Security Affairs
GitLab Users Urged to Patch After Research Reveals Critical RCE Chain|EFF: Most Smart Wearables Still Fall Short on Privacy and Transparency|LockBit5 and Qilin Lead Ransomware Attacks Against Italian Organizations|SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 107|Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Credentials|Security Affairs newsletter Round 587 by Pierluigi Paganini – INTERNATIONAL EDITION|Iran-Linked Actors Breach Are Targeting US Water and Energy Control Systems|Australian energy provider Origin Energy disclosed a data breach impacting customer data|Google Fined €890M Under EU Digital Markets Act Over Search and Play Store Practices|Thailand’s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged|UAC-0099 Is Now Hiding Malware Inside a Fake Notepad++ Plugin to Target Ukrainian Organizations|The AI Trust Paradox: Businesses Are Racing Ahead, but Consumers Are Hesitating|GitLab Users Urged to Patch After Research Reveals Critical RCE Chain|EFF: Most Smart Wearables Still Fall Short on Privacy and Transparency|LockBit5 and Qilin Lead Ransomware Attacks Against Italian Organizations|SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 107|Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Credentials|Security Affairs newsletter Round 587 by Pierluigi Paganini – INTERNATIONAL EDITION|Iran-Linked Actors Breach Are Targeting US Water and Energy Control Systems|Australian energy provider Origin Energy disclosed a data breach impacting customer data|Google Fined €890M Under EU Digital Markets Act Over Search and Play Store Practices|Thailand’s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged|UAC-0099 Is Now Hiding Malware Inside a Fake Notepad++ Plugin to Target Ukrainian Organizations|The AI Trust Paradox: Businesses Are Racing Ahead, but Consumers Are Hesitating|
Advertisement

Ad Placeholder

Full Width × 90

Breaking News

EFF: Most Smart Wearables Still Fall Short on Privacy and Transparency

EFF says most smart wearables lack basic privacy protections, with Apple standing out for end-to-end encryption and transparency. Most smart wearables still treat privacy like an optional extra, and that’s a problem. The Electronic Frontier Foundation (EFF)’s review of major smart watches, rings, and bands makes the case plainly: these devices collect deeply personal health […]

Smart Wearables

EFF says most smart wearables lack basic privacy protections, with Apple standing out for end-to-end encryption and transparency.

Most smart wearables still treat privacy like an optional extra, and that’s a problem. The Electronic Frontier Foundation (EFF)’s review of major smart watches, rings, and bands makes the case plainly: these devices collect deeply personal health data, but most vendors still don’t give users the protections or transparency they should expect from the start.

“Oura Rings, Garmin GPS fitness watches, Apple Watches, Whoop bands—every year, more and more tech devices are promising to monitor our health and fitness, guide us toward healthier living, and provide useful health metrics to take to our doctors. But few of these tools provide the sorts of privacy and security promises we demand from all technology, let alone tech that captures personal health data.” reads the report published by EFF. “It’s time they step up and start providing transparency reports and stronger encryption options.”

The EFF looked at ten popular consumer health-device makers, including Apple, Google/Fitbit, Garmin, Oura, Polar, Suunto, and Whoop, then checked public policies and followed up by email. That matters because this isn’t a narrow complaint about one weak product line or one sloppy vendor. It’s a broader look at a market that keeps asking people to hand over sensitive data while offering very uneven safeguards in return.

What the group found is pretty simple: only Apple and Google currently publish transparency reports, and only Apple Watch supports end-to-end encryption for health data stored in its Health app. In practice, that means Apple’s users get a stronger privacy model than the rest of the market, while most competitors still rely on protections that stop outsiders but not the company itself from seeing the data.

“Only two of the companies we surveyed, Apple and Google (which also owns Fitbit), currently publish transparency reports. AppleGoogle, and Whoop promise to notify users of law enforcement requests in publicly available documentation.” states EFF.

That gap matters because health data is now a real target in investigations, and wearable data can help reconstruct where someone was, how they moved, and even what they were doing at a given time. If a company won’t say how often it gets legal demands, users are left guessing, and that’s a strange way to build trust around products that track sleep, movement, heart rate, and location all day.

“And that’s it. Apple is the only one. No other popular consumer health wearable offers end-to-end encryption for the data it collects and stores online. Not Google. Not Garmin.” continues the report. “Not Oura. Most of these companies instead offer encryption in transit and at rest, but this means those companies can still see and use your data. This is the industry standard, but it doesn’t have to be.”

The EFF’s point is not that every company must copy Apple feature for feature. It’s that if these firms are going to sell devices that track health, movement, and sleep, they should at least offer transparency reports and a real end-to-end encryption option. Right now, the market mostly offers partial protections, vague assurances, and the usual “we take privacy seriously” line, which is doing a lot of work for a very small sentence.

The real problem is that the industry is still treating privacy as a differentiator instead of a baseline requirement. With many major tech companies already publishing information about government data requests, wearable manufacturers have little reason to remain opaque. Users deserve clear protections, not vague assurances.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Smart Wearables)