We gratefully acknowledge support from
the Simons Foundation and member institutions.
Full-text links:

Download:

Current browse context:

cs.CR

Change to browse by:

cs

References & Citations

DBLP - CS Bibliography

Bookmark

(what is this?)
CiteULike logo BibSonomy logo Mendeley logo del.icio.us logo Digg logo Reddit logo

Computer Science > Cryptography and Security

Title: Attacks on Fitness Trackers Revisited: A Case-Study of Unfit Firmware Security

Authors: Jakob Rieck
Abstract: Fitness trackers - wearables that continuously record a wearer's step count and related activity data - are quickly gaining in popularity. Apart from being useful for individuals seeking a more healthy lifestyle, their data is also being used in court and by insurance companies to adjust premiums. For these use cases, it is essential to ensure authenticity and integrity of data. Here we demonstrate a flaw in the way firmware for Withings' Activit\'e is verified, allowing an adversary to compromise the tracker itself. This type of attack has so far not been applied to fitness trackers. Vendors have started mitigating previous attacks, which manipulated data by interfering with wireless channels, or by physically moving the tracker to fool sensors. Hardware similarities amongst different trackers suggest findings can be transferred to other tracker as well.
Comments: GI Sicherheit 2016
Subjects: Cryptography and Security (cs.CR)
Cite as: arXiv:1604.03313 [cs.CR]
  (or arXiv:1604.03313v1 [cs.CR] for this version)

Submission history

From: Jakob Rieck [view email]
[v1] Tue, 12 Apr 2016 09:14:49 GMT (64kb,D)

Link back to: arXiv, form interface, contact.