Live data from Hacker News

Oura says it gets government demands for user data

this.weekinsecurity.com

121–130 of 168 posts

Re: Oura says it gets government demands for user data

#121
post #76
post #3

"In my previous blog, I revealed that Oura data is not end-to-end encrypted. That means that an Oura user's health data can be unscrambled at certain points as it travels from a person's ring, through their phone app, over the internet, and as it lands on Oura's servers." Very strange -- it seems to be conflating end-to-end encryption with encryption-in-transit.

Not very strange but E2EE is thrown around a lot and everyone interprets it differently. And in some cases the expectations are unrealistic. Take a messenger app using a server as middleman. E2EE means only the 2 users get to see the content, not the middleman company server. For Oura there’s only a user and the company server and a lot of people assume Oura can’t read the data, like the Signal or WhatsApp servers ca…

> everyone interprets it differently.

No, they don't. You're spreading misinformation. If the service provider can see the data then it is not E2EE. There is no room for negotiation here. Let me be perfectly clear that any service provider that claims E2EE while having access to user data is committing blatant fraud.

That said, it does not appear that Oura ever claimed E2EE. The author is merely making it clear to the reader that this is not the case.

Re: Oura says it gets government demands for user data

#122

Earlier quoted context omitted.

Cell phone services don't record your heart rate. As has been noted on HN several times, there are cars that monitor when you have sex in them. You might be surprised what is known and by whom.

> As has been noted on HN several times, there are cars that monitor when you have sex in them. You might be surprised what is known and by whom. There is no proof they actually have that capability, it is just mentioned in their privacy policy.

It is an interesting juncture that we have come to

Re: Oura says it gets government demands for user data

#123
post #3

"In my previous blog, I revealed that Oura data is not end-to-end encrypted. That means that an Oura user's health data can be unscrambled at certain points as it travels from a person's ring, through their phone app, over the internet, and as it lands on Oura's servers." Very strange -- it seems to be conflating end-to-end encryption with encryption-in-transit.

I don't see the conflation? The author makes it clear that the data is not E2EE. It does sound like it's encrypted in transit (this is table stakes for the past 20 years or so). I think that saying that the data gets "unscrambled at certain points as it travels" is a perfectly reasonable way to explain the practical difference between the two approaches to a nontechnical reader.

Re: Oura says it gets government demands for user data

#124
post #74

Earlier quoted context omitted.

Target infamously was inferring when teenage girls were pregnant before their parents knew based on reward card data records of single merchant retail purchases.... in 2002. Tech companies when they speak to VCs: look at all the creepy things we can infer with ooodles of aggregated data and AI to maximize targeted ad revenue, we're worth 50x what an equivalent non-tech company in our sector is valued, because of all…

Accidentally inferring. They were using basic machine learning to send coupons for predicted future purchases based on past purchases and general trends. And as far as I’m aware, it only happened once (or was only publicized once).

It almost certainly happened regularly since the entire point of the program was to make accurate predictions about future purchases. The practical impact of acting on those predictions only caused mild controversy and became publicized the one time (at least that I'm aware of) but we have no reason to expect that the program was unsuccessful and every reason to expect that it was.

Re: Oura says it gets government demands for user data

#125
post #71

Earlier quoted context omitted.

My understanding is that E2E encryption implies encryption in transit. The message is encrypted at the source and only decrypted at the destination, so it is encrypted everywhere in between.

The term has kind of degraded, because people started marketing that "end-to-end encryption" is the "right" answer. Encryption in transit means that network intermediates can't read the data. The two endpoints of the network communication can. E2E encryption is more context-sensitive, and its context mostly comes from messaging. It means that the data is encrypted and that operational intermediates cannot read it. So…

this is such a hacker news comment. expounding needlessly. e2e implies encryption at the source and endpoint which entails encryption along all transit paths. its not that deep. if its not encrypted at the source “ring”, then it cant be e2e. I get your semantics but its just a waste, as is my comment here.

Re: Oura says it gets government demands for user data

#126
post #76
post #3

"In my previous blog, I revealed that Oura data is not end-to-end encrypted. That means that an Oura user's health data can be unscrambled at certain points as it travels from a person's ring, through their phone app, over the internet, and as it lands on Oura's servers." Very strange -- it seems to be conflating end-to-end encryption with encryption-in-transit.

Not very strange but E2EE is thrown around a lot and everyone interprets it differently. And in some cases the expectations are unrealistic. Take a messenger app using a server as middleman. E2EE means only the 2 users get to see the content, not the middleman company server. For Oura there’s only a user and the company server and a lot of people assume Oura can’t read the data, like the Signal or WhatsApp servers ca…

There is no interpretation issue, some people are just confused.

Oura is not claiming E2EE and Oura is not E2EE. E2EE in the health apps would mean that Oura would not see the data. Only user could see the data in their app. Oura's privacy policy states that they do not sell your data, they limit internal access using strict safeguards (like pseudonymization, where your name is separated from your health stats), and they pledge to push back against overbroad government data requests.

Contrast Oura to Apple Health that is true E2EE. Only you and your trusted devices have the keys, Apple can't see the keys, and Apple has noting to give is it gets government request.

Re: Oura says it gets government demands for user data

#127

[flagged]

I like paying $100/month to be monitored by the f3ds to Claude or Open(Closed)AI, or in some cases Max Premium subscriptions of $200/month.

But oh don't worry, since they are selling the tokens at a loss, this data sale doesn't matter.

My non-training data should be such that I pay them to extract it from me.

Re: Oura says it gets government demands for user data

#128
post #48

Earlier quoted context omitted.

> I'm more concerned about Automatic Content Recognition (ACR) on smartTV You’re more concerned about privacy when it comes to TV viewing than medical data? What a strange hijacking of a serious thread…

When you buy a medical data collection device and it collects medical data that’s not exactly a surprise

The problem isn’t the collecting, it’s who has access to the data.

Re: Oura says it gets government demands for user data

#129
post #24

This is why although I don't love my Apple Watch, I'm not using anything else. It's very sensitive data and Apple is the only company worth trusting with it. They're not perfect but compared to others there's no competition.

You may want to reevaluate. Apple has a great PR (propaganda) department that has convinced many people they respect your privacy. In truth, they do not. They're "better" than Google, but only slightly. And only so slightly that realistically it doesn't matter. "Apple is taking the unprecedented step of removing its highest level data security tool from customers in the UK, after the government demanded access to use…

I'm confused what you think Apple should have done differently there. If the government presents you with a legal demand generally your only options are to either comply or leave the market. Would you prefer Apple to have pulled out of the UK entirely?

I'm not even much of a fan of Apple but I really don't think you can hold it against them when they loudly protest but ultimately comply with legal demands.

Re: Oura says it gets government demands for user data

#130
post #63

Earlier quoted context omitted.

Why would they be careful, given that the chances of any serious consequences for ignoring such provisions are effectively zero?

Why would they be careful, given that the chances of any serious consequences for ignoring such provisions are effectively zero? Your cynicism is at odds with reality. I got a check for nearly $500 because when I was an Illinois resident, one of the SV tech companies violated that law. All it takes is one or two people to get in the ear of the right class action lawyer, and ignoring the rules quickly becomes expensiv…

You got a check for $500, but now your info is who knows where and the company involved is still making more money than not. You lost out.
Post reply on HN