If Carrier IQ on iOS only collects information about calls and location data during those calls and if it is turned off by default and if Apple is explicit about the data they collect† then there is no problem.
It seems obvious to me that carriers or manufacturers can collect that data if the user explicitly agrees to it (by actually flipping a switch without being forced or tricked into doing so).
Carrier IQ is only a problem if it is turned on by default and if it collects more data than is explicitly said∆.
—
† If the Diagnostics & Usage switch indeed controls Carrier IQ then we already know that the last two conditions are met.
∆ This is only the minimum viable evilness. Worse kinds of evil are imaginable, like not telling users anywhere that data is being or collected or making it hard for users to turn the collection of data off.
I disassembled the iOS version of Carrier IQ, and it exits on startup if not enabled. Even when enabled, it runs as an unprivileged user and connects via SSL so should not be any "attack vector".
It seems obvious to me that carriers or manufacturers can collect that data if the user explicitly agrees to it (by actually flipping a switch without being forced or tricked into doing so).
Carrier IQ is only a problem if it is turned on by default and if it collects more data than is explicitly said∆.
—
† If the Diagnostics & Usage switch indeed controls Carrier IQ then we already know that the last two conditions are met.
∆ This is only the minimum viable evilness. Worse kinds of evil are imaginable, like not telling users anywhere that data is being or collected or making it hard for users to turn the collection of data off.