Just received this through the door, "oh, just a random survey about internet use" nope, much more terrifying than that!
1/
1/
First off, it makes you install an app, seems harmless, then I looked at the install guide: https://irispanel.ipsos.com/wp-content/uploads/2020/10/android_phone_install.pdf
So, literally encouraging random non-tech savvy members of the public to not only have their phone listening to TV broadcasts but also to install a root certificate and VPN, allowing Ipsos MORI to decrypt literally any internet traffic from the device.
3/
3/
Oh, but it's fine, they say they don't capture "usernames, passwords, contacts, photos or documents." Just because they say they don't, doesn't mean they can't, they have their root certificate and VPN installed. Surely that makes them a huge attack target?
4/
4/
But don't worry everyone, using the Ipsos iris blue app is really simple! Just lie back on your couch safe in the knowledge that you've totally obliterated the security functions of your device.
Totally preying on non-tech savvy people - destroy your privacy for £5-£10/mo.
5/
Totally preying on non-tech savvy people - destroy your privacy for £5-£10/mo.
5/
So another observation from @CraigSnowden - the iOS install guide references "*.realitymine.com" (screenshot on Page 6): https://irispanel.ipsos.com/wp-content/uploads/2020/10/apple_ios_phone_install.pdf
This leads to this press release: https://www.realitymine.com/ipsos-announces-partnership-with-realitymine-to-deliver-ipsos-iris/
Which mentions this product: https://www.realitymine.com/realitymeter/
6/
This leads to this press release: https://www.realitymine.com/ipsos-announces-partnership-with-realitymine-to-deliver-ipsos-iris/
Which mentions this product: https://www.realitymine.com/realitymeter/
6/
Update, it looks as though the Android app potentially runs the VPN server locally on the device.
However, the iOS install guide doesn't show an app, it appears to be a web page with install instructions, can't see potential for a local server here: https://irispanel.ipsos.com/wp-content/uploads/2020/10/apple_ios_phone_install.pdf
7/
However, the iOS install guide doesn't show an app, it appears to be a web page with install instructions, can't see potential for a local server here: https://irispanel.ipsos.com/wp-content/uploads/2020/10/apple_ios_phone_install.pdf
7/