Live data from Hacker News

Oura says it gets government demands for user data

this.weekinsecurity.com

1–10 of 168 posts

Re: Oura says it gets government demands for user data

#2
I was definitely interested in some sort of comprehensive sensor bundle for my healthcare.

But every one of these devices demands some Android/Apple app, and shipping all my health data to basically non-HIPAA data brokers.

Id be all over a local-only no-data-exfiltration health tracker. But the companies do NOT want to provide that.

I, uh, guess, "go surveillance capitalism", for more choices?

Re: Oura says it gets government demands for user data

#3
"In my previous blog, I revealed that Oura data is not end-to-end encrypted. That means that an Oura user's health data can be unscrambled at certain points as it travels from a person's ring, through their phone app, over the internet, and as it lands on Oura's servers."

Very strange -- it seems to be conflating end-to-end encryption with encryption-in-transit.

Re: Oura says it gets government demands for user data

#4
post #3

"In my previous blog, I revealed that Oura data is not end-to-end encrypted. That means that an Oura user's health data can be unscrambled at certain points as it travels from a person's ring, through their phone app, over the internet, and as it lands on Oura's servers." Very strange -- it seems to be conflating end-to-end encryption with encryption-in-transit.

It also doesn't sound like its encrypted at rest. Perhaps each in-transit is held to be a unique e2e IP exchange?

Re: Oura says it gets government demands for user data

#6

I was definitely interested in some sort of comprehensive sensor bundle for my healthcare. But every one of these devices demands some Android/Apple app, and shipping all my health data to basically non-HIPAA data brokers. Id be all over a local-only no-data-exfiltration health tracker. But the companies do NOT want to provide that. I, uh, guess, "go surveillance capitalism", for more choices?

I am using Withings in combination Tredict. Both GDPR-compliant.

Re: Oura says it gets government demands for user data

#7

This is why although I don't love my Apple Watch, I'm not using anything else. It's very sensitive data and Apple is the only company worth trusting with it. They're not perfect but compared to others there's no competition.

Google's Health Connect system doesn't share this data either (without a consent prompt for third party apps, off course). This is to the point where I wish it would just support some kind of sync, because two devices hooked up to the same accounts need a third party app to transfer the health info.

Apple is subject to the same laws Oura is. The competition is too.

Re: Oura says it gets government demands for user data

#8
post #4
post #3

"In my previous blog, I revealed that Oura data is not end-to-end encrypted. That means that an Oura user's health data can be unscrambled at certain points as it travels from a person's ring, through their phone app, over the internet, and as it lands on Oura's servers." Very strange -- it seems to be conflating end-to-end encryption with encryption-in-transit.

It also doesn't sound like its encrypted at rest. Perhaps each in-transit is held to be a unique e2e IP exchange?

Encrypted at rest means something different. It means if you pull the hard drive out no one can decrypt it. Not that it is encrypted in the database.
Post reply on HN