Journal
CRYPTOGRAPHY
Volume 5, Issue 4, Pages -Publisher
MDPI
DOI: 10.3390/cryptography5040029
Keywords
confidentiality; general data protection regulation (GDPR); Internet of Things (IoT); personal data; privacy; smart devices
Ask authors/readers for more resources
This research focuses on the threat posed by smart wearable devices to individual data privacy and security, examining data transmission and privacy policies to identify risks in some commercial fitness tracking applications. The impact of personal data collection and transmission on network security and individual privacy is a key consideration.
Individual users' sensitive information, such as heart rate, calories burned, or even sleep patterns, are casually tracked by smart wearable devices to be further processed or exchanged, utilizing the ubiquitous capabilities of Internet of Things (IoT) technologies. This work aims to explore the existing literature on various data privacy concerns, posed by the use of wearable devices, and experimentally analyze the data exchanged through mobile applications, in order to identify the underlying privacy and security risks. Emulating a man-in-the-middle attack scenario, five different commercial fitness tracking bands are examined, in order to test and analyze all data transmitted by each vendor's suggested applications. The amount of personal data collected, processed, and transmitted for advertising purposes was significant and, in some cases, highly affected the network's total overhead. Some of the applications examined requested access for sensitive data driven device functionalities, such as messaging, phone calling, audio recording, and camera usage, without any clear or specific reason stated by their privacy policy. This paper concludes by listing the most critical aspects in terms of privacy and security concerning some of the most popular commercial fitness tracking applications.
Authors
I am an author on this paper
Click your name to claim this paper and add it to your profile.
Reviews
Recommended
No Data Available