Pretty cool what they did. There doesn't seem to be a mainstream embedded OS that allows dynamically loading binaries, but it would be so nice.
NuttX is the only one I can think of off the top of my head with this feature.
61–70 of 77 posts
Pretty cool what they did. There doesn't seem to be a mainstream embedded OS that allows dynamically loading binaries, but it would be so nice.
NuttX is the only one I can think of off the top of my head with this feature.
What is the "so what" here? Are these internet connected?
Author here. Fair question! They get access to the internet via the Garmin Connect companion app. But if you're asking to know if they can be exploited from the internet, that's not what we showed yeah. The vulnerabilities we've disclosed require a malicious app to be installed (e.g. from the CIQ app store) so let's not cry wolf. What I think this project highlights and what we should remember is the current level of…
https://forums.garmin.com/outdoor-recreation/outdoor-recreat...
Earlier quoted context omitted.
Right, anonymized data that shares your vitals 24/7 (which are fairly unique) and location data which totally cannot infer your home and work locations. You’re deluded if you believe this can truly be anonymized and stay anonymized.
Depends on the device I'm guessing. AFAIK, not all Garmin devices log location 24/7, but only when explicit activities have been started.
What is the "so what" here? Are these internet connected?
Author here. Fair question! They get access to the internet via the Garmin Connect companion app. But if you're asking to know if they can be exploited from the internet, that's not what we showed yeah. The vulnerabilities we've disclosed require a malicious app to be installed (e.g. from the CIQ app store) so let's not cry wolf. What I think this project highlights and what we should remember is the current level of…
I wonder if these are secured differently or merely obscured behind the encrypted firmware on newer models.
MonkeyC is such a funky language to write. It's obviously modeled on top of java, just with some syntactic differences making it instead look like a mashup with javascript. I get why they made their own high level language to some extent, instead of shoehorning in something else. But making your whole stack from scratch must lead to lots of holes like these. But a very nice blog post. Learned loads more about what's…
For a long time this didn’t really matter since the Apple Watch and Garmin devices really appealed to two very different market segments - Garmin had a huge moat in first party fitness capabilities, maps, and battery life, and Apple had a huge moat in UX, their app ecosystem, the screen quality and device style, and smartwatch functionality.
Now, both companies are closing the gap in both directions on many of these aspects. It will be interesting to see what effect (if any) this will or will not have on the CiQ tooling and the CiQ ecosystem.
Earlier quoted context omitted.
Depends on the device I'm guessing. AFAIK, not all Garmin devices log location 24/7, but only when explicit activities have been started.
Don't a lot of people start and/or end their regular fitness runs or bike rides at their doorstep? The thing about these fitness tracking tools is that you start wanting to track all your activities to get the statistical trends. It becomes integrated into your day to day lifestyle.
Most of my friends who exercise also does it at places at least a couple of hundred meters away from their home. The ones that live outside the city, probably do start their run right outside their doors though.
My sense, as someone who has written more than one CiQ app is that Garmin got caught completely by surprise with the popularity of 3rd party apps on wearable platforms and MonkeyC graduated from “interesting side project” to “critical ecosystem capability” in the space of a couple months, years ago. The early CiQ SDK versions had some truly insane conventions like using constants named “THAI_SPICY_HOT” for font sizes…
[0]: https://github.com/anvilsecure/garmin-ciq-app-research/blob/... [1]: https://github.com/anvilsecure/garmin-ciq-app-research/blob/...
Earlier quoted context omitted.
Author here. Fair question! They get access to the internet via the Garmin Connect companion app. But if you're asking to know if they can be exploited from the internet, that's not what we showed yeah. The vulnerabilities we've disclosed require a malicious app to be installed (e.g. from the CIQ app store) so let's not cry wolf. What I think this project highlights and what we should remember is the current level of…
Do you have thoughts on the NFC and particularly Garmin Pay features? I wonder if these are secured differently or merely obscured behind the encrypted firmware on newer models.
Anyone got a recommendation for fitness wearables where you can opt out of having to sign up with an account, and can export data out of it in open/standard formats?