Secret key-logging software found on millions of phones

woofy

The Master of Disaster
Staff member
Administrator
Millions of Android, Nokia and BlackBerry phones are secretly tracking their users, according to an Android developer.


magnifying_glass.jpg


Trevor Eckhart says he's uncovered a piece of spyware that monitors the phone's location even when location services are disabled, and which logs every keystroke. It ignores the 'Force stop' button and ins nearly impossible to remove, he says.


The software - which Eckhart describes as a rootkit, because of the way it's so hidden - comes from Carrier IQ, which initially threatened legal action against Eckhart, although it backed down when the Electronic Frontier Foundation intervened.


Eckhart's posted a video on YouTube showing the software on his own phone, recording keystrokes, search queries, texts and locations.
"The Carrier IQ application is receiving not only HTTP strings directly from browser, but also HTTPs strings," he says.


"HTTPs data is the only thing protecting much of the 'secure' internet. Queries of what you search, HTTPs plain text login strings (yuck, but yes), even exact details of objects on page are shown in the JS/CSS/GIF files above - and can be seen going into the Carrier IQ application."
Carrier IQ says its software is designed only to help carriers improve their network performance.


"While we look at many aspects of a device
 
Well, I for one, absolutely believe Carrier IQ when they say "While we look at many aspects of a device’s performance, we are counting and summarizing performance, not recording keystrokes or providing tracking tools. The metrics and tools we derive are not designed to deliver such information, nor do we have any intention of developing such tools,".....NOT!!! Maybe this guy has actually discovered who the cyber criminals are and how, much of, the information required to commit these crimes is being obtained. Guaranteed the public is too damn gullible to do anything about this. Solution? Return every phone running Android and demand a replacement that is not using Carrier IQ. No carrier would have any need to access any https strings. This simply proves that the internet has zero security whn companies are using software that does what this does. Don't need to worry about hackers now, do we?
 
Back
Top