Author:
Cook Stephen,Mehrnezhad Maryam,Toreini Ehsan
Abstract
AbstractThe number of digital health products is increasing faster than ever. These technologies (e.g. mobile apps and connected devices) collect massive amounts of data about their users, including health, medical, sex life, and other intimate data. In this paper, we study a set of 21 Internet of Things (IoT) devices advertised for general and intimate health purposes of female bodies (aka female-oriented technologies or FemTech). We focus on the security of the Bluetooth connection and communications between the IoT device and the mobile app. Our results highlight serious security issues in the current off-the-shelf FemTech devices. These include unencrypted Bluetooth traffic, unknown Bluetooth services and insecure Bluetooth authentication when connecting to the app. We implement Bluetooth attacks on the communication between these devices and apps, resulting in malfunctioning of the device and app. We discuss our results and provide recommendations for different stakeholders to improve the security practices of Bluetooth-enabled IoT devices in such a sensitive and intimate domain.
Funder
Engineering and Physical Sciences Research Council
Publisher
Springer Science and Business Media LLC
Reference42 articles.
1. Almeida, T., Mehrnezhad, M., Cook, S.: The importance of collective privacy in digital sexual and reproductive health. In: 17th Annual UK Fertility Conference, and The Human Fertility Journal, (2023)
2. Almeida, T., Shipp, L., Mehrnezhad, M., Toreini, E.: Bodies like yours: enquiring data privacy in FemTech. In NordiCHI Adjunct ’22: Adjunct Proceedings of the 2022 Nordic Human-Computer Interaction Conference. ACM (2022)
3. Brauer, S., Zubow, A., Zehl, S., Roshandel, M., Mashhadi-Sohi, S.: On Practical selective jamming of bluetooth low energy advertising. In 2016 IEEE Conference on Standards for Communications and Networking (CSCN) (2016)
4. Brown, E.: Supercharged sexism: the triple threat of workplace monitoring for women. Available at SSRN 3680861 (2020)
5. Brown, E.: The FemTech paradox: how workplace monitoring threatens women’s equity. Jurimetrics (2021)