03-08-2016
14:10
- last edited on
04-25-2016
17:05
by
VivisFitbit
03-08-2016
14:10
- last edited on
04-25-2016
17:05
by
VivisFitbit
I have serious concerns about Fitbit's security measures.
My account got hacked (complaint #09288432, a chat and a phone call), the customer service department has proven to be inept and I had to set up a new account just to be able to post here.
FitBit has allowed the change of the account Id (the email) to a known ephemeral email service/domain @grr.la that is commonly used for hacking purposes. All this without the basic security measures like 2 factor identification – why not use the app as the 2nd factor?
Considering the GPS location data and company dashboard that my account is connected to, I would say it includes relatively sensitive information.
I have also voiced my concerns with my company’s CISO and we both contacted HR and asked them to reevaluate their benefits relationship with Fitbit.
After seeing how weak FitBit’s security measures are, I have asked my wife and daughter to disable the GPS in their app as I would not want that data in the wild.
This has experience has been a master class on how not to deal with a security issue.
04-25-2016
14:16
- last edited on
04-25-2016
17:01
by
ErickFitbit
04-25-2016
14:16
- last edited on
04-25-2016
17:01
by
ErickFitbit
Welcome @Keepod! I'm sorry to know about this, I reached out to our Security Team and they reassured me that someone has reached out to you. Please take a moment to check your email inbox for correspondence from us. I suggest following up with the Security Team via their email for further updates.