Catch up on stories from the past week (and beyond) at the Slashdot story archive

 



Forgot your password?
typodupeerror
×
Android Cellphones Privacy Your Rights Online

CarrierIQ: Most Phones Ship With "Rootkit" 447

First time accepted submitter Kompressor writes "According to a developer on the XDA forums, TrevE, many Android, Nokia, and BlackBerry smartphones have software called Carrier IQ that allows your carrier full access into your handset, including keylogging, which apps have been run, URLs that have been loaded in the browser, etc." Since this was submitted, a few more details have come to light. The software was designed to give carriers useful feedback on aggregate usage patterns, but the software runs as root and the privacy implications are pretty severe.
This discussion has been archived. No new comments can be posted.

CarrierIQ: Most Phones Ship With "Rootkit"

Comments Filter:
  • by Anonymous Coward on Wednesday November 16, 2011 @11:58AM (#38073950)

    With a walled garden, Apple keeps the carriers out too.

  • Cyanogen (Score:5, Insightful)

    by Tsingi ( 870990 ) <.moc.liamg. .ta. .kcir.maharg.> on Wednesday November 16, 2011 @11:59AM (#38073960)

    Nice.

    Buy a phone you can root and put CyanogenMod on it. It works great!

  • Re:Doesn't Matter (Score:5, Insightful)

    by Anonymous Coward on Wednesday November 16, 2011 @11:59AM (#38073970)
    In open source, the user can do whatever he or she wants with the software.
    In proprietary software, it's the other way around.
  • Re:Doesn't Matter (Score:5, Insightful)

    by WorBlux ( 1751716 ) on Wednesday November 16, 2011 @12:03PM (#38074014)
    But many of the drivers and first stage bootloaders aren't
  • by Anonymous Coward on Wednesday November 16, 2011 @12:04PM (#38074034)

    oh boy you are so naive and wrong about that

  • by Pieroxy ( 222434 ) on Wednesday November 16, 2011 @12:05PM (#38074056) Homepage

    With a walled garden, Apple keeps the carriers out too.

    Yes, walled gardens have pros and cons. This is definitely a pro in my book.

  • by Tr3vin ( 1220548 ) on Wednesday November 16, 2011 @12:08PM (#38074094)
    Unless, of course, those walls have security cameras mounted on them.
  • by WorBlux ( 1751716 ) on Wednesday November 16, 2011 @12:09PM (#38074118)
    This is why I'm not buying a "smart" phone until until they release one with a fully open software stack (excluding the little bit of firmware that controls the cellular modem.)
  • Re:Doesn't Matter (Score:5, Insightful)

    by ByOhTek ( 1181381 ) on Wednesday November 16, 2011 @12:14PM (#38074182) Journal

    I think the GPs point is that, in this case, the latter can also be true for open source software.

  • by sribe ( 304414 ) on Wednesday November 16, 2011 @12:20PM (#38074294)

    ...but that's acceptable since you're getting the phone at a huge discount.

    I don't even believe that. As long as you continue to pay your contract, you should be able to unlock the phone.

  • by Anonymous Coward on Wednesday November 16, 2011 @12:42PM (#38074598)
    Absence of evidence != Evidence of absence... Anyone even vaguely familiar with scientific principles (or information security) should know this.
  • Re:Doesn't Matter (Score:4, Insightful)

    by Bert64 ( 520050 ) <bert AT slashdot DOT firenzee DOT com> on Wednesday November 16, 2011 @01:04PM (#38074908) Homepage

    But the point is that an open version is available, and thanks to third party mods like cyanogen if you don't like the version shipped with the phone you can replace it...

  • Re:list? (Score:4, Insightful)

    by Anonymous Coward on Wednesday November 16, 2011 @01:06PM (#38074944)

    I can only speak for my Employer... BlackBerry: 0
    It's a very misleading article. Yes it shows that a "root kit" install has appeared on an Android device, but it is clear that the author has no idea about the security restrictions applicable to BB devices. Want to block your Carrier's Application? Simply go to Security Options -> Advanced Security Options -> Certificates. Find your Carrier certs and revoke them. It won't block your phone calls, or data connections, but any app which your carrier has installed to your device with a Service Book will be prevented from running.
    Oh, and you can also see exactly what modules are stored on your device under the Options->Applications listings. I seriously doubt you will ever find this stuff in there.

  • by pancake_lover ( 310091 ) on Wednesday November 16, 2011 @01:09PM (#38074974)

    [citation needed]

  • Re:Doesn't Matter (Score:5, Insightful)

    by marcosdumay ( 620877 ) <marcosdumay&gmail,com> on Wednesday November 16, 2011 @01:15PM (#38075054) Homepage Journal

    Or maybe his point was that, if Android was really open such things would be easy to fix.

  • by jeffmeden ( 135043 ) on Wednesday November 16, 2011 @01:23PM (#38075130) Homepage Journal
    Jesus, mods, way to fall for a troll. Parent should be (Score:-5, Lying). There is no suggestion in any of the articles on this subject that the iPhone has this software, other than a CarrierIQ job requirement listing iPhone experience as optional...
  • Re:Really? (Score:4, Insightful)

    by gstrickler ( 920733 ) on Wednesday November 16, 2011 @01:26PM (#38075188)

    There is a HUGE difference between knowing who you call or what websites you visit (available from network info) and knowing which apps you're using or monitoring your key strokes. The latter is none of their business, and key logging can allow them to access your passwords. That's completely inappropriate and probably a crime.

  • Re:Doesn't Matter (Score:2, Insightful)

    by Tharsman ( 1364603 ) on Wednesday November 16, 2011 @01:29PM (#38075236)

    I'll tell my grandma to go do that right away! She is always paranoid about her privacy, I'll tell her all she needs to do is get cyanogen and replace her OS!

  • by hawguy ( 1600213 ) on Wednesday November 16, 2011 @01:31PM (#38075260)

    Care to explain how it doesn't keep the carriers out of the phone? Last I checked, and yes employing traffic monitoring is standard on my network, there was no remote access nor capabilities to do so.

    How did you check when you have no access to the IOS source code and no idea what it's really doing? Would you really know it if AT&T had some code buried in the kernel that sends your tracking data in some GSM control messages that aren't accessible in user-land on the phone? Making a phone work with a new carrier is more than just slapping a new radio in it -- there's software involved as well.

  • Re:Doesn't Matter (Score:4, Insightful)

    by Runaway1956 ( 1322357 ) on Wednesday November 16, 2011 @01:31PM (#38075274) Homepage Journal

    What Marcos said. Android is not "open source". It's "kinda sorta open to downstream proprietors, but not to end users", which is not open source at all.

    I'm one who likes a lot of what Google does, but I'm no blind fanboi. Google dropped the ball when they permitted downstream customers to close their source. And, that's why I'm using a "dumb phone"*, with no plans to upgrade. I'm not about to pay the phone company hundreds of dollars, PLUS an exorbitant contract fee, so that they can spy on me.

    * It should be noted that even old "dumb phones" are pretty easy to spy on, albeit to a lesser extent than is exposed in this and other recent articles.

  • by LordLimecat ( 1103839 ) on Wednesday November 16, 2011 @01:35PM (#38075326)

    Article is a load of crap, they give no details on how they know its there. They show screenshots of 2 android phones with visible GUIs which show CIQ, and then claim its on iPhone and Blackberry as well. Sorry, Ive dug through all the servicebooks on several blackberries (8250, 9600, 7200) and Ive never seen a CIQ service book.

    And as for this statement...

    According to TrevE, the software is installed as a rootkit software in the RAM of devices where it resides. This software basically is completely hidden from view and in it virtually invisible,

    Someone doesnt understand the volatile nature of RAM, or is terrible at communicating. Rootkits dont reside in RAM, because then they would be removable with a battery removal. As for "completely hidden", why then does he have screenshots of a CIQ GUI where theres a "disable CIQ" checkbox?

    The credibility factor of this story is in the negatives, especially when they really dont explain what their proof is and they have one guy on a forum claiming this-- its not even a researcher with a known real name. Who says this isnt a massive troll?

  • Re:Doesn't Matter (Score:5, Insightful)

    by zill ( 1690130 ) on Wednesday November 16, 2011 @01:37PM (#38075358)
    No, you cannot replace the first stage bootloader and the baseband, so they will forever remain proprietary. There is no way to have a working Android phone without running proprietary code unfortunately.

    You can, however, get Android running without relying on proprietary code. It just won't work as a phone unfortunately.
  • Re:2 Questions (Score:2, Insightful)

    by dukerobillard ( 582741 ) on Wednesday November 16, 2011 @01:42PM (#38075416)

    1) Don't buy your phone from a Carrier. I bought my Nexus One from Google. I bought my previous (non-smart) phone from some guy on Ebay.

  • by kiwimate ( 458274 ) on Wednesday November 16, 2011 @02:30PM (#38076008) Journal

    Disclaimer: I don't know what Baloroth's opinions in general are, so this isn't necessarily aimed at you. And I hope this doesn't sound too snide.

    That said, this is where I see a double standard in Slashdot from time to time. Go back to stories about broadcasting SSIDs and setting up computers and so forth. Most Slashdotters tend to say it is on the part of the consumer to understand, read manuals, etc. Setting up encryption, for example - the prevailing opinion on here is that that that is just part of the modern world in which we live, and if consumers can't be bothered to read and understand, then they get what they deserve.

    I think that's a pretty cavalier and smug attitude. Beyond that, however, if the same attitude doesn't work both ways, then I'm not terribly sympathetic. I don't understand all the legalese when I sign a mortgage, say...so I make sure I ask someone. And if I don't understand, I don't sign until I do. (And it's been pretty amazing. Example a - watching the glib sales girl who breezily said "read everything, take your time" and then got visibly cooler in her attitude when I proceeded to do just that. Example b - the Wells Fargo reps who responded "umm, we don't know" when I asked them what a particular phrase in their mortgage paperwork meant, and didn't think it was a problem to say "but it's standard language, so it's okay to sign anyway".)

  • by The Moof ( 859402 ) on Wednesday November 16, 2011 @02:34PM (#38076048)

    They are not legally binding in sane jurisdictions.

    That, right there, is the catch. If you're in the US, you're not in a sane jurisdiction. Have you seen some of the egregious things they've been putting in EULAs these days that are actually being held up in court?

  • Re:Doesn't Matter (Score:4, Insightful)

    by Drakino ( 10965 ) on Wednesday November 16, 2011 @02:37PM (#38076074) Journal

    Only parts of Android are open source. Other parts, including key infrastructure pieces and the majority of apps people use that ship on the devices are closed.

    And open source here is a license that doesn't require Google to disclose the source when shipping, leading to every Android Honeycomb tablet that shipped this year being a closed platform until this week.

    Google has severely muddied the meaning of open and open source compared to what we are used to from the GPL and Linux worlds.

    Never let your hatred of Apple, Microsoft or whoever to cloud your judgement of the companies you do cling to. Google's "open" message is eerily similar to FUD messages Microsoft was spreading in the 90s when it came to Java and "open computing". The quicker we hold these companies accountable, the quicker it improves. Getting stuck in fanboy wars and putting on the blinders helps no one.

  • Re:Doesn't Matter (Score:5, Insightful)

    by adolf ( 21054 ) <flodadolf@gmail.com> on Wednesday November 16, 2011 @03:50PM (#38077000) Journal

    There is no spoon.

  • Re:Doesn't Matter (Score:4, Insightful)

    by nurb432 ( 527695 ) on Wednesday November 16, 2011 @06:19PM (#38079238) Homepage Journal

    Google dropped the ball when they permitted downstream customers to close their source

    And if they hadn't, no manufacturer would have adopted it.

Software production is assumed to be a line function, but it is run like a staff function. -- Paul Licker

Working...