Feeds

Software maker sorry for trying to silence security researcher

Withdraws legal threats over mobile 'rootkit' claims

Boost IT visibility and business value

A Silicon Valley software maker has withdrawn legal threats against an Android developer who claimed the company's diagnostic application amounted to a rootkit that posed a privacy threat to millions of handset owners.

In a statement issued on Wednesday, Mountain View, California-based Carrier IQ apologized to Trevor Eckhart for threatening to sue him for publishing training manuals he said supported his rootkit characterization. The about face came a few days after the Connecticut-based Android developer received legal support from the Electronic Frontier Foundation, which asserted his postings were protected by the US Constitution's First Amendment.

"Our action was misguided and we are deeply sorry for any concern or trouble that our letter may have caused Mr. Eckhart," the statement read. "We sincerely appreciate and respect EFF's work on his behalf, and share their commitment to protecting free speech in a rapidly changing technological world."

Eckhart's posting claimed that Carrier IQ software was able to log detailed information on millions of phones powered by Google's Android, Research in Motion's Blackberry, and Nokia operating systems. A user's GPS coordinates, key taps, and websites visited were just some of the details phone makers and carriers used the software to track, he claimed.

Eckhart also objected to the lack of disclosure given to handset owners that their devices contained the software. In some cases, he said, Carrier IQ versions were modified so phones showed no signs the software was installed and running. That led to claims Carrier IQ was no different than rootkits installed to secretly track and control devices.

Carrier IQ officials responded that the software didn't log keystrokes, track users' whereabouts or report on the content of emails or text messages at all. Rather, they said, the software helped network providers to diagnose a range of problems, including identifying causes of premature battery drainage, dropped calls, and other system problems.

In an email sent to The Register shortly after Carrier IQ dropped its claims, Eckhart held his ground.

"I stand by my statements still and hope that Carrier IQ will engage anyone who has questions with direct answers to facts posted," he wrote. "The community needs to know exactly what is recorded, who has access to it, and why we cant remove – especially from devices not under carriers contract."

He made no apologies.

"I saw something wrong, clearly logging data without user consent," he wrote. "Anything logging sensitive data should not be hidden and have clear opt-in guides. I was lucky to have the support of the EFF though who I cannot thank enough for this." ®

Follow @dangoodin001.

Gartner critical capabilities for enterprise endpoint backup

More from The Register

next story
Microsoft: We plan to CLEAN UP this here Windows Store town
Paid-for apps that provide free downloads? Really
Snowden on NSA's MonsterMind TERROR: It may trigger cyberwar
Plus: Syria's internet going down? That was a US cock-up
Who needs hackers? 'Password1' opens a third of all biz doors
GPU-powered pen test yields more bad news about defences and passwords
e-Borders fiasco: Brits stung for £224m after US IT giant sues UK govt
Defeat to Raytheon branded 'catastrophic result'
Hear ye, young cyber warriors of the realm: GCHQ wants you
Get involved, get a job and then never discuss work ever again
Chinese hackers spied on investigators of Flight MH370 - report
Classified data on flight's disappearance pinched
Microsoft cries UNINSTALL in the wake of Blue Screens of Death™
Cache crash causes contained choloric calamity
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
7 Elements of Radically Simple OS Migration
Avoid the typical headaches of OS migration during your next project by learning about 7 elements of radically simple OS migration.
BYOD's dark side: Data protection
An endpoint data protection solution that adds value to the user and the organization so it can protect itself from data loss as well as leverage corporate data.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?