07-24-2018 06:32
07-24-2018 06:32
Recently, a vulnerability in Bluetooth has been found dealing with how devices communicate with one another. The gist is that a "man in the middle" attach may be possible.
More information is here:
https://www.kb.cert.org/vuls/id/304725
Fitbit isn't listed in the vendors affected at the bottom of the article, but I'm sure it's not a complete list. Are we affected by this? If my phone vendor (for me, an iPhone) patches the issue, will that be sufficient to plug the hole? Or will Fitbit also have to issue a firmware patch (for me, an Ionic)?
Thank you!
07-27-2018 05:07
07-27-2018 05:07
Hello @SunsetRunner!
Thanks for sharing your concerns! Rest assured that our products have been designed with security in mind, and efforts have been made to prevent Bluetooth hacking. Personal data sent between your tracker and fitbit.com is protected through encryption. It should only be possible for the site to collect data from your computer or mobile device and we continually look for and mitigate security threats. For details about our privacy policy and how we use your data, see our article at https:
Feel free to reach out if you need any assistance.
07-27-2018 05:36
07-27-2018 05:36
Thank you for your reply. However, the concern I had was not the transmission of data between my Ionic and Fitbit.com. Instead, the concern was transmission between my Ionic and my phone (the bluetooth connection). This appears to be a flaw in the bluetooth technology.
08-13-2018 05:08
08-13-2018 05:08
I agree to emulator.
I also would like to know, if fitbit will fix the communication between my eg IONIC and any device try to connect to it via bluetooth, if there are any security issues which are offical released ?
Just to mention "BtleJack" which does a "man in the middle attack" which will surely work with the fitbit trackers too.
So do you patch such issues and secure the communication ?
And (hopefully yes) when ?
BR
08-14-2018 10:22
08-14-2018 10:22
@SunsetRunner, @Frager At this time, we are aware that this issue has been discovered in other devices, but do not currently have an indication that it affects Fitbit trackers. We will continue to investigate this matter as part of our ongoing device security work.
Actively managing your weight? Find accountability buddies on the Manage Weight board