Every day, millions of people worldwide record every aspect of their lives, their thoughts, their experiences, and the accomplishments of their activities (also known as self-tracking or life logging). People who engage in self-tracking do so for a variety of reasons. Given the volume of personal data that is created, transmitted, and stored in various places, privacy and security are important issues for users of these devices and applications.
Symantec has discovered security risks in a significant number of self-tracking devices and apps. One of the key findings was that all of the wearable activity devices it examined, including some leading brands, are vulnerable to location tracking.
The researchers created a series of scanning devices using Raspberry Pi minicomputers and by placing them at sporting events and busy public places, they discovered that tracking individuals was possible and feasible.
Symantec found vulnerabilities in how personal data is stored and managed, such as unencrypted password transfer and incomplete session management when connecting applications to servers.
How do self-tracking systems work?
Many people who are involved in self-tracking implement it with gadgets such as electronic wristbands, smart watches, pendants, and even “smart” clothing. These gadgets typically contain a series of sensors, a processor, memory, and a communication interface. These gadgets allow the user to collect, store, and transmit their data effortlessly to another computer for processing and analysis.
Despite the increasing use of specially designed gadgets, smartphones are perhaps the most common tools that people use to perform self-tracking. A modern smartphone is equipped with a wide range of different sensors that can be used for a number of self-tracking applications. Most people always have their mobile phones with them, and the abundance of free self-tracking applications makes it easier than ever for users to do self-tracking.
To start self-tracking, users simply choose from the wide range of apps available in app markets, install one, sign up for it and start tracking. At the end of each session, the user can review and synchronize the data collected to a cloud-based server for storage.
How safe is electronic recording of yourself?
When our personal data concerning electronically recorded information about ourselves is at the disposal of providers, does this automatically mean that we trust them? How do we know that they are taking all the necessary measures to protect our data and our privacy? In order to be able to see what is happening, we examined what companies are doing to protect users of their services, through popular devices and applications on the market.
Location tracking of wearable devices
All wearable activity tracking devices can be located via wireless transmission protocols.
There are many wearable sports tracking devices on the market. These devices generally contain sensors to detect movement, but most are not designed for location tracking. The data collected by these devices must be synchronized with another device or computer so that it can be processed. For convenience, many manufacturers use Bluetooth Low Energy to allow the device to wirelessly synchronize data with a smartphone or computer. This convenience comes at a price; the device can provide information that allows it to be located from one location to another.
To test how these devices can be located, we created a portable Bluetooth scanning device using Raspberry Pi minicomputers and other peripherals such as a Bluetooth 4.0 adaptor, a battery pack, and an SD card. This was combined with open source software and standard scripting. Each device cost around US$75 and could easily be built by anyone with basic IT skills.
The results of the research show that manufacturers of these devices (including the market leaders) have not seriously considered how to address the privacy issues of these products. As a result, the devices, and those who wear them, can be easily tracked by anyone with basic IT skills and the help of inexpensive tools.
Why should we be concerned about this?
It is possible that thieves or those who are spying on us could use location information for malicious purposes. There are examples of thieves using location systems to find out when a potential victim is not at home!
20% of applications transmit user credentials without being encrypted.
Many of these applications and services have a cloud server that users must upload and store the data collected by their applications for storage and analysis. In addition to simply storing activity data, some services collect additional personal information such as date of birth, address, photos and other statistics. To prevent unauthorized access to user data, these services require users to create an account that will be protected by a username and password.
The issue we observed was that an unacceptably large percentage of these applications do not handle sensitive data, such as usernames (e.g. email addresses) and passwords, securely. Many of them transmit user-generated data, such as login credentials, over an insecure medium like the internet, without any attempt to protect it (e.g. through encryption). This means that the data can easily be intercepted and read by attackers. The lack of basic security is a significant omission and raises questions about how these services handle the information they have stored on their servers.
Why should we be concerned about this?
Passing credentials in clear text is particularly problematic given that a large majority of people tend to reuse login credentials across multiple websites. Thanks to reuse, login details stolen from one service can potentially be used to gain access to sensitive services such as email accounts or online shopping accounts.
Lack of privacy policies
Self-tracking apps are by their nature designed to collect and analyze personal information. It is therefore reasonable to expect, and indeed required by law in many countries (such as the Online Privacy Protection Act 2003), that companies that collect and process personal data have a privacy policy that is clearly visible and easily accessible. Privacy policies should be easy to understand and displayed to users before they sign up for the service, so that they have a choice before deciding to use it. Despite the importance of having a privacy policy, the majority of apps did not have one!
Why should we be concerned about this?
The lack of a privacy policy is a possible indicator of how self-tracking service and app providers handle security. Users should be well-informed and take this into account before signing up for these services.
Inadvertent data leakage
The maximum number of unique domains that a single application contacted was 14, and the average was 5.
On average, we found that applications contacted 5 different Internet domains. In the worst case, we found an application that contacted 14 different domains during its short period of operation. While it is understandable that applications may need to communicate with a small number of domains so that they can transmit collected data and access certain APIs, such as in advertising, it may come as a surprise that a significant number of applications contact 10 or more different domains for various purposes. Many of the applications report to analytics services, while others use these analytics to examine the application’s performance for any potential failure issues.
Despite the good intentions of app developers, information about user activities can be exposed in the most unlikely of ways, thanks to how the app uses third-party services. There are a number of examples where the app can inadvertently leak your data.
Why should we worry about this?
While many of us enjoy sharing details of our lives with friends and family, there are some things we don't necessarily want to share. When we choose not to share something, we certainly don't want service providers to do that for us.
Other security vulnerabilities
In any shared service, user accounts are used to separate the user's status and data from others. Sessions are used to manage and process the flow of data, so that users can only access their own data and perform operations on the data they have access to. Poor session management can be exploited by cybercriminals who can infiltrate sessions and "impersonate" other users. This can result in information leakage, information vandalism, and other problems.
Why should we be concerned about this?
Poorly designed systems can expose serious vulnerabilities and be exploited by attackers. This can lead to a complete breach of user data on the part of the service provider. Depending on the sensitivity of the data, the impact on users can range from insignificant to very serious.
What can you do about this?
At first glance, electronic recording and privacy seem to be incompatible. How can recording a lot of data about yourself and maintaining your privacy be possible? Considering the security and privacy issues that have arisen, the obvious conclusion is that if you are looking for your privacy, it is best not to engage in self-tracking at all!!
Despite the potential security and privacy risks, the movement supporting electronic recording of ourselves continues to grow significantly and is expected to continue its growth for several more years. To ensure that users continue to enjoy this activity safely, Symantec suggests that they take some basic steps to protect themselves, aiming to shield themselves from the risk of exposing personal self-tracking information.
– Use a screen lock or a password to prevent unauthorized access to your device
– Do not use the same username and password on different websites
– Use 'strong' passwords
– Turn off Bluetooth when you don't need it
– Be careful when websites and services ask for unnecessary or excessive information
– Be careful when using the ability to share this information on social media
– Avoid the ability to share your location details on social media
– Avoid applications and services that do not display their privacy policy in a prominent place
– Read and understand the privacy policy of the applications and services you use
– Install updates to applications and operating systems when they become available
– Use a security solution for your device
– Use full device encryption if available
Source: allaboutandroid.gr
