5 ms·
Remember when people were up in arms about how much location data iPhones stored locally? This is 1000 times worse.
by mcritz 15y ago
Remember when people were up in arms about how much location data iPhones stored locally?
This is 1000 times worse.
- kayzee 15y agoI agree with this (maybe not 1000x worse, but still). Anything Apple does wrong is blown out of proportion. Yes the Apple collected data wasn't encrypted, but now it is. What if this data is compromised at this CIQ company? I hope the data is traceable to an IMEI number ONLY which would make it okay, but still! Why do they need to receive text messages coming in to the phone???
- interlagos 15y agoThe location data concern was that if anyone got possession of your phone or a copy of your backup, they could discern your entire location history. With this finding, if someone got possession of your phone, they could apparently discern...nothing. Instead a subset of data is sent to a company contracted by the carriers (or at least one - Sprint) for the purposes of network monitoring/quality monitoring. Of course the carriers already know your location history through time (just as they know every SMS you sent, picture you sent, data you transmitted, voice call you made, etc), whether you're on a smartphone or dumbphone, and everyone knows and is aware of this. Is this app sending too much data? I guess we'll find out. Is it "1000 times worse" than a forever location log easily exploitable? Not really. EDIT (while sitting at -4 while the hysterics have their fit of vapours): Moderation in this story has demonstrated to me once and for all that HN is largely populated by ignorant bottom-feeders now. It is a sad state of affairs, and this site desperately needs a turn off moderation from dipshits option for users to toggle.
- arunabha 15y agoIf someone got your phone, they could get all the passwords you typed in. Its certainly not 'nothing' that they could discern.
- interlagos 15y ago??? Really, how so. How are they going to get all of the passwords you typed in? Can you point out where anyone has noted any log on the device of this data? This whole story is that they have system event hooks. That's it. Maybe a real security researcher will find something deeper, but as is it's a nothing story of limited interest. When people like you carry it further than reality you just add ignorance to the conversation.
- hackoder 15y agoI think it is certainly a lot worse. All user data (since it is a keylogger?) being logged and sent to a third party without user knowledge or consent, how is that not worse than just logging user information on the device? To get access to your location data on the iPhone, someone would have to steal your phone or get into your itunes account. This is happening in the background.
- interlagos 15y ago>All user data (since it is a keylogger?) being logged and sent to a third party without user knowledge or consent Where does anyone say that it is being sent to a third party? This rather noob-ish developer noted that they have a keyboard hook, but in no way does that mean that they send all of your keystrokes to a third party. Honestly I think I expect too much from HN. The level of discourse on here is absolutely no better than any typical blowhard site.
- hackoder 15y agoI dont see how meta comments on HN help the discussion? Directly from the article: > “Our technology is not real time,” he said at the time. "It's not constantly reporting back. It's gathering information up and is usually transmitted in small doses.” The issue is, we don't know what this software is gathering and sending. It is not being done with consent. But you're right, this needs to be looked into before getting the pitchforks out. But certainly, having the presence of a keylogger is bad enough in itself.
- interlagos 15y agoI'm sure people consented through some random paragraph in a two hundred page long EULA, usually under the guise of quality monitoring. The meta is pertinent. I expect the sort of knee-jerk reaction among non-software developers. I don't among a more educated in the realm crowd. There is little chance this company is recording, much less transmitting, everything you type, every message you receive, etc. I would hazard a guess that they do, however, record basic usage patterns to let the carrier know how people are using their devices ("6975 characters average per day, send 256 messages while receiving 12. Spends an average 37 seconds in the dialer.").
- recoiledsnake 15y agoWhy does this have to be made into an iPhone vs. Android oneupmanship game? This has been alarmingly on the rise here on HN these days.
- epo 15y agoWell, for one, because the legion of fandroids would be here raving about the "evil Apple empire" if this story were about Apple, as it is about Android these same fandroids are saying that Apple are just as bad, if not worse.
- jbm 15y agoI was going to post a comment mentioning how I heard it was installed on the iPhone but I was wrong it seems. http://lifehacker.com/5863895/carrier-iq-how-the-widespread-rootkit-can-track-everything-on-your-phone-and-how-to-remove-it http://lifehacker.com/5863895/carrier-iq-how-the-widespread-... "Update: Our original article stated that the software also came preinstalled on iPhones and dumphones, which has not been confirmed. That information came from this article at Geeks.com, and we actually believe that to be a typo. Considering it hasn't been mentioned in any other source, and that the iPhone isn't on Eckhart's list of affected devices, we're removing it until other sources say otherwise. Thanks to everyone who pointed this out."
- nicwest 15y agoI have a horribly naive and defiantly uninformed question: this was detected on an android device which is a fairly open platform when compared to the iPhone/Windows phones in terms of software transparency, correct? Is there any way to know for certain that Apple/MS aren't doing this exact same/similar sort of thing?
- masklinn 15y ago> Is there any way to know for certain that Apple/MS aren't doing this exact same/similar sort of thing? You can't really ever know things "for certain", but considering the number of jailbroken iOS devices in researcher hands it's likely this would have been discovered.
- Tobu 15y agoMicrosoft has in fact done the same sort of thing in Windows Update, though it denied it. Certainly nothing as brazen as a keylogger, but in 2003 it was caught phoning home a list of all installed software, and hardware identifiers, in an SSL connection.
- zyb09 15y agoYes this is much worse and should get 10x the attention. The reason comparatively minor iPhone scandal gets so big is because everything Apple related gets now over-hyped in the media. You could say Jobs has marketed the Apple brand very well.
- zyb09 15y agoYes this is much worse and should get 10x the attention. Reason for me to be suspicious of every Android phone I'll get (I assume there are ways to remove it and that it's not shipped on non-contract Nexus). The reason a comparatively minor iPhone scandal gets so big is because everything Apple related gets now over-hyped in the media. You could say Jobs has marketed the Apple brand very well.