4 ms·
TL;DR - On a Sprint HTC Android phone, an app is running without the user's knowledge, which cannot be disabled, which monitors nearly everything you do, down t
by billybob 15y ago
TL;DR - On a Sprint HTC Android phone, an app is running without the user's knowledge, which cannot be disabled, which monitors nearly everything you do, down to keypresses, and reports back to the third-party company CarrierIQ, which presumably shares it with the carrier for QoS. Alarmingly, it includes even HTTPS passwords, even when you're connecting over WiFi.
- jellicle 15y agoNote that under U.S. law, any information you voluntarily relinquish to an entity that is not your ISP has basically zero protection. None, nada. Any law enforcement agency can get every bit of data stored about you by CarrierIQ without ever notifying you, and you don't have a 4th Amendment privacy right in the data.
- cgag 15y agoWhat protection do we get with information given to an ISP?
- jellicle 15y agoThis: http://en.wikipedia.org/wiki/Electronic_Communications_Privacy_Act http://en.wikipedia.org/wiki/Electronic_Communications_Priva... which is low, but better than nothing.
- billybob 15y agoIs it considered voluntary if the app is running without your knowledge and can't be turned off? To me, that's about as "voluntary" as having your house bugged.
- ajross 15y agoThe MitM attack inserted into the HTTPS implementation is the most depressing part. I'm just stunned that serious people would have ever agreed to this. Now how long until an on-device attack against CiQ compromises real data?
- MichaelGG 15y agoI think you mean it includes HTTPS URLs. At least from the video, there doesn't seem to be any information about logging HTTP authentication or form submitted data. This is also a reason why you shouldn't put sensitive information in the querystring even if using HTTPS - too many systems might accidentally log or show that in history.
- 3pt14159 15y agoWell put two and two together. They record key strokes and HTTPS URLS. If I go to gmail.com and type in z a c h a y s a n [CLICK ONTO OTHER FORM FIELD] m y p a s s w o r d Then they have access to my data. Period. This is why two step authentication is so important.
- Cyranix 15y agoSomehow I don't think that doing a secondary authentication over SMS would help much in the scenario you're outlining.
- 3pt14159 15y agoIt would, because they wouldn't just be able to passively log in, they would have to enter the password, reroute the sms (so that I didn't see it) and then log in to the email system (which is recorded on "this account was last accessed at").