TECH
Personal data of military personnel exposed by fitness application
According to the international press, Flow, which is a social network based on physical activity and owned by Polar, has a serious security flaw that can expose the personal address of several military and spies who use the device.As Bellingcat and De Correspondent explain, Flow shares all the physical activities of its users on a common map. This makes it possible to segment the activity of a given account, check the races that start on a military base or any other building affecting the security forces of that country and isolate the remaining ones by identifying any existing pattern with a common point, being that, as a general rule, this common point is the personal housing of the user.Many of the people who use Flow appear on the social network with their real name and it is common to end their exercise sessions near their homes or hotels where they are housed, making it easy to exercise any location.Investigators who conducted the study looked at data from 6,500 users, including soldiers in conflict zones such as Baghdad, NSA employees and the CEO of a large industrial company. This batch increases the security risk inherent in the publication of this data, since any external threat to the security of a country can benefit from the location of its security forces.In response, Polar has already suspended functionality that allows you to exploit other users' physical activity and has admitted that you are developing new options that will help users maintain their privacy and delete their activity logs in their entirety.The study also suggests that companies with fitness solutions that can monitor and share user activity should work on the security and privacy of the systems they offer. The researchers conclude that companies such as Polar and Strava have been very focused on offering social features and that they do not spend so much time in ensuring that users share only those records that are safe to show to the rest of the community.
Sapo
No comments:
Post a Comment