Lookout releases free Carrier IQ detection app
Sniffs out controversial software on Android smartphones, but doesn't delete it
Computerworld - A mobile security software company last Friday released a tool that detects Carrier IQ, the software embedded in numerous smartphones that has raised questions from users, privacy advocates and even Congress.
Lookout, best known for its Android security software by the same name, launched the free Carrier IQ Detector last week. It can be downloaded from the Android Market.
The tool only detects the presence of Carrier IQ on Android handsets: It does not scrub the software from the smartphone.
Lookout said that Carrier IQ was "deeply integrated with handset firmware [and] users would be required to attain special device privileges in order to remove it," then warned that doing so incorrectly could "put users at further risk of malware infection" and possibly make them unable to receive future phone updates.
The release of Carrier IQ Detector followed comments from Lookout last week that it would not classify the software as malware, and questioned the label "rootkit" for the tracking and network diagnostic program.
Tim Wyatt, a principal engineer with Lookout, refused to call Carrier IQ "malware," arguing that it just didn't fit the definition.
"Absolutely not," said Wyatt when asked if Carrier IQ was malware. "This is something that was pre-loaded by carriers, not downloaded by users," said Wyatt in an interview last week, arguing that because users hadn't been duped into launching a Trojan horse, Carrier IQ technically wasn't malware.
"It wasn't malware hidden inside an app, so it doesn't fit the Trojan pattern," Wyatt said. "All indications are that it is intended to improve user experience. What's at question is what data is sent to the carrier."
He acknowledged that Lookout and its users were worried about the privacy implications.
"We do have concerns about the data, and under what circumstances it's going out," Wyatt said, noting that his opinion was a reflection of the feedback his company had received from users. "We definitely think that users should be told, and have a choice of opting out in circumstances like this telemetry."
Other security researchers have said much the same.
In a blog post Monday, Dan Rosenberg, a consultant at Virtual Security Research, said that his analysis of Carrier IQ had not found any malicious intent.
"I have repeatedly stated that based on my knowledge of the software, claims that keystrokes, SMS bodies, email bodies, and other data of this nature are being collected are erroneous," said Rosenberg, who like Lookout, called for more transparency from Carrier IQ, handset makers and mobile service providers.
Lookout also called the "rootkit" label many have attached to Carrier IQ "a bit of hyperbole," with Wyatt adding that in the company's view, the software was not conducting "a criminal activity."
Some disagree. Both Congress and consumer advocates have asked the Federal Trade Commission, the Department of Justice and the Federal Communications Commission to investigate Carrier IQ and its practices. The Mountain View, Calif.-based Carrier IQ has also been hit with multiple lawsuits seeking class-action status.
And Carrier IQ's own marketing materials seem to undercut its most recent claims that the software is designed only to diagnose problems in smartphones and the mobile service provider networks they run on.
Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at
@gkeizer or subscribe to Gregg's RSS feed
. His e-mail address is gkeizer@computerworld.com.
Carrier IQ
- Lawmaker pushes consumer notification bill in wake of Carrier IQ concerns
- Goodbye 2011 ... What a year!
- Sprint disables Carrier IQ software on its handsets
- Iran tricked U.S. spy drone into landing in country, report says
- FBI never sought Carrier IQ data, director says
- Carrier IQ moves to allay fears of its tracking software
- FBI rejects FOIA request for Carrier IQ info
- Google's Schmidt calls Carrier IQ software a keylogger
- Carrier IQ downplays 2010 patent request
- 8 companies hit with lawsuit over Carrier IQ software
Read more about Mobile and Wireless in Computerworld's Mobile and Wireless Topic Center.


- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Mobile Middleware Strategies
- Learn why a mobile development platform is critical to be able to support today's complex enterprise mobility strategies. Learn what to look for...
- The Evolution of Enterprise Mobile App Development
- Driven by explosive growth in smartphone and tablet sales, enterprise mobility has become an essential part of business. Organizations across industries are developing...
- Native & HTML5 Mobile Apps: Not an either or, but a where and when
- Learn how developers are using HTML5 and native development methods to build mobile apps. Get practical insights on how these tools are being...
- Enabling Remote Employees with High Quality Video
- In this paper, we analyze the delivery of live and on-demand mobile video content. It focuses on specific ways in which organizations can...
- What to Look For in Solutions For Mobile Device Management
- Managing an increasingly mobile workforce has become one of the most challenging - and important - responsibilities for IT departments. This paper examines... All Mobile and Wireless White Papers
- The Office of Tomorrow with BlackBerry
- Curious about the office of the future and how to prepare with BlackBerry solutions? This session discusses the office needs of tomorrow and...
- The Changing Role of Tablets in the Enterprise
- Do you understand all the capabilities and potential of the BlackBerry PlayBook tablet? BlackBerry® PlayBook™ tablet can help enterprises do business differently.
This webcast... - Security Certifications 101 - BlackBerry and all those acronyms what do they mean and why they matter?
- FIPS, Common Criteria, CAPS, AISEP, NFC, NIST, Fraunhofer SIT, CESG, DSD - these are just some of the government and industry certifications which...
- PlayBook Video about two Grade 6 classrooms that are using PlayBook tablets
- RIM recently worked with Park Manor Public School in Elmira, ON to integrate BlackBerry PlayBook tablets in two Grade 6 classrooms. The project...
- McCain Canada deployed BlackBerry PlayBook tablets with a custom application to their salesforce
- McCain Foods Limited (McCain) has deployed BlackBerry® PlayBook™ tablets in order to enhance mobility within their sales force- along with a customized application... All Mobile and Wireless Webcasts
Prepaid service has started to transform from a source of cheap, bottom-of-the-barrel phones into a viable outlet for compelling smartphones. Read more...
