This is why I'm so disappointed that I haven't seen any of these devices let you log to your own servers.
I'm not saying make it easy, I can hijack a DNS entry and host a server pretending to be you, just open the protocol and let me host the darn server myself.
The give-away to their goals, is that these devices you buy are one-time purchases that rely on cloud services. Who's paying for the servers your device is uploading to, and how are they coming up with that money now that they have this wealth of health data on you and millions of other people. I have nightmares about what most business people would do in that situation, and it's why I stopped using my device.
The solution to this is very simple: cut off their access entirely.
I use an SSL proxy at home and if you attempt to pin certificates such that the local certificate store is ignored or inaccessible. Your device can be guaranteed to not have access from my network. End of story.
Comments
This is why I'm so disappointed that I haven't seen any of these devices let you log to your own servers.
I'm not saying make it easy, I can hijack a DNS entry and host a server pretending to be you, just open the protocol and let me host the darn server myself.
The give-away to their goals, is that these devices you buy are one-time purchases that rely on cloud services. Who's paying for the servers your device is uploading to, and how are they coming up with that money now that they have this wealth of health data on you and millions of other people. I have nightmares about what most business people would do in that situation, and it's why I stopped using my device.
Not for long.[1]
[1] https://blog.mozilla.org/security/2015/04/30/deprecating-non...
The solution to this is very simple: cut off their access entirely.
I use an SSL proxy at home and if you attempt to pin certificates such that the local certificate store is ignored or inaccessible. Your device can be guaranteed to not have access from my network. End of story.
I don't think these watches use a browser to reach their servers (i.e. the cloud).
Once it's the norm for browsers it wouldn't make much sense not to use HTTPS everywhere.