December 6, 2011

Carrier IQ: What You Should Know

What is Carrier IQ?
Carrier IQ is diagnostic software that comes pre-installed on some mobile devices. Mobile network operators use information gathered on your location and call activity to improve network coverage and reduce instances of dropped calls. Recently there has been a large amount of press coverage over the perceived privacy and security violations posed by Carrier IQ software. At Lookout, it is our belief that much of this coverage has been overstated. While there are a number of real privacy issues at play, based on our understanding Carrier IQ is not malware nor has malicious intent. We do believe that companies big and small should always take a transparent approach when it comes to data they are collecting from people.

To find out whether you have Carrier IQ installed on your Android device, download our free Carrier IQ Detector App from the Android Market.

What information is or isn’t collected?
Based on credible reports, it appears that Carrier IQ has the ability to report the following information:

  • The sequence of dialer buttons to determine phone call destination
  • GPS location information, in some situations
  • The URLs visited from your mobile browser

From our current understanding, CarrierIQ does not appear to have the ability to record SMS messages, email content, or the contents of web pages you’ve visited. In addition, Carrier IQ cannot record arbitrary keystrokes (or buttons you press) from your mobile device.

Why is Carrier IQ getting so much attention?
The biggest issue for most users is that they do not know whether they have Carrier IQ on their mobile device. In addition, there is no clear opt-out path available for those users who do have Carrier IQ installed and would prefer not to have it on their device. To find out if you have Carrier IQ on your Android device, download the Carrier IQ Detector app.

Can I remove Carrier IQ from my phone?
Because Carrier IQ software is deeply integrated with the built-in firmware on the mobile device, users would have to get special device privileges (also known as ‘root’ privileges) in order to remove it. Side effects of this process have the potential to put users at further risk of malware infection, while making devices ineligible to receive firmware updates in the future. If you are sure you know what you are doing and would like to remove Carrier IQ software from your phone, there are a number of guides available online.

How do I know if I have Carrier IQ on my phone?
Lookout has recently released Carrier IQ Detector, a free Android application that can quickly determine whether or not you have Carrier IQ software on your mobile device. Download it Now.

18 comments
  1. ctkatz says:

    carrieriq’s problem was they were never upfront about the program’s existence or what it did. I can bet that a lot of people would not have reacted the way they did if this program were known and opt-in

  2. christopher says:

    My carrier is metropcs, and my phone will be reset to manufactures defaulted settings when i upgrade on their site. My question is: Am i able to reinstall Lookout premium back on this phone since i had already purchased it?

  3. Bradley Stevens says:

    Yes I believe that if everyone would give the opt in option they would see a much better
    Result then what they are getting.

  4. G says:

    Just another way for the government to be all up in your life!!

  5. [...] Lookout Mobile Security Blog AKPC_IDS += "2905,";Print [...]

  6. Amy says:

    @Christopher, thanks for your message. Absolutely, you will just want to download Lookout to your new device and use the same email and password you used originally to sign up for your account. You should then see Lookout Premium enabled on your device. If you have any other questions, please let us know: support@mylookout[dot]com. Thank you!

  7. Jerome says:

    @G: Since the software was created by a private company (look up Carrier IQ one the web–their site is http://www.carrieriq.com), I don’t understand your comment. Surely you know that “government” is not the only entity that might be interested in aspects of your life?!

  8. mya says:

    I don’t like this

  9. Michael Marlin says:

    I presently think your oppinion of this app. is good.

  10. stephen freeman says:

    Lookout is the best sacurity that I had ever had on my phone thanks lookout

  11. hilary says:

    I’m a bit confused. If one downloads carrieriq to determine if it’s installed, but, as you say uninstalling it can lead to more vulnarabilities and threats (while it’s presence hasn’t really been determined to be harmful), is this not a situation of ‘ignorance is bliss?’
    Best wishes for a happy, healthy and safe new year.

  12. Dustin says:

    What business does Carrier IQ have with decrypting my personal information when I’m in secure locations, including passwords and credit card information? I can understand what CIQ is trying to do collecting the other data, but decrypting previously encrypted information seems malicious and dishonest.

  13. Quisiera tener una buena seguridad

  14. lue says:

    Its ok but u have to pay for the full thing. I think that it sud be free for the full thing

  15. max says:

    Thanks for the information but i won’t worry about the small stuff since i’m not doing nothing illegal. Have a happy newyear .

  16. Tootsie says:

    Omg!!! I don’t like this!!!

  17. phil says:

    The carriers need to be taught a LESSON!

  18. jametra Dawson says:

    Its ok I like it so far. Yes I hate that we can’t. Get all of it but I’ll thankful that I can track my phone if I lose it. To whom ever this may concern thank u for the ones u let us try out 4 free.

Leave a comment