USENIX Security2018Top-tier venue
Analysis of Privacy Protections in Fitness Tracking Social Networks -or- You can run, but can you hide?
Wajih Ul Hassan, Saad Hussain, Adam Bates
Abstract
Mobile fitness tracking apps allow users to track their workouts and share them with friends through online social networks. Although the sharing of personal data is an inherent risk in all social networks, the dangers presented by sharing personal workouts comprised of geospatial and health data may prove especially grave. While fitness apps offer a variety of privacy features, at present it is unclear if these countermeasures are sufficient to thwart a determined attacker, nor is it clear how many of these services' users are at risk. In this work, we perform a systematic analysis of privacy behaviors and threats in fitness tracking social networks. Collecting a month-long snapshot of public posts of a popular fitness tracking service (21 million posts, 3 million users), we observe that 16.5% of users make use of Endpoint Privacy Zones (EPZs), which conceal fitness activity near user-designated sensitive locations (e.g., home, office). We go on to develop an attack against EPZs that infers users' protected locations from the remaining available information in public posts, discovering that 95.1% of moderately active users are at risk of having their protected locations extracted by an attacker. Finally, we consider the efficacy of state-of-the-art privacy mechanisms through adapting geo-indistinguishability techniques as well as developing a novel EPZ fuzzing technique. The affected companies have been notified of the discovered vulnerabilities and at the time of publication have incorporated our proposed countermeasures into their production systems.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext b70ca75e-606d-4a2e-9625-9bd2d935ec11Cited by top-tier papers5
- On (The Lack Of) Location Privacy in Crowdsourcing ApplicationsSpyros Boukoros, Mathias Humbert, Stefan Katzenbeisser, Carmela TroncosoUSENIX Security 2019 · 28 citations
- A Run a Day Won't Keep the Hacker Away: Inference Attacks on Endpoint Privacy Zones in Fitness Tracking Social NetworksKarel Dhondt, Victor Le Pochat, Alexios Voulimeneas, Wouter Joosen et al.CCS 2022 · 11 citations
- Swipe Left for Identity Theft: An Analysis of User Data Privacy Risks on Location-based Dating AppsKarel Dhondt, Victor Le Pochat, Yana Dimova, Wouter Joosen et al.USENIX Security 2024 · 4 citations
- Everyone's Privacy Matters! An Analysis of Privacy Leakage from Real-World Facial Images on Twitter and Associated User BehaviorsYuqi Niu, Weidong Qiu, Peng Tang, Lifan Wang et al.CSCW 2025 · 3 citations
- Watch your Watch: Inferring Personality Traits from Wearable Activity TrackersNoé Zufferey, Mathias Humbert, Romain Tavenard, Kévin HugueninUSENIX Security 2023
Builds on2
Related papers
- Users Can Deduce Sensitive Locations Protected by Privacy Zones on Fitness Tracking AppsJaron Mink, Amanda Rose Yuile, Uma Pal, Adam J. Aviv et al.CHI 2022 · 11 citations
- From Options to Action: Evaluating Adoption of Privacy Features in Fitness - Tracking PlatformsPantelina Ioannou, Angeliki Aktypi, Elias AthanasopoulosCHI 2026 · 1 citation
- If This Then What?: Controlling Flows in IoT AppsIulia Bastys, Musard Balliu, Andrei SabelfeldCCS 2018 · 119 citations
- "I'm not as afraid as a woman might be about sharing my exact location: " On the Intersection of Identity and Privacy Concerns in Fitness TrackingYeeun Jo, Mahnoor Jameel, Camille Cobb, Adam BatesCHI 2025 · 1 citation
- Understanding Fitness Tracker Users' Security and Privacy Knowledge, Attitudes and BehavioursSandra Gabriele, Sonia ChiassonCHI 2020 · 61 citations
