Symantec: Tracking and monitoring activity through wearable gadgets
Those who love to electronically record their lives are creating a flood of personal information through apps and devices. Is this data safe from prying eyes?;
Every day, millions of people around the world record every aspect of their lives, their thoughts, their experiences, and their activity accomplishments (also known as self-tracking or life logging). People who engage in self-tracking do so for a variety of reasons. Given the volume of personal data that is created, transmitted, and stored in various places, privacy and security are important concerns for users of these devices and apps. Symantec discovered security risks in a significant number of self-tracking devices and apps. One of the key findings was that all of the wearable activity devices we examined, including some leading brands, are vulnerable to location tracking.

The researchers created a series of scanning devices using Raspberry Pi minicomputers and by placing them at sporting events and busy public places, they discovered that tracking individuals was possible and feasible.
Symantec found vulnerabilities in how personal data is stored and managed, such as unencrypted password transfer and incomplete session management when connecting applications to servers.
How do self-tracking systems work?
Many people who engage in self-tracking do so with gadgets such as electronic wristbands, smart watches, pendants, and even “smart” clothing. These gadgets typically contain a series of sensors, a processor, memory, and a communication interface. These gadgets allow the user to collect, store, and transmit their data effortlessly to another computer for processing and analysis.

Figure 1. What a typical recording device includes
Despite the increasing use of specially designed gadgets, smartphones are perhaps the most common tools that people use to perform self-tracking. A modern smartphone is equipped with a wide range of different sensors that can be used for a number of self-tracking applications. Most people always have their mobile phones with them, and the abundance of free self-tracking applications makes it easier than ever for users to do self-tracking.

Figure 2. Modern smartphones have a range of sensors
To start self-tracking, users simply choose from the wide range of apps available in app markets, install one, sign up for it and start tracking. At the end of each session, the user can review and synchronize the data collected to a cloud-based server for storage.
How secure is recording yourself electronically?
When our personal data concerning electronically recorded information about ourselves is at the disposal of providers, does this automatically mean that we trust them? How do we know that they are taking all the necessary measures to protect our data and our privacy? To be able to see what is happening, we examined what companies are doing to protect users of their services, through popular devices and applications on the market.
Location tracking of wearable devices
All wearable activity tracking devices can be tracked via wireless transmission protocols.
There are many wearable fitness trackers on the market. These devices generally contain sensors to detect movement, but most are not designed for location tracking. The data collected by these devices must be synced with another device or computer so that it can be processed. For convenience, many manufacturers use Bluetooth Low Energy to allow the device to wirelessly sync data with a smartphone or computer. This convenience comes at a price, however; the device may provide information that allows it to be tracked from one location to another.
To test how these devices could be detected, we created a portable Bluetooth scanning device using Raspberry Pi minicomputers and other peripherals such as a Bluetooth 4.0 adaptor, a battery pack and an SD card. This was combined with open source software and standard scripting. Each device cost around US$75 and could easily be built by anyone with basic computer skills.
The results of the research show that manufacturers of these devices (including the market leaders) have not seriously thought about how to address the privacy issues of these products. As a result, the devices, and the people who wear them, can be easily tracked by anyone with basic IT skills and the help of inexpensive tools.
Why should we be concerned about this?
It is possible that thieves or those who are spying on us could use location information for malicious purposes. There are examples of thieves using location systems to find out when a potential victim is not at home!
Transmission of personal data and location information in text format
20% of applications transmit user credentials without being encrypted.
Many of these applications and services have a cloud server that users must upload and store the data collected by their applications for storage and analysis. In addition to simply storing activity data, some services collect additional personal information such as date of birth, address, photos and other statistics. To prevent unauthorized access to user data, these services require users to create an account that will be protected by a username and password.
The issue we observed was that an unacceptably large percentage of these applications do not handle sensitive data, such as usernames (e.g. email addresses) and passwords, securely. Many of them transmit user-generated data, such as login credentials, over an insecure medium like the internet, without any attempt to protect it (e.g. through encryption). This means that the data can easily be intercepted and read by attackers. The lack of basic security is a significant omission and raises questions about how these services handle the information they have stored on their servers.
Why should we be concerned about this?
Passing credentials in clear text is particularly problematic given that a large majority of people tend to reuse login credentials across multiple websites. Thanks to reuse, login details stolen from one service can potentially be used to gain access to sensitive services such as email accounts or online shopping accounts.
Lack of privacy policies
52% of apps reviewed do not have privacy policies
Self-tracking apps are by their nature designed to collect and analyze personal information. It is therefore reasonable to expect, and indeed required by law in many countries (such as the Online Privacy Protection Act 2003), that companies that collect and process personal data have a privacy policy that is clearly visible and easily accessible. Privacy policies should be easy to understand and displayed to users before they sign up for the service, so that they have a choice before deciding to use it. Despite the importance of having a privacy policy, the majority of apps did not have one!
Why should we be concerned about this?
The lack of a privacy policy is a possible indicator of how self-tracking service and app providers handle security. Users should be well-informed and take this into account before signing up for these services.
Unintentional data leak
The maximum number of unique domains contacted by a single application was 14 and the average was 5.
On average, we found that apps interact with 5 different Internet domains. In the worst case, we found one app interacting with 14 different domains during its short period of operation. While it is understandable that apps may need to communicate with a small number of domains so that they can transmit collected data and access certain APIs, such as in advertising, it may come as a surprise that a significant number of apps interact with 10 or more different domains for various purposes. Many of the apps report to analytics services, while others use these analytics to examine the app’s performance for any potential performance issues.
Despite the good intentions of app developers, information about user activities can be exposed in the most unlikely of ways, thanks to how the app uses third-party services. There are a number of examples where the app can inadvertently leak your data.
Why should we worry about this?
While many of us enjoy sharing details of our lives with friends and family, there are some things we don't necessarily want to share. When we choose not to share something, we certainly don't want service providers to do that for us.
Other security vulnerabilities
In any shared service, user accounts are used to separate the user's status and data from others. Sessions are used to manage and process the flow of data, so that users can only access their own data and perform operations on the data they have access to. Poor session management can be exploited by cybercriminals who can infiltrate sessions and “impersonate” other users. This can result in information leakage, information vandalism, and other problems.
Why should we be concerned about this?
Poorly designed systems can expose serious vulnerabilities and be exploited by attackers. This can lead to a complete breach of user data on the part of the service provider. Depending on the sensitivity of the data, the impact on users can range from insignificant to very serious.
What can you do about this issue?
At first glance, electronic recording and privacy seem incompatible. How can recording a wealth of data about yourself and maintaining your privacy be possible? Considering the security and privacy issues that have arisen, the obvious conclusion is that if you are looking for your privacy, it is best not to engage in self-tracking at all!!
Despite the potential security and privacy risks, the movement supporting electronic self-tracking continues to grow significantly and is expected to continue its growth for several more years. To ensure that users continue to enjoy this activity safely, Symantec recommends taking some basic steps to protect themselves against the risk of exposing personal self-tracking information.
- Use a screen lock or a password to prevent unauthorized access to your device
- Do not use the same username and password on different websites
- Use 'strong' passwords
- Turn off Bluetooth when you don't need it
- Be careful when websites and services ask you for unnecessary or excessive information
- Be careful when using the ability to share this information on social media
- Avoid sharing your location details on social media
- Avoid apps and services that do not prominently display their privacy policy
- Read and understand the privacy policy of the apps and services you use
- Install updates to applications and operating systems when they become available
- Use a security solution for your device
- Use full device encryption if available
More information
Those who need more information on this topic can read the latest whitepaper entitled: How secure is electronic recording of yourself?
