Scottish Daily Mail

Now trendy Fitbits are latest target for hackers

Attempt to steal health data

- By Sam Walker

THEY are the must-have gadget for fitness fanatics and those who are trying to get more exercise.

But it has now emerged Fitbit bands could be abused by hackers to reduce health and life insurance premiums for the lazy.

An Edinburgh University study has found that vulnerabil­ities in the device’s security means data gained by a healthy person could be stolen.

The informatio­n, intercepte­d as the device communicat­es with its digital ‘cloud’ server, can then be used to create fake health records and issued to insurance companies to lower annual payments.

Security weak spots found in two of the bestsellin­g devices, Fitbit Flex and the more expensive Fitbit One, could allow unauthoris­ed sharing of personal data with third parties including online retailers and marketing agencies, the team found.

American company Fitbit yesterday announced the launch of a series of ‘patches’ to strengthen security in the wake of the findings.

Dr Paul Patras, of the university’s School of Informatic­s, who took part in the study, added: ‘Our work demonstrat­es security and privacy measures implemente­d in popular wearable devices continue to lag behind the pace of new technology developmen­t.

‘We welcome Fitbit’s receptiven­ess to our findings, their profession­al attitude towards understand­ing the vulnerabil­ities we identified and the timely manner in which they have improved the affected services.’

Working with Germany’s Technische Universitä­t Darmstadt and the University of Padua, Italy, the team of scientists analysed the Fitbit Flex and Fitbit One, which retail for £55 and £95 respective­ly.

The waterproof devices are worn night and day to track heart rate, calories burned and steps taken,

During the study researcher­s discovered a way of intercepti­ng messages transmitte­d between fitness trackers and cloud servers – where data is sent for analysis. This allowed them to access personal informatio­n and create false activity records.

The team also managed to falsify the informatio­n stored on the devices by physically taking them apart.

The study names health and life insurance provider Vitality as one of the companies that could potentiall­y be targeted by hackers.

It rewards Fitbit-wearing policy holders with ‘points’ for hitting a set amount of steps per day, periods of elevated heart rates between 30 to 60 minutes, and for burning calories. The more points they amass, the greater the discount.

Researcher­s have produced guidelines to help manufactur­ers remove similar weaknesses from future designs to ensure personal data is kept secure.

The findings will be presented at the Internatio­nal

‘Will roll out updates’

Symposium on Research in Attacks, Intrusions and Defences (RAID) in Atlanta, United States, on Monday.

The research was partfunded by the Scottish Informatic­s and Computer Science Alliance.

A spokesman for Fitbit said: ‘We are committed to protecting consumer privacy and keeping data safe. We are always looking for ways to strengthen the security of our devices, and in the upcoming days will start rolling out updates that improve device security, including ensuring encrypted communicat­ions for trackers launched prior to Surge.

‘The trust of our customers is paramount and we carefully design security measures for new products, continuous­ly monitor for new threats, and diligently respond to identified issues.

‘We continue to value the research the security community does and their collaborat­ion with us.’

A spokesman for Vitality said: ‘We ensure our members’ data is protected at all times.

‘We work with a range of partners to reward members for healthy behaviour.

‘The member then has a direct relationsh­ip with the partner or app, and it is at the member’s own discretion whether they choose to share their data with us via the manufactur­er.’

 ??  ?? Security fear: Fitbit band
Security fear: Fitbit band

Newspapers in English

Newspapers from United Kingdom