HorizonForumsone horizon
Log inSign up

[ms] · Est. May 2002

Music madethis place,we just kept itgoing...

One durable person. One social graph. Many communities—and every way people speak, share, listen, write, gather and remember.

Forums / Computers / Electronics / Games

Carrier IQ

6 durable postsStarted 2011-12-01Latest 2011-12-02
#111115Post 1 of 6

:evil::evil:

[video=youtube;T17XQI_AYNo]http://www.youtube.com/watch?v=T17XQI_AYNo&feature=player_embedded[/video]

The Android developer who raised the ire of a mobile-phone monitoring company last week is on the attack again, producing a video of how the Carrier IQ software secretly installed on millions of mobile phones reports most everything a user does on a phone. Though the software is installed on most modern Android, BlackBerry and Nokia phones, [URL="http://www.carrieriq.com/"]Carrier IQ[/URL] was virtually unknown until 25-year-old [URL="http://androidsecuritytest.com/features/logs-and-services/loggers/carrieriq/carrieriq-part2/"]Trevor Eckhart[/URL] of Connecticut analyzed its workings, revealing that the software secretly chronicles a user’s phone experience — ostensibly so carriers and phone manufacturers can do quality control. But now he’s released a video actually showing the logging of text messages, encrypted web searches and, well, you name it. Eckhart labeled the software a “[URL="http://en.wikipedia.org/wiki/Rootkit"]rootkit[/URL],” and the Mountain View, California-based software maker[URL="http://www.wired.com/threatlevel/2011/11/rootkit-brouhaha/"]threatened him with legal action[/URL] and huge money damages. The Electronic Frontier Foundation came to his side last week, and the company [URL="http://www.wired.com/threatlevel/2011/11/rootkit-brouhaha-apology/"]backed off on its threats[/URL]. The company told Wired.com last week that Carrier IQ’s wares are for “gathering information off the handset to understand the mobile-user experience, where phone calls are dropped, where signal quality is poor, why applications crash and battery life.” The company denies its software logs keystrokes. Eckhart’s 17-minute video clearly undercuts that claim. In a Thanksgiving post, we mentioned this software as [URL="http://www.wired.com/threatlevel/2011/11/reasons-to-wear-tinfoil-hats/"]one of nine reasons [/URL]to wear a tinfoil hat. The video shows the software logging Eckhart’s online search of “hello world.” That’s despite Eckhart using the [URL="http://en.wikipedia.org/wiki/HTTP_Secure"]HTTPS[/URL] version of Google which is supposed to hide searches from those who would want to spy by intercepting the traffic between a user and Google. Cringe as the video shows the software logging each number as Eckhart fingers the dialer. “Every button you press in the dialer before you call,” he says on the video, “it already gets sent off to the IQ application.” From there, the data — including the content of text messages — is sent to Carrier IQ’s servers, in secret. By the way, it cannot be turned off without rooting the phone and replacing the operating system. And even if you stop paying for wireless service from your carrier and decide to just use Wi-Fi, your device still reports to Carrier IQ. It’s not even clear what privacy policy covers this. Is it Carrier IQ’s, your carrier’s or your phone manufacturer’s? And, perhaps, most important, is sending your communications to Carrier IQ a violation of the federal government’s ban on wiretapping? And even more obvious, Eckhart wonders why aren’t mobile-phone customers informed of this rootkit and given a way to opt out?

#1569345Post 2 of 6

Re: Carrier IQ

For us Android folks running non-rooted devices, check for carrier iq

[url]https://market.android.com/details?id=org.projectvoodoo.simplecarrieriqdetector[/url]

#1569346Post 3 of 6

Re: Carrier IQ

So far it looks as though I am safe on WP7 (from what I have read). But you never know with AT&T.

#1569376Post 4 of 6

Re: Carrier IQ

ANNNNNNND here come the lawsuits :lol:

[url]http://gizmodo.com/5864488/carrier-iq-htc--and-samsung-sued-for-millions-over-tracking[/url]

#1569377Post 5 of 6

Re: Carrier IQ

Not completely related at all but along a similar vein:

[URL]http://nakedsecurity.sophos.com/2011/12/01/android-permissions-glitch-allows-eavesdropping-data-theft/[/URL]

[B][COLOR=#d3d3d3]Android permissions glitch allows eavesdropping, data theft[/COLOR][/B] [FONT=arial][COLOR=#d3d3d3]

[/COLOR][/FONT] [COLOR=#333333][FONT=arial][COLOR=#333333][FONT=arial][COLOR=#d3d3d3][IMG]http://sophosnews.files.wordpress.com/2011/12/androidlock250.jpg?w=250&h=250[/IMG]

Researchers have found multiple holes in Android phones' permissions-based security that would allow a hacker to snatch data, monitor geolocation, send SMS messages, and even eavesdrop on conversations.[/COLOR][/FONT][/COLOR] [COLOR=#333333][FONT=arial][COLOR=#d3d3d3]A group of security researchers from North Carolina State University found the glitches in eight handsets from HTC, Motorola, Samsung and Google.[/COLOR][/FONT][/COLOR] [COLOR=#333333][FONT=arial][COLOR=#d3d3d3]The researchers found "explicit capability leaks" that would allow hackers to bypass key security defenses of Android that require users to grant permission to apps before those apps gain access to personal information and functions such as texting.[/COLOR][/FONT][/COLOR] [COLOR=#333333][FONT=arial][COLOR=#d3d3d3]The glitchy code lies within interfaces and services added by the phone manufacturers to beef up stock firmware from Google.[/COLOR][/FONT][/COLOR] [COLOR=#333333][FONT=arial][COLOR=#d3d3d3]The researchers were "surprised to find" the phones lying down on the permissions front in the war against intrusion, they said in a [/COLOR][URL="http://www.csc.ncsu.edu/faculty/jiang/pubs/NDSS12_WOODPECKER.pdf"][COLOR=#d3d3d3]paper[/COLOR][/URL][COLOR=#d3d3d3] due to be presented next year at the [/COLOR][URL="http://www.isoc.org/isoc/conferences/ndss/12/"][COLOR=#d3d3d3]Network and Distributed System Security Symposium[/COLOR][/URL][COLOR=#d3d3d3].[/COLOR][/FONT][/COLOR][INDENT][COLOR=#333333][FONT=arial][COLOR=#d3d3d3]In this paper, we systematically study eight popular Android smartphones from leading manufacturers, including HTC, Motorola, and Samsung and are surprised to find out these stock phone images do not properly enforce the permission-based security model. Specifically, several privileged (or dangerous) permissions that protect access to sensitive user data or phone features are unsafely exposed to other apps which do not need to request these permissions for the actual use.[/COLOR][/FONT][/COLOR] [/INDENT] [COLOR=#333333][FONT=arial][COLOR=#d3d3d3]These capability leaks constitute "a tangible security weakness for many Android smartphones in the market today," they said.[/COLOR][/FONT][/COLOR] [COLOR=#333333][FONT=arial][COLOR=#d3d3d3]And, they added, the snazzier the phone, the buggier the picture, given that the more pre-loaded apps are present, the more likely the gadget is to have explicit capability leaks.[/COLOR][/FONT][/COLOR] [COLOR=#333333][FONT=arial][COLOR=#d3d3d3]These are the eight Android smartphones they tested and found to be at risk:[/COLOR][/FONT][/COLOR] [COLOR=#333333][FONT=arial][COLOR=#d3d3d3][B][U]HTC[/U]:

  • Legend
  • EVO 4G
  • Wildfire S[/B][/COLOR][/FONT][/COLOR] [COLOR=#333333][FONT=arial][COLOR=#d3d3d3][B][B][U]Motorola[/U]:
  • Droid
  • Droid X[/B][/B][/COLOR][/FONT][/COLOR] [COLOR=#333333][FONT=arial][COLOR=#d3d3d3][B][B][B][U]Samsung[/U]:
  • Epic 4G[/B][/B][/B][/COLOR][/FONT][/COLOR] [COLOR=#333333][FONT=arial][COLOR=#d3d3d3][B][B][B][B][U]Google[/U]:
  • Nexus One
  • Nexus S[/B][/B][/B][/B][/COLOR][/FONT][/COLOR] [COLOR=#333333][FONT=arial][COLOR=#d3d3d3][B][B][B][B]As if all this weren't grim enough, the researchers note that the tool they're using to validate the smartphones, which they've dubbed Woodpecker, has a number of limitations.[/B][/B][/B][/B][/COLOR][/FONT][/COLOR] [COLOR=#333333][FONT=arial][COLOR=#d3d3d3][B][B][B][B]For one, Woodpecker doesn't handle native code; it only handles bytecode from Dalvik, the process virtual machine in the Android operating system that runs Android apps.[/B][/B][/B][/B][/COLOR][/FONT][/COLOR] [COLOR=#333333][FONT=arial][COLOR=#d3d3d3][B][B][B][B]Woodpecker is also limited to handling 13 defined permissions, although many more exist, and apps are free to define new ones.[/B][/B][/B][/B][/COLOR][/FONT][/COLOR] [COLOR=#333333][FONT=arial][COLOR=#d3d3d3][B][B][B][B]"Extending the system to handle more predefined permissions is expected to produce much the same results," the researchers say.[/B][/B][/B][/B][/COLOR][/FONT][/COLOR] [COLOR=#333333][FONT=arial][COLOR=#d3d3d3][B][B][B][B]Not enough? There's more.[/B][/B][/B][/B][/COLOR][/FONT][/COLOR] [COLOR=#333333][FONT=arial][COLOR=#d3d3d3][B][B][B][B]Adding support for app-defined permissions will lead to another class of capability leaks altogether: namely, chained capability leaks, where a permission might be safely passed from one app to a second app, which then unsafely passes it on along to a third app.[/B][/B][/B][/B][/COLOR][/FONT][/COLOR] [COLOR=#333333][FONT=arial][COLOR=#d3d3d3][B][B][B][B][IMG]http://sophosnews.files.wordpress.com/2011/12/istockvirusbug250.jpg?w=250&h=250[/IMG] Another rugto lift to look for more bugs is among third-party apps, given that the security researches only examined pre-loaded apps in the smartphones' firmware.[/B][/B][/B][/B][/COLOR][/FONT][/COLOR] [COLOR=#333333][FONT=arial][COLOR=#d3d3d3][B][B][B][B]The researchers note that capability leaks — particularly explicit ones — on phone images "are of great interest to malicious third parties." Implicit leaks are fairly rare, they say, and more likely tied to software engineering defects than constituting actual security risks.[/B][/B][/B][/B][/COLOR][/FONT][/COLOR] [COLOR=#333333][FONT=arial][COLOR=#d3d3d3][B][B][B][B]But implicit leaks could be due for their day in the sun when it comes to third-party apps, since they could open the smartphones up to "collusion attacks," the researchers said.[/B][/B][/B][/B][/COLOR][/FONT][/COLOR][INDENT][COLOR=#333333][FONT=arial][COLOR=#d3d3d3][B][B][B][B]A cohort of seemingly innocuous apps could conspire together to perform malicious activities and the user may not be informed of the true scope of their permissions within the system.[/B][/B][/B][/B][/COLOR][/FONT][/COLOR] [/INDENT] [COLOR=#333333][FONT=arial][COLOR=#d3d3d3][B][B][B][B]Wasn't it just last week that Google's Open Source Programs Manager, Chris DiBona, was [/B][/B][/B][/B][/COLOR][B][B][B][B][URL="http://nakedsecurity.sophos.com/2011/11/23/googles-open-source-geezer-gets-shirty-about-security/"][COLOR=#d3d3d3]railing against[/COLOR][/URL][/B][/B][/B][/B][COLOR=#d3d3d3][B][B][B][B] vendors of Android anti-virus software (and any minion scurrilous enough to work for one), summing up the ragged lot as being likely "charlatans and scammers?"[/B][/B][/B][/B][/COLOR][/FONT][/COLOR] [COLOR=#333333][FONT=arial][COLOR=#d3d3d3][B][B][B][B]Yes, yes, I do believe it was last week that Mr. DiBona told such "scammers" that if they worked selling virus protection "for android, rim or IOS you should be ashamed of yourself [sic]."[/B][/B][/B][/B][/COLOR][/FONT][/COLOR] [COLOR=#333333][FONT=arial][COLOR=#d3d3d3][B][B][B][B]Should the North Carolina State University researchers, Michael Grace, Yajin Zhou, Zhi Wang, and Xuxian Jiang, bow their heads and slink home in shame for finding the current crop of Android bugs?[/B][/B][/B][/B][/COLOR][/FONT][/COLOR] [COLOR=#333333][FONT=arial][COLOR=#d3d3d3][B][B][B][B]Well, if their cheeks do burn red, I hope they don't slink out of sight before they present their paper and roll out an even better version of Woodpecker.[/B][/B][/B][/B][/COLOR][/FONT][/COLOR] [/FONT][/COLOR]
#1569385Post 6 of 6

Re: Carrier IQ

Apparently this carrier IQ only affects phone that were bought in North America as the carriers forced the manufacturers to implement it.

Log in to reply