Live data from Hacker News

Oura says it gets government demands for user data

this.weekinsecurity.com

91–100 of 168 posts

Re: Oura says it gets government demands for user data

#91

This is why although I don't love my Apple Watch, I'm not using anything else. It's very sensitive data and Apple is the only company worth trusting with it. They're not perfect but compared to others there's no competition.

I don't trust them.

https://www.mintpressnews.com/apple-israel-unit-8200-hiring/...

Re: Oura says it gets government demands for user data

#92
post #53
post #29

What will the government even do with my heart rate and blood oxygen data? "Mr Smith has been running again, we better bring him in for questioning!" Edit: to be clear, the government is requesting the data, so clearly they're doing something with it... But what? I don't see it!

Location and time

They already have that from your cellphone

Re: Oura says it gets government demands for user data

#93
post #10

Oura doesn't even have GPS does it? Government can already get ALL your celltower locations without a warrant AND read all your emails and text messages that are over 6 months old, without a warrant

The ring doesn't have gps but its app requires location permission so it gets it from your phone. It continually asks me to turn on background sync, which would presumably upload my location regularly as well. I decline and only allow location when the app is open to sync.

Location is used for tracking distance/speed for certain activities and measuring VO2 max levels, and for finding a lost ring.

Re: Oura says it gets government demands for user data

#94
post #10

Oura doesn't even have GPS does it? Government can already get ALL your celltower locations without a warrant AND read all your emails and text messages that are over 6 months old, without a warrant

The ring doesn't have gps but its app requires location permission so it gets it from your phone. It continually asks me to turn on background sync, which would presumably upload my location regularly as well. I decline and only allow location when the app is open to sync.

They already know where your phone is…

Re: Oura says it gets government demands for user data

#95
It's been over a decade since the Snowden revelations. We know full well that the large tech companies collect massive amounts of your personal data and secretly share it all with the US government. Not requests, not occasionally, not some - everything. And there are even formal mechanisms for this, like National Security Letters, which essentially guarantee silence.

So, why are we seeing articles like this, which raise suspcision that maybe a wearable smart-device company _might_ be sharing _some_ data, _sometimes_? Or expectations of voluntary transparency?

Yes, the government spies on you. Not because you're important, but because they spy on everybody. It's cheap, convenient and has no negative political consequences (so far).

References:

* https://en.wikipedia.org/wiki/National_security_letter

* https://www.pcmag.com/news/the-10-most-disturbing-snowden-re...

Re: Oura says it gets government demands for user data

#96
post #73

Earlier quoted context omitted.

Garmin can be used completely offline? AFAIK, they even have some watches with no radio hardware so that they can be used in sensible environments.

Yup. It’s a bit of a pain, but you don’t have to use the connect app. Devices and data can be accessed with direct USB connection as standard storage. You will lose some features and I think firmware updates become difficult (or impossible?)

I think firmware updates and even map routes can be uploaded offline by mounting the watch as a USB mass storage device?

I wish Casio, Polar, Suunto and others provided this functionality.

There is some community software for Polar that enables offline data exchange, but it is a bit hacky, and OFC no firmware updates.

Suunto used to have a really good offline solution, but they discontinued that and moved to the cloud.

Re: Oura says it gets government demands for user data

#98
post #58

Earlier quoted context omitted.

"Things might change in the future" is a perfectly general statement which applies to any state of affairs which is not restricted by natural law. That makes it very nearly meaningless.

Maybe, weren't it for the fact that we're having age verification and IDV ("protect the kids"), hardware attestation, removal of 3rd party APKs, etc. heaved upon us. We've never had so many threats to our privacy and liberties heaved upon us, and the rate is accelerating.

Apple certainly lobbied against this stupidity.

> Cook conveyed to lawmakers that device-level age assurance proposals should not require the collection of sensitive data like birth certificate or social security number, and that parents should be trusted to provide the age of a child when creating a child's account. Any data used for determining age should not be kept by app stores or developers, according to Apple.

https://www.macrumors.com/2025/12/10/tim-cook-age-verificati...

Re: Oura says it gets government demands for user data

#99
post #29

What will the government even do with my heart rate and blood oxygen data? "Mr Smith has been running again, we better bring him in for questioning!" Edit: to be clear, the government is requesting the data, so clearly they're doing something with it... But what? I don't see it!

They'll know when and how often you're awake or sleep (including how well you slept), sick, fucking, drunk or high, anxious or upset, relaxed, shitting, menstruating, medicated, etc. Combined with other data and tracked over time there is a shocking amount of intimate information you can get from just those two things which is why companies like Oura and Fitbit are so eager to get their hands on it.

Re: Oura says it gets government demands for user data

#100
post #61

Earlier quoted context omitted.

Does encryption at rest actually do much? The percentage of attacks that were perpetrated by people getting physical access to a drive must approach zero.

I think it's also meant to protect from potential mistakes in handling of hard disk decommissioning which presumably is a common thing with data centers.

Used to be, but e.g. where I work any decommissioned drive has to be DBANed (if it's spinning platters) or secure-erased (SSDs). If it can't be for some reason (e.g. it has failed) it needs to be physically destroyed. I would hope most data centers have similar policies in 2026, but that may be optimistic I guess.
Post reply on HN