Full Disclosure mailing list archives

Re: Carrier IQ for your phone


From: coderman <coderman () gmail com>
Date: Sun, 4 Dec 2011 11:20:39 -0800

On Sat, Dec 3, 2011 at 4:14 AM, Alan J. Wylie
<shyyqvfpybfher () wylie me uk> wrote:
...
| Yes, Carrier IQ is a vast digital fishing net that sees geographic
| locations and the contents of text messages and search queries
| swimming inside the phones the software monitors.. But except
| in rare circumstances, that data is dumped out of a phone's internal
| memory almost as quickly as it goes in.


one thing many of these stories seem to miss is that
these limits assume a carrier in control and acting responsibly.

if you're under a MitM attack these "not used" features sitting latent
are now actively acting against your interests.

similar to CALEA capabilities leveraged for clandestine surveillance,
 e.g. the Athens Affair...

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Current thread: