Cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Bluetooth Security Concern

Replies are disabled for this topic. Start a new one or visit our Help Center.

Recently, a vulnerability in Bluetooth has been found dealing with how devices communicate with one another. The gist is that a "man in the middle" attach may be possible. 

 

More information is here:

 

https://www.kb.cert.org/vuls/id/304725

 

Fitbit isn't listed in the vendors affected at the bottom of the article, but I'm sure it's not a complete list. Are we affected by this? If my phone vendor (for me, an iPhone) patches the issue, will that be sufficient to plug the hole? Or will Fitbit also have to issue a firmware patch (for me, an Ionic)?

 

Thank you!

Best Answer
0 Votes
4 REPLIES 4

Hello @SunsetRunner! 

 

Thanks for sharing your concerns! Rest assured that our products have been designed with security in mind, and efforts have been made to prevent Bluetooth hacking. Personal data sent between your tracker and fitbit.com is protected through encryption. It should only be possible for the site to collect data from your computer or mobile device and we continually look for and mitigate security threats. For details about our privacy policy and how we use your data, see our article at https://help.fitbit.com/articles/en_US/Help_article/1758.

 

Feel free to reach out if you need any assistance.

Lanuza | Community Moderator

Remember to vote for posts that helped you out! Tired of the same workout music? Try a Podcast! 🙂

Best Answer

Thank you for your reply. However, the concern I had was not the transmission of data between my Ionic and Fitbit.com. Instead, the concern was transmission between my Ionic and my phone (the bluetooth connection). This appears to be a flaw in the bluetooth technology. 

Best Answer

I agree to emulator.

 

I also would like to know, if fitbit will fix the communication between my eg IONIC and any device try to connect to it via bluetooth, if there are any security issues which are offical released ?

 

Just to mention "BtleJack" which does a "man in the middle attack" which will surely work with the fitbit trackers too.

 

So do you patch such issues and secure the communication ?

And (hopefully yes) when ?

 

BR

Best Answer
0 Votes

@SunsetRunner, @Frager At this time, we are aware that this issue has been discovered in other devices, but do not currently have an indication that it affects Fitbit trackers. We will continue to investigate this matter as part of our ongoing device security work.

Actively managing your weight? Find accountability buddies on the Manage Weight board

Best Answer