Earlier quoted context omitted.
How did the perpetrator plant such a device in the first place? Did he have permission? If not, perhaps a different crime was committed.
To use a situation analogous to the situation with CarrierIQ, he did not have permission and you never even knew he was there or that the camera was there. However, the camera is digital, it is connected to your power outlet with a battery-backed UPS, and it has an active wireless modem attached to it. Maybe he did send data, maybe he didn't. But he's also sent you a CnD notice and threatening to sue you if you tell…
Secret app on millions of phones logs key taps
171–180 of 193 posts
Re: Secret app on millions of phones logs key taps
#172Earlier quoted context omitted.
...if it's 90GB (the upper limit before the recruiter would have been shouting about terabytes)... A terabyte is 1000GB. Why would they be shouting about terabytes if it were anything over .09 terabytes?
Because that's how recruiter math works. They round to the nearest buzz word.
And isn't it likely that some phones are set to transfer more data than others?
Re: Secret app on millions of phones logs key taps
#173Earlier quoted context omitted.
Because that's how recruiter math works. They round to the nearest buzz word.
Don't you think it's a pretty shaky argument? They're not transferring much data on your phone because of "recruiter math"? And isn't it likely that some phones are set to transfer more data than others?
Re: Secret app on millions of phones logs key taps
#174Earlier quoted context omitted.
I'm not even sure what I should say to explain the difference here. It should be obvious...
You're implying the difference is intent. I'm saying, their intent isn't known. Their own statement is that they don't want the raw characters, just the stats. Meanwhile, there are plenty of pieces of code strewn throughout your system that get access to similar bits of sensitive data. For instance, every BSD system has a BPF device and driver that exists solely to tap your network traffic. Luckily, nobody sells a BP…
Besides, the BPF driver in every BSD system is probably open-source and could be reviewed for intent if in doubt. It's not easy, not everybody can do it, but it is possible.
However, you cannot do that for CarrierIQ. Even if such logs aren't getting sent, you don't know that they haven't installed some kind of mechanism to trigger such an upload on demand.
Re: Secret app on millions of phones logs key taps
#175Earlier quoted context omitted.
Whether they are sending a full log report of my actions TODAY is beside the main point. I do however know two things. 1) That their local software processes almost every key stroke made. 2) And that they do send at least some portion of this data back to their servers. At this point it would be trivial for them to send my private information TOMORROW if they decided to do so. I don't know that they don't have a subr…
This is, of course, an attitude that is going to "deftly" shoot down any new fact or analysis brought into the discussion. Your starting point was that they were collecting † data that could jeopardize national security ††. You clearly based that argument on the idea that their own recruiter mentioned "10s of gigabytes a day". Now, in true message board geek fashion, you're going to steadily move the goalposts. What?…
Now you're defending/rationalizing whatever disgusting bullshit Carrier IQ is up to.
What's wrong with you?
Just like we didn't have absolute proof that Aaron's indictment was politically motivated, we can't be absolutely sure that Carrier IQ is a company full of shit and devoid of morals.
But it's blindingly obvious that both are very, very likely.
In case you're just blissfully unaware of how full of shit the world actually is, here's a report on your justice system fraudulently, systematically signing away people's homes: http://www.rollingstone.com/politics/news/matt-taibbi-courts...
Re: Secret app on millions of phones logs key taps
#176Earlier quoted context omitted.
Whether they are sending a full log report of my actions TODAY is beside the main point. I do however know two things. 1) That their local software processes almost every key stroke made. 2) And that they do send at least some portion of this data back to their servers. At this point it would be trivial for them to send my private information TOMORROW if they decided to do so. I don't know that they don't have a subr…
This is, of course, an attitude that is going to "deftly" shoot down any new fact or analysis brought into the discussion. Your starting point was that they were collecting † data that could jeopardize national security ††. You clearly based that argument on the idea that their own recruiter mentioned "10s of gigabytes a day". Now, in true message board geek fashion, you're going to steadily move the goalposts. What?…
I don't think there's any goalpost moving here at all: Hundreds of millions of keyloggers -- rootkits, really, as the article states -- are installed and unremovable. Whether they are being abused or not at the moment is irrelevant; it should be outrageous and unacceptable that such a datastream is going through a third-party without any kind of transparency, acceptance, or even tacit acknowledgement.
Likewise, your rhetorical refutation here (very thorough, in the abstract) would be a lot more damning if there wasn't, you know, video evidence of this rootkit collecting exactly this data and sending it back.
Re: Secret app on millions of phones logs key taps
#177Earlier quoted context omitted.
> So if all we're doing here is condemning CarrierIQ I asked someone who is quite good with crypto a question about a possible MITM attack on 141 million phones. I didn't condemn CarrierIQ, I avoided dramatic language, I even added qualifiers to avoid stating something as fact if it wasn't yet confirmed.
Sorry. You're right. I let the ultra dumbness of this whole thread bring me down a bit. Doing an SSL MITM from agent software installed by the carrier on a phone seems pretty silly, since the carrier is in a position to see anything you're typing into your phone anyways (in the sense that it controls the OS). I'm not sure I buy any analysis that suggests CarrierIQ is really "MITM'ing" SSL --- though that's trivial fo…
I'm just curious if that's the way phones will be forever: with the OS controlled by the carrier and with no right to tinker/hack/modify the device you buy & pay huge monthly fees to use.
Re: Secret app on millions of phones logs key taps
#178Earlier quoted context omitted.
This is, of course, an attitude that is going to "deftly" shoot down any new fact or analysis brought into the discussion. Your starting point was that they were collecting † data that could jeopardize national security ††. You clearly based that argument on the idea that their own recruiter mentioned "10s of gigabytes a day". Now, in true message board geek fashion, you're going to steadily move the goalposts. What?…
Here's a thread full of you vehemently defending/rationalizing police state -like behaviour: http://news.ycombinator.com/item?id=2802917 Now you're defending/rationalizing whatever disgusting bullshit Carrier IQ is up to. What's wrong with you? Just like we didn't have absolute proof that Aaron's indictment was politically motivated, we can't be absolutely sure that Carrier IQ is a company full of shit and devoid of…
Re: Secret app on millions of phones logs key taps
#179Why is this whole company and all of it's employees not indicted for trespassing, breaking and entering, burglary, etc????? How is stealing the most sensitive of data off my phone without my knowledge/consent ANY different then walking into my house and taking my passport??
Because there is no evidence of any data leaving your phone. It's not stealing. It's just a debugger/logger.
Re: Secret app on millions of phones logs key taps
#180Earlier quoted context omitted.
They say they are installed on > 148.3M phones. If we imagine that they are gathering 10GB per day then that's about 76 bytes per phone, if it's 90GB (the upper limit before the recruiter would have been shouting about terabytes) then it's 680 bytes. It's more likely to be in the middle (because otherwise the recruiter would have rounded up) so you are talking 100s of bytes per phone per day. I don't think it's reali…
But simple zip on raw text is what? 3 or 4 to 1? Particularly when you're talking about urls. So now you're talking about at least a couple kbytes of raw data. So logging all of everyone's texts is probably still out. But easily logging their browsing patterns. Probably app installation and use. And certainly they retain the capability to log texts containing keywords without going too far outside that aggregate rang…