<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>XenoActive.org</title>
	<atom:link href="http://www.xenoactive.org/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.xenoactive.org</link>
	<description>Internet Security And Privacy</description>
	<lastBuildDate>Tue, 31 Jan 2012 18:44:01 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Mobile Device Privacy Act</title>
		<link>http://www.xenoactive.org/2012/01/mobile-device-privacy-act/</link>
		<comments>http://www.xenoactive.org/2012/01/mobile-device-privacy-act/#comments</comments>
		<pubDate>Tue, 31 Jan 2012 18:09:49 +0000</pubDate>
		<dc:creator>stickman</dc:creator>
				<category><![CDATA[Communications]]></category>
		<category><![CDATA[Headline]]></category>
		<category><![CDATA[law]]></category>
		<category><![CDATA[MDPA]]></category>
		<category><![CDATA[mobile]]></category>
		<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://www.xenoactive.org/?p=1091</guid>
		<description><![CDATA[<p>In light of the recent confusion and fingerpointing regarding the extend of CarrierIQ snooping, Representative Ed Markey has released a <a href="http://markey.house.gov/sites/markey.house.gov/files/documents/Mobile%20Device%20Privacy%20Act%20--%20Rep.%20Markey%201-30-12_0.pdf">draft of the Mobile Device Privacy Act</a>. The intent of the proposed legislation is require that cell phone consumers &#8230;</p>]]></description>
			<content:encoded><![CDATA[<p>In light of the recent confusion and fingerpointing regarding the extend of CarrierIQ snooping, Representative Ed Markey has released a <a href="http://markey.house.gov/sites/markey.house.gov/files/documents/Mobile%20Device%20Privacy%20Act%20--%20Rep.%20Markey%201-30-12_0.pdf">draft of the Mobile Device Privacy Act</a>. The intent of the proposed legislation is require that cell phone consumers get notifications and express consent before any monitoring takes place. The draw law requires all cell phone manufacturers, service providers and resellers to disclose the types of information collected, the identity of anyone receiving the information, and how the information will be used.</p>
<p>In the case of CarrierIQ, the software maker denied that it collected any information, and then backtracked saying that it was the service providers that were the actual data recipients. This law would require consumers to receive clear disclosures and give explicit consent before any monitoring takes place. The proposed law would also require notifications and consent if monitoring software is installed after the phone is purchased.</p>
<p>The MDPA also requires that anyone that receives and stores monitoring data must establish and implement policies for protecting the security of the data. The proposed law give the FTC and the FCC power to enforce the law, as well as gives consumers a private right of action. A consumer may sue in state or district court for $1000 per violation plus court costs. Willful violations may result in triple damages. The monitoring agreements must be filed with the FTC and FCC.</p>
<p>In Rep. Markey&#8217;s <a href="http://markey.house.gov/press-release/markey-releases-discussion-draft-mobile-device-privacy-act-wake-carrier-iq-software">press release</a>, he stated &#8220;Consumers have the right to know and to say no to the presence of software on their mobile devices that can collect and transmit their personal and sensitive information.&#8221;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.xenoactive.org/2012/01/mobile-device-privacy-act/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sites Go Dark to Protest SOPA</title>
		<link>http://www.xenoactive.org/2012/01/site-go-dark-to-protest-sopa/</link>
		<comments>http://www.xenoactive.org/2012/01/site-go-dark-to-protest-sopa/#comments</comments>
		<pubDate>Wed, 18 Jan 2012 05:03:20 +0000</pubDate>
		<dc:creator>stickman</dc:creator>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[In Other News]]></category>
		<category><![CDATA[law]]></category>
		<category><![CDATA[PIPA]]></category>
		<category><![CDATA[protest]]></category>
		<category><![CDATA[SOPA]]></category>

		<guid isPermaLink="false">http://www.xenoactive.org/?p=1089</guid>
		<description><![CDATA[<p>Several popular website are going dark to protest the proposed <a href="http://en.wikipedia.org/wiki/en:Stop_Online_Piracy_Act" target="_blank">SOPA</a>/<a href="http://en.wikipedia.org/wiki/en:PROTECT_IP_Act" target="_blank">PIPA</a> legislation. <a href="http://en.wikipedia.org/wiki/Wikipedia:SOPA_initiative/Action" target="_blank">Wikipedia</a> has announced that the English version of the site will be dark today. Other notable sites protesting the legislation include the <a href="https://blog.torproject.org/blog/blackout-against-copyright-overreach-stop-sopa-and-pipa" target="_blank">Tor Project</a>, <a href="http://blog.reddit.com/2012/01/stopped-they-must-be-on-this-all.html" target="_blank">Reddit</a>&#8230;</p>]]></description>
			<content:encoded><![CDATA[<p>Several popular website are going dark to protest the proposed <a href="http://en.wikipedia.org/wiki/en:Stop_Online_Piracy_Act" target="_blank">SOPA</a>/<a href="http://en.wikipedia.org/wiki/en:PROTECT_IP_Act" target="_blank">PIPA</a> legislation. <a href="http://en.wikipedia.org/wiki/Wikipedia:SOPA_initiative/Action" target="_blank">Wikipedia</a> has announced that the English version of the site will be dark today. Other notable sites protesting the legislation include the <a href="https://blog.torproject.org/blog/blackout-against-copyright-overreach-stop-sopa-and-pipa" target="_blank">Tor Project</a>, <a href="http://blog.reddit.com/2012/01/stopped-they-must-be-on-this-all.html" target="_blank">Reddit</a>, <a href="http://imgur.com/blog/2012/01/16/imgur-joins-blackout/" target="_blank">Imgur</a>, and <a href="http://en.blog.wordpress.com/2012/01/18/join-our-censorship-protest/" target="_blank">WordPress.com</a>.</p>
<p>Opponents of the legislation fear the once passed copyright holders will be able to take down legitimate websites without any judicial oversight. For example, Monster Cable could theoretically use the law to take down websites they claim to be <a href="http://www.monstercable.com/counterfeit/dealers_blk.asp" target="_blank">unauthorized resellers</a>. While their list now just lists unauthorized sellers on <a href="http://www.ebay.com/" target="_blank">eBay.com</a> and <a href="http://www.craigslist.com/" target="_blank">Craigslist.com</a>, a <a href="http://web.archive.org/web/20110714113757/http://www.monstercable.com/counterfeit/dealers_blk.asp" target="_blank">previous version</a> of the list included the two domains without exceptions. Department store <a href="http://www.sears.com/shc/s/search_10153_12605?vName=Computers+%26+Electronics&amp;cName=Power+%26+Cables&amp;keyword=monster+cable&amp;viewItems=25&amp;autoRedirect=true&amp;redirectType=CAT_REC_PRED&amp;prop17=monster%20cable" target="_blank">Sears sells Monster Cable products</a> on their site, and the <a href="http://www.sears.com/" target="_blank">sears.com</a> domain is included in the list. Curiously <a href="http://www.buy.com/" target="_blank">buy.com</a> is listed in both the unauthorized seller list and the list of <a href="http://www.monstercable.com/counterfeit/dealers.asp" target="_blank">authorized home theater dealers</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.xenoactive.org/2012/01/site-go-dark-to-protest-sopa/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IT Zanshin</title>
		<link>http://www.xenoactive.org/2012/01/it-zanshin/</link>
		<comments>http://www.xenoactive.org/2012/01/it-zanshin/#comments</comments>
		<pubDate>Tue, 17 Jan 2012 06:01:55 +0000</pubDate>
		<dc:creator>stickman</dc:creator>
				<category><![CDATA[Data Management]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[change management]]></category>
		<category><![CDATA[configuration management]]></category>
		<category><![CDATA[itil]]></category>

		<guid isPermaLink="false">http://www.xenoactive.org/?p=1086</guid>
		<description><![CDATA[<p><em>This article is part one of a three part series on applying the martial arts concept of zanshin to the information technology sector.<br />
</em></p>
<p>In the martial arts world, there is a concept called <a href="http://en.wikipedia.org/wiki/Zanshin" target="_blank">zanshin</a>. It&#8217;s defined as a state &#8230;</p>]]></description>
			<content:encoded><![CDATA[<p><em>This article is part one of a three part series on applying the martial arts concept of zanshin to the information technology sector.<br />
</em></p>
<p>In the martial arts world, there is a concept called <a href="http://en.wikipedia.org/wiki/Zanshin" target="_blank">zanshin</a>. It&#8217;s defined as a state of readiness and alertness to meet an opposing attack. How does this apply to the IT world? While physical attacks are rare in the IT environment, other opposing forces such as economics, resource availability, competition, and hackers do come into play and need to be addressed. An IT organization that is fully aware of its environment and processes is better prepared to meet challenges when they arise. The three major facets of IT zanshin are configuration and change management, service monitoring and metrics, and business continuity and disaster recovery. Each of these by itself is a major work effort to be done correctly, but well worth the investment.</p>
<p>Configuration and change management are the foundation for the other aspects of IT zanshin. Configuration management involves taking inventory, documenting configurations, and identifying relationships. Extending beyond a simple inventory of hardware, software, and processes, the configuration management system must tracks relationships between each of the items. All of this takes time and is often ignored. When new hardware arrives on the dock, everyone&#8217;s first instinct is to unbox and start building systems. An IT organization that utilizes configuration management can reap the benefits of standardization and streamlined deployments.</p>
<p>Implementing change management processes of creates grumbles and mutterings from system administrators and developers who are forced to work with the newly established procedures. They&#8217;ll claim that collecting their approvals will actually slow them down, and they won&#8217;t be able to make those already aggressive release dates. Change management is not implemented to stop an organization from moving forward. It&#8217;s meant to capture changes in the environment, make sure that they are properly vetted, and ensure that the outcomes are expected. A successful change management process will also help communications to staff and customers. <em>Why are we suddenly getting helpdesk calls about application X? Who authorized the shutdown of that server?</em> It&#8217;s all in the change management system. There should be no surprises. After all, key people are involved in the process.</p>
<blockquote><p><strong>Recommendation:</strong> Implementing configuration and change management systems does always high dollar expenses. IT needs vary greatly between organizations. Start by building documentation repositories and implementing an open source tool like <a href="http://www.combodo.com/itop" target="_blank">iTop</a> or <a href="http://www.i-doit.com/en/" target="_blank">i-doit</a>. With simple open source tools, IT organizations can gain exposure to the concepts without the license costs.</p></blockquote>
<p>Data from configuration and change management systems are the building blocks of service monitoring and metrics. It&#8217;s very difficult to properly monitor and measure services without know what all the component pieces are and how they are related. While not very glamorous, the benefits to an IT organization well outweigh the cost and time to create such critical foundation.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.xenoactive.org/2012/01/it-zanshin/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Verified Twitter Accounts?</title>
		<link>http://www.xenoactive.org/2012/01/verified-twitter-accounts/</link>
		<comments>http://www.xenoactive.org/2012/01/verified-twitter-accounts/#comments</comments>
		<pubDate>Wed, 04 Jan 2012 15:47:51 +0000</pubDate>
		<dc:creator>stickman</dc:creator>
				<category><![CDATA[Communications]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[identity]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://www.xenoactive.org/?p=1085</guid>
		<description><![CDATA[<p>Public access to the Twitter <a href="http://support.twitter.com/articles/119135-about-verified-accounts" target="_blank">account verification</a> system has been <a href="http://support.twitter.com/groups/32-something-s-not-working/topics/116-account-settings-problems/articles/122966-why-wasn-t-my-account-verified" target="_blank">closed</a> for quite a while. The verification system was intended to be an easy way to allow followers to distinguish authentic Twitter accounts from parody or fake accounts. A TNW &#8230;</p>]]></description>
			<content:encoded><![CDATA[<p>Public access to the Twitter <a href="http://support.twitter.com/articles/119135-about-verified-accounts" target="_blank">account verification</a> system has been <a href="http://support.twitter.com/groups/32-something-s-not-working/topics/116-account-settings-problems/articles/122966-why-wasn-t-my-account-verified" target="_blank">closed</a> for quite a while. The verification system was intended to be an easy way to allow followers to distinguish authentic Twitter accounts from parody or fake accounts. A TNW article from 2010 mentions that the beta was shutdown <em>to build a system that will be better for users</em>. That phrase no longer appears in the <a href="http://support.twitter.com/articles/119135-about-verified-accounts" target="_blank">About Account Verification</a> web page.</p>
<p>So far no such replacement system has been made public; however, Twitter does appear to still be verifying accounts. The site does state that <em>some trusted sources</em> are still being verified.</p>
<blockquote><p>From Twitter&#8217;s Why Wasn&#8217;t My Account Verified:<br />
In the meantime, we&#8217;re still verifying some trusted sources, such as our advertisers and partners. If you&#8217;re one of our partners or advertisers, please follow up with your account manager for details.</p></blockquote>
<p>Are those verified accounts really trustworthy? Recent news of the <a href="http://www.telegraph.co.uk/technology/twitter/8989848/Fake-Wendi-Deng-account-fools-Twitter.html" target="_blank">faked Wendi_Deng account</a> on Twitter does raise concerns. The account was marked as verified without the account holder or the real Wendi Deng&#8217;s knowledge. The account holder has sent a tweet to Twitter <a href="http://twitter.com/#!/Wendi_Deng/status/154567174248333313" target="_blank">wondering how this happened</a>. The account is no longer flagged as verified, but it does raise a question. How many other spoofed and faked accounts are quietly holding onto a verification badge?</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.xenoactive.org/2012/01/verified-twitter-accounts/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Anonymous Hits Stratfor Website</title>
		<link>http://www.xenoactive.org/2011/12/anonymous-hits-stratfor-website/</link>
		<comments>http://www.xenoactive.org/2011/12/anonymous-hits-stratfor-website/#comments</comments>
		<pubDate>Wed, 28 Dec 2011 18:54:56 +0000</pubDate>
		<dc:creator>stickman</dc:creator>
				<category><![CDATA[In Other News]]></category>
		<category><![CDATA[Anonymous]]></category>

		<guid isPermaLink="false">http://www.xenoactive.org/?p=1083</guid>
		<description><![CDATA[<p>Anonymous has claimed an attack on the <a href="http://www.stratfor.com/" target="_blank">Stratfor Global Intelligence</a> website. As of this time, the website is currently undergoing maintenance. <a href="http://www.identityfinder.com/" target="_blank">Identity Finder</a> released <a href="http://www.identityfinder.com/blog/post/Identity-Finder-Releases-Detailed-Analysis-of-Personal-Information-e28098Anonymouse28099-Attack-on-Stratfor.aspx" target="_blank">an analysis of the information</a> posted online by Anonymous. The analysis reveals that Anonymous was able &#8230;</p>]]></description>
			<content:encoded><![CDATA[<p>Anonymous has claimed an attack on the <a href="http://www.stratfor.com/" target="_blank">Stratfor Global Intelligence</a> website. As of this time, the website is currently undergoing maintenance. <a href="http://www.identityfinder.com/" target="_blank">Identity Finder</a> released <a href="http://www.identityfinder.com/blog/post/Identity-Finder-Releases-Detailed-Analysis-of-Personal-Information-e28098Anonymouse28099-Attack-on-Stratfor.aspx" target="_blank">an analysis of the information</a> posted online by Anonymous. The analysis reveals that Anonymous was able to grab at least 27,537 phone numbers, 86,594 email addresses, and 50,277 credit card numbers. A <a href="http://www.nytimes.com/2011/12/26/technology/hackers-breach-the-web-site-of-stratfor-global-intelligence.html" target="_blank">NY Times article</a> states that some of the pilfered credit card numbers were using to make charitable donations.</p>
<p>According to a <a href="http://pastebin.com/8yrwyNkt" target="_blank">Pastebin post by A GUEST</a>, the attack is not the work of Anonymous.</p>
<blockquote><p>Stratfor has been purposefully misrepresented by these so-called Anons and portrayed in false light as a company which engages in activity similar to HBGary. Sabu and his crew are nothing more than opportunistic attention whores who are possibly agent provocateurs. As a media source, Stratfor&#8217;s work is protected by the freedom of press, a principle which Anonymous values greatly.</p>
<p>This hack is most definitely not the work of Anonymous.</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.xenoactive.org/2011/12/anonymous-hits-stratfor-website/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Feds Looking into CarrierIQ</title>
		<link>http://www.xenoactive.org/2011/12/feds-looking-into-carrieriq/</link>
		<comments>http://www.xenoactive.org/2011/12/feds-looking-into-carrieriq/#comments</comments>
		<pubDate>Wed, 14 Dec 2011 20:29:10 +0000</pubDate>
		<dc:creator>stickman</dc:creator>
				<category><![CDATA[In Other News]]></category>
		<category><![CDATA[mobile]]></category>
		<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://www.xenoactive.org/?p=1079</guid>
		<description><![CDATA[<p>The Washington Post is reporting that executives from CarrierIQ are <a href="http://www.washingtonpost.com/business/economy/feds-probing-carrier-iq/2011/12/14/gIQA9nCEuO_story.html" target="_blank">meeting</a> with the Federal Trade Commission. Although the FBI has <a href="http://www.muckrock.com/news/archives/2011/dec/12/fbi-carrier-iq-files-used-law-enforcement-purposes/" target="_blank">refused to disclose</a> how they use CarrierIQ data, the company has claimed that it has <a href="http://www.washingtonpost.com/business/technology/carrier-iq-weve-never-provided-info-to-the-fbi/2011/12/13/gIQA0R7urO_story.html" target="_blank">never provided any data</a> to &#8230;</p>]]></description>
			<content:encoded><![CDATA[<p>The Washington Post is reporting that executives from CarrierIQ are <a href="http://www.washingtonpost.com/business/economy/feds-probing-carrier-iq/2011/12/14/gIQA9nCEuO_story.html" target="_blank">meeting</a> with the Federal Trade Commission. Although the FBI has <a href="http://www.muckrock.com/news/archives/2011/dec/12/fbi-carrier-iq-files-used-law-enforcement-purposes/" target="_blank">refused to disclose</a> how they use CarrierIQ data, the company has claimed that it has <a href="http://www.washingtonpost.com/business/technology/carrier-iq-weve-never-provided-info-to-the-fbi/2011/12/13/gIQA0R7urO_story.html" target="_blank">never provided any data</a> to the FBI. The company has also released <a href="http://carrieriq.com/company/PR.20111212.pdf" target="_blank">another document</a> with more information on how the IQ Agent works.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.xenoactive.org/2011/12/feds-looking-into-carrieriq/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Adobe Exploit in the Wild</title>
		<link>http://www.xenoactive.org/2011/12/adobe-exploit-in-the-wild/</link>
		<comments>http://www.xenoactive.org/2011/12/adobe-exploit-in-the-wild/#comments</comments>
		<pubDate>Tue, 06 Dec 2011 22:29:29 +0000</pubDate>
		<dc:creator>stickman</dc:creator>
				<category><![CDATA[In Other News]]></category>
		<category><![CDATA[acrobat]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[Reader]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.xenoactive.org/?p=1078</guid>
		<description><![CDATA[<p>Adobe has released a <a href="http://www.adobe.com/support/security/advisories/apsa11-04.html" target="_blank">security advisory</a> for Adobe Acrobat and Adobe Reader. The zero day vulnerability, which is being actively exploited, allows an attacker to take control of a vulnerable computer. Adobe states in a <a href="http://blogs.adobe.com/asset/2011/12/background-on-cve-2011-2462.html" target="_blank">blog post</a> that they have &#8230;</p>]]></description>
			<content:encoded><![CDATA[<p>Adobe has released a <a href="http://www.adobe.com/support/security/advisories/apsa11-04.html" target="_blank">security advisory</a> for Adobe Acrobat and Adobe Reader. The zero day vulnerability, which is being actively exploited, allows an attacker to take control of a vulnerable computer. Adobe states in a <a href="http://blogs.adobe.com/asset/2011/12/background-on-cve-2011-2462.html" target="_blank">blog post</a> that they have only received reports of attacks on the Windows versions. Adobe is planning an out of cycle patch for the vulnerability, and it will be released no later than Dec 12th. Mac and Unix users will need to wait for the quarterly update, which will be released Jan 10th of next year. This vulnerability is being tracked as <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2462" target="_blank">CVE-2011-2462</a>. Watch for the patch, and update when it is available.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.xenoactive.org/2011/12/adobe-exploit-in-the-wild/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Carrier IQ Excitement</title>
		<link>http://www.xenoactive.org/2011/12/carrier-iq-excitement/</link>
		<comments>http://www.xenoactive.org/2011/12/carrier-iq-excitement/#comments</comments>
		<pubDate>Mon, 05 Dec 2011 00:57:30 +0000</pubDate>
		<dc:creator>stickman</dc:creator>
				<category><![CDATA[In Other News]]></category>
		<category><![CDATA[mobile]]></category>
		<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://www.xenoactive.org/?p=1075</guid>
		<description><![CDATA[<p>Working with his own HTC Evo phone, Trevor Eckart discovered the Carrier IQ activities. Carrier IQ responded with a <a href="https://www.eff.org/sites/default/files/eckhart_cease_desist_demand_redacted.pdf" target="_blank">cease and desist letter</a>, which was answered with the <a href="https://www.eff.org/sites/default/files/eckhart_c%26d_response.pdf" target="_blank">help of the EFF</a>. Carrier IQ withdrew the cease and &#8230;</p>]]></description>
			<content:encoded><![CDATA[<p>Working with his own HTC Evo phone, Trevor Eckart discovered the Carrier IQ activities. Carrier IQ responded with a <a href="https://www.eff.org/sites/default/files/eckhart_cease_desist_demand_redacted.pdf" target="_blank">cease and desist letter</a>, which was answered with the <a href="https://www.eff.org/sites/default/files/eckhart_c%26d_response.pdf" target="_blank">help of the EFF</a>. Carrier IQ withdrew the cease and desist letter and apologized. The press release claimed that the Carrier IQ software <em>does not record your keystrokes</em> and it <em>does not inspect or report the content of your communications</em>.</p>
<p>The news has also drawn the attention of some government officials. Senator Al Franken has sent <a href="http://franken.senate.gov/files/letter/111201_Letter_to_CarrierIQ.pdf" target="_blank">a letter to Carrier IQ</a> requesting more information about the extent of the data logging. Trevor Eckart has released <a href="http://www.youtube.com/watch?v=T17XQI_AYNo" target="_blank">a followup video</a> demonstrating the phone interactions appearing in the debugging logs. Carrier IQ has also released <a href="http://www.carrieriq.com/company/PR.CIQ_Press_Statement_DEC_1_11.pdf">a clarification</a> to their previous letter. In effect, the end of the letter states that Carrier IQ does not collect the information, but instead it is collected by the phone operators that purchase the software.</p>
<blockquote><p>From the letter:<br />
Carrier IQ acts as an agent for the operators. Each implementation is different and the<br />
diagnostic information actually gathered is determined by our customers – the mobile<br />
operators. Carrier IQ does not gather any other data from devices.</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.xenoactive.org/2011/12/carrier-iq-excitement/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

