<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
><channel><title>M32 Security &#187; developers</title> <atom:link href="http://m32consulting.com/tag/developers/feed/" rel="self" type="application/rss+xml" /><link>http://m32consulting.com</link> <description>Network Security Info, News, and Resources</description> <lastBuildDate>Sun, 22 Jan 2012 23:37:02 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <item><title>Mobile Carriers In Very Hot Water Over Carrier IQ &#8220;Rootkit&#8221;</title><link>http://m32consulting.com/2011/12/mobile-carriers-in-very-hot-water-over-carrier-iq-rootkit/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=mobile-carriers-in-very-hot-water-over-carrier-iq-rootkit</link> <comments>http://m32consulting.com/2011/12/mobile-carriers-in-very-hot-water-over-carrier-iq-rootkit/#comments</comments> <pubDate>Thu, 01 Dec 2011 19:04:55 +0000</pubDate> <dc:creator>Kyle</dc:creator> <category><![CDATA[Customer]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[Software]]></category> <category><![CDATA[Your Rights]]></category> <category><![CDATA[Android]]></category> <category><![CDATA[CarrierIQ]]></category> <category><![CDATA[Cell]]></category> <category><![CDATA[developers]]></category> <category><![CDATA[eckhart]]></category> <category><![CDATA[galaxy]]></category> <category><![CDATA[isc]]></category> <category><![CDATA[kit]]></category> <category><![CDATA[Logs]]></category> <category><![CDATA[middleware]]></category> <category><![CDATA[power]]></category> <category><![CDATA[release]]></category> <category><![CDATA[Rootkit]]></category> <category><![CDATA[Samsung]]></category> <category><![CDATA[SMS]]></category> <category><![CDATA[Sprint]]></category> <category><![CDATA[Trevor Eckhart]]></category> <category><![CDATA[tw]]></category> <category><![CDATA[violation of privacy]]></category> <category><![CDATA[XDA Developers]]></category><guid
isPermaLink="false">http://m32consulting.com/?p=229</guid> <description><![CDATA[I first took attention to Carrier IQ when it was discovered by custom ROM developers for the phone I personally have; the Sprint Epic4G made by Samsung. The device is part of the massively popular Galaxy S line of Android-powered devices that virtually every major cellular carrier in the world sells. Around June, it was [...]]]></description> <content:encoded><![CDATA[<div
class="wp-caption alignright" style="width: 213px"><a
href="http://www.crunchbase.com/company/carrier-iq" target="_blank"><img
class="zemanta-img-inserted zemanta-img-configured" title="Image representing Carrier IQ as depicted in C..." src="http://www.crunchbase.com/assets/images/resized/0003/4918/34918v1-max-450x450.png" alt="Image representing Carrier IQ as depicted in C..." width="203" height="63" /></a><p
class="wp-caption-text">Image via CrunchBase</p></div><p>I first took attention to <a
class="zem_slink" title="Carrier IQ" href="http://www.crunchbase.com/company/carrier-iq" rel="crunchbase" target="_blank">Carrier IQ</a> when it was discovered by custom ROM developers for the phone I personally have; the Sprint Epic4G made by Samsung. The device is part of the massively popular Galaxy S line of Android-powered devices that virtually every major cellular carrier in the world sells. Around June, it was discovered that this software records virtually everything a user does with their phone from each screen-tap to every site they visit to recording audio and even the physical orientation of the device itself.</p><p>A thread (which I now cannot find on <a
class="zem_slink" title="XDA Developers" href="http://xda-developers.com/" rel="homepage" target="_blank">XDA-Developers</a>) outlined this &#8220;middleware&#8221; and it was surmised that individual Carriers like Sprint used it solely for coverage and troubleshooting issues. An effort was undertaken to remove this software from the Android Linux kernel as it was discovered to hinder the device&#8217;s performance. Developers notably had a very difficult time removing Carrier IQ, but managed to eventually remove it for their custom Android ROMs.</p><p>Fast forward to Fall of 2011 where a developer named Trevor Eckhart decided to look into Carrier IQ a bit deeper and found that Carrier IQ was essentially a rootkit and actually recorded almost all actions performed with a device it was installed on and phoned home with that information. He has released a video showing proof of Carrier IQ recording his location with location turned off, un-encrypted HTTPS streams, all SMS messages sent/received, and even EVERY touch of the device screen he makes.</p><p><a
href="http://www.youtube.com/watch?v=T17XQI_AYNo">Carrier IQ Part #2</a></p><p>Essentially what everything boils down to is that carriers can spy on literally everything you do with your phone. This is obviously a blatant violation of privacy rights and repercussions are sure to come. Developing&#8230;</p><p>&nbsp;</p><p>&nbsp;</p><h6 class="zemanta-related-title" style="font-size: 1em;">Related articles</h6><ul
class="zemanta-article-ul"><li
class="zemanta-article-ul-li"><a
href="http://www.pcworld.com/article/245229/carrier_iq_rootkit_logs_everything_on_millions_of_phones.html" target="_blank">Carrier IQ Rootkit Reportedly Logs Everything On Millions Of Phones</a> (pcworld.com)</li><li
class="zemanta-article-ul-li"><a
href="http://gizmodo.com/5864123/you-can-test-your-android-for-carrier-iq-sort-of" target="_blank">You Can Test Your Android For Carrier IQ (Sort Of) [Carrier Iq]</a> (gizmodo.com)</li><li
class="zemanta-article-ul-li"><a
href="http://www.businessinsider.com/carrier-iq-2011-12" target="_blank">People Are Freaking Out About Carrier IQ, The Hidden Smartphone Program That Tracks Everything You Do</a> (businessinsider.com)</li><li
class="zemanta-article-ul-li"><a
href="http://techcrunch.com/2011/12/01/carrier-iq-how-to-find-it-and-how-to-deal-with-it/" target="_blank">Carrier IQ: How To Find It, And How To Deal With It &#8211; TechCrunch</a> (techcrunch.com)</li><li
class="zemanta-article-ul-li"><a
href="http://www.businessinsider.com/blackberry-carrier-iq-2011-12" target="_blank">Silicon Alley Insider: RIM: We Do Not Authorize Carrier IQ On BlackBerry Phones (RIMM)</a> (businessinsider.com)</li><li
class="zemanta-article-ul-li"><a
href="http://gigaom.com/2011/12/01/verizon-no-carrieriq-no-way/" target="_blank">Verizon: No CarrierIQ, No way</a> (gigaom.com)</li><li
class="zemanta-article-ul-li"><a
href="http://www.zdnet.com/blog/hardware/so-theres-a-rootkit-hidden-in-millions-of-cellphones/16708" target="_blank">So, there&#8217;s a rootkit hidden in millions of cellphones</a> (zdnet.com)</li><li
class="zemanta-article-ul-li"><a
href="http://www.textually.org/textually/archives/2011/12/029871.htm" target="_blank">Phone &#8216;Rootkit&#8217; Maker Carrier IQ May Have Violated Wiretap Law In Millions Of Cases</a> (textually.org)</li></ul><div
class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><img
class="zemanta-pixie-img" style="border: none; float: right;" src="http://img.zemanta.com/pixy.gif?x-id=d3d557d6-4c31-40d8-900f-c3eaee90d41f" alt="" /></div>Tags: <a
href="http://m32consulting.com/tag/android/" title="Android" rel="tag">Android</a>, <a
href="http://m32consulting.com/tag/carrieriq/" title="CarrierIQ" rel="tag">CarrierIQ</a>, <a
href="http://m32consulting.com/tag/cell/" title="Cell" rel="tag">Cell</a>, <a
href="http://m32consulting.com/tag/developers/" title="developers" rel="tag">developers</a>, <a
href="http://m32consulting.com/tag/eckhart/" title="eckhart" rel="tag">eckhart</a>, <a
href="http://m32consulting.com/tag/galaxy/" title="galaxy" rel="tag">galaxy</a>, <a
href="http://m32consulting.com/tag/isc/" title="isc" rel="tag">isc</a>, <a
href="http://m32consulting.com/tag/kit/" title="kit" rel="tag">kit</a>, <a
href="http://m32consulting.com/tag/logs/" title="Logs" rel="tag">Logs</a>, <a
href="http://m32consulting.com/tag/middleware/" title="middleware" rel="tag">middleware</a>, <a
href="http://m32consulting.com/tag/power/" title="power" rel="tag">power</a>, <a
href="http://m32consulting.com/tag/release/" title="release" rel="tag">release</a>, <a
href="http://m32consulting.com/tag/rootkit/" title="Rootkit" rel="tag">Rootkit</a>, <a
href="http://m32consulting.com/tag/samsung/" title="Samsung" rel="tag">Samsung</a>, <a
href="http://m32consulting.com/tag/sms/" title="SMS" rel="tag">SMS</a>, <a
href="http://m32consulting.com/tag/sprint/" title="Sprint" rel="tag">Sprint</a>, <a
href="http://m32consulting.com/tag/trevor-eckhart/" title="Trevor Eckhart" rel="tag">Trevor Eckhart</a>, <a
href="http://m32consulting.com/tag/tw/" title="tw" rel="tag">tw</a>, <a
href="http://m32consulting.com/tag/violation-of-privacy/" title="violation of privacy" rel="tag">violation of privacy</a>, <a
href="http://m32consulting.com/tag/xda-developers/" title="XDA Developers" rel="tag">XDA Developers</a><br
/> ]]></content:encoded> <wfw:commentRss>http://m32consulting.com/2011/12/mobile-carriers-in-very-hot-water-over-carrier-iq-rootkit/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>When security software becomes the malware itself</title><link>http://m32consulting.com/2009/05/when-security-software-becomes-the-malware-itself/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=when-security-software-becomes-the-malware-itself</link> <comments>http://m32consulting.com/2009/05/when-security-software-becomes-the-malware-itself/#comments</comments> <pubDate>Sat, 02 May 2009 08:19:20 +0000</pubDate> <dc:creator>Kyle</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Software]]></category> <category><![CDATA[blocking software]]></category> <category><![CDATA[bug reports]]></category> <category><![CDATA[developers]]></category> <category><![CDATA[faithful users]]></category> <category><![CDATA[friedrich nietzsche]]></category> <category><![CDATA[malware]]></category> <category><![CDATA[mozilla]]></category> <category><![CDATA[noscript]]></category> <category><![CDATA[outrage]]></category> <category><![CDATA[security software]]></category> <category><![CDATA[self interest]]></category> <category><![CDATA[viruses]]></category><guid
isPermaLink="false">http://m32consulting.com/?p=17</guid> <description><![CDATA[&#8220;Be careful when you fight the monsters, lest you become one.&#8221; -Friedrich Nietzsche The developers of popular Mozilla extension AdBlock Plus had been receiving bug reports of &#8220;issues&#8221; with another popular extension, NoScript, after an update was issued by the developer of the script-blocking software. The AdBlock Plus developers decided to take a look into [...]]]></description> <content:encoded><![CDATA[<blockquote><p>&#8220;Be careful when  you fight the monsters, lest you become one.&#8221; -<strong>Friedrich Nietzsche</strong></p></blockquote><p>The developers of popular Mozilla extension AdBlock Plus had been receiving bug reports of &#8220;issues&#8221; with another popular extension, NoScript, after an update was issued by the developer of the script-blocking software. The AdBlock Plus developers decided to take a look into what was wrong and found something extremely disturbing. The 1.9.2 update of NoScript had incorporated an obfuscated piece of code that actually made changes to AdBlock Plus to allow for ads on the NoScipt and related sites to be shown. In otherwords, it does what a viruses and other malware does to antivirus software only in reverse; instead of blocking access to update sites, it forced AdBlock Plus to allow ads to be shown for the developer&#8217;s site explicitly. This most likely would have flown under the radar had it not completely broken Adblock Plus and get caught doing unethical things to other software for self-interest. The issue snowballed when the issue made it to Reddit and caused an outrage amongst faithful users of both extensions. To make things worse, the developer only slightly backtracked; allowing the user to allow or disallow the code modification upon installation of NoScript. The developer eventually removed the code completely in version 1.9.2.6, but not without severely impacting user opinion of the software and spurring discussion of a policy change regarding Mozilla Extensions.</p><p>More after the jump.</p><p><a
href="http://adblockplus.org/blog/attention-noscript-users" target="_blank" class="broken_link">http://adblockplus.org/blog/attention-noscript-users</a></p>Tags: <a
href="http://m32consulting.com/tag/blocking-software/" title="blocking software" rel="tag">blocking software</a>, <a
href="http://m32consulting.com/tag/bug-reports/" title="bug reports" rel="tag">bug reports</a>, <a
href="http://m32consulting.com/tag/developers/" title="developers" rel="tag">developers</a>, <a
href="http://m32consulting.com/tag/faithful-users/" title="faithful users" rel="tag">faithful users</a>, <a
href="http://m32consulting.com/tag/friedrich-nietzsche/" title="friedrich nietzsche" rel="tag">friedrich nietzsche</a>, <a
href="http://m32consulting.com/tag/malware/" title="malware" rel="tag">malware</a>, <a
href="http://m32consulting.com/tag/mozilla/" title="mozilla" rel="tag">mozilla</a>, <a
href="http://m32consulting.com/tag/noscript/" title="noscript" rel="tag">noscript</a>, <a
href="http://m32consulting.com/tag/outrage/" title="outrage" rel="tag">outrage</a>, <a
href="http://m32consulting.com/tag/security/" title="Security" rel="tag">Security</a>, <a
href="http://m32consulting.com/tag/security-software/" title="security software" rel="tag">security software</a>, <a
href="http://m32consulting.com/tag/self-interest/" title="self interest" rel="tag">self interest</a>, <a
href="http://m32consulting.com/tag/viruses/" title="viruses" rel="tag">viruses</a><br
/> ]]></content:encoded> <wfw:commentRss>http://m32consulting.com/2009/05/when-security-software-becomes-the-malware-itself/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: enhanced
Database Caching 7/22 queries in 0.047 seconds using disk: basic
Object Caching 1488/1533 objects using disk: basic

Served from: m32consulting.com @ 2012-02-11 15:29:12 -->
