious, I'm just glad their crap isn't on my phone.
Re: Secret app on millions of phones logs key taps
#188Earlier quoted context omitted.
Nothing. There's just a likely innocent explanation for all three of those things: 1. CarrierIQ is a "secret" in the same sense as the network management software that Sprint uses that can also see all your SMS messages is a "secret": (a) nobody at Sprint thinks its relevant to you, and (b) nobody at Sprint thinks its any of your business. Which, if you take a breath, strictly speaking about the performance metrics t…
In their shoes, I would have contacted the researcher and explained myself. While unsurprising, that move was unwise, and I would imagine that you agree on that point at least. I think someone once said that sufficiently advanced incompetence is indistinguishable from malice. Whether they're dumb or malicious, I'm just glad their crap isn't on my phone.
I don't know whether some other shoe is about to drop; for instance, someone could actually show that they're transmitting real keycodes and not just metrics data. But in the absence of that shoe dropping, especially given how many people have jumped to a conclusion about CarrierIQ, I'm inclined to believe that what they do is actually benign. If you want to get upset at someone, get upset at the carriers themselves. When you do, remember, they're already recording all your messages without CarrierIQ.
Re: Secret app on millions of phones logs key taps
#189Earlier quoted context omitted.
They themselves use the phrase "raw data" to describe what they collect (as "metrics"). Metrics are not comprised of raw data, but of measurements, so unless they're being hinky with word choice, a plain reading of their own materials would suggest that they do indeed receive user content.
They've said repeatedly that they do not collect that data. This is a common attitude on HN threads: the idea that the only facts for us to discuss are the ones in the article itself or in other comments on the thread. There are more facts just a Google search away for you. Their own words are not dispositive; I'm not suggesting that they are. But here you're trying to interpret their words in a way that contradicts…
Re: Secret app on millions of phones logs key taps
#190Earlier quoted context omitted.
In their shoes, I would have contacted the researcher and explained myself. While unsurprising, that move was unwise, and I would imagine that you agree on that point at least. I think someone once said that sufficiently advanced incompetence is indistinguishable from malice. Whether they're dumb or malicious, I'm just glad their crap isn't on my phone.
Even they seem to agree with it; rather than just shutting up about their C&D, they actually issued a formal apology to Trevor. That's an uncommon move. I don't know whether some other shoe is about to drop; for instance, someone could actually show that they're transmitting real keycodes and not just metrics data. But in the absence of that shoe dropping, especially given how many people have jumped to a conclusion…