Next Article in Journal
Proposal for a Battery to Evaluate Functional Capacity in Older Adults with Disabilities
Previous Article in Journal
Multi-Scale Convolutional Attention and Structural Re-Parameterized Residual-Based 3D U-Net for Liver and Liver Tumor Segmentation from CT
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
Article

The Newer, the More Secure? Standards-Compliant Bluetooth Low Energy Man-in-the-Middle Attacks on Fitness Trackers

1
Department of Mathematics and Computer Science, Phillips-University of Marburg, 35032 Marburg, Germany
2
Department of Epileptology, Medical Faculty, University Hospital Bonn, 53127 Bonn, Germany
*
Author to whom correspondence should be addressed.
Sensors 2025, 25(6), 1815; https://doi.org/10.3390/s25061815
Submission received: 29 January 2025 / Revised: 28 February 2025 / Accepted: 12 March 2025 / Published: 14 March 2025
(This article belongs to the Special Issue Cybersecurity in IoT-Based Applications)

Abstract

The trend in self-tracking devices has remained unabated for years. Even if they record a large quantity of sensitive data, most users are not concerned about their data being transmitted and stored in a secure way from the device via the companion app to the vendor’s server. However, the secure implementation of this chain from the manufacturer is not always given, as various publications have already shown. Therefore, we first provide an overview of attack vectors within the ecosystem of self-tracking devices. Second, we evaluate the data security of eight contemporary fitness trackers from leading vendors by applying four still partly standards-compliant Bluetooth Low-Energy Man-in-the-Middle (MitM) attacks. Our results show that the examined devices are partially vulnerable against the attacks. For most of the trackers, the manufacturers put different security measures in place. These include short and user-initiated visibility and connectivity or app-level authentication to limit the attack surface. Interestingly, newer models are more likely to be attackable, underlining the constant need for verifying the security of BLE devices, reporting found vulnerabilities, and also strengthening standards and improving security awareness among manufacturers and users. Therefore, we finish our work with recommendations and best practices for law- and regulation-makers, vendors, and users on how to strengthen the security of BLE devices.
Keywords: fitness tracker; security; Bluetooth Low Energy; BLE; Internet of Things; IoT fitness tracker; security; Bluetooth Low Energy; BLE; Internet of Things; IoT

Share and Cite

MDPI and ACS Style

Greß, H.; Krüger, B.; Tischhauser, E. The Newer, the More Secure? Standards-Compliant Bluetooth Low Energy Man-in-the-Middle Attacks on Fitness Trackers. Sensors 2025, 25, 1815. https://doi.org/10.3390/s25061815

AMA Style

Greß H, Krüger B, Tischhauser E. The Newer, the More Secure? Standards-Compliant Bluetooth Low Energy Man-in-the-Middle Attacks on Fitness Trackers. Sensors. 2025; 25(6):1815. https://doi.org/10.3390/s25061815

Chicago/Turabian Style

Greß, Hannah, Björn Krüger, and Elmar Tischhauser. 2025. "The Newer, the More Secure? Standards-Compliant Bluetooth Low Energy Man-in-the-Middle Attacks on Fitness Trackers" Sensors 25, no. 6: 1815. https://doi.org/10.3390/s25061815

APA Style

Greß, H., Krüger, B., & Tischhauser, E. (2025). The Newer, the More Secure? Standards-Compliant Bluetooth Low Energy Man-in-the-Middle Attacks on Fitness Trackers. Sensors, 25(6), 1815. https://doi.org/10.3390/s25061815

Note that from the first issue of 2016, this journal uses article numbers instead of page numbers. See further details here.

Article Metrics

Back to TopTop