Video summary
The video explores the critical privacy risks associated with the booming market for fitness trackers and wearable health devices, highlighting a significant gap between consumer expectations of data security and current industry practices. Hosts Hudson Hongo and Christian Romero introduce an investigation by Thorin Klosowski from the Electronic Frontier Foundation (EFF), which surveyed ten leading companies in this sector to assess their commitment to protecting sensitive user information. The findings reveal that most manufacturers fail to provide transparency reports, documents that disclose how often law enforcement requests data and whether such requests are fulfilled. Furthermore, apart from Apple's Health app, no other major company offers end-to-end encryption for stored health data, leaving users vulnerable because the device makers themselves retain access to their personal biological information.
To understand why these measures matter, the discussion explains that without transparency reports, consumers must rely on anecdotal evidence or legal leaks to learn if their private data has been handed over to governments, a process that often occurs through obscure court cases rather than public disclosure. The hosts emphasize that end-to-end encryption is essential because it mathematically ensures that only the user can access their health metrics, preventing both the vendor and third parties from selling or sharing this information even if compelled by legal orders. Additionally, the episode suggests an alternative privacy strategy: utilizing offline modes where data stays on the local device or phone without syncing to a cloud server. While some advanced users already employ open-source apps like Gadgetbridge for this purpose, mainstream companies have yet to make these secure options easy and default choices for everyday buyers who may not possess technical expertise.
The conversation concludes with actionable advice for consumers seeking to reclaim control over their digital lives through "digital hygiene" practices and direct engagement with manufacturers. The hosts encourage users to utilize feature request forms on company forums and social platforms like Reddit to demand specific privacy protections such as transparency reports, encryption, and offline capabilities, noting that companies often respond positively when they realize these features can be marketed as selling points rather than just technical necessities. Ultimately, the video argues that while individual vigilance is important, systemic change requires a combination of consumer pressure, public policy advocacy, and corporate responsibility to ensure that health data remains personal and secure against prying eyes from marketers, insurers, and government agencies.
Read the full video transcript
Watches, bands, and rings. If you want
to digitally monitor your fitness, more
companies than ever are selling devices
to do it. And more Americans than ever
now own at least one wearable health
device.
>> What are the companies that make fitness
trackers doing to protect our sensitive
data from prying eyes? Like those
belonging to marketers, insurers, and
even the government. A lot less than
they could be, it turns out. I'm Hudson
Hongo.
>> And I'm Christian Romero. This is a
factor from the Electronic Frontier
Foundation.
>> Later, I'll be quizzing Christian about
the health and fitness wearable
landscape.
>> We'll also let you know about some
upcoming opportunities to connect with
EFF.
>> But first, we'll be talking about a
troubling new EFF survey of fitness
tracker companies and what it reveals
about the privacy of consumer health
data.
So, uh Christian, do you um any kind of
fitness tracker?
>> No, not at all. I I struggle to even
wear a watch on a daily basis. So, no.
>> I I personally did the Fitbit thing for
a while. The sort of end result of that
was just leading me to get uh a regular
watch and wear it, which I think was a
good development. Uh it turns out the
thing that I really needed to track was
just like the uh passage of time.
>> Yeah, it's super important. I wish I
wore my watch more regularly. Have you
uh seen this thing? It's called uh Ollie
Watch, where you can mod like a Casio to
add fitness tracker-y stuff to it. It'll
do like step counting and heart rate
monitoring and stuff. It's It's kind of
cool.
>> I I honestly that appeals
quite a lot to me. I did like just sort
of having I don't know that all of the
data was like really useful, right?
Other than just like oh, basic activity
and like it was good for me to know uh
numerically how much I slept, right? Not
just like how it felt. I can sort of
compare inputs and outputs on that end.
but this is probably the part where we
should put our uh privacy hawk hats on,
which
I imagine as having lots of feathers.
>> And not that comfortable.
>> [laughter]
>> Wouldn't wouldn't be very Yeah, right.
But like but uh covering a lot of the
face, right? A a privacy hawk hat. There
we go. Uh
there are a lot of potential privacy
issues that come with the health and
fitness wearables. Fundamentally, these
are devices that take information from
your body and uh digitize it, which
makes it easier to take a look if, you
know, I want to know how much I've
slept, but also makes it into like
something that's incredibly transferable
to a variety of different parties.
>> Yeah, and uh parties that I think you
typically wouldn't think about when you
like see a flashy ad that's like, "Look
at all this
life-saving stuff this wearable can do
and stuff, you know, you're not thinking
about anything else, but I want that."
>> Right. So, recently our colleague Thorin
Klosowski, uh senior security and
privacy activist at EFF, looked into
this sort of whole category of devices.
Specifically, he surveyed leading
fitness wearable companies to see if
they offered uh two key things, which
were end-to-end encryption and something
called uh transparency reports, which
we'll get into more.
To learn more about exactly what he
found, I chatted with Thorin. Let's
listen in.
Well, hi Thorin. Thanks for dropping by.
>> Yeah, thanks for having me.
>> I wanted to talk today about your
findings on wearable devices and
privacy. So, first off, what inspired
you to take a closer look at this uh
category of devices, which these days I
think includes like
all kinds of fitness watches, rings. I
know that bands are like popular now.
>> Uh it's kind of a long long process in
my brain of looking at this stuff. Um
before I was at EFF, I was at
Wirecutter, so I looked at a lot of like
fitness devices. And so, it's always
kind of been like a thing in my brain.
Um, and then somewhat recently,
journalist Zack Whittaker I was pushing
on Oura, the company who makes like
basically the most popular smart ring,
about their transparency reports, or
lack of transparency reports, I should
say. Um, and then their lack of
end-to-end encryption. And reading his
work kind of inspired me to look at this
again for the first time in maybe five
or six years.
And it turns out not a lot has changed
in that time when it comes to these two
things. Um, so like the basic top-level
thing is that most companies don't do
transparency reports, which is a
very simple report that basically tells
us whether or not law enforcement goes
to them and whether or not law they hand
any data over to law enforcement. It's
usually just a number, like a number of
times they've done this or not done it.
Um, and then no one but Apple offers
end-to-end encryption for the data
that's stored in their health app or
whatever, you know, corresponding app
they use. Um, which is kind of
remarkable, cuz I think people think of
their health data as a very private, um,
kind of just for them sort of thing.
>> Yeah. We know there's a lot of devices
like this on the market today. And well,
as I understand it, a pretty high
percentage of people now own a wearable
health device of some kind. Is that
right?
>> Yeah, well, somewhere around 40% own
one. I think, you know, there's a lot of
caveats there and how often they use it,
you know, all that sort of thing. But,
um, I think most people have interacted
with one of these devices at some point
in the last 10 years or so, and even if
they don't currently, you know, use one
or not.
>> Right. Obviously, any device that's, uh,
as these are, constantly collecting data
produced by your human body,
that's going to pose a variety of
potential privacy risks. Um,
you said the two that you were focusing
on, which were transparency reports and
end-to-end encryption.
Um
I want to get back, why are like
transparency reports important?
>> I think it helps us kind of really
establish
how law enforcement or governments might
be using this sort of data. There's a
lot of like
theory. You know, we can kind of think
through like a lot of the possible
risks, the ways that this might play
out. But without like an actual idea of
how often this happens, you know, how
much governments are coming to these
companies, like it we're just kind of
theorizing. And it would be really nice
to know exactly like how often this
happens, how useful it is. And as like a
you know, a buyer of one of these
things, you kind of want to know what
potential risks there might be there and
like how legitimate that fear is. Like
is it like justified to be worried about
that or is this pretty rare? Like it's
really hard to tell without going
through like literally every court
document.
>> It feels like we find out a lot of about
these vectors for like
government data collection, like just in
really weird anecdotal ways, right?
There'll be like a one court case where
we find out, "Oh, they're using some
sort of smart watch data or something to
try to establish a timeline." And
>> [laughter]
>> that doesn't seem to be a great way to
find out how our sort of personal data
is getting into government hands.
>> Yeah, exactly. It's kind of like that
and then we also have like
evidence is too strong of a word, but we
know that some of the surveillance
companies that like kind of provide
technology to law enforcement have
pointed to wearables as a potential
vector for information that they maybe
haven't thought of. So PenLink has like
a blog that's about that that's like,
"Oh, like if you're you know, looking
into something, like don't forget to
check in with the wearable company to
see if maybe there's some data there you
could use." So we have just like a lot
of this kind of like anecdotal stuff
that like without like really and we in
some cases obviously we know that
they've been used, but like there should
and could be more.
>> Right. And as we know, law enforcement
can get really excited about what they
think they've determined via
uh personal data, and they're not always
uh correct on on those uh conclusions.
>> Yeah, exactly. And these devices make a
lot of uh intuitions about what the data
means that, you know, could easily be,
you know, misunderstood, I think.
>> Okay, so uh I know from your blog that
you looked at 10 specific companies that
are sort of leaders in the consumer
health device space. I'm going to try to
read all of their names now. Uh Amazfit,
Apple, Coros, Garmin, Google, which owns
Fitbit, a Hume, Oura, Polar, Suunto, and
Whoop. And you said of these companies,
who
has made any sort of commitment around
uh government requests for our data?
>> Apple and Google are the two who have
like public commitments that are
actually happening. Um after Zach's
reporting, Oura uh
seems to be considering possibly doing
it also.
>> [laughter]
>> Um so, I think we're going to kind of
hold them to that and make sure that
they actually kind of come through with
that promise. Um another company,
Suunto, um suggested that maybe they
would also consider thinking about it
also. So, we, you know, making a little
bit of a dent and kind of at least
making these companies think about this
stuff. Um I think that Garmin's kind of
the big um
the biggest elephant in the room here
aside from those. It's probably the
biggest It's hard to tell sales-wise,
but I'm guessing it's one of the bigger
companies.
Um they definitely have a law
enforcement portal, so like a place for
law enforcement to come ask for
information, but they didn't respond to
our emails and don't have a transparency
report right now. So, I think pushing on
them a little bit is kind of um
the
the easy Not the easiest target, but the
next clear like big company that needs
to be looked at here.
>> Yeah, and I it
as you sort of suggested like
when you bring these sorts of issues to
the attention of these companies through
reporting, uh public pressure, these
things like that, they often do
I mean, you can nudge them.
>> Yeah, and I think that like maybe these
companies, you know, giving them the
benefit of the doubt here, like maybe
they haven't really thought about this
as an important, you know, utility for
like buyers and you know, something to
to help make their decision a little bit
clearer when you're like deciding
between these devices. They probably
just think of it as like, oh, like what
different health metrics can we collect
and how can we provide that to users? Um
so
hopefully they're thinking about it now
in a way that they weren't before and
they could see this as something that is
a a useful metric for any potential
buyers of their products.
>> So, as you said, the other thing you
looked at was end-to-end encryption. Um
lots of our listeners are probably
familiar with this tool, but for those
who aren't, what is end-to-end
encryption? Why does it matter?
>> Yeah, like the kind of shorthand version
is like end-to-end encryption provides a
way to store data
that the company who makes the device
can't access it. Um so in the case of
health data, it would basically make it
so whatever wearable you have
you know, it syncs to your phone
whatever is stored there, um can only be
accessed by you. That means the company
wouldn't be able to access it and it
means they couldn't provide anything to
law enforcement. That's kind of why
these two things kind of play together.
>> Right. Keeping it private to you means
that maybe the
company, uh the vendor can't access it
and third parties who can,
uh
make any sort of requests to that
company can't access it, either.
>> Yeah, exactly. It makes you know, a lot
of these companies will have a promise
that they don't share or sell data, um
Um, but this kind of is a is a
mathematical assurance if they really
don't have a lot of data to sell or
share anyway.
>> So, I know you've uh personally pressed
a a wide variety of tech companies to
implement end-to-end encryption more
widely. Did you say that the only one of
these um uh health wearable companies
that is using end-to-end encryption is
Apple?
>> Correct. Apple's the only one that has
it um and that's through their health
app only. It's kind of a it's a
important caveat because I think if you
are a Apple Watch wearer, you know that
you can install apps on it and all sorts
of things. Um, and many of those may
collect health data on their own.
They're going to have their own privacy
practices and policies, but if you're
just using an Apple Watch and just using
the Apple Health app, um that is
supporting end-to-end encryption and has
been for a very like since the watch
came out.
>> Okay, so you've mentioned uh what these
companies aren't doing and some of the
things they should be doing. Um, what
else can these companies do to protect
our privacy better?
>> I think the kind of like third pillar
here that kind of all works with with
the previous two, um is offering some
sort of offline mode or a way to like
not sync to the cloud at all. Um, I
think that's kind of a
perhaps easier engineering ask than
employing end-to-end encryption, but
kind of still creates like the same sort
of privacy guarantees. So, like if I
have a Garmin watch, I can have it sync
to my phone and then it just stays there
on my phone and it doesn't leave.
Um, and maybe if I, you know, lose my
phone, I lose that data and but that's
on me. That's my problem, not theirs.
Um, so I think that's kind of the
low-hanging fruit of a solution and it's
kind of like a lot of these devices kind
of operate on the wearable itself
anyway. Like you can technically use a
Garmin watch and just just the watch and
never attach it to the app. Um, you're
going to get like less data and you're
going to be looking at a, you know, 1-in
screen or whatever it is, but like it is
feasible. So, there's it's easy to
imagine that functioning on a phone
also. Um in fact, there's an Android app
called Gadgetbridge that does just this.
It works with a bunch of different
wearable companies.
Um allows you to just store the data in
that app. It doesn't go anywhere. Um and
so, it's it's a proof of concept. It
clearly works. You know, you might lose
out some features. You obviously
wouldn't have the sort of social stuff
um that some of these wearables have. Um
there's a bunch of AI stuff that may or
may not work depending on how they're
employing that. Um but I think as a
choice for consumers to make, it's it's
a it's one that people really
understand. I think it would benefit a
lot of people. Um you know, end-to-end
encryption is nice cuz it's kind of like
um
setting that you don't have to think
about, you know, if like get my mom who
doesn't care about technology at all
like a watch, like it kind of guarantees
that she's able to get those features
where it's, you know, syncing and backed
up to the cloud and kind of do whatever
without like any privacy concerns. Um
whereas offline's a little bit more like
uh nerdier approach to kind of like
control your own data. Um which is still
great and we definitely approve of, but
it is like a different sort of level.
>> But right, easier sort of
technologically and just giving
consumers a choice, right? Instead of
having my extremely personal data about
what my body's doing just kind of out
there, having it contained with the
devices I can physically interact with
and secure.
>> Yeah, I think there's been a um
a whittling down of these apps and these
technologies to like the kind of like
simplest seamless use, and I think that,
you know, we kind of need to introduce a
little bit more friction there for
people who want it. Um because I think
that it's a good way to get your privacy
back without like losing as many of the
features as you might, you know, by just
using the actual device itself, if it
even has a screen.
>> So, we've we've talked about sort of the
vendor end. What can we as consumers do?
>> You know, there's not a lot, but I think
that one thing you can do is if you if
you own one of these devices to kind of
go to the forums, um go to feature
requests, go to the Reddit subreddits,
and like ask for this stuff. I think
being an actual user of the device is
going to give you much more power than
just me being someone saying something
in a blog. Like I think like these
companies really respond to their users
in a way that like it's just going to be
more impactful in that way. And so I
think if you want this stuff like hit
their forums, hit their feature request
pages, and like ask for it.
>> Yeah.
There's a few diff So right, as you
mentioned basically, there's a few
different levers to get these uh
companies that handle our data to be
more privacy protective. And
I I think you mentioned some great ones.
Uh
public campaigns and also just as a
individual consumer saying, "Hey, like
do this for me."
>> Yeah, like I don't remember which ones
exactly have feature requests forms, but
sometimes it's very easy. It's like it's
kind of a somewhat seamless process
where you're just filling out a form and
just being like, "Hey, I would love to
have these three things, you know,
transparency reports, end-to-end
encryption, and a better offline mode."
Um and I think that
you know, it's not like they're going to
listen to every single person, but
they're going to have like a
They want to make their users happy, and
they want to sell more devices. So
whatever they think is going to get them
there. Um and if we if we argue that
privacy is a is a is a standout feature
that they could offer, I think that's
you know, it's something that's a good
selling point, frankly.
>> Well, this was very illuminating. Uh
thanks again for stopping by, Thorin.
>> Yeah, thank you.
>> So really interesting conversation with
Thorin. Uh had me thinking, Christian,
how do you think about
data privacy when you're like looking at
getting a a new device of some kind?
>> Being totally honest here, probably not
as much as I should or as you'd expect.
Like that that primal like I just want
this thing really takes over, you know?
And then it's after the fact where I'm
like, crap, what what does all this
stuff actually do?
>> I I have to say my I myself use
something that's closer to like a a
vibes based auditing system, right?
Like, oh,
listening device of some kind, that's
kind of obviously creepy to me, so I'm
not going to use this.
A few weeks ago, I was thinking about,
you know, maybe a
video doorbell of some kind would be
helpful, but I do know at least with
those often how little control you have
over the data, specifically
the video footage.
I I'm not going to
I can't go individually through the
manufacturers, but like they're
frequently like not end-to-end
encrypted, and even if they offered
that, it's like not on by default. So,
I'm not really into that, but it's not a
particularly structured or thoughtful
approach.
>> And it's so hard, too. Every device
category has its own different things
that you need to worry about, whether it
is something like a camera, or maybe you
want to get like a speaker that listens
to you, and you can call out to the
ether like, hey, turn the lights on and
off and stuff. You know, you you can
kind of figure out what companies you
should stray away from, since a lot of
them have like a suite of products,
but it takes a lot of research to kind
of figure these things out, I would say.
>> And I I think
I know I ended up in this place, that
the instinct is like, oh, can I just
like, is there a way to just like buy my
research and shop my way out of these
issues? Which, you know, to some extent
it's like good to know, like you said,
okay, what is this company specifically,
what sort of protections do they have,
you know, what are they doing, but
one thing that I've really liked about
the way that
Thorin approaches devices and privacy is
something that's closer to like I I
think we've used this term, like digital
hygiene, right? You know, oh, it's that
time of year again, I need a dental
cleaning, and also I should check, you
know, what apps are on my phone that I
don't need anymore.
>> Yeah, this is something I should really
implement more regularly. Um I also
appreciate that in a lot of the work
Thorin does and EFF does in general,
it's a lot of like demanding all
companies to do better. It's not just
like the big players. We need standards.
You shouldn't need to put this much
thought into like
um is this company sending my
information to like
uh the government or AI data centers or
anything without me knowing? [laughter]
>> Right. I mean, right. And I'm you know,
and there's different levers, right?
There's like uh
true sort of uh public policy. There's
like I said, sort of the individual
thing, which is always what we kind of
want is like, can I just sort of solve
it? But a really important one is just
getting these companies to do right by
their customers. And you know, you can
be part of that. Like Thorin said, you
can say, "Hey, please do this thing."
>> Yeah, and you know, people being loud
about what they want, like it works a
little better than you would think, I'd
I'd say.
>> Yeah, right. I mean, there's they do
have some sort of sensitivity when it
comes to, "Oh, our customers are very
upset." Or, you know, sometimes it's
they think about it like a feature and
just not enough people have demanded it.
Or even like, I know in some cases that
internally with these companies, there
are people there who like want to bring
the feature out, but don't have the kind
of mandate they'd need from customer
requests, right? Like, "Oh, this would
be good, but nobody really cares, so
we're not going to do it." But if people
say they care, maybe they will. Anyway,
this is a good time as ever to I I
should put it on my calendar, but do a
like uh one of these digital hygiene
checks.
Delete the apps I don't need, don't use,
and uh check who's getting access to my
location data. Sort of a left turn from
um
health wearables, but you know, always
good.
>> Quick break to remind you EFF is a
member-supported nonprofit and your
support is what makes this work
possible. If you want to help EFF keep
fighting for your digital privacy, head
to eff.org/podfan.
>> [music]
>> For as little as $10 a month, you'll get
our latest member t-shirt and join the
community of over 30,000 EFF members
fighting to make sure technology works
for everyone. That's eff.org/podfan.
One more time, eff.org/podfan.
All right,
>> [music]
>> back to the show.
>> Okay, Christian. So, this week I wanted
to test just how closely you read
Thorin's blog post. He looked at 10
companies that make health and fitness
wearables. Do you think you could
remember the names of all of those
companies?
>> I remember like glossing through the
list of companies and being like, I what
are some of these names?
>> This is a bit like last time when I
asked you to
um
Well, I want to do this quiz a little
bit like the last one when I asked you
to distinguish the names of real bills
in the Kids Act from names I made up. Uh
this time I'm going to ask you about
companies that make fitness tracking
devices and whether it's a real name or
one I came up with.
Are you Are you feeling ready for this?
>> Yeah, we'll we'll see if you're just as
good at naming companies as you were at
naming
bill acronyms. We'll see.
>> Good. Okay.
Here we go. I'm going to do three sets.
First one, uh which is the real fitness
and health wearable company?
Whoop or Hoot?
>> Whoop is right.
>> Okay, good. That was I was trying to
start you off with an easy one. That's
like a fairly popular
company in the space. I think Hoot would
be a great name.
>> It would be a hoot. Yes, it would.
>> Yeah, and the and the logo's so obvious.
You get a little owl, maybe like a buff
owl. I don't know.
>> Actually imagining a buff owl in my head
is not not really a pleasant thought, I
don't think. No. [laughter]
>> You know, kind of like Smokey the Bear,
but just like, you know, an owl. I don't
know about rip birds. Okay, next one.
Uh Bewellist or Amazfit?
>> You know, Amazfit Amazfit is not a very
good name, but I know that's the right
one.
>> Great. Good job. Correct. Bewellist,
that's the one I made up.
>> I think Bewellist is better, honestly.
>> [laughter]
>> I don't want to clown on like a random
company's name, but I do not like
Amazfit Amazfit. I can't even say it
right.
>> it's not That's the problem is it's not
immediately clear
how you say that. A second A. Okay.
You're two for two. Last one.
Kant or Hume?
>> Oh, this one's actually hard.
Uh I'm going to go with
Kant.
>> That is incorrect.
>> Dang. I was like the It's got to be the
worst-sounding one. No offense to your
name, but
>> No, I mean well, the real company's Hume
and I thought, you know, that's also the
name of a
philosopher. I've went with a different
18th-century philosopher, Immanuel Kant,
and I thought that was the closest. I
think Hume is like supposed to be like
maybe human, I don't know.
>> It's clever. Clever.
Clever on all fronts right now.
>> Well, good. Well, you were two for
three, which is pretty good given that
these are kind of, you know, they're
device makers, they're nonsense sounds.
You just need something that's a unique
string of characters, and how many words
do we have left?
>> Yeah, you you couldn't go
uh all of the companies that were listed
cuz then at some point it would have
been like, you know, is the name Apple
or banana?
>> Yeah, right. [laughter]
Not much of a quiz there. Okay, I think
you did pretty good. And you And you
actually knew them instead of just
detecting which one was fake.
And now, events and opportunities.
Christian, how can people connect with
EFF in the weeks to come? Yeah, next
week starting on August 3rd, you can
catch EFF at the three Las Vegas
security conferences, uh BSides Las
Vegas, Black Hat, and Def Con. We'll
have our limited Def Con t-shirt for the
full week. So, if you're in Vegas, stop
by our membership booth and grab one
while you're there. I just saw that the
weather check for the whole week is like
over 110, so come beat the heat with
EFF, I guess.
Um then the following weekend, August
14th through the 16th, you can catch EFF
at HOPE in New York. The conference is
back in Manhattan this year, and current
members should be on the lookout for a
speak easy invitation, as well. And
looking further ahead, EFF will be at
TechCrunch Disrupt at the end of
October. If you're planning to attend,
you can get discounts on tickets with
our code TCEFF
Disrupt. Uh you can find that code and
learn more about other events EFF is
attending at eff.org/events.
>> Very cool. That sounds like a lot of
travel for you in the future, Christian.
>> Yeah, you'll see me on uh
the West Coast for an entire week, and
then like 2 days later, I'm going to the
East Coast. Going on tour, come say hi.
I love chatting with people.
>> You need to get it like the just the
Christian tour shirt with all of the
uh cities on the back.
>> Actually, that's a really good shirt
idea, yeah. I'm I'm going to get right
on that.
>> Cool. Well, that's it for this week's
Affecter.
Uh Affecter is a podcast by the
Electronic Frontier Foundation, the
leading nonprofit defending online civil
liberties.
Our music is I don't know by Grapes.
>> EFF promotes digital innovation, defends
free speech, fights illegal
surveillance, and protects rights and
freedoms for all. Become an EFF member
today at eff.org/podfan.
>> Your organization can also join the
fight for digital freedom by supporting
EFF in this podcast. Our work inspires a
broad audience of activists,
technologists, legal experts, creators,
gamers, hackers, and everyone who relies
on digital tools in their daily lives.
Learn more about sponsorship at
eff.org/thanks.