Carrier IQ, the privacy of millions of users has been violated

In recent weeks we have learned of a dialer able to track our movements, spy on our communications, read our SMS … the privacy of millions of users has been violated!  A disturbing application, multi-platform, which had not been reported previously.
The news is troubling because it puts into serious consideration the privacy rights of the citizen and the need to inform himself of any tracking operations.
The manufacturer that produced the application is the Carrier IQ and its software is capable of monitoring the use of the communication device without the user can notice it.

Trevor Eckhart has posted a video on YouTube to demonstrate how software from Carrier IQ recorded in real time, every action made on the handset which he had reset to factory settings prior to the test. With a packet sniffer while he has demonstrated that his device was in airplane mode each numeric tap and how every text message is logged received by the software.

It would seem that is the software used to operate able silently for which reason he wassingled out by the developer as a rootkit software that enables continued to privileged access to computers to whilea ctively hiding from ITS presence administrators by subverting standard operating system functionality or other applications.

Having found the application, Carrier IQ is running for cover the event citing unconvincing and stupid reasons, declaring that the distributed application is being used exclusively for remote maintenance. There is no real spy intent nor the company maintains and analyzes the information gathered.

Here you are the statement made ​​by Carrier IQ:

We measure and summarize performance of the device to assist Operators in delivering better service.
While a few individuals have identified that there is a great deal of information available to the Carrier IQ software inside the handset, our software does not record, store or transmit the contents of SMS messages, email, photographs, audio or video. For example, we understand whether an SMS was sent accurately, but do not record or transmit the content of the SMS. We know which applications are draining your battery, but do not capture the screen.

Too late I would say! The credibility of the company is to a minimum.

But let’s do, from a neutral point of view, some simple reflection:

  • Is it possible that a firm is able to deploy an application so controversial in a silent mode?
  • News these days is the inability to remove the same from the users because they do not have the necessary rights, rights that in some way evidently those of Carrier IQ were able to obtain. How it got them?
  • How did the Carrier IQ to develop a multi-platform application circumventing the guest operating systems and hardware manufacturers ((AT&T, Sprint Nextel, T-Mobile USA, HTC, Apple, Samsung, and Motorola Mobility) ) of the devices on which you installed?

“Too many doubts and questions rightful us through your head. The shadow of big brother who once again tried to control, spying on citizens going well beyond their means.” This is the thought of those who support the conspiracy theory, the super partis power able to agree to hardware manufacturers and software and to distribute an application silently so dangerous.

Speaking at a Google-hosted conference on internet freedom in the Hague, Google CEO, Mr Eric Schmidt has condemned Carrier IQ saying: ” Google’s smartphone operating system, which runs on the majority of smartphones sold today, is an “open” platform, there was nothing his firm could do to restrict Carrier IQ’s software.” “We certainly don’t work with them,” said Mr Schmidt, describing the software as a “keylogger”.

Do you believe him?  As if that was not enough the Privacy issue continues today with a new regarding the FBI position on this case.  Apparently the FBI was aware of what the Carrier IQ technology is able to do, and the Bureau is not willing to reveal anything regarding Carrier IQ. The FBI denies the release of information about their use of Carrier IQ, consider also the position of Government watchdog site MuckRock believes Carrier IQ data is being used by the FBI in an investigation.

 

MuckRock sent an Freedom of Information Act request to the FBI, asking for “manuals, documents or other written guidance used to access or analyze data gathered by programs developed or deployed by Carrier IQ.” That FOIA request was met with what MuckRock called a “telling denial.”

Let me conclude with a personal account:
What happened is very serious. I think it useless to discuss freedom of expression when I read about this news.
Compounding my perception of the incident are considerations of a technical nature, having worked in the field of telephony and having a particular experience in the mobile devices. I hope that there are no involvement of governments and of the manufacturers themselves.

Pierluigi Paganini

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

Meta stopped covert operations from Iran, China, and Romania spreading propaganda

Meta stopped three covert operations from Iran, China, and Romania using fake accounts to spread…

19 hours ago

US Treasury sanctioned the firm Funnull Technology as major cyber scam facilitator

The U.S. sanctioned Funnull Technology and Liu Lizhi for aiding romance scams that caused major…

1 day ago

ConnectWise suffered a cyberattack carried out by a sophisticated nation state actor<gwmw style="display:none;"></gwmw><gwmw style="display:none;"></gwmw>

ConnectWise detected suspicious activity linked to a nation-state actor, impacting a small number of its…

1 day ago

Victoria’s Secret ‘s website offline following a cyberattack

Victoria’s Secret took its website offline after a cyberattack, with experts warning of rising threats…

2 days ago

China-linked APT41 used Google Calendar as C2 to control its TOUGHPROGRESS malware

Google says China-linked group APT41 controlled malware via Google Calendar to target governments through a…

2 days ago

New AyySSHush botnet compromised over 9,000 ASUS routers, adding a persistent SSH backdoor.

GreyNoise researchers warn of a new AyySSHush botnet compromised over 9,000 ASUS routers, adding a…

2 days ago