Feeds

Garmin Connect exposes cycle trip details to world

Takes Facebookian attitude to privacy

Secure remote control for conventional and virtual desktops

FourSquare is notorious for disclosing the location of users to world+dog, but the perils of applications that tell potential burglars or stalkers you aren't at home extend far beyond social networks.

Garmin Connect, which allows members to upload GPS computer data from cycling trips, shares this data by default, creating a privacy issue that many users may have failed to notice. The feature was spotted by Mark Croonen, secretary of the Australian Defense Cycling Club.

Croonen warns that even if a user shields ride data from public view these changes will not be applied retrospectively, so previous ride data will be disclosed.

"When you upload your ride data, by default Garmin Connect shares your data with the world unless you specifically change the privacy settings," Croonen explains. "So all things being equal the average user won’t give this a second thought and will leave the settings on public access. Furthermore even if you do change the default settings it won’t change the settings for any rides you have already uploaded, you’ll have to go back and manually change the setting for each ride."

Surfers can browse the Garmin Connect site to identify riders in a particular area and times when are habitually away from home without even having to log on, arguably creating a handy utility for potential burglars in the process. The perils of making location updates available through social networking services such as FourSquare, most clearly illustrated by the PleaseRobMe site, also apply to Garmin Connect, and probably many other web applications.

"I don’t mean to pick on Garmin Connect as I’m sure other services probably have the same issue but if you are going to use these services this is probably something you want to keep in mind," Croonen concludes in a thought-provoking entry on his blog, The Cycle Way. ®

Bootnote

A hat tip to the security researchers at Sunbelt for bringing this issue to wider attention.

New hybrid storage solutions

More from The Register

next story
Google recommends pronounceable passwords
Super Chrome goes into battle with Mr Mxyzptlk
Infosec geniuses hack a Canon PRINTER and install DOOM
Internet of Stuff securo-cockups strike yet again
Snowden, Dotcom, throw bombs into NZ election campaign
Claim of tapped undersea cable refuted by Kiwi PM as Kim claims extradition plot
Reddit wipes clean leaked celeb nudie pics, tells users to zip it
Now we've had all THAT TRAFFIC, we 'deplore' this theft
Apple Pay is a tidy payday for Apple with 0.15% cut, sources say
Cupertino slurps 15 cents from every $100 purchase
YouTube, Amazon and Yahoo! caught in malvertising mess
Cisco says 'Kyle and Stan' attack is spreading through compromised ad networks
TorrentLocker unpicked: Crypto coding shocker defeats extortionists
Lousy XOR opens door into which victims can shove a foot
prev story

Whitepapers

Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.