Investigating Wearable Fitness Applications: Data Privacy and Digital Forensics Analysis on Android

Wearable devices are becoming more and more prevalent in our daily lives as people become more curious about how well they are doing in monitoring, improving, or maintaining their health and fitness. Fitness trackers and smartwatches have become almost ubiquitous, so these devices have begun to play...

Full description

Bibliographic Details
Main Authors: Shinelle Hutchinson, Mohammad Meraj Mirza, Nicholas West, Umit Karabiyik, Marcus K. Rogers, Tathagata Mukherjee, Sudhir Aggarwal, Haeyong Chung, Carrie Pettus-Davis
Format: Article
Language:English
Published: MDPI AG 2022-09-01
Series:Applied Sciences
Subjects:
Online Access:https://www.mdpi.com/2076-3417/12/19/9747
_version_ 1797480710631587840
author Shinelle Hutchinson
Mohammad Meraj Mirza
Nicholas West
Umit Karabiyik
Marcus K. Rogers
Tathagata Mukherjee
Sudhir Aggarwal
Haeyong Chung
Carrie Pettus-Davis
author_facet Shinelle Hutchinson
Mohammad Meraj Mirza
Nicholas West
Umit Karabiyik
Marcus K. Rogers
Tathagata Mukherjee
Sudhir Aggarwal
Haeyong Chung
Carrie Pettus-Davis
author_sort Shinelle Hutchinson
collection DOAJ
description Wearable devices are becoming more and more prevalent in our daily lives as people become more curious about how well they are doing in monitoring, improving, or maintaining their health and fitness. Fitness trackers and smartwatches have become almost ubiquitous, so these devices have begun to play a critical role in forensic investigations. In this paper, the authors conducted a forensic analysis of the controlling applications for three popular fitness bands and smartwatches (i.e., Amazon Halo, Garmin Connect, and Mobvoi) on an Android smartphone device to (1) provide forensic investigators with a road-map of forensically relevant data that are stored within these applications and (2) highlight any privacy concerns that the stored data within these applications may present to the applications’ users. Our findings indicate that the three fitness applications store a wealth of user data. In particular, the Amazon Halo app stores daily, weekly, and monthly activity-related data for at least the last 13 days. The user’s Tone Analysis results were also recovered. The Garmin Connect application also records detailed user activity information, as it was possible to recover the last 15 days worth of user activity data. The Garmin Connect user’s general location was also determined via the application’s weather notification feature. Lastly, the Mobvoi application records all data points from the time the device is first used until the last time the device is used. These data points may include heart rates taken every 5 min and step counts. Our findings highlight the possibility of collecting personally identifiable information about users of these devices and apps, including their profile information, habits, location, and state of mind. These findings would be pertinent to forensic investigators in the event that these or similar applications are part of an investigation.
first_indexed 2024-03-09T22:04:00Z
format Article
id doaj.art-e07105e0a6504b45a3139594be39768d
institution Directory Open Access Journal
issn 2076-3417
language English
last_indexed 2024-03-09T22:04:00Z
publishDate 2022-09-01
publisher MDPI AG
record_format Article
series Applied Sciences
spelling doaj.art-e07105e0a6504b45a3139594be39768d2023-11-23T19:45:02ZengMDPI AGApplied Sciences2076-34172022-09-011219974710.3390/app12199747Investigating Wearable Fitness Applications: Data Privacy and Digital Forensics Analysis on AndroidShinelle Hutchinson0Mohammad Meraj Mirza1Nicholas West2Umit Karabiyik3Marcus K. Rogers4Tathagata Mukherjee5Sudhir Aggarwal6Haeyong Chung7Carrie Pettus-Davis8Department of Computer and Information Technology, Purdue University, West Lafayette, IN 47905, USADepartment of Computer and Information Technology, Purdue University, West Lafayette, IN 47905, USADepartment of Computer Science, University of Alabama in Huntsville, Huntsville, AL 35899, USADepartment of Computer and Information Technology, Purdue University, West Lafayette, IN 47905, USADepartment of Computer and Information Technology, Purdue University, West Lafayette, IN 47905, USADepartment of Computer Science, University of Alabama in Huntsville, Huntsville, AL 35899, USADepartment of Computer Science, Florida State University, Tallahassee, FL 32304, USADepartment of Computer Science, University of Alabama in Huntsville, Huntsville, AL 35899, USAJustice System Partners, P.O. Box 970, South Easton, MA 02375, USAWearable devices are becoming more and more prevalent in our daily lives as people become more curious about how well they are doing in monitoring, improving, or maintaining their health and fitness. Fitness trackers and smartwatches have become almost ubiquitous, so these devices have begun to play a critical role in forensic investigations. In this paper, the authors conducted a forensic analysis of the controlling applications for three popular fitness bands and smartwatches (i.e., Amazon Halo, Garmin Connect, and Mobvoi) on an Android smartphone device to (1) provide forensic investigators with a road-map of forensically relevant data that are stored within these applications and (2) highlight any privacy concerns that the stored data within these applications may present to the applications’ users. Our findings indicate that the three fitness applications store a wealth of user data. In particular, the Amazon Halo app stores daily, weekly, and monthly activity-related data for at least the last 13 days. The user’s Tone Analysis results were also recovered. The Garmin Connect application also records detailed user activity information, as it was possible to recover the last 15 days worth of user activity data. The Garmin Connect user’s general location was also determined via the application’s weather notification feature. Lastly, the Mobvoi application records all data points from the time the device is first used until the last time the device is used. These data points may include heart rates taken every 5 min and step counts. Our findings highlight the possibility of collecting personally identifiable information about users of these devices and apps, including their profile information, habits, location, and state of mind. These findings would be pertinent to forensic investigators in the event that these or similar applications are part of an investigation.https://www.mdpi.com/2076-3417/12/19/9747data privacydata securityfitness trackersforensic analysisIoT forensicsmobile forensics
spellingShingle Shinelle Hutchinson
Mohammad Meraj Mirza
Nicholas West
Umit Karabiyik
Marcus K. Rogers
Tathagata Mukherjee
Sudhir Aggarwal
Haeyong Chung
Carrie Pettus-Davis
Investigating Wearable Fitness Applications: Data Privacy and Digital Forensics Analysis on Android
Applied Sciences
data privacy
data security
fitness trackers
forensic analysis
IoT forensics
mobile forensics
title Investigating Wearable Fitness Applications: Data Privacy and Digital Forensics Analysis on Android
title_full Investigating Wearable Fitness Applications: Data Privacy and Digital Forensics Analysis on Android
title_fullStr Investigating Wearable Fitness Applications: Data Privacy and Digital Forensics Analysis on Android
title_full_unstemmed Investigating Wearable Fitness Applications: Data Privacy and Digital Forensics Analysis on Android
title_short Investigating Wearable Fitness Applications: Data Privacy and Digital Forensics Analysis on Android
title_sort investigating wearable fitness applications data privacy and digital forensics analysis on android
topic data privacy
data security
fitness trackers
forensic analysis
IoT forensics
mobile forensics
url https://www.mdpi.com/2076-3417/12/19/9747
work_keys_str_mv AT shinellehutchinson investigatingwearablefitnessapplicationsdataprivacyanddigitalforensicsanalysisonandroid
AT mohammadmerajmirza investigatingwearablefitnessapplicationsdataprivacyanddigitalforensicsanalysisonandroid
AT nicholaswest investigatingwearablefitnessapplicationsdataprivacyanddigitalforensicsanalysisonandroid
AT umitkarabiyik investigatingwearablefitnessapplicationsdataprivacyanddigitalforensicsanalysisonandroid
AT marcuskrogers investigatingwearablefitnessapplicationsdataprivacyanddigitalforensicsanalysisonandroid
AT tathagatamukherjee investigatingwearablefitnessapplicationsdataprivacyanddigitalforensicsanalysisonandroid
AT sudhiraggarwal investigatingwearablefitnessapplicationsdataprivacyanddigitalforensicsanalysisonandroid
AT haeyongchung investigatingwearablefitnessapplicationsdataprivacyanddigitalforensicsanalysisonandroid
AT carriepettusdavis investigatingwearablefitnessapplicationsdataprivacyanddigitalforensicsanalysisonandroid