Affiliate Disclosure
If you buy through our links, we may get a commission. Read our ethics policy.

Apple Watch comes out ahead in study of fitness tracker privacy, security

Last updated

When it comes to the privacy and security of user data, the Apple Watch and its accompanying software ecosystem are the most well-designed products in the wearable marketplace, a new study shows.

Bluetooth privacy protections — or lack thereof — were central the study's findings. Of the eight devices tested, Apple's wearable was the only one which regularly altered the MAC address broadcast by its Bluetooth radio.

Randomization of the MAC address on Bluetooth Low Energy products is accomplished by a BLE feature known as "LE Privacy." This is important, because unpaired Bluetooth products are designed to send "advertising" packets at regular intervals for discovery — that's how your iPhone knows that there's a nearby Apple Watch available for pairing.

Without this feature, researchers at Canadian privacy non-profit Open Effect and the University of Toronto note that it's relatively trivial to track the movements of individual users when their fitness bands are not actively paired with a device.

Fitbit blamed the "fragmented Android ecosystem" for the lack of LE Privacy support.

Contacted by the researchers about the fault, Fitbit noted that compatibility issues within the "fragmented Android ecosystem" prevent them from adding LE Privacy, despite hardware support in their products. Through corporate parent Intel, Basis noted that using the Peak while not paired to a smartphone was an edge case and did not commit to a fix.

None of the other companies in the test — Garmin, Jawbone, Mio, Withings, or Xiaomi — came back with "notable responses."

In addition to the Bluetooth issues, several companion software packages were found to be insecure. The researchers were variously able to intercept and read fitness data or write false data to disk.

The Garmin Connect app does not use HTTPs for connections, allowing a man-in-the-middle attack to read and write data. A similar attack was possible against Withings's Health Mate app on Android, while Jawbone's Up could allow users to send arbitrary fitness data to the cloud, an issue with potentially severe consequences:

"These findings concerning fitness tracker data integrity could call into question several real-world uses of fitness data," the researchers wrote. "Fitness tracking data has been introduced as evidence in court cases...meaning that at least some attorneys are relying upon generated fitness data as a possibly objective indicator of a person's activities at a given point in time. For Jawbone and Withings we created fraudulent fitness data which indicated that a passive measuring device, the fitness device, recorded a person taking steps at a specific time when no such steps occurred."



7 Comments

lkrupp 19 Years · 10521 comments


Without this feature, researchers at Canadian privacy non-profit Open Effect and the University of Toronto note that it's relatively trivial to track the movements of individual users when their fitness bands are not actively paired with a device.
Fitbit blamed the "fragmented Android ecosystem" for the lack of LE Privacy support.
Contacted by the researchers about the fault, Fitbit noted that compatibility issues within the "fragmented Android ecosystem" prevent them from adding LE Privacy, despite hardware support in their products. Through corporate parent Intel, Basis noted that using the Peak while not paired to a smartphone was an edge case and did not commit to a fix.

But since Android rules the world nobody cares about this and Apple is Doomed™. Millions upon millions of Android users walking around with security flaws that won’t or can’t be fixed because their devices don’t get updates. But that’s okay because Android dominates and not of word if this ever makes it into tech news reports. All we hear about is Apple’s projected growth slowdown. And let some German nerds figure out how to bypass TouchID with expensive high resolution printers and it’s gloom and doom for Apple security.

cali 10 Years · 3494 comments

I wonder if any tech sites are reporting this? Probably not.

This is why I come to Apple Insider a lot.

larrya 13 Years · 608 comments

So, if my device is paired, involuntary tracking is a non-issue. And if I have a Garmin device, someone could add steps or activities.  Yawn.  

I still choose GPS and waterproofing and battery life. 

tjwolf 12 Years · 423 comments

larrya said:
So, if my device is paired, involuntary tracking is a non-issue. And if I have a Garmin device, someone could add steps or activities.  Yawn.  

I still choose GPS and waterproofing and battery life. 

Or heart rate (I don't actually know if your Garmin has that).  In any event, as people become dependent on accurate heart rate measurements, getting that data messed with by someone is hardly a yawn.

And, of course, some have more capable fitness tracking devices - so there's not just steps and activities.

512ke 19 Years · 781 comments

Great. But I agree that GPS, battery life, and utility independent of a phone are more important drivers of sales.