Thai
Elite Member
Link: Fitness trackers are leaking lots of your data, study finds | PCWorld
Here is the actual study: https://openeffect.ca/reports/Every_Step_You_Fake.pdf
From PCworld article:
"Some of the more popular sports wearables don’t just let you track your fitness, they let other people track you.
All the devices studied except for the Apple Watch transmitted a persistent, unique Bluetooth identifier, allowing them to be tracked by the beacons increasingly being used by retail stores and shopping malls to recognize and profile their customers.
In addition, companion apps for the wearables variously leaked login credentials, transmitted activity tracking information in a way that allowed interception or tampering, or allowed users to submit fake activity tracking information.
Using a man-in-the-middle attack, researchers were able to spy on traffic between the apps and the servers for all but two of the apps, Apple’s Watch 2.1 and Intel’s Basis Peak 1.14.0. For the six remaining apps, this allowed them to observe even encrypted data sent via HTTPS.
Users of the Jawbone and Withings apps could falsify their fitness records, perhaps allowing them to erase evidence of medical problems or fake their sporting prowess. This is bad news for health insurers, some of which have begun to use fitness tracker data to offer lower premiums, and courts, which have admitted the data as evidence in a number of cases.
While the trackers are not considered medical devices, and thus escape the most stringent aspects of U.S. privacy law, the data they generate is considered personal information under European data protection law and so ought to be protected, the researchers said."
Here is the actual study: https://openeffect.ca/reports/Every_Step_You_Fake.pdf
From PCworld article:
"Some of the more popular sports wearables don’t just let you track your fitness, they let other people track you.
All the devices studied except for the Apple Watch transmitted a persistent, unique Bluetooth identifier, allowing them to be tracked by the beacons increasingly being used by retail stores and shopping malls to recognize and profile their customers.
In addition, companion apps for the wearables variously leaked login credentials, transmitted activity tracking information in a way that allowed interception or tampering, or allowed users to submit fake activity tracking information.
Using a man-in-the-middle attack, researchers were able to spy on traffic between the apps and the servers for all but two of the apps, Apple’s Watch 2.1 and Intel’s Basis Peak 1.14.0. For the six remaining apps, this allowed them to observe even encrypted data sent via HTTPS.
Users of the Jawbone and Withings apps could falsify their fitness records, perhaps allowing them to erase evidence of medical problems or fake their sporting prowess. This is bad news for health insurers, some of which have begun to use fitness tracker data to offer lower premiums, and courts, which have admitted the data as evidence in a number of cases.
While the trackers are not considered medical devices, and thus escape the most stringent aspects of U.S. privacy law, the data they generate is considered personal information under European data protection law and so ought to be protected, the researchers said."