Please login or register.
Login with username, password and session length

UNYSOC.ORG - Upstate NY Subaru Owners Club

May 22, 2012, 01:12:14 AM
Pages: [1] 2   Go Down

Author Topic: Attention All Smartphone Users  (Read 427 times)

0 Members and 1 Guest are viewing this topic.

Offline ipodwinner31

  • Member
  • **
  • Posts: 136
  • Karma: +3/-8

Attention All Smartphone Users
« on: December 01, 2011, 09:22:38 AM »
http://www.pcworld.com/article/245229/carrier_iq_rootkit_reportedly_logs_everything_on_millions_of_phones_updated.html

Quote
Carrier IQ Rootkit Reportedly Logs Everything On Millions Of Phones

If you use an Android, BlackBerry, or Nokiasmartphonethen you may be at risk of being illegally wire-tapped by Carrier IQ--a provider of performance monitoring software for smartphones--according to reports.

Earlier this month, security researcher Trevor Eckhart announced that he found software made by Carrier IQ that may be logging your every move on your mobile phone. Trevor referred to it as a "rootkit", a piece of software that hides itself while utilizing privileged access like watching your every move. Carrier IQ didn't take too kindly to this accusation, and responded aggressively with a cease-and-desist letter, and went on to deny this accusation. However, to further back his accusation, Eckhart released a video that he says shows the software in action.

In the video, Eckhart navigates to a list of running applications on his phone, and he found that the application IQRD--made by Carrier IQ--was not shown. However, when he searched all of the applications on the device, Eckhart discovered that IQRD showed up with the option to force stop it; therefore, he determined that the app must have been running. However, when he tried to stop the application, the force stop function did absolutely nothing. Additionally, this application always runs when the device is started, according to his research.

After connecting his HTC device to hiscomputer,Trevorfound thatIQRDissecretly logging every single button that he taps on the phone--even on the touchscreen number pad. IQRD is also shown to be logging text messages.

In the video, Eckhart shows that Carrier IQ is also logging Web searches. While this doesn't sound all that bad by itself, it suggeststhatCarrier IQ is logging what happens during an HTTPS connection which is supposed to be encrypted information. Additionally, it can do this over a Wi-Fi connection with no 3G, so even if your phone serviceisdisconnected,IQRDstilllogstheinformation.

Wired goes on to say that the application "cannot be turned off without rooting the phone and replacing the operating system."

While Eckhart tested his accusation on an HTC device it is likely that Carrier IQ is logging information on millions of more devices.According to Carrier IQ (pdf)"Carrier IQ’s Mobile Intelligenceplatform is currently deployed with more than 150 million devices worldwide."

While Carrier IQ has since backed off and apologized for its aggressive legal action against Eckhart, this isn't the end of the
 story for Carrier IQ. Paul Ohm, a former Justice Department
prosecutor and professor at the University of Colorado Law School, told Forbes that this isn't just creepy, but it's also likely grounds for a class action lawsuit, citing a federal wiretapping law.

Make sure to check out the video below to see what Trevor discovered.

 http://www.youtube.com/watch?nomobile=1&v=legx3K_Ul_I
]

Saw this on another forum........thoughts?

Edit: you Iphone users arent safe either. Safer, but not totally safe.

 http://gizmodo.com/5864107/yes-your-iphone-is-tracking-you-with-carrieriq-too

Quote
All hellbrokeloose yesterday when it was discoveredthatmost Android phones (and BlackBerries, and others) are recording every keystroke you make. Now, references to the same software have been discovered in Apple'siOS. But in this case, it only logs technical data and it's off by default. Last night, prominent iOS hacker chpwn tweeted that he had found reference to the same, now notorious Carrier IQ software in iOS 3. After just a little more poking and prodding, it was confirmed that these references exist all the way up to modern day iOS 5, they're just under a different name: /usr/bin/awd_ice2. But wait, beforeeveryone starts returning their iPhones (none of you were going to do that anyway), there's a bit of good news.

It seems that the data Carrier IQ has access to is much more limited than it is on Android. From chpwn's blog: "...it does not appear the daemon has any access or communication with the UI layer, where text entry is done." That is extremely good news if it proves to be true, because it would mean that iOS wouldn't be logging your passwords, emails, SMS messages, etc. Even more good news: CarrierIQ only kicks in when the iPhone is in Diagnostic Mode, which is off by default. So you'd have to actively tinker with settings you never use for it to work.

When activated,though, CarrierIQ does appear to log your name, phone number, carrier information, some info about the calls you are making, and your location (if Location Services are enabled). There may well be more, they just haven't found it yet. We'll update as we learn more.[chpwn viaThe Verge viaTheNextWeb]
« Last Edit: December 01, 2011, 09:34:24 AM by ipodwinner31 »

Offline RedRoof2

  • ScoobyDooby Specialist
  • ****
  • Posts: 1,796
  • Karma: +340/-293
  • Blah Blah Subaru Blah Rally Blah Low Compression

Re: Attention All Smartphone Users
« Reply #1 on: December 01, 2011, 10:03:53 AM »
Yep.  Saw this article.  Not like I'm watching child porn or anything, but this still pisses me off.  I access my accounts through my phone.  If they're logging data and keystrokes, it'd really SUCK if someone hacked into their database and stole all that info.  Just like someone did to Hannaford a few years back.
"Excellent ideas, poor execution ~ It's what makes a Subaru a Subaru"  -- Kavik

These images are actual illustrations from Toyota's Mr2 Service Manual.  No, really.

Offline LarenF3D5

  • ScoobyDooby Specialist
  • ****
  • Posts: 939
  • Karma: +57/-58
  • Smiles per gallon > Miles per gallon

Re: Attention All Smartphone Users
« Reply #2 on: December 01, 2011, 10:05:27 AM »
I'm insured against identity theft. /shrug
2002 WRB WRX Stage II - Tuned by Dom
http://getadomtune.com

Offline skyphix

  • Waaaay to much time on their hands!
  • *****
  • Posts: 4,253
  • Karma: +104/-38
    • http://www.skyphix.com

Re: Attention All Smartphone Users
« Reply #3 on: December 01, 2011, 10:16:07 AM »
CYANOGENMOD.
Eric

Quote me now while I'm feeling good about it.  I've decided a WRX will be the vehicle that replaces the Jeep.  I can't see paying Evo prices or justifying purchasing a halfassed/beat to death example for the same asinine amount of money.  For an affordable, point to point, all-weather capable performance car, a wagon fits the bill.  A swapped wagon, even better.

Offline madlife

  • ScoobyDooby Specialist
  • ****
  • Posts: 1,016
  • Karma: +29/-25

Re: Attention All Smartphone Users
« Reply #4 on: December 01, 2011, 10:24:42 AM »
I'm insured against identity theft. /shrug

I always wondered how insurance works against identity theft.   I can see if someone steals your passwords and wipes your bank accounts out, but what would they do if you one day went to get a loan and pull a credit score of 145?   

Thank god my blackberry is so old that it cant even open my bank's website.

Offline ed

  • Administrator
  • ScoobyDooby Specialist
  • *****
  • Posts: 1,306
  • Karma: +79/-20
    • UNYSOC.ORG

Re: Attention All Smartphone Users
« Reply #5 on: December 01, 2011, 10:52:53 AM »
CYANOGENMOD.

Seriously.

Overblown anyway. None of my phones have this issue.
'08 Honda Billet Silver Pilot EX-L - current
'08 Honda Nighthawk Black Pearl Element SC - sold!
'07 VW Black Magic GTI MKV - sold!
'03 Subaru Sonic Yellow WRX - sold!
'92 Honda White Civic LX - sold!

http://www.droidhype.com
http://www.gideontech.com

Offline TheBigChill

  • Waaaay to much time on their hands!
  • *****
  • Posts: 2,684
  • Karma: +307/-214

Re: Attention All Smartphone Users
« Reply #6 on: December 01, 2011, 11:41:34 AM »
CYANOGENMOD.

 ^ For the phones that are easily rooted.  My Hero was stupid easy to root.  My Legend, not so much.


 So if this is on my phone, I should be able to find it in the "system/app" folder, if IQRD is in fact installed ?
"Blah Blah Blah Blah"  -You



Offline skyphix

  • Waaaay to much time on their hands!
  • *****
  • Posts: 4,253
  • Karma: +104/-38
    • http://www.skyphix.com

Re: Attention All Smartphone Users
« Reply #7 on: December 01, 2011, 11:46:41 AM »
http://www.extremetech.com/computing/107427-carrier-iq-which-phones-are-infected-and-how-to-remove-it

EDIT: Also, didn't realize that revolutionary didn't support the Legend. That kind of sucks. I am exceedingly happy with my Thunderbolt and Cyanogenmod running at 1.4Ghz.
« Last Edit: December 01, 2011, 11:49:08 AM by skyphix »
Eric

Quote me now while I'm feeling good about it.  I've decided a WRX will be the vehicle that replaces the Jeep.  I can't see paying Evo prices or justifying purchasing a halfassed/beat to death example for the same asinine amount of money.  For an affordable, point to point, all-weather capable performance car, a wagon fits the bill.  A swapped wagon, even better.

Offline Kavik

  • Waaaay to much time on their hands!
  • *****
  • Posts: 8,110
  • Karma: +286/-250

Re: Attention All Smartphone Users
« Reply #8 on: December 01, 2011, 11:48:10 AM »
 This sucks......but, if we can't trust the official software that comes on our phones, how are we supposed to know that the aftermarket OS's don't have something similar with, perhaps, more sinister intent?
 There was a pretty big issue a year or so ago when one of the bigger developers (I wanna say it was the Liberty OS) proved that he could do a lot of freaky shit with your phone, then accidentally put out that code in one of the nightly updates.

 And how many people don't even look at the permissions (or look, but don't understand what they're saying okay to) on some of these free apps we download?  Free financial planners, password storage tools, etc....who's to say that any program that allows writing to the sd card "for backing up the software settings" or "for saved game data" and full internet access "for embedding advertisements" isn't really a keylogger uploading to an online server?


*sighs* time to go build another layer into my foil hat  :|
-Daryl (Albany)                                                                                   ಠ_ಠ
['02 PSM WRX Sedan]     ['03 Sonic Yellow WRX Wagon]     ['05 WRB WRX Wagon]

Offline skyphix

  • Waaaay to much time on their hands!
  • *****
  • Posts: 4,253
  • Karma: +104/-38
    • http://www.skyphix.com

Re: Attention All Smartphone Users
« Reply #9 on: December 01, 2011, 11:51:03 AM »
And thats why you don't overlook app permissions.

As far as trusting the 3rd party developers, larger ones (like CM/etc.) Have a large enough community to cross-check whats actually going on. The beauty of open source software.

Also, you could always roll your own from the source. I mean, that is sort of the point of the AOSP.
« Last Edit: December 01, 2011, 11:55:50 AM by skyphix »
Eric

Quote me now while I'm feeling good about it.  I've decided a WRX will be the vehicle that replaces the Jeep.  I can't see paying Evo prices or justifying purchasing a halfassed/beat to death example for the same asinine amount of money.  For an affordable, point to point, all-weather capable performance car, a wagon fits the bill.  A swapped wagon, even better.

Offline RedRoof2

  • ScoobyDooby Specialist
  • ****
  • Posts: 1,796
  • Karma: +340/-293
  • Blah Blah Subaru Blah Rally Blah Low Compression

Re: Attention All Smartphone Users
« Reply #10 on: December 01, 2011, 11:51:42 AM »
I've got a feeling they'll be answering to congress on this one.  It's going to get nasty, fast.

I'll be following directions on removing it this evening when i'm home.
« Last Edit: December 01, 2011, 11:56:12 AM by RedRoof2 »
"Excellent ideas, poor execution ~ It's what makes a Subaru a Subaru"  -- Kavik

These images are actual illustrations from Toyota's Mr2 Service Manual.  No, really.

Offline Kavik

  • Waaaay to much time on their hands!
  • *****
  • Posts: 8,110
  • Karma: +286/-250

Re: Attention All Smartphone Users
« Reply #11 on: December 01, 2011, 12:10:53 PM »
And thats why you don't overlook app permissions.

As far as trusting the 3rd party developers, larger ones (like CM/etc.) Have a large enough community to cross-check whats actually going on. The beauty of open source software.

Also, you could always roll your own from the source. I mean, that is sort of the point of the AOSP.

honestly though, people overlook them all the time

For example:

Angry Birds - 50 million + downloads
Permissions:
Modify/delete SD card content
Read phone state and identity
Full Internet Access
Coarse (network based) location

Words With Friends - 10 million + downloads
Same as above, but instead of Coarse Location, this one has access to read all your contact data instead


And that's just for a couple, retardedly popular, free games.  You want real scary potential, go look at GO SMS Pro.  I use it for my text messaging program, and all those permissions do have valid functions within the program....but my God, it's scary to think the things they could do with what they have access to
« Last Edit: December 01, 2011, 12:13:51 PM by Kavik »
-Daryl (Albany)                                                                                   ಠ_ಠ
['02 PSM WRX Sedan]     ['03 Sonic Yellow WRX Wagon]     ['05 WRB WRX Wagon]

Offline TheBigChill

  • Waaaay to much time on their hands!
  • *****
  • Posts: 2,684
  • Karma: +307/-214

Re: Attention All Smartphone Users
« Reply #12 on: December 01, 2011, 12:27:48 PM »

 Great.  So I can't even check to see if this piece of crap is on my phone.  Rooting the Legend is a PITA.  I had to be different, and buy a Canadian phone.  Sheesh
"Blah Blah Blah Blah"  -You



Offline spoolordie

  • Waaaay to much time on their hands!
  • *****
  • Posts: 3,133
  • Karma: +204/-129
  • Get Frig'd

Re: Attention All Smartphone Users
« Reply #13 on: December 01, 2011, 12:28:10 PM »


My minutes are unlimted, never have to charge it, cant send SMS but hey my Verizon/beeferoni's  plan is free
02 WRX Domtuned/Hella Slammed/Turbo Swapped
93 Impreza L 1.8 Liters of Fury Donated to GF
08 DRZ400sm super-motarded
92 Mazda Miata For Sale !!!!!!!!!
http://slideny.com/
The Unysoc Hella Flush Thread President
http://overboostnoooo.mybrute.com

Offline RedRoof2

  • ScoobyDooby Specialist
  • ****
  • Posts: 1,796
  • Karma: +340/-293
  • Blah Blah Subaru Blah Rally Blah Low Compression

Re: Attention All Smartphone Users
« Reply #14 on: December 01, 2011, 03:13:39 PM »


My minutes are unlimted, never have to charge it, cant send SMS but hey my Verizon/beeferoni's  plan is free

No n00d p1cz either.  sux.
"Excellent ideas, poor execution ~ It's what makes a Subaru a Subaru"  -- Kavik

These images are actual illustrations from Toyota's Mr2 Service Manual.  No, really.

Offline Kavik

  • Waaaay to much time on their hands!
  • *****
  • Posts: 8,110
  • Karma: +286/-250

Re: Attention All Smartphone Users
« Reply #15 on: December 01, 2011, 03:28:11 PM »
he probably has a playboy cutout taped on the inside bottom  :-D
-Daryl (Albany)                                                                                   ಠ_ಠ
['02 PSM WRX Sedan]     ['03 Sonic Yellow WRX Wagon]     ['05 WRB WRX Wagon]

Offline spoolordie

  • Waaaay to much time on their hands!
  • *****
  • Posts: 3,133
  • Karma: +204/-129
  • Get Frig'd

Re: Attention All Smartphone Users
« Reply #16 on: December 01, 2011, 03:34:41 PM »
damn I've been compromised   :x
02 WRX Domtuned/Hella Slammed/Turbo Swapped
93 Impreza L 1.8 Liters of Fury Donated to GF
08 DRZ400sm super-motarded
92 Mazda Miata For Sale !!!!!!!!!
http://slideny.com/
The Unysoc Hella Flush Thread President
http://overboostnoooo.mybrute.com

Offline ipodwinner31

  • Member
  • **
  • Posts: 136
  • Karma: +3/-8

Re: Attention All Smartphone Users
« Reply #17 on: December 01, 2011, 03:53:36 PM »
So apparently the HTC incredible doesn't have it....my cousin is a computer security grad and him and his friend checked it out. Glad I have an incredible ;)

Offline hydrochloric

  • ScoobyDooby Specialist
  • ****
  • Posts: 1,412
  • Karma: +50/-189

Re: Attention All Smartphone Users
« Reply #18 on: December 02, 2011, 12:34:23 AM »
Glad I have an LG... uh....  Is crap-box-shit-piece an LG model? :-D  It's an enV Touch, so at best it's a stupid-phone, if not a troglodyte-phone.  Besides, the browser is so shit anyway, I barely use it.

I'm sort of happy I have an iPod Touch now.
-'00 BRP 2.5RS- rustbucket DD with cheap suspension  :D
-'66 VW Type III 1600 Squareback- Survivor, 42k miles, competing in the Great Race 2012
-'83 944- mostly-un-broken track car
-'84 Fiero- V8 swapped, soon to get new fuel injected LT1

Offline ipodwinner31

  • Member
  • **
  • Posts: 136
  • Karma: +3/-8

Re: Attention All Smartphone Users
« Reply #19 on: December 02, 2011, 08:12:36 AM »
Haha I used to have the env touch....not a bad phone, just kinda......outdated...

Offline LarenF3D5

  • ScoobyDooby Specialist
  • ****
  • Posts: 939
  • Karma: +57/-58
  • Smiles per gallon > Miles per gallon

Re: Attention All Smartphone Users
« Reply #20 on: December 02, 2011, 09:30:03 AM »
While I'm aware that this also effects iOS devices to a point is it wrong for me to say I'm glad my apps require an approval process and Apple has a vested interest in keeping my info in their own grubby hands?

I know its not necessarily a better situation, but with a review process of sorts I feel somewhat better about what's on my phone.
2002 WRB WRX Stage II - Tuned by Dom
http://getadomtune.com

Offline skyphix

  • Waaaay to much time on their hands!
  • *****
  • Posts: 4,253
  • Karma: +104/-38
    • http://www.skyphix.com

Eric

Quote me now while I'm feeling good about it.  I've decided a WRX will be the vehicle that replaces the Jeep.  I can't see paying Evo prices or justifying purchasing a halfassed/beat to death example for the same asinine amount of money.  For an affordable, point to point, all-weather capable performance car, a wagon fits the bill.  A swapped wagon, even better.

Offline hydrochloric

  • ScoobyDooby Specialist
  • ****
  • Posts: 1,412
  • Karma: +50/-189

Re: Attention All Smartphone Users
« Reply #22 on: December 02, 2011, 10:28:45 AM »
Haha I used to have the env touch....not a bad phone, just kinda......outdated...

Did you keep yours in your pocket?  If you did, I can't figure out how you didn't hate it.  I figured, being a touchscreen, it would be like my iPod, not activate anything in my pocket.  What I found out is the touchscreen on the enV can be activated by anything, and the side button unlocks it way too easily.  I have butt-dialed, butt-texted, butt-bought-an-"app", and even butt-took-a-picture.

That and it turns itself off all the time.  Verizon store tech said it was a battery issue and "he would send out a new one."  That was the beginning of the summer.  Still no battery.
-'00 BRP 2.5RS- rustbucket DD with cheap suspension  :D
-'66 VW Type III 1600 Squareback- Survivor, 42k miles, competing in the Great Race 2012
-'83 944- mostly-un-broken track car
-'84 Fiero- V8 swapped, soon to get new fuel injected LT1

Offline ed

  • Administrator
  • ScoobyDooby Specialist
  • *****
  • Posts: 1,306
  • Karma: +79/-20
    • UNYSOC.ORG

Re: Attention All Smartphone Users
« Reply #23 on: December 02, 2011, 10:40:20 AM »
honestly though, people overlook them all the time

For example:

Angry Birds - 50 million + downloads
Permissions:
Modify/delete SD card content
Read phone state and identity
Full Internet Access
Coarse (network based) location

Words With Friends - 10 million + downloads
Same as above, but instead of Coarse Location, this one has access to read all your contact data instead


And that's just for a couple, retardedly popular, free games.  You want real scary potential, go look at GO SMS Pro.  I use it for my text messaging program, and all those permissions do have valid functions within the program....but my God, it's scary to think the things they could do with what they have access to

WWF reads contact data because it uses it to find friends that you can play with.

Btw, CM never had and never will have CIQ. Only the stock OTA releases from carriers have been caught with it. Honestly, I never run stock OTA because it's garbage so I can't say I'm too worried. And to think people always wonder wtf I'm messing with my phone so much and telling folks to root their shit. Shrug.
'08 Honda Billet Silver Pilot EX-L - current
'08 Honda Nighthawk Black Pearl Element SC - sold!
'07 VW Black Magic GTI MKV - sold!
'03 Subaru Sonic Yellow WRX - sold!
'92 Honda White Civic LX - sold!

http://www.droidhype.com
http://www.gideontech.com

Offline Malachoz

  • ScoobyDooby Specialist
  • ****
  • Posts: 1,756
  • Karma: +56/-53
  • Tigers blood and winning since '79

Re: Attention All Smartphone Users
« Reply #24 on: December 06, 2011, 09:28:14 AM »
Ed. I love you. /thread

I'll be googling how to root my Evo 3D later.
Dan (Monroe)
-Your Finance Guru-

Ride: 2011 SWP STi Hatch - "Stanley"
Beater: 1995 Ford Taurus - Torrie the Taurus.-Sold
New Beater: (Thanks Nissan!) 2011 Sentra SR
Pages: [1] 2   Go Up