Feeds

Garmin Connect exposes cycle trip details to world

Takes Facebookian attitude to privacy

Internet Security Threat Report 2014

FourSquare is notorious for disclosing the location of users to world+dog, but the perils of applications that tell potential burglars or stalkers you aren't at home extend far beyond social networks.

Garmin Connect, which allows members to upload GPS computer data from cycling trips, shares this data by default, creating a privacy issue that many users may have failed to notice. The feature was spotted by Mark Croonen, secretary of the Australian Defense Cycling Club.

Croonen warns that even if a user shields ride data from public view these changes will not be applied retrospectively, so previous ride data will be disclosed.

"When you upload your ride data, by default Garmin Connect shares your data with the world unless you specifically change the privacy settings," Croonen explains. "So all things being equal the average user won’t give this a second thought and will leave the settings on public access. Furthermore even if you do change the default settings it won’t change the settings for any rides you have already uploaded, you’ll have to go back and manually change the setting for each ride."

Surfers can browse the Garmin Connect site to identify riders in a particular area and times when are habitually away from home without even having to log on, arguably creating a handy utility for potential burglars in the process. The perils of making location updates available through social networking services such as FourSquare, most clearly illustrated by the PleaseRobMe site, also apply to Garmin Connect, and probably many other web applications.

"I don’t mean to pick on Garmin Connect as I’m sure other services probably have the same issue but if you are going to use these services this is probably something you want to keep in mind," Croonen concludes in a thought-provoking entry on his blog, The Cycle Way. ®

Bootnote

A hat tip to the security researchers at Sunbelt for bringing this issue to wider attention.

Choosing a cloud hosting partner with confidence

More from The Register

next story
Webcam hacker pervs in MASS HOME INVASION
You thought you were all alone? Nope – change your password, says ICO
You really need to do some tech support for Aunty Agnes
Free anti-virus software, expires, stops updating and p0wns the world
USB coding anarchy: Consider all sticks licked
Thumb drive design ruled by almighty buck
Attack reveals 81 percent of Tor users but admins call for calm
Cisco Netflow a handy tool for cheapskate attackers
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
prev story

Whitepapers

Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
The hidden costs of self-signed SSL certificates
Exploring the true TCO for self-signed SSL certificates, including a side-by-side comparison of a self-signed architecture versus working with a third-party SSL vendor.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.