Submind YouTube summaries
Thumbnail for Health Data Is Personal. Fitness Trackers Should Keep It That Way.

Health Data Is Personal. Fitness Trackers Should Keep It That Way.

Watch on YouTube

Video summary

The video explores the critical privacy risks associated with the booming market for fitness trackers and wearable health devices, highlighting a significant gap between consumer expectations of data security and current industry practices. Hosts Hudson Hongo and Christian Romero introduce an investigation by Thorin Klosowski from the Electronic Frontier Foundation (EFF), which surveyed ten leading companies in this sector to assess their commitment to protecting sensitive user information. The findings reveal that most manufacturers fail to provide transparency reports, documents that disclose how often law enforcement requests data and whether such requests are fulfilled. Furthermore, apart from Apple's Health app, no other major company offers end-to-end encryption for stored health data, leaving users vulnerable because the device makers themselves retain access to their personal biological information. To understand why these measures matter, the discussion explains that without transparency reports, consumers must rely on anecdotal evidence or legal leaks to learn if their private data has been handed over to governments, a process that often occurs through obscure court cases rather than public disclosure. The hosts emphasize that end-to-end encryption is essential because it mathematically ensures that only the user can access their health metrics, preventing both the vendor and third parties from selling or sharing this information even if compelled by legal orders. Additionally, the episode suggests an alternative privacy strategy: utilizing offline modes where data stays on the local device or phone without syncing to a cloud server. While some advanced users already employ open-source apps like Gadgetbridge for this purpose, mainstream companies have yet to make these secure options easy and default choices for everyday buyers who may not possess technical expertise. The conversation concludes with actionable advice for consumers seeking to reclaim control over their digital lives through "digital hygiene" practices and direct engagement with manufacturers. The hosts encourage users to utilize feature request forms on company forums and social platforms like Reddit to demand specific privacy protections such as transparency reports, encryption, and offline capabilities, noting that companies often respond positively when they realize these features can be marketed as selling points rather than just technical necessities. Ultimately, the video argues that while individual vigilance is important, systemic change requires a combination of consumer pressure, public policy advocacy, and corporate responsibility to ensure that health data remains personal and secure against prying eyes from marketers, insurers, and government agencies.
Read the full video transcript
Watches, bands, and rings. If you want to digitally monitor your fitness, more companies than ever are selling devices to do it. And more Americans than ever now own at least one wearable health device. >> What are the companies that make fitness trackers doing to protect our sensitive data from prying eyes? Like those belonging to marketers, insurers, and even the government. A lot less than they could be, it turns out. I'm Hudson Hongo. >> And I'm Christian Romero. This is a factor from the Electronic Frontier Foundation. >> Later, I'll be quizzing Christian about the health and fitness wearable landscape. >> We'll also let you know about some upcoming opportunities to connect with EFF. >> But first, we'll be talking about a troubling new EFF survey of fitness tracker companies and what it reveals about the privacy of consumer health data. So, uh Christian, do you um any kind of fitness tracker? >> No, not at all. I I struggle to even wear a watch on a daily basis. So, no. >> I I personally did the Fitbit thing for a while. The sort of end result of that was just leading me to get uh a regular watch and wear it, which I think was a good development. Uh it turns out the thing that I really needed to track was just like the uh passage of time. >> Yeah, it's super important. I wish I wore my watch more regularly. Have you uh seen this thing? It's called uh Ollie Watch, where you can mod like a Casio to add fitness tracker-y stuff to it. It'll do like step counting and heart rate monitoring and stuff. It's It's kind of cool. >> I I honestly that appeals quite a lot to me. I did like just sort of having I don't know that all of the data was like really useful, right? Other than just like oh, basic activity and like it was good for me to know uh numerically how much I slept, right? Not just like how it felt. I can sort of compare inputs and outputs on that end. but this is probably the part where we should put our uh privacy hawk hats on, which I imagine as having lots of feathers. >> And not that comfortable. >> [laughter] >> Wouldn't wouldn't be very Yeah, right. But like but uh covering a lot of the face, right? A a privacy hawk hat. There we go. Uh there are a lot of potential privacy issues that come with the health and fitness wearables. Fundamentally, these are devices that take information from your body and uh digitize it, which makes it easier to take a look if, you know, I want to know how much I've slept, but also makes it into like something that's incredibly transferable to a variety of different parties. >> Yeah, and uh parties that I think you typically wouldn't think about when you like see a flashy ad that's like, "Look at all this life-saving stuff this wearable can do and stuff, you know, you're not thinking about anything else, but I want that." >> Right. So, recently our colleague Thorin Klosowski, uh senior security and privacy activist at EFF, looked into this sort of whole category of devices. Specifically, he surveyed leading fitness wearable companies to see if they offered uh two key things, which were end-to-end encryption and something called uh transparency reports, which we'll get into more. To learn more about exactly what he found, I chatted with Thorin. Let's listen in. Well, hi Thorin. Thanks for dropping by. >> Yeah, thanks for having me. >> I wanted to talk today about your findings on wearable devices and privacy. So, first off, what inspired you to take a closer look at this uh category of devices, which these days I think includes like all kinds of fitness watches, rings. I know that bands are like popular now. >> Uh it's kind of a long long process in my brain of looking at this stuff. Um before I was at EFF, I was at Wirecutter, so I looked at a lot of like fitness devices. And so, it's always kind of been like a thing in my brain. Um, and then somewhat recently, journalist Zack Whittaker I was pushing on Oura, the company who makes like basically the most popular smart ring, about their transparency reports, or lack of transparency reports, I should say. Um, and then their lack of end-to-end encryption. And reading his work kind of inspired me to look at this again for the first time in maybe five or six years. And it turns out not a lot has changed in that time when it comes to these two things. Um, so like the basic top-level thing is that most companies don't do transparency reports, which is a very simple report that basically tells us whether or not law enforcement goes to them and whether or not law they hand any data over to law enforcement. It's usually just a number, like a number of times they've done this or not done it. Um, and then no one but Apple offers end-to-end encryption for the data that's stored in their health app or whatever, you know, corresponding app they use. Um, which is kind of remarkable, cuz I think people think of their health data as a very private, um, kind of just for them sort of thing. >> Yeah. We know there's a lot of devices like this on the market today. And well, as I understand it, a pretty high percentage of people now own a wearable health device of some kind. Is that right? >> Yeah, well, somewhere around 40% own one. I think, you know, there's a lot of caveats there and how often they use it, you know, all that sort of thing. But, um, I think most people have interacted with one of these devices at some point in the last 10 years or so, and even if they don't currently, you know, use one or not. >> Right. Obviously, any device that's, uh, as these are, constantly collecting data produced by your human body, that's going to pose a variety of potential privacy risks. Um, you said the two that you were focusing on, which were transparency reports and end-to-end encryption. Um I want to get back, why are like transparency reports important? >> I think it helps us kind of really establish how law enforcement or governments might be using this sort of data. There's a lot of like theory. You know, we can kind of think through like a lot of the possible risks, the ways that this might play out. But without like an actual idea of how often this happens, you know, how much governments are coming to these companies, like it we're just kind of theorizing. And it would be really nice to know exactly like how often this happens, how useful it is. And as like a you know, a buyer of one of these things, you kind of want to know what potential risks there might be there and like how legitimate that fear is. Like is it like justified to be worried about that or is this pretty rare? Like it's really hard to tell without going through like literally every court document. >> It feels like we find out a lot of about these vectors for like government data collection, like just in really weird anecdotal ways, right? There'll be like a one court case where we find out, "Oh, they're using some sort of smart watch data or something to try to establish a timeline." And >> [laughter] >> that doesn't seem to be a great way to find out how our sort of personal data is getting into government hands. >> Yeah, exactly. It's kind of like that and then we also have like evidence is too strong of a word, but we know that some of the surveillance companies that like kind of provide technology to law enforcement have pointed to wearables as a potential vector for information that they maybe haven't thought of. So PenLink has like a blog that's about that that's like, "Oh, like if you're you know, looking into something, like don't forget to check in with the wearable company to see if maybe there's some data there you could use." So we have just like a lot of this kind of like anecdotal stuff that like without like really and we in some cases obviously we know that they've been used, but like there should and could be more. >> Right. And as we know, law enforcement can get really excited about what they think they've determined via uh personal data, and they're not always uh correct on on those uh conclusions. >> Yeah, exactly. And these devices make a lot of uh intuitions about what the data means that, you know, could easily be, you know, misunderstood, I think. >> Okay, so uh I know from your blog that you looked at 10 specific companies that are sort of leaders in the consumer health device space. I'm going to try to read all of their names now. Uh Amazfit, Apple, Coros, Garmin, Google, which owns Fitbit, a Hume, Oura, Polar, Suunto, and Whoop. And you said of these companies, who has made any sort of commitment around uh government requests for our data? >> Apple and Google are the two who have like public commitments that are actually happening. Um after Zach's reporting, Oura uh seems to be considering possibly doing it also. >> [laughter] >> Um so, I think we're going to kind of hold them to that and make sure that they actually kind of come through with that promise. Um another company, Suunto, um suggested that maybe they would also consider thinking about it also. So, we, you know, making a little bit of a dent and kind of at least making these companies think about this stuff. Um I think that Garmin's kind of the big um the biggest elephant in the room here aside from those. It's probably the biggest It's hard to tell sales-wise, but I'm guessing it's one of the bigger companies. Um they definitely have a law enforcement portal, so like a place for law enforcement to come ask for information, but they didn't respond to our emails and don't have a transparency report right now. So, I think pushing on them a little bit is kind of um the the easy Not the easiest target, but the next clear like big company that needs to be looked at here. >> Yeah, and I it as you sort of suggested like when you bring these sorts of issues to the attention of these companies through reporting, uh public pressure, these things like that, they often do I mean, you can nudge them. >> Yeah, and I think that like maybe these companies, you know, giving them the benefit of the doubt here, like maybe they haven't really thought about this as an important, you know, utility for like buyers and you know, something to to help make their decision a little bit clearer when you're like deciding between these devices. They probably just think of it as like, oh, like what different health metrics can we collect and how can we provide that to users? Um so hopefully they're thinking about it now in a way that they weren't before and they could see this as something that is a a useful metric for any potential buyers of their products. >> So, as you said, the other thing you looked at was end-to-end encryption. Um lots of our listeners are probably familiar with this tool, but for those who aren't, what is end-to-end encryption? Why does it matter? >> Yeah, like the kind of shorthand version is like end-to-end encryption provides a way to store data that the company who makes the device can't access it. Um so in the case of health data, it would basically make it so whatever wearable you have you know, it syncs to your phone whatever is stored there, um can only be accessed by you. That means the company wouldn't be able to access it and it means they couldn't provide anything to law enforcement. That's kind of why these two things kind of play together. >> Right. Keeping it private to you means that maybe the company, uh the vendor can't access it and third parties who can, uh make any sort of requests to that company can't access it, either. >> Yeah, exactly. It makes you know, a lot of these companies will have a promise that they don't share or sell data, um Um, but this kind of is a is a mathematical assurance if they really don't have a lot of data to sell or share anyway. >> So, I know you've uh personally pressed a a wide variety of tech companies to implement end-to-end encryption more widely. Did you say that the only one of these um uh health wearable companies that is using end-to-end encryption is Apple? >> Correct. Apple's the only one that has it um and that's through their health app only. It's kind of a it's a important caveat because I think if you are a Apple Watch wearer, you know that you can install apps on it and all sorts of things. Um, and many of those may collect health data on their own. They're going to have their own privacy practices and policies, but if you're just using an Apple Watch and just using the Apple Health app, um that is supporting end-to-end encryption and has been for a very like since the watch came out. >> Okay, so you've mentioned uh what these companies aren't doing and some of the things they should be doing. Um, what else can these companies do to protect our privacy better? >> I think the kind of like third pillar here that kind of all works with with the previous two, um is offering some sort of offline mode or a way to like not sync to the cloud at all. Um, I think that's kind of a perhaps easier engineering ask than employing end-to-end encryption, but kind of still creates like the same sort of privacy guarantees. So, like if I have a Garmin watch, I can have it sync to my phone and then it just stays there on my phone and it doesn't leave. Um, and maybe if I, you know, lose my phone, I lose that data and but that's on me. That's my problem, not theirs. Um, so I think that's kind of the low-hanging fruit of a solution and it's kind of like a lot of these devices kind of operate on the wearable itself anyway. Like you can technically use a Garmin watch and just just the watch and never attach it to the app. Um, you're going to get like less data and you're going to be looking at a, you know, 1-in screen or whatever it is, but like it is feasible. So, there's it's easy to imagine that functioning on a phone also. Um in fact, there's an Android app called Gadgetbridge that does just this. It works with a bunch of different wearable companies. Um allows you to just store the data in that app. It doesn't go anywhere. Um and so, it's it's a proof of concept. It clearly works. You know, you might lose out some features. You obviously wouldn't have the sort of social stuff um that some of these wearables have. Um there's a bunch of AI stuff that may or may not work depending on how they're employing that. Um but I think as a choice for consumers to make, it's it's a it's one that people really understand. I think it would benefit a lot of people. Um you know, end-to-end encryption is nice cuz it's kind of like um setting that you don't have to think about, you know, if like get my mom who doesn't care about technology at all like a watch, like it kind of guarantees that she's able to get those features where it's, you know, syncing and backed up to the cloud and kind of do whatever without like any privacy concerns. Um whereas offline's a little bit more like uh nerdier approach to kind of like control your own data. Um which is still great and we definitely approve of, but it is like a different sort of level. >> But right, easier sort of technologically and just giving consumers a choice, right? Instead of having my extremely personal data about what my body's doing just kind of out there, having it contained with the devices I can physically interact with and secure. >> Yeah, I think there's been a um a whittling down of these apps and these technologies to like the kind of like simplest seamless use, and I think that, you know, we kind of need to introduce a little bit more friction there for people who want it. Um because I think that it's a good way to get your privacy back without like losing as many of the features as you might, you know, by just using the actual device itself, if it even has a screen. >> So, we've we've talked about sort of the vendor end. What can we as consumers do? >> You know, there's not a lot, but I think that one thing you can do is if you if you own one of these devices to kind of go to the forums, um go to feature requests, go to the Reddit subreddits, and like ask for this stuff. I think being an actual user of the device is going to give you much more power than just me being someone saying something in a blog. Like I think like these companies really respond to their users in a way that like it's just going to be more impactful in that way. And so I think if you want this stuff like hit their forums, hit their feature request pages, and like ask for it. >> Yeah. There's a few diff So right, as you mentioned basically, there's a few different levers to get these uh companies that handle our data to be more privacy protective. And I I think you mentioned some great ones. Uh public campaigns and also just as a individual consumer saying, "Hey, like do this for me." >> Yeah, like I don't remember which ones exactly have feature requests forms, but sometimes it's very easy. It's like it's kind of a somewhat seamless process where you're just filling out a form and just being like, "Hey, I would love to have these three things, you know, transparency reports, end-to-end encryption, and a better offline mode." Um and I think that you know, it's not like they're going to listen to every single person, but they're going to have like a They want to make their users happy, and they want to sell more devices. So whatever they think is going to get them there. Um and if we if we argue that privacy is a is a is a standout feature that they could offer, I think that's you know, it's something that's a good selling point, frankly. >> Well, this was very illuminating. Uh thanks again for stopping by, Thorin. >> Yeah, thank you. >> So really interesting conversation with Thorin. Uh had me thinking, Christian, how do you think about data privacy when you're like looking at getting a a new device of some kind? >> Being totally honest here, probably not as much as I should or as you'd expect. Like that that primal like I just want this thing really takes over, you know? And then it's after the fact where I'm like, crap, what what does all this stuff actually do? >> I I have to say my I myself use something that's closer to like a a vibes based auditing system, right? Like, oh, listening device of some kind, that's kind of obviously creepy to me, so I'm not going to use this. A few weeks ago, I was thinking about, you know, maybe a video doorbell of some kind would be helpful, but I do know at least with those often how little control you have over the data, specifically the video footage. I I'm not going to I can't go individually through the manufacturers, but like they're frequently like not end-to-end encrypted, and even if they offered that, it's like not on by default. So, I'm not really into that, but it's not a particularly structured or thoughtful approach. >> And it's so hard, too. Every device category has its own different things that you need to worry about, whether it is something like a camera, or maybe you want to get like a speaker that listens to you, and you can call out to the ether like, hey, turn the lights on and off and stuff. You know, you you can kind of figure out what companies you should stray away from, since a lot of them have like a suite of products, but it takes a lot of research to kind of figure these things out, I would say. >> And I I think I know I ended up in this place, that the instinct is like, oh, can I just like, is there a way to just like buy my research and shop my way out of these issues? Which, you know, to some extent it's like good to know, like you said, okay, what is this company specifically, what sort of protections do they have, you know, what are they doing, but one thing that I've really liked about the way that Thorin approaches devices and privacy is something that's closer to like I I think we've used this term, like digital hygiene, right? You know, oh, it's that time of year again, I need a dental cleaning, and also I should check, you know, what apps are on my phone that I don't need anymore. >> Yeah, this is something I should really implement more regularly. Um I also appreciate that in a lot of the work Thorin does and EFF does in general, it's a lot of like demanding all companies to do better. It's not just like the big players. We need standards. You shouldn't need to put this much thought into like um is this company sending my information to like uh the government or AI data centers or anything without me knowing? [laughter] >> Right. I mean, right. And I'm you know, and there's different levers, right? There's like uh true sort of uh public policy. There's like I said, sort of the individual thing, which is always what we kind of want is like, can I just sort of solve it? But a really important one is just getting these companies to do right by their customers. And you know, you can be part of that. Like Thorin said, you can say, "Hey, please do this thing." >> Yeah, and you know, people being loud about what they want, like it works a little better than you would think, I'd I'd say. >> Yeah, right. I mean, there's they do have some sort of sensitivity when it comes to, "Oh, our customers are very upset." Or, you know, sometimes it's they think about it like a feature and just not enough people have demanded it. Or even like, I know in some cases that internally with these companies, there are people there who like want to bring the feature out, but don't have the kind of mandate they'd need from customer requests, right? Like, "Oh, this would be good, but nobody really cares, so we're not going to do it." But if people say they care, maybe they will. Anyway, this is a good time as ever to I I should put it on my calendar, but do a like uh one of these digital hygiene checks. Delete the apps I don't need, don't use, and uh check who's getting access to my location data. Sort of a left turn from um health wearables, but you know, always good. >> Quick break to remind you EFF is a member-supported nonprofit and your support is what makes this work possible. If you want to help EFF keep fighting for your digital privacy, head to eff.org/podfan. >> [music] >> For as little as $10 a month, you'll get our latest member t-shirt and join the community of over 30,000 EFF members fighting to make sure technology works for everyone. That's eff.org/podfan. One more time, eff.org/podfan. All right, >> [music] >> back to the show. >> Okay, Christian. So, this week I wanted to test just how closely you read Thorin's blog post. He looked at 10 companies that make health and fitness wearables. Do you think you could remember the names of all of those companies? >> I remember like glossing through the list of companies and being like, I what are some of these names? >> This is a bit like last time when I asked you to um Well, I want to do this quiz a little bit like the last one when I asked you to distinguish the names of real bills in the Kids Act from names I made up. Uh this time I'm going to ask you about companies that make fitness tracking devices and whether it's a real name or one I came up with. Are you Are you feeling ready for this? >> Yeah, we'll we'll see if you're just as good at naming companies as you were at naming bill acronyms. We'll see. >> Good. Okay. Here we go. I'm going to do three sets. First one, uh which is the real fitness and health wearable company? Whoop or Hoot? >> Whoop is right. >> Okay, good. That was I was trying to start you off with an easy one. That's like a fairly popular company in the space. I think Hoot would be a great name. >> It would be a hoot. Yes, it would. >> Yeah, and the and the logo's so obvious. You get a little owl, maybe like a buff owl. I don't know. >> Actually imagining a buff owl in my head is not not really a pleasant thought, I don't think. No. [laughter] >> You know, kind of like Smokey the Bear, but just like, you know, an owl. I don't know about rip birds. Okay, next one. Uh Bewellist or Amazfit? >> You know, Amazfit Amazfit is not a very good name, but I know that's the right one. >> Great. Good job. Correct. Bewellist, that's the one I made up. >> I think Bewellist is better, honestly. >> [laughter] >> I don't want to clown on like a random company's name, but I do not like Amazfit Amazfit. I can't even say it right. >> it's not That's the problem is it's not immediately clear how you say that. A second A. Okay. You're two for two. Last one. Kant or Hume? >> Oh, this one's actually hard. Uh I'm going to go with Kant. >> That is incorrect. >> Dang. I was like the It's got to be the worst-sounding one. No offense to your name, but >> No, I mean well, the real company's Hume and I thought, you know, that's also the name of a philosopher. I've went with a different 18th-century philosopher, Immanuel Kant, and I thought that was the closest. I think Hume is like supposed to be like maybe human, I don't know. >> It's clever. Clever. Clever on all fronts right now. >> Well, good. Well, you were two for three, which is pretty good given that these are kind of, you know, they're device makers, they're nonsense sounds. You just need something that's a unique string of characters, and how many words do we have left? >> Yeah, you you couldn't go uh all of the companies that were listed cuz then at some point it would have been like, you know, is the name Apple or banana? >> Yeah, right. [laughter] Not much of a quiz there. Okay, I think you did pretty good. And you And you actually knew them instead of just detecting which one was fake. And now, events and opportunities. Christian, how can people connect with EFF in the weeks to come? Yeah, next week starting on August 3rd, you can catch EFF at the three Las Vegas security conferences, uh BSides Las Vegas, Black Hat, and Def Con. We'll have our limited Def Con t-shirt for the full week. So, if you're in Vegas, stop by our membership booth and grab one while you're there. I just saw that the weather check for the whole week is like over 110, so come beat the heat with EFF, I guess. Um then the following weekend, August 14th through the 16th, you can catch EFF at HOPE in New York. The conference is back in Manhattan this year, and current members should be on the lookout for a speak easy invitation, as well. And looking further ahead, EFF will be at TechCrunch Disrupt at the end of October. If you're planning to attend, you can get discounts on tickets with our code TCEFF Disrupt. Uh you can find that code and learn more about other events EFF is attending at eff.org/events. >> Very cool. That sounds like a lot of travel for you in the future, Christian. >> Yeah, you'll see me on uh the West Coast for an entire week, and then like 2 days later, I'm going to the East Coast. Going on tour, come say hi. I love chatting with people. >> You need to get it like the just the Christian tour shirt with all of the uh cities on the back. >> Actually, that's a really good shirt idea, yeah. I'm I'm going to get right on that. >> Cool. Well, that's it for this week's Affecter. Uh Affecter is a podcast by the Electronic Frontier Foundation, the leading nonprofit defending online civil liberties. Our music is I don't know by Grapes. >> EFF promotes digital innovation, defends free speech, fights illegal surveillance, and protects rights and freedoms for all. Become an EFF member today at eff.org/podfan. >> Your organization can also join the fight for digital freedom by supporting EFF in this podcast. Our work inspires a broad audience of activists, technologists, legal experts, creators, gamers, hackers, and everyone who relies on digital tools in their daily lives. Learn more about sponsorship at eff.org/thanks.