{"id":6480,"date":"2014-10-30T16:52:15","date_gmt":"2014-10-30T20:52:15","guid":{"rendered":"https:\/\/www.kaspersky.com\/blog\/?p=6480"},"modified":"2019-11-15T07:11:03","modified_gmt":"2019-11-15T12:11:03","slug":"fitness-trackers-privacy","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com\/blog\/fitness-trackers-privacy\/6480\/","title":{"rendered":"Your fitness is their business. Nothing personal"},"content":{"rendered":"<p>It has become somewhat of an embarrassment to talk about privacy these days. What use is it to protect privacy if careless users are eager to exhibit their personal data to anyone on social networks anyways? Today, users are readily spending their hard-earned money to sign up, deliberately, for house arrest-style services similar to those used for tracking criminals.<\/p>\n<p>We are not talking about just wristbands or clips here; don\u2019t forget about the thousands of apps tracking your sleep and movements, diet and cycle, and symptoms and medication schedules. For being so varied, they are not all that different: all of them are sending your data to a network.<\/p>\n<p>And that\u2019s where the big \u2018oops!\u2019 is. Research published by FTC this May, brought to light some interesting <a href=\"http:\/\/www.ftc.gov\/system\/files\/documents\/public_events\/195411\/consumer-health-data-webcast-slides.pdf\" target=\"_blank\" rel=\"noopener nofollow\">features<\/a>\u00a0that these apps (free and paid) have, after analyzing 43 apps. To start with, 26 percent of free apps, and 40 percent of paid, do not deploy any kind of privacy policy.<\/p>\n<p>Impressed so far? How about this revelation: 20 apps on the list sent data to third-party companies (70 recipients in total), who mostly represent advertisers and ad analysts using the data to better target their campaigns. As for data encryption, the situation is even more drastic: only 13 percent of free and 10 percent of paid apps had this capability enabled. So, just one out of ten tracking apps had at least basic means to protect user data!<\/p>\n<blockquote class=\"twitter-pullquote\"><p>Just one out of ten #fitness #tracking apps has some #data #encryption<\/p><a href=\"https:\/\/twitter.com\/share?url=https%3A%2F%2Fkas.pr%2Fm9aC&amp;text=Just+one+out+of+ten+%23fitness+%23tracking+apps+has+some+%23data+%23encryption\" class=\"btn btn-twhite\" data-lang=\"en\" data-count=\"0\" target=\"_blank\" rel=\"noopener nofollow\">Tweet<\/a><\/blockquote>\n<p>The next stage of the research involved 12 apps and two wearables. The data was sent to 73 third-party organizations without a user\u2019s consent. By the way, the information those fitness and health app developers tampered with so irresponsibly included the user\u2019s sex, name, device IDs, e-mail, information on physical exercises and diet, postal code and location, symptoms searches and the user\u2019s unique IDs that are able to track him\/her through other apps.<\/p>\n<div class=\"pullquote\">Information those fitness and health app developers tampered with so irresponsibly included the user\u2019s name, sex, device ID and other additional data, making it possible to track him\/her through other apps.<\/div>\n<p>Just to help you deal with the fact that your data is no longer yours, we recommend that you check out the researchers\u2019 <a href=\"http:\/\/thedatamap.org\/\" target=\"_blank\" rel=\"noopener nofollow\">website<\/a> to better understand how information about you is sent through apps to their developers. That means that not only law enforcement officials, but other bureaus and companies as well may get full access to your data, and most likely, without any constraints, given how bad app developers are at <a href=\"http:\/\/techcrunch.com\/2011\/07\/03\/sexual-activity-tracked-by-fitbit-shows-up-in-google-search-results\/\" target=\"_blank\" rel=\"noopener nofollow\">keeping your data private<\/a>.<\/p>\n<p>Even though major fitness tracker vendors have <a href=\"http:\/\/www.motherjones.com\/politics\/2014\/01\/are-fitbit-nike-and-garmin-selling-your-personal-fitness-data\" target=\"_blank\" rel=\"noopener nofollow\">assured<\/a> users that they do not discreetly pass private information to third-party companies, it does not mean they would not intend to do it in the future. Even anonymous data (something the companies in question are eager to boast about) may be of use, especially when combined with open source information and metadata \u2013 in that case, it\u2019s like Christmas came early for all the interested parties.<\/p>\n<blockquote class=\"twitter-pullquote\"><p>Half of tested #fitness #tracking apps sent data to third-party companies<\/p><a href=\"https:\/\/twitter.com\/share?url=https%3A%2F%2Fkas.pr%2Fm9aC&amp;text=Half+of+tested+%23fitness+%23tracking+apps+sent+data+to+third-party+companies\" class=\"btn btn-twhite\" data-lang=\"en\" data-count=\"0\" target=\"_blank\" rel=\"noopener nofollow\">Tweet<\/a><\/blockquote>\n<p>Fitness trackers, for instance, employ smart movement sensors, which can help to identify movements other than hiking and running. With that in mind, BP\u2019s <a href=\"http:\/\/hr.bpglobal.com\/lifebenefits\/sites\/core\/bp-life-benefits\/employee-benefits-handbook\/bp-medical-program\/how-the-bp-medical-program-works\/health-savings-ooa-option-summary-chart\/bp-wellness-program.aspx\" target=\"_blank\" rel=\"noopener nofollow\">initiative<\/a> to provide all employees and their families with free Misfit trackers looked particularly fishy. Misfit\u2019s CEO <a href=\"http:\/\/www.forbes.com\/sites\/parmyolson\/2014\/04\/17\/the-quantified-other-nest-and-fitbit-chase-a-lucrative-side-business\/\" target=\"_blank\" rel=\"noopener nofollow\">admitted<\/a> that such deals presupposing the discounted sale of thousands of trackers equipped with tracking software to corporate clients, is one of the fastest-growing domains of the company\u2019s business.<\/p>\n<p>Don\u2019t assume that this data is processed by only a handful of people, and that maybe they have no time to get to yours due to a heavy workload. That\u2019s not how it works. All of this bulk data is easily processed by Big Data technologies without involving any human efforts. Your profile is not a file on the shelf among millions of similar files, where it can eventually get lost. Your profile is a batch of bytes which may be stored at anyone\u2019s place, depending on the interest this company or person might have in you, based on the particular patterns the system would find in your data.<\/p>\n<div align=\"center\">\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\"><a href=\"https:\/\/twitter.com\/hashtag\/Privacy?src=hash&amp;ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">#Privacy<\/a> is a precious thing people should protect no matter what. Sometimes the columnists don't reflect our opinion <a href=\"http:\/\/t.co\/3LTXJ7EAZA\" target=\"_blank\" rel=\"noopener nofollow\">http:\/\/t.co\/3LTXJ7EAZA<\/a><\/p>\n<p>\u2014 Eugene Kaspersky (@e_kaspersky) <a href=\"https:\/\/twitter.com\/e_kaspersky\/status\/505395547541626880?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">August 29, 2014<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script>\n<\/p><\/div>\n<p><a href=\"http:\/\/gizmodo.com\/why-a-fitness-tracking-app-is-selling-its-data-to-city-1572964149\" target=\"_blank\" rel=\"noopener nofollow\">Urban planning<\/a>, <a href=\"http:\/\/gizmodo.com\/this-beautifully-simple-app-wants-to-change-how-public-1548777582\" target=\"_blank\" rel=\"noopener nofollow\">traffic control<\/a>,\u00a0<a href=\"http:\/\/www.forbes.com\/sites\/kashmirhill\/2012\/02\/16\/how-target-figured-out-a-teen-girl-was-pregnant-before-her-father-did\/\" target=\"_blank\" rel=\"noopener nofollow\">targeted advertising<\/a> and even <a href=\"http:\/\/www.businessweek.com\/news\/2013-06-05\/states-hospital-data-for-sale-leaves-veteran-s-privacy-at-risk\" target=\"_blank\" rel=\"noopener nofollow\">de-anonymizing<\/a> are mere peanuts compared to the shock you may get one day upon receiving increased insurance bills. \u2018Why is that?\u2019 you\u2019d ask. But it would be due to the fact you were less actively moving, doing less physical exercise, and slept less than last year and thus are more exposed to the risk of heart and neurological diseases. Some developers <a href=\"http:\/\/www.dailymail.co.uk\/news\/article-2409486\/personal-details-smartphone-fitness-apps-sold-firms-20-used-products-pass-information-nearly-70-companies.html\" target=\"_blank\" rel=\"noopener nofollow\">confessed<\/a> that selling data like this to insurance companies generates 50% of their earnings.<\/p>\n<p>So, perhaps it is time to just give up thinking that your life is private. It is well known that your health is someone\u2019s business. Nothing personal. The good news is that at the moment, law-abiding citizens are not forced to use trackers. So all you have to do to keep this particular bit of your life private is to avoid this kind of stuff.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Today, users are readily spending their money on house arrest-style services similar to those used for tracking criminals. They call them fitness trackers. <\/p>\n","protected":false},"author":637,"featured_media":6481,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5],"tags":[584,43,45,812,855],"class_list":{"0":"post-6480","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-news","8":"tag-mobile","9":"tag-privacy","10":"tag-smartphones","11":"tag-tracking","12":"tag-wearable"},"hreflang":[{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/fitness-trackers-privacy\/6480\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/fitness-trackers-privacy\/4295\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/fitness-trackers-privacy\/4219\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/fitness-trackers-privacy\/4739\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/fitness-trackers-privacy\/5862\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/fitness-trackers-privacy\/5264\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/fitness-trackers-privacy\/5862\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/fitness-trackers-privacy\/6480\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/fitness-trackers-privacy\/6480\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com\/blog\/tag\/tracking\/","name":"tracking"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/6480","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/users\/637"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/comments?post=6480"}],"version-history":[{"count":2,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/6480\/revisions"}],"predecessor-version":[{"id":30673,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/6480\/revisions\/30673"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media\/6481"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media?parent=6480"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/categories?post=6480"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/tags?post=6480"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}