Investigating Wearable Fitness Applications: Data Privacy and Digital Forensics Analysis on Android
Wearable devices are becoming more and more prevalent in our daily lives as people become more curious about how well they are doing in monitoring, improving, or maintaining their health and fitness. Fitness trackers and smartwatches have become almost ubiquitous, so these devices have begun to play...
Main Authors: | , , , , , , , , |
---|---|
Format: | Article |
Language: | English |
Published: |
MDPI AG
2022-09-01
|
Series: | Applied Sciences |
Subjects: | |
Online Access: | https://www.mdpi.com/2076-3417/12/19/9747 |
_version_ | 1797480710631587840 |
---|---|
author | Shinelle Hutchinson Mohammad Meraj Mirza Nicholas West Umit Karabiyik Marcus K. Rogers Tathagata Mukherjee Sudhir Aggarwal Haeyong Chung Carrie Pettus-Davis |
author_facet | Shinelle Hutchinson Mohammad Meraj Mirza Nicholas West Umit Karabiyik Marcus K. Rogers Tathagata Mukherjee Sudhir Aggarwal Haeyong Chung Carrie Pettus-Davis |
author_sort | Shinelle Hutchinson |
collection | DOAJ |
description | Wearable devices are becoming more and more prevalent in our daily lives as people become more curious about how well they are doing in monitoring, improving, or maintaining their health and fitness. Fitness trackers and smartwatches have become almost ubiquitous, so these devices have begun to play a critical role in forensic investigations. In this paper, the authors conducted a forensic analysis of the controlling applications for three popular fitness bands and smartwatches (i.e., Amazon Halo, Garmin Connect, and Mobvoi) on an Android smartphone device to (1) provide forensic investigators with a road-map of forensically relevant data that are stored within these applications and (2) highlight any privacy concerns that the stored data within these applications may present to the applications’ users. Our findings indicate that the three fitness applications store a wealth of user data. In particular, the Amazon Halo app stores daily, weekly, and monthly activity-related data for at least the last 13 days. The user’s Tone Analysis results were also recovered. The Garmin Connect application also records detailed user activity information, as it was possible to recover the last 15 days worth of user activity data. The Garmin Connect user’s general location was also determined via the application’s weather notification feature. Lastly, the Mobvoi application records all data points from the time the device is first used until the last time the device is used. These data points may include heart rates taken every 5 min and step counts. Our findings highlight the possibility of collecting personally identifiable information about users of these devices and apps, including their profile information, habits, location, and state of mind. These findings would be pertinent to forensic investigators in the event that these or similar applications are part of an investigation. |
first_indexed | 2024-03-09T22:04:00Z |
format | Article |
id | doaj.art-e07105e0a6504b45a3139594be39768d |
institution | Directory Open Access Journal |
issn | 2076-3417 |
language | English |
last_indexed | 2024-03-09T22:04:00Z |
publishDate | 2022-09-01 |
publisher | MDPI AG |
record_format | Article |
series | Applied Sciences |
spelling | doaj.art-e07105e0a6504b45a3139594be39768d2023-11-23T19:45:02ZengMDPI AGApplied Sciences2076-34172022-09-011219974710.3390/app12199747Investigating Wearable Fitness Applications: Data Privacy and Digital Forensics Analysis on AndroidShinelle Hutchinson0Mohammad Meraj Mirza1Nicholas West2Umit Karabiyik3Marcus K. Rogers4Tathagata Mukherjee5Sudhir Aggarwal6Haeyong Chung7Carrie Pettus-Davis8Department of Computer and Information Technology, Purdue University, West Lafayette, IN 47905, USADepartment of Computer and Information Technology, Purdue University, West Lafayette, IN 47905, USADepartment of Computer Science, University of Alabama in Huntsville, Huntsville, AL 35899, USADepartment of Computer and Information Technology, Purdue University, West Lafayette, IN 47905, USADepartment of Computer and Information Technology, Purdue University, West Lafayette, IN 47905, USADepartment of Computer Science, University of Alabama in Huntsville, Huntsville, AL 35899, USADepartment of Computer Science, Florida State University, Tallahassee, FL 32304, USADepartment of Computer Science, University of Alabama in Huntsville, Huntsville, AL 35899, USAJustice System Partners, P.O. Box 970, South Easton, MA 02375, USAWearable devices are becoming more and more prevalent in our daily lives as people become more curious about how well they are doing in monitoring, improving, or maintaining their health and fitness. Fitness trackers and smartwatches have become almost ubiquitous, so these devices have begun to play a critical role in forensic investigations. In this paper, the authors conducted a forensic analysis of the controlling applications for three popular fitness bands and smartwatches (i.e., Amazon Halo, Garmin Connect, and Mobvoi) on an Android smartphone device to (1) provide forensic investigators with a road-map of forensically relevant data that are stored within these applications and (2) highlight any privacy concerns that the stored data within these applications may present to the applications’ users. Our findings indicate that the three fitness applications store a wealth of user data. In particular, the Amazon Halo app stores daily, weekly, and monthly activity-related data for at least the last 13 days. The user’s Tone Analysis results were also recovered. The Garmin Connect application also records detailed user activity information, as it was possible to recover the last 15 days worth of user activity data. The Garmin Connect user’s general location was also determined via the application’s weather notification feature. Lastly, the Mobvoi application records all data points from the time the device is first used until the last time the device is used. These data points may include heart rates taken every 5 min and step counts. Our findings highlight the possibility of collecting personally identifiable information about users of these devices and apps, including their profile information, habits, location, and state of mind. These findings would be pertinent to forensic investigators in the event that these or similar applications are part of an investigation.https://www.mdpi.com/2076-3417/12/19/9747data privacydata securityfitness trackersforensic analysisIoT forensicsmobile forensics |
spellingShingle | Shinelle Hutchinson Mohammad Meraj Mirza Nicholas West Umit Karabiyik Marcus K. Rogers Tathagata Mukherjee Sudhir Aggarwal Haeyong Chung Carrie Pettus-Davis Investigating Wearable Fitness Applications: Data Privacy and Digital Forensics Analysis on Android Applied Sciences data privacy data security fitness trackers forensic analysis IoT forensics mobile forensics |
title | Investigating Wearable Fitness Applications: Data Privacy and Digital Forensics Analysis on Android |
title_full | Investigating Wearable Fitness Applications: Data Privacy and Digital Forensics Analysis on Android |
title_fullStr | Investigating Wearable Fitness Applications: Data Privacy and Digital Forensics Analysis on Android |
title_full_unstemmed | Investigating Wearable Fitness Applications: Data Privacy and Digital Forensics Analysis on Android |
title_short | Investigating Wearable Fitness Applications: Data Privacy and Digital Forensics Analysis on Android |
title_sort | investigating wearable fitness applications data privacy and digital forensics analysis on android |
topic | data privacy data security fitness trackers forensic analysis IoT forensics mobile forensics |
url | https://www.mdpi.com/2076-3417/12/19/9747 |
work_keys_str_mv | AT shinellehutchinson investigatingwearablefitnessapplicationsdataprivacyanddigitalforensicsanalysisonandroid AT mohammadmerajmirza investigatingwearablefitnessapplicationsdataprivacyanddigitalforensicsanalysisonandroid AT nicholaswest investigatingwearablefitnessapplicationsdataprivacyanddigitalforensicsanalysisonandroid AT umitkarabiyik investigatingwearablefitnessapplicationsdataprivacyanddigitalforensicsanalysisonandroid AT marcuskrogers investigatingwearablefitnessapplicationsdataprivacyanddigitalforensicsanalysisonandroid AT tathagatamukherjee investigatingwearablefitnessapplicationsdataprivacyanddigitalforensicsanalysisonandroid AT sudhiraggarwal investigatingwearablefitnessapplicationsdataprivacyanddigitalforensicsanalysisonandroid AT haeyongchung investigatingwearablefitnessapplicationsdataprivacyanddigitalforensicsanalysisonandroid AT carriepettusdavis investigatingwearablefitnessapplicationsdataprivacyanddigitalforensicsanalysisonandroid |