Android, Blackberry, and Nokia phone users should know about this:

billbillw
billbillw Posts: 6,745
edited March 2012 in The Clubhouse
Startling discoveries about a 'rootkit' type software that is running on most Smartphones.

http://gizmodo.com/5863849/your-android-phone-is-secretly-recording-everything-you-do

I'm not some super privacy advocate, but this software goes way beyond what is acceptable to me!
For rig details, see my profile. Nothing here anymore...
Post edited by billbillw on

Comments

  • logo896
    logo896 Posts: 322
    edited December 2011
    Not surprising at all. I mean its similar to how search engines make money as well. You can't do anything without it being tracked now. Id love to go off the grid.
  • F1nut
    F1nut Posts: 50,511
    edited December 2011
    That's bad, real bad!
    Political Correctness'.........defined

    "A doctrine fostered by a delusional, illogical minority and rabidly promoted by an unscrupulous mainstream media, which holds forth the proposition that it is entirely possible to pick up a t-u-r-d by the clean end."


    President of Club Polk

  • billbillw
    billbillw Posts: 6,745
    edited December 2011
    Yeah, search engine data mining, tracking cookies, etc., are one thing, but logging/sending plain text and keystroke monitoring for everything you do? Especially when it is supposed to be https? That's a whole new level of spying IMO.
    For rig details, see my profile. Nothing here anymore...
  • dkg999
    dkg999 Posts: 5,647
    edited December 2011
    So is this really a surprise? Google, FaceBook, LinkedIn, etc. need to fund millions of dollars in technology hardware so that you cheap b$stages can have free memberships and use. So how they gonna do that hoss? One of the answers is to make sure they have opt-in policies for free memberships that can monetize every stink'in piece of data. I'm not so sure the cell-phone companies actually provided the consumer notice and opt-in that would of been expected, however they probably soon will. I'm a big proponent of industry self-regulation, however these companies are shooting themselves and the whole industry in the proverbial foot!
    DKG999
    HT System: LSi9, LSiCx2, LSiFX, LSi7, SVS 20-39 PC+, B&K 507.s2 AVR, B&K Ref 125.2, Tripplite LCR-2400, Cambridge 650BD, Signal Cable PC/SC, BJC IC, Samsung 55" LED

    Music System: Magnepan 1.6QR, SVS SB12+, ARC pre, Parasound HCA1500 vertically bi-amped, Jolida CDP, Pro-Ject RM5.1SE TT, Pro-Ject TubeBox SE phono pre, SBT, PS Audio DLIII DAC
  • Drenis
    Drenis Posts: 2,871
    edited December 2011
    I'm a Blackberry user myself... not good news.
  • heiney9
    heiney9 Posts: 25,165
    edited December 2011
    dkg999 wrote: »
    So is this really a surprise? Google, FaceBook, LinkedIn, etc. need to fund millions of dollars in technology hardware so that you cheap b$stages can have free memberships and use. So how they gonna do that hoss? One of the answers is to make sure they have opt-in policies for free memberships that can monetize every stink'in piece of data. I'm not so sure the cell-phone companies actually provided the consumer notice and opt-in that would of been expected, however they probably soon will. I'm a big proponent of industry self-regulation, however these companies are shooting themselves and the whole industry in the proverbial foot!

    Doug, so far Gizmodo goes way beyond just tracking and compiling for trends and specific marketing. It's scary that someone can eavesdrop on anything you send via your Android OS phone. It's too invasive and they are trying like hell to cover it up.

    H9
    "Appreciation of audio is a completely subjective human experience. Measurements can provide a measure of insight, but are no substitute for human judgment. Why are we looking to reduce a subjective experience to objective criteria anyway? The subtleties of music and audio reproduction are for those who appreciate it. Differentiation by numbers is for those who do not".--Nelson Pass Pass Labs XA25 | EE Avant Pre | EE Mini Max Supreme DAC | MIT Shotgun S1 | Pangea AC14SE MKII | Legend L600 | BlueSound Node 3 - Tubes add soul!
  • tonyb
    tonyb Posts: 32,957
    edited December 2011
    It's called greed Doug. Anything thats of value is for sale to whoever wants it. Now who would want such info ?
    HT SYSTEM-
    Sony 850c 4k
    Pioneer elite vhx 21
    Sony 4k BRP
    SVS SB-2000
    Polk Sig. 20's
    Polk FX500 surrounds

    Cables-
    Acoustic zen Satori speaker cables
    Acoustic zen Matrix 2 IC's
    Wireworld eclipse 7 ic's
    Audio metallurgy ga-o digital cable

    Kitchen

    Sonos zp90
    Grant Fidelity tube dac
    B&k 1420
    lsi 9's
  • billbillw
    billbillw Posts: 6,745
    edited December 2011
    I don't think its greed directly. I honestly don't think they are looking to sell your personal data. I think its careless programming. If they are going to collect that data to help troubleshoot and make the 'user experience' better, they must have some level of encryption on the data stream. It was shown that this data being sent out in plain text. With that knowledge, criminal hackers could get passwords and login IDs for sensitive accounts (bank, email, network, etc) and commit great fraud! Bottom line, CIQ has been caught with their pants down and as news of this continues to spread, the carriers and manufacturers are going to catch hell from the users.
    For rig details, see my profile. Nothing here anymore...
  • nadams
    nadams Posts: 5,877
    edited December 2011
    Anywhere I see ads while I'm browsing... there's always one for Polk Audio. Sometimes every single one is for the Ultrafit headphones :) I'm outraged.
    Ludicrous gibs!
  • exalted512
    exalted512 Posts: 10,735
    edited December 2011
    I don't see the big deal. No where in the video does it show anything getting beyond the USB port of the phone. It might be an issue if you lose your phone I suppose, but I can delete everything on my phone remotely.
    -Cody
    Music is like candy, you have to get rid of the rappers to enjoy it
  • exalted512
    exalted512 Posts: 10,735
    edited December 2011
    I should have worded that better. I don't agree with the program, it should have never made its way to the phone in the first place. But this video makes it seem like everything in your phone is being sent to Carrier IQ, which doesn't appear to be the case.
    -Cody
    Music is like candy, you have to get rid of the rappers to enjoy it
  • billbillw
    billbillw Posts: 6,745
    edited December 2011
    Cody, the stream that is being shown on the screen (via USB connection) is the same stream that is being sent out over WiFi/3G/4G connection. That is why this is such a big deal. And I think you are wrong, everything you do on your phone IS being sent to CIQ. That much is clear.
    For rig details, see my profile. Nothing here anymore...
  • dkg999
    dkg999 Posts: 5,647
    edited December 2011
    I work in the information business. I spend days attempting to figure out where data is sourced from and if it was collected with sufficient consumer notice and is compliant to use for building products with. Any and all the data referenced in this thread is available from multiple sources, especially in South America and Eastern Europe. A 30TB feed of data of which cellphone numbers called which other cell and landline numbers last month, there's an app for that and a price. So this is just the latest discovery, and while the data may have been collected for a genuinely valid purpose, someone will realize they can monetize that data either at the most granular or at an aggregated level.

    Don't like that .................. don't use a cell phone and don't use the internet.
    DKG999
    HT System: LSi9, LSiCx2, LSiFX, LSi7, SVS 20-39 PC+, B&K 507.s2 AVR, B&K Ref 125.2, Tripplite LCR-2400, Cambridge 650BD, Signal Cable PC/SC, BJC IC, Samsung 55" LED

    Music System: Magnepan 1.6QR, SVS SB12+, ARC pre, Parasound HCA1500 vertically bi-amped, Jolida CDP, Pro-Ject RM5.1SE TT, Pro-Ject TubeBox SE phono pre, SBT, PS Audio DLIII DAC
  • exalted512
    exalted512 Posts: 10,735
    edited December 2011
    billbillw wrote: »
    Cody, the stream that is being shown on the screen (via USB connection) is the same stream that is being sent out over WiFi/3G/4G connection. That is why this is such a big deal. And I think you are wrong, everything you do on your phone IS being sent to CIQ. That much is clear.

    Then why did he have to put it in USB debugging mode and sync it the software before anything got sent out?

    I'm not for sure one way or another, but I don't take any websites seriously unless I see video proof otherwise (ie: packet capture). This particular video didn't prove otherwise.

    Maybe someone geekier than me can confirm or deny that.
    -Cody
    Music is like candy, you have to get rid of the rappers to enjoy it
  • billbillw
    billbillw Posts: 6,745
    edited December 2011
    The USB debugging is so that you can see the data stream on the PC screen. It is happening no matter what the phone is doing.
    For rig details, see my profile. Nothing here anymore...
  • exalted512
    exalted512 Posts: 10,735
    edited December 2011
    Or is it?

    USB debugging is used to copy data between your computer and your device and to read log data, which essentially is what this guy is doing. It's also used for development purposes...seeing a trend with what USB debugging is made to do and what the guy on the video is showing?

    Like I said, it doesnt show data going ANYWHERE other than the screen that its attached to. Until I see packets being sent, I doubt this is anything to be TOO alarmed about.
    -Cody
    Music is like candy, you have to get rid of the rappers to enjoy it
  • cfrizz
    cfrizz Posts: 13,415
    edited December 2011
    Well now, I'm really glad I just use my phone as a phone.
    heiney9 wrote: »
    Doug, so far Gizmodo goes way beyond just tracking and compiling for trends and specific marketing. It's scary that someone can eavesdrop on anything you send via your Android OS phone. It's too invasive and they are trying like hell to cover it up.

    H9
    Marantz AV-7705 PrePro, Classé 5 channel 200wpc Amp, Oppo 103 BluRay, Rotel RCD-1072 CDP, Sony XBR-49X800E TV, Polk S60 Main Speakers, Polk ES30 Center Channel, Polk S15 Surround Speakers SVS SB12-NSD x2
  • BeRad
    BeRad Posts: 736
    edited December 2011
    If you go to XDA-developers, they have lots of pople working on new roms for android phones that are stripped of all CIQ garbage. It seems that Rogers in Canada isn't that bad, but apparently AT&T phones are loaded with CIQ processes that run in the background and even slow the phone down a bit.

    I have only recently started using an android phone (Galaxy S2) and I am quite happy so far with how many quality roms and kernels are coming out from the developers on that site. For my phone, they actually made a rom from the stock Rogers phones to put on the AT&T version for the sole purpose of eliminating CIQ.
  • BeRad
    BeRad Posts: 736
    edited December 2011
    exalted512 wrote: »
    Then why did he have to put it in USB debugging mode and sync it the software before anything got sent out?

    He probably had to turn on USB debugging to be able to show what was going on in the background.
  • billbillw
    billbillw Posts: 6,745
    edited December 2011
    Unfortunately 99% of the population doesn't have a clue how to install a custom rom on their phone. Not to mention, for most of the carriers, it voids any warranty. I went an looked at my phone's apps today. I couldn't find anything that had IQ in it, but there was one called data collector. I was able to stop it though.
    For rig details, see my profile. Nothing here anymore...
  • Drenis
    Drenis Posts: 2,871
    edited December 2011
    Canadian retailers do not use or load this product. RIM confirms they also do not so I'm safe. :)
  • herman04
    herman04 Posts: 3
    edited March 2012
    What a great blog post! Thanks for sharing it on your site.
    nokia mobile
  • Kex
    Kex Posts: 5,176
    edited March 2012
    User reported for spamming.
    Alea jacta est!