Most fitness wearables lack end-to-end encryption and don't disclose government data demands, says EFF
Millions of people use smart fitness wearables for tracking their health, sleep, and more, but most of the top devices on the market lack security features and basic data transparency that everyone should expect as standard.
Earlier this year, I looked at the popular Oura wearable ring and found that it does not end-to-end encrypt users' data, which leaves open a back-door for governments to demand personal and health information about its users. Oura wouldn't say how many legal demands it has received to date; instead, the company said it would consider disclosing the figures in a future transparency report.
The Electronic Frontier Foundation went further and took a broader look at the state of security and privacy practices of the ten most popular smart watches, health trackers, and wearables. The EFF checked with device makers like Apple, Fitbit, Garmin — and yes, Oura. But they found that only Apple Watch uses end-to-end encryption, meaning the users' data is scrambled so that not even Apple can access it.
More from the EFF's blog:
"...No other popular consumer health wearable offers end-to-end encryption for the data it collects and stores online. Not Google. Not Garmin. Not Oura. Most of these companies instead offer encryption in transit and at rest, but this means those companies can still see and use your data..."
As the EFF notes, health data is increasingly used in law enforcement investigations. That means a person's data is only a subpoena or a search warrant away. We also don't know how frequently the wearable makers receive demands for data, because almost none of them say how often cops lean on them for users' information. Only Apple and Google (which owns Fitbit) disclose their law enforcement request figures on a semi-regular basis.
Transparency reports became a tool of rebuttal by tech companies in response to the surveillance abuses revealed by the Edward Snowden leaks in 2013, which saw the publishing of top-secret documents detailing how the U.S. government tapped users' data from tech giants. It was a massive scandal at the time, so the tech giants fought back by disclosing how often the government came knocking on their doors.
Most of them still post transparency reports, proving that there is no good reason for any tech or phone company not to publicly reveal the number of legal demands they receive.
The wearable makers may not want to disclose that they are turning over some, or even any of their customers' data to the authorities. The fix, then, is to encrypt users' data in a way that makes it impossible for anyone other than the user to access it — like Apple did. Following the publication of its first transparency report in 2013, Apple went all-in on end-to-end encryption soon after.
It's amazing to me that the wearable makers haven't put more effort behind making security and privacy a selling point. Unless the logic is that the companies want access to our data, at which point we should be asking why.
Personally, I would love a compact wearable fitness tracker that stores my data locally, or end-to-end encrypted in the cloud. It's about time the wearables market had a shake-up.