Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

"From leaked training documents we can see that portal operators can view and task metrics by equipment ID, subscriber ID, and more. So instead of seeing dropped calls in California, they now know “Joe Anyone’s” location at any given time, what he is running on his device, keys being pressed, applications being used."

"Verizon has publicly came forward with a statement regarding their usage on Carrier IQ statistics and give users a way to stop them from selling the information outside of Verizon"

Wow. No surprise that they would like to suppress that information, but they should've known better than to be so heavy-handed with the lawyering. They might have been able to spin it a little more positive with some decent PR, but now it just screams that they're being evil.



"...keys being pressed..."

Is it possible, then, that carriers have in their databases the passwords of every server that every system admin has connected to over ssh from their smartphone?


Of course not! They promise really hard that they're not keylogging, despite installing a keylogger that sends opaque encrypted data packets back.


This may be the heart of the problem. If the databases built with this include keypresses, then when a user logs into a site using https, their credentials are being recorded before they are encrypted. This opens another vector for hackers to get and sell the information for malicious use by surreptitiously acquiring the data from the tier 1 carrier like Sprint or Verizon instead of needing to get it by hacking a bank.

With such a large number of potential victims, it would be difficult to determine if a wave of thefts from a particular institution were the result of the institution's security being compromised or if a CarrierIQ database was compromised.

I develop some on Android and have been aware of this product for many months now but I have no idea what data it collects and transmits. Just what it is capable of. So this may be a non-issue. For now, at least.


I find myself more and more joyful to be contained within Apple's walled garden every passing day.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: