ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Apple and Nike don't toe security line

Leader ZDNet.co.uk

Published: 14 Dec 2006 17:41 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment
Apple and Nike don't toe security line

Apple and Nike may be top consumer brands, but you can't say they never put a foot wrong. The companies thought highly of their alliance to make running shoes report on exercise parameters via an iPod; after all, it neatly targets their preferred demographic. And if you can prevent the shoe-mounted sensor from catching fire mid-stride, what could possibly go wrong?

The answer, as both companies now realise, is privacy. Surreal as it may seem, security researchers have found a way to make the system tell tales on its users. Because the radio link between shoe and iPod isn't encrypted and contains a unique identifier, a determined snooper can automatically track their athletic prey — even plotting their course on Google Maps. The most intriguing and worrying aspect of it wasn't that it's possible to just do it, but that it can be done for a few pounds and with middling amounts of IT skills.

We doubt very much that anyone will suffer as a result of using this system, apart from the ever-present danger of ridicule due to conspicuous brand addiction. The message to Apple and Nike, though, is one that all companies should get: any product or service that stores or communicates personal data is a security risk. At some point during the development cycle, it should be looked at in that light. Even if the risk is considered too light to be worth fixing, the company should be aware of what could happen.

The warning comes at an apt time. As it becomes easier and cheaper to put intelligence and communication into ordinary objects, they'll join the connected world with all its penchant for convenience and unforeseen consequences. We expect safety standards to protect us with a device's physical and electrical characteristics. There is no safety standard for devices that says no communication can be intercepted nor personal information extracted. There should be: one day, there will be.

For now, individual companies must bear the responsibility for specifying and following their own best practice in this field. Apple and Nike were lucky: the solution to their problems is a little more design, and the worst they've suffered is a bit of embarrassment and some free publicity. That may not be the case next time some heel decides to snitch.

 

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
69 out of 133 people found this useful


Company/Topic Alerts

Create a new alert from the list below:







Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Facebook Bans Firefox 3

Ok this is the issue. Because I dared to try and access facebook with firefox 3, and all the cookies disabled, it won't let me back on there with firefox ever again, even though... More

1 comment

GoDaddy suspends travel-getaways.com d...

I'm very pleased to say that GoDaddy has suspended the travel-getaways.com domain. I blogged in June that to my surprise I had found I was the site administrator for travel-getaways.com,... More

1 comment

Hello, I’m a PC. I’m a Handheld.

Hello, I’m a PC. I’m a Handheld. Author: Eric Everson, Founder MyMobiSafe.com I have said it before and I am sure I’ll say it again, mobile devices are simply replacing computers.... More

Post a comment