Live data from Hacker News

Oura says it gets government demands for user data

this.weekinsecurity.com

71–80 of 168 posts

Re: Oura says it gets government demands for user data

#71
post #3

"In my previous blog, I revealed that Oura data is not end-to-end encrypted. That means that an Oura user's health data can be unscrambled at certain points as it travels from a person's ring, through their phone app, over the internet, and as it lands on Oura's servers." Very strange -- it seems to be conflating end-to-end encryption with encryption-in-transit.

My understanding is that E2E encryption implies encryption in transit. The message is encrypted at the source and only decrypted at the destination, so it is encrypted everywhere in between.

The term has kind of degraded, because people started marketing that "end-to-end encryption" is the "right" answer.

Encryption in transit means that network intermediates can't read the data. The two endpoints of the network communication can.

E2E encryption is more context-sensitive, and its context mostly comes from messaging. It means that the data is encrypted and that operational intermediates cannot read it. So in the context of messaging, the servers that run the messaging system cannot read the messages. Or, for an email, only the sender and recipient, not any of the intermediate email servers.

There's a big difference -- you can't really control or predict your network intermediates, but you can in theory know the operational intermediates. Whether something is E2E encrypted often depends on what intermediates you bring in to scope.

For example:

> That means that an Oura user's health data can be unscrambled at certain points as it travels from a person's ring, through their phone app, over the internet, and as it lands on Oura's servers.

If the ring uses Bluetooth to sync the data to your phone and the phone syncs data to the Oura servers, but the data is in the clear on your phone, then by this definition, it is not E2E encrypted. However, that's a pretty reasonable setup, depending on how the data on the phone is stored.

Re: Oura says it gets government demands for user data

#72
post #29

What will the government even do with my heart rate and blood oxygen data? "Mr Smith has been running again, we better bring him in for questioning!" Edit: to be clear, the government is requesting the data, so clearly they're doing something with it... But what? I don't see it!

Buys your heart rate and blood oxygen data from Oura. Collects your iris data from Eyez. Purchases your fitness data from Borg. Sees your purchasing patterns through Krump. Knows everything you've said online through Gwimp. Gets your sequenced DNA from FamaTree. Tracks your location data from, well, nearly every app in existance.

What could they possibly do from this single variable???

Re: Oura says it gets government demands for user data

#73

I considered an Oura but went with an Apple watch instead. I turned on Advanced Data Protection on the paired iPhone for peace of mind. No other large data providers really provide anything equivalent to ADP’s E2EE protection with zero access encryption, especially in the consumer space for activity trackers.

Garmin can be used completely offline?

AFAIK, they even have some watches with no radio hardware so that they can be used in sensible environments.

Re: Oura says it gets government demands for user data

#74
post #29

What will the government even do with my heart rate and blood oxygen data? "Mr Smith has been running again, we better bring him in for questioning!" Edit: to be clear, the government is requesting the data, so clearly they're doing something with it... But what? I don't see it!

Target infamously was inferring when teenage girls were pregnant before their parents knew based on reward card data records of single merchant retail purchases.... in 2002. Tech companies when they speak to VCs: look at all the creepy things we can infer with ooodles of aggregated data and AI to maximize targeted ad revenue, we're worth 50x what an equivalent non-tech company in our sector is valued, because of all…

Accidentally inferring. They were using basic machine learning to send coupons for predicted future purchases based on past purchases and general trends. And as far as I’m aware, it only happened once (or was only publicized once).

Re: Oura says it gets government demands for user data

#75
post #61

Earlier quoted context omitted.

Encrypted at rest means something different. It means if you pull the hard drive out no one can decrypt it. Not that it is encrypted in the database.

Does encryption at rest actually do much? The percentage of attacks that were perpetrated by people getting physical access to a drive must approach zero.

I think it's also meant to protect from potential mistakes in handling of hard disk decommissioning which presumably is a common thing with data centers.

Re: Oura says it gets government demands for user data

#76
post #3

"In my previous blog, I revealed that Oura data is not end-to-end encrypted. That means that an Oura user's health data can be unscrambled at certain points as it travels from a person's ring, through their phone app, over the internet, and as it lands on Oura's servers." Very strange -- it seems to be conflating end-to-end encryption with encryption-in-transit.

Not very strange but E2EE is thrown around a lot and everyone interprets it differently. And in some cases the expectations are unrealistic.

Take a messenger app using a server as middleman. E2EE means only the 2 users get to see the content, not the middleman company server. For Oura there’s only a user and the company server and a lot of people assume Oura can’t read the data, like the Signal or WhatsApp servers can’t read the data because of E2EE. The marketing usually allows or encourages this misunderstanding.

If they claim E2EE though, the interface between the user and the service (the ring or at worst the app) should mandate the encryption and the data should be decrypted only at the other end on Oura’s servers. If at any point in between these 2 ends the data is decrypted then it’s not E2EE.

Re: Oura says it gets government demands for user data

#77
post #71

Earlier quoted context omitted.

My understanding is that E2E encryption implies encryption in transit. The message is encrypted at the source and only decrypted at the destination, so it is encrypted everywhere in between.

The term has kind of degraded, because people started marketing that "end-to-end encryption" is the "right" answer. Encryption in transit means that network intermediates can't read the data. The two endpoints of the network communication can. E2E encryption is more context-sensitive, and its context mostly comes from messaging. It means that the data is encrypted and that operational intermediates cannot read it. So…

> If the ring uses Bluetooth to sync the data to your phone and the phone syncs data to the Oura servers, but the data is in the clear on your phone, then by this definition, it is not E2E encrypted.

Yet another angle would be that both the phone and the ring are in one's material possession, whereas the cloud is someone else's computer, and to display a nice web UI it has to have the data unencrypted over there.

In that case, the cloud is the potentially untrusted intermediate between the data and one's eyeballs.

All of these are equally valid, it all depends on what is your threat model.

Re: Oura says it gets government demands for user data

#78
post #24

This is why although I don't love my Apple Watch, I'm not using anything else. It's very sensitive data and Apple is the only company worth trusting with it. They're not perfect but compared to others there's no competition.

You may want to reevaluate. Apple has a great PR (propaganda) department that has convinced many people they respect your privacy. In truth, they do not. They're "better" than Google, but only slightly. And only so slightly that realistically it doesn't matter. "Apple is taking the unprecedented step of removing its highest level data security tool from customers in the UK, after the government demanded access to use…

Did you just post an article where Apple refused a UK government order to weaken their encryption as "proof" that Apple doesn't respect customer privacy?

Also, the US Government has already demanded that Apple weaken device encryption.

Apple fought it in court, and the government dropped their demand rather than set a privacy precedent they wanted to avoid.

Re: Oura says it gets government demands for user data

#79
post #16

Earlier quoted context omitted.

In the US. Apple's policies are flexible when it comes to other nation states. All it takes is a political sea change for E2EE to go away. Apple already has to hand over a wealth of information when asked by the feds.

Apple literally removed encrypted file storage as a feature in the UK rather than comply with demands for access to encrypted customer data from the UK government. Previously, they refused US government demands for a backdoor that would allow them to unlock locked devices.

> Apple literally removed encrypted file storage as a feature in the UK rather than comply with demands for access to encrypted customer data from the UK government.

Does that mean that instead of UK government accessing the data (through a backdoor), UK government can now access to data (because it's not encrypted at all)?

Re: Oura says it gets government demands for user data

#80
post #66
post #65

Earlier quoted context omitted.

Depends on what kind of data is in question. Backups and old incremential data can stay encrypted while disks are otherwise in use.

Hm yeah, I always think of encryption at rest as "the drive handles encryption itself", rather than "we encrypted these archives before we wrote them", but fair enough.

Not necessarily the drive, but yeah, where standards mandate encryption at rest you need to have the files on the live disk encrypted.

Usually it's much less of a headache to luks/bitlocker/SED the whole drive so that you don't have to worry about swap files and logs

Post reply on HN