Are Fitness Trackers Fit For Security?

Are Fitness Trackers Fit For Security?

Article
Heart & Vascular Health
Current Medical News
+1
Contributed byMaulik P. Purohit MD MPHSep 21, 2016

They may look like a normal watch but are capable to do much more than just showing the time: So called fitness trackers are collecting data on their users' lifestyle and health status on a large scale helping them with training or losing weight. Ahmad-Reza Sadeghi, system security professor at the cybersecurity profile area (CYSEC) of TU Darmstadt and his team investigated fraud opportunities with fitness trackers and detected serious security flaws.

The popularity of these devices is constantly growing. Worldwide, nearly 20 million fitness trackers have been sold in the first quarter of 2016. Many of them track via GPS the kilometers the user run, measure heart rate and pulse or check if the user is asleep. "These data are not only used for the original purpose but are increasingly being used by third parties," explains professor Sadeghi.

Data collected by fitness trackers have been used as evidence in court trials in the US, as reported by Forbes Magazine in 2014. Police and attorneys have started to recognize wearable devices as the human body's "black box," the NY Daily News wrote in April 2016. Some health insurance companies recently started to offer discounts if the insured persons provide personal data from their fitness trackers. This could attract scammers who manipulate the tracked data to fraudulently gain financial benefits or even influence a court trial, says Sadeghi. This makes it all the more important that transmission, processing and storing of the sensitive personal data meet high security standards.

To investigate this, Sadeghi and his team conducted a study in cooperation with the University of Padua (Italy) on 17 different fitness trackers including devices from less well-known manufacturers as well as devices from popular brands like Xiaomi, Garmin and Jawbone. The researchers concentrated on manipulating the data on their way to the cloud server by a "man-in-the-middle" attack and examined the security of communication protocols used by the fitness trackers.

The result: Although all cloud-based tracking systems use an encrypted protocol like HTTPS to transfer data, the researchers were able to falsify data in all cases. Out of all fitness trackers examined, only devices from four manufacturers took some minor measures to protect data integrity, i.e. to ensure that data remain intact and unaltered. "These hurdles cannot stop a motivated attacker. Scammers can manipulate the data even with very little IT knowledge," Sadeghi warns, as none of the trackers employ End-to-End encryption or other effective tamper protection measures when synchronizing data.

Five of the examined fitness trackers did not provide a possibility to synchronize fitness data with an online service. However, these manufacturers store the collected fitness data in plain-text, i.e. un-encrypted and readable by everyone, on the smartphone which introduces a potential risk of unauthorized data leakage should the smartphone be stolen or infected with malware. This is another serious security flaw of fitness trackers the researchers from TU Darmstadt and University of Padua found.

"Health insurances and all other companies who want to use fitness trackers for their services should seek advice from security experts before doing so," Sadeghi suggests. The flaws found in the study could be fixed with known standard technologies, "it's just that the manufacturers have to put some more effort in employing these technologies in their products."


The above post is reprinted from materials provided by Technische Universität DarmstadtNote: Content may be edited for style and length.

Disclaimer: DoveMed is not responsible for the adapted accuracy of news releases posted to DoveMed by contributing universities and institutions.

Was this article helpful

On the Article

Maulik P. Purohit MD MPH picture
Approved by

Maulik P. Purohit MD MPH

Assistant Medical Director, Medical Editorial Board, DoveMed Team

0 Comments

Please log in to post a comment.

Related Articles

Test Your Knowledge

Asked by users

Related Centers

Loading

Related Specialties

Loading card

Related Physicians

Related Procedures

Related Resources

Join DoveHubs

and connect with fellow professionals

Related Directories

Who we are

At DoveMed, our utmost priority is your well-being. We are an online medical resource dedicated to providing you with accurate and up-to-date information on a wide range of medical topics. But we're more than just an information hub - we genuinely care about your health journey. That's why we offer a variety of products tailored for both healthcare consumers and professionals, because we believe in empowering everyone involved in the care process.
Our mission is to create a user-friendly healthcare technology portal that helps you make better decisions about your overall health and well-being. We understand that navigating the complexities of healthcare can be overwhelming, so we strive to be a reliable and compassionate companion on your path to wellness.
As an impartial and trusted online resource, we connect healthcare seekers, physicians, and hospitals in a marketplace that promotes a higher quality, easy-to-use healthcare experience. You can trust that our content is unbiased and impartial, as it is trusted by physicians, researchers, and university professors around the globe. Importantly, we are not influenced or owned by any pharmaceutical, medical, or media companies. At DoveMed, we are a group of passionate individuals who deeply care about improving health and wellness for people everywhere. Your well-being is at the heart of everything we do.

© 2023 DoveMed. All rights reserved. It is not the intention of DoveMed to provide specific medical advice. DoveMed urges its users to consult a qualified healthcare professional for diagnosis and answers to their personal medical questions. Always call 911 (or your local emergency number) if you have a medical emergency!