Live data from Hacker News

Oura says it gets government demands for user data

this.weekinsecurity.com

131–140 of 168 posts

Re: Oura says it gets government demands for user data

#131
post #24

This is why although I don't love my Apple Watch, I'm not using anything else. It's very sensitive data and Apple is the only company worth trusting with it. They're not perfect but compared to others there's no competition.

You may want to reevaluate. Apple has a great PR (propaganda) department that has convinced many people they respect your privacy. In truth, they do not. They're "better" than Google, but only slightly. And only so slightly that realistically it doesn't matter. "Apple is taking the unprecedented step of removing its highest level data security tool from customers in the UK, after the government demanded access to use…

>> "Apple is taking the unprecedented step of removing its highest level data security tool from customers in the UK, after the government demanded access to user data."

They did exactly what they should have. Their choices were build a backdoor or disable the advanced data protection feature in the UK. They also made it incredibly public.

Re: Oura says it gets government demands for user data

#132
post #76

Earlier quoted context omitted.

Not very strange but E2EE is thrown around a lot and everyone interprets it differently. And in some cases the expectations are unrealistic. Take a messenger app using a server as middleman. E2EE means only the 2 users get to see the content, not the middleman company server. For Oura there’s only a user and the company server and a lot of people assume Oura can’t read the data, like the Signal or WhatsApp servers ca…

> everyone interprets it differently. No, they don't. You're spreading misinformation. If the service provider can see the data then it is not E2EE. There is no room for negotiation here. Let me be perfectly clear that any service provider that claims E2EE while having access to user data is committing blatant fraud. That said, it does not appear that Oura ever claimed E2EE. The author is merely making it clear to th…

Agreed. Weird to see a bunch of posts trying to argue that E2E doesn't imply that provider can't see the data, at rest or in transit.

Re: Oura says it gets government demands for user data

#133
post #61

Earlier quoted context omitted.

Encrypted at rest means something different. It means if you pull the hard drive out no one can decrypt it. Not that it is encrypted in the database.

Does encryption at rest actually do much? The percentage of attacks that were perpetrated by people getting physical access to a drive must approach zero.

It generally has to do with risk models, especially in single tenant environments.

What I mean is, say I am a b2b service provider and I have a single database for some subset of my clients. That is, multiple clients data are held in the same database. There are many ways to do this but one way I have see is BYOK (Bring Your Own Key). You can have your clients give you secure access to a public/private key pair (e.g. through AWS secrets manager). Then you encrypt anything that gets written into the database using their key.

This means that if there is some security hole in your software that accidentally allows data to be exfiltrated from your servers (e.g. one malicious client sends API requests that allow for a query of data from another target client), the data the API returns will be encrypted using the target clients public/private key.

My own experience with security is that nothing is perfect and good security is like an onion. Encryption at rest isn't perfect and won't handle every possible malicious attack, but it is a layer in the broader strategy. The attacker has to both find a way to exfiltrate the data and trick the server into revealing the shared key. The idea being it is harder to do both than it may be to do either individually.

Re: Oura says it gets government demands for user data

#134
post #67

Earlier quoted context omitted.

Ordering a taxi after running outside of US? Probably missed some mass transport. Raise the price boys... like good old Uber back in the day based on iphone battery level. Really the possibilities are endless if you're evil. Bad health? Raise the insurance premiums? Or anything more evil I can't think of. edit: grammar

None of those things sounds like stuff the government would have a hand in, unless you live in some communist country where the taxis are state-owned?

That'd probably be nice.

A capitalist, or as in this case, fascist, state might figure out all sorts of interesting things from mass surveillance, such as who might be disloyal, who is eligible for eugenic culling, who might be fun to deport, and who is vulnerable to sticks or carrots or both and could do something for the state that the state does not want to do directly.

Re: Oura says it gets government demands for user data

#136
post #10

Oura doesn't even have GPS does it? Government can already get ALL your celltower locations without a warrant AND read all your emails and text messages that are over 6 months old, without a warrant

They can read all your emails that are over 6 months old? What are you basing this on? First I've heard of it.

Re: Oura says it gets government demands for user data

#137
post #10

Oura doesn't even have GPS does it? Government can already get ALL your celltower locations without a warrant AND read all your emails and text messages that are over 6 months old, without a warrant

> AND read all your emails and text messages that are over 6 months old, without a warrant

Source for this? Was it big news? First I've heard of it.

Re: Oura says it gets government demands for user data

#138
post #29

What will the government even do with my heart rate and blood oxygen data? "Mr Smith has been running again, we better bring him in for questioning!" Edit: to be clear, the government is requesting the data, so clearly they're doing something with it... But what? I don't see it!

Also if you're a woman biological signals can be used to know when you are on your cycle and thus missed it.

Given the keen interest in women's reproductive biology exhibited by many conservatives, I could definitely see them trying to, say, catch pregnant people who suddenly become non-pregnant.

Re: Oura says it gets government demands for user data

#139

Earlier quoted context omitted.

I think it's also meant to protect from potential mistakes in handling of hard disk decommissioning which presumably is a common thing with data centers.

Used to be, but e.g. where I work any decommissioned drive has to be DBANed (if it's spinning platters) or secure-erased (SSDs). If it can't be for some reason (e.g. it has failed) it needs to be physically destroyed. I would hope most data centers have similar policies in 2026, but that may be optimistic I guess.

When the company that owns the physical hardware goes out of business, all of this stuff is moot.

Re: Oura says it gets government demands for user data

#140

Earlier quoted context omitted.

Also if you're a woman biological signals can be used to know when you are on your cycle and thus missed it.

Given the keen interest in women's reproductive biology exhibited by many conservatives, I could definitely see them trying to, say, catch pregnant people who suddenly become non-pregnant.

Yep exactly my point. My partner will not even use cycle apps at this point because states can and undoubtedly will access that data to prove termination of pregnancy.
Post reply on HN