RCR Wireless
  • News
  • Channels
    • 5G
    • 6G
    • BSS OSS
    • Carriers
    • IoT
    • Network Infrastructure
    • Open RAN
    • Private 5G
    • Telco AI
    • Telco Cloud
    • Test & Measurement
  • Resources
    • Reports
    • Webinars
    • White papers
    • AI Fundamentals
    • Analyst Angle
    • Editorial Calendar
    • Fundamentals
      • 5G NR Release 17
      • AI
        • Telco AI in 2025
    • Podcasts
      • Let’s Get Digital with Carrie Charles
      • Wireless Connectivity to Enable Industry 4.0 for the Middleprise
      • Well Technically…
      • Will 5G Change the World
      • Accelerating Industry 4.0 Digitalization
  • AI Infrastructure
  • Programs
  • Events
  • RCRtv
  • Advertise
  • Subscribe
Tuesday, August 18, 2026
RCR Wireless
  • News
  • Channels
    • 5G
    • 6G
    • BSS OSS
    • Carriers
    • IoT
    • Network Infrastructure
    • Open RAN
    • Private 5G
    • Telco AI
    • Telco Cloud
    • Test & Measurement
  • Resources
    • Reports
    • Webinars
    • White papers
    • AI Fundamentals
    • Analyst Angle
    • Editorial Calendar
    • Fundamentals
      • 5G NR Release 17
      • AI
        • Telco AI in 2025
    • Podcasts
      • Let’s Get Digital with Carrie Charles
      • Wireless Connectivity to Enable Industry 4.0 for the Middleprise
      • Well Technically…
      • Will 5G Change the World
      • Accelerating Industry 4.0 Digitalization
  • AI Infrastructure
  • Programs
  • Events
  • RCRtv
  • Advertise
  • Subscribe
Add RCR Wireless as a preferred source on Google
  • Qualcomm 6G Insights
  • Huawei Content Hub
  • Qualcomm – 6G Vision
  • OSS/BSS Channel
  • RCRTech Roundtable: AI Infrastructure
RCR Wireless
RCR Wireless
  • Advanced Mimo
  • Mobile mmWave
  • 5G Positioning
  • Green Networks
  • Metaverse
  • Automotive
  • Industrial and Wide-area IoT
Copyright 2021 - All Right Reserved
Home - Reality Check: Wearable devices underscore need for secure design
OpinionReality Check

Reality Check: Wearable devices underscore need for secure design

by Reality Check April 26, 2016
written by Reality Check April 26, 2016 Share
LinkedinEmail
Share 0LinkedinEmail
wearable devices
127

Security issues connected with consumer uptake of wearable devices and the ‘Internet of Things’ remains a significant hurdle for the market

Wearable computing devices are changing the way humans interact with technology and that shift has security implications that must be addressed.

Wearable fitness tracking devices – which intersect fitness and health data with wearable, networked technology – manifest old sources of risk, historically seen in desktop and Web applications, in novel ways. At the same time, consumers are increasingly embracing wearables and their capabilities. Nearly half of all consumers plan to buy wearable devices, including fitness trackers, by 2019, according to a 2014 Forbes article.

These devices, of course, don’t just read and display your vital signs, they transmit those intimately personal data to other devices and to the cloud. As the consumer market for wearables expands beyond fitness tracking devices and, particularly, as devices interact in increasingly complex ways, the potential attack surface presented by these devices will grow apace.

This growing source of risk highlights a truth across the software industry: today’s focus on finding and fixing security defects is insufficient. We must expand that focus to include secure design decisions before the first line of code is written and, by doing so we can prevent many of the worst security failures.

A fictitious design as proxy

The recent “WearFit: Security design analysis of a wearable fitness tracker” report is based on a fictitious fitness tracking device design, but mirrors actual devices on the market. The report begins with a system overview of the device’s hardware and software architecture, as well as detailing the mobile application used for communicating health data and the backend website that round out the device ecosystem. The balance of the report uses the top 10 software security design flaws – originally published in the IEEE report “Avoiding the top 10 software security design flaws” – to walk the reader through the security design decisions that are most important to the WearFit system. This work was accomplished under the auspices of the IEEE Cybersecurity Initiative and its offshoot the IEEE Center for Secure Design, whose mission is to shift the software industry’s focus from a reactive search for bugs to a more proactive focus on secure design that prevents vulnerabilities.

Consumer awareness and IoT

Although the report is written specifically for software security designers, we’d be pleased if a broad swath of stakeholders, including consumers, came to understand wearable device security is a very real concern with real-world implications. While consumers do not need to understand the arcana of secure software design, software architect and developers, even in nonsecurity roles, will benefit immensely from an understanding of and investment in addressing secure design considerations.

We’ve all read the headlines about data breaches. Consumers should be aware that wearable technology, from a security standpoint, shares the same basic risk vectors as other computing devices. How consumers choose and utilize devices can impact the severity and nature of risk. The privacy and security implications of a fitness and health data might not be immediately obvious to end users, but our report highlights why personal fitness information needs strong protections and some of the ways it can be abused if its confidentiality or integrity is compromised.

Baking security in

As you can imagine, space does not permit us to fully summarize the WearFit report’s findings, but it’s worth delving into one of the design flaws it covers as an example. Let’s use No. 8: Always consider the users.

“Avoiding the top 10 software security design flaws” mentions that:
“The security stance of a software system is inextricably linked to what its users do with it. It is … important that all security related mechanisms are designed [to make] it easy to deploy, configure, use and update the system securely. Security is not a feature that can simply be added to a software system, but rather a property emerging from how the system was built and is operated.”

As a consumer device, of course, the entire WearFit system is built around the end user. Many of the fundamental architecture decisions in the system were made to promote a positive user experience, the key to market success. But there’s always a trade off between ease-of-use and security.

For example, WearFit users interact most frequently with the Web application, and the user experience begins with authentication. New users must register a strong password with the site and access a secure recovery procedure if they forget their password. Password strength increases when 32 characters are required, but usability is increased when four-digit PINs are allowed. The middle ground calls for an eight character minimum with three distinct character types and no dictionary words allowed. Users can also authenticate using third-party services, including Google Plus and Facebook.

Looking beyond password policies for another example, the WearFit device is, of course, portable. That requires adequate battery life be paired with the modest memory, computational power, storage space and long-distance communication capabilities available in that form factor.

Because of these hardware limitations, the device seizes every opportunity to inexpensively upload activity data to the WearFit server. In some instances, data is transmitted over other WearFit devices running the WearFit mobile application, which requires additional security controls to ensure that users can’t see or tamper with other users’ data.

This link between the user and secure design decisions is critical to understand. WearFit users aren’t security professionals and often aren’t aware certain data is sensitive or how to secure them. Security architecture making it easy for users to do the right (most secure) thing is just one example of how strong security design decisions reduce risk.

Jacob West is chief architect for security products at NetSuite, a founding member of the IEEE Center for Secure Design and lead author of “WearFit: Security design analysis of a wearable fitness tracker.”

Editor’s Note: The RCR Wireless News Reality Check section is where C-level executives and advisory firms from across the mobile industry share unique insights and experiences.

You Might Also Like
  • Thursday (telco diary) | Ghosts in the machine – Wanted: more humans to build AI
  • Wednesday (telco diary) | Smells like team spirit – and that tech-bro Musk
  • Tuesday (telco diary) | About open RAN, c/o Dell’Oro…
  • Europe’s AI ambitions will fail without sovereign cloud infrastructure (Reader Forum)
  • Monday (telco diary) | Digging in, moving up – lessons from Lumen
  • Friday (telco diary) | Friday night fare – private 5G to go

Table of Contents

  • Security issues connected with consumer uptake of wearable devices and the ‘Internet of Things’ remains a significant hurdle for the market
  • A fictitious design as proxy
  • Consumer awareness and IoT
  • Baking security in
Share 0 LinkedinEmail
Reality Check

Subject to editorial review and copy edit, RCR Wireless News accepts bylined thought leadership articles, up to 1000 words, from industry executives. Submitted articles become property of RCR Wireless News. Submit articles to [email protected] with "Reality Check" in subject line.

previous post
What is devops and why is it important for telecom?
next post
Reality Check: Looking for meaning in Verizon Q1 results

White Papers

  • Norton eBook: The 2026 Telco Playbook

  • Enea White Paper: Why Intelligent AAA is the Swiss Army Knife of Telecom

  • CSG White Paper: Telco AI Enabler: Mediation’s Defining Role

  • Enea White Paper: Scalable Database Design for 5G and Beyond

  • Supermicro and NVIDIA Whitepaper: Powering sovereign AI at scale

Editorial Reports

  • Report: NTN in motion — evolving standards, expanding services

  • Market Pulse Report: Telco AI in 2026 – Trends, Challenges and Opportunities

  • Nvidia Report: The State of AI in Telecommunications: 2026 Trends

Webinars

  • Webinar: Building 6G — aligning technology, policy and purpose

  • SIMCom Webinar: Scaling your next deployment – from plastic to provisioning

  • Webinar: Rethinking the RAN as AI, cloud and openness converge

  • Webinar: Scale-Up, Scale-Out, Scale-Across – Building AI-Era Network Fabrics

  • Webinar: NTN in motion – evolving standards, expanding services

Since 1982, RCR Wireless News has been providing wireless and mobile industry news, insights, and analysis to mobile and wireless industry professionals, decision makers, policy makers, analysts and investors.

Facebook Twitter Youtube Linkedin Envelope Rss

Useful Links

  • Subscribe
  • About RCR Wireless News
  • Contact Us
  • Advertise
  • Editorial Calendar
  • Archive
  • RSS
  • Wireless News Archive
  • Subscribe
  • About RCR Wireless News
  • Contact Us
  • Advertise
  • Editorial Calendar
  • Archive
  • RSS
  • Wireless News Archive

Edtior's Picks

The bulk-managed Wi-Fi threat didn’t die – it fragmented (Analyst Angle)
Indosat, Nvidia launch AI center as telco expands AI infra
Lockheed’s NetSense turns Verizon’s 5G network into a drone-tracking system

Latest Articles

The bulk-managed Wi-Fi threat didn’t die – it fragmented (Analyst Angle)
Indosat, Nvidia launch AI center as telco expands AI infra
Lockheed’s NetSense turns Verizon’s 5G network into a drone-tracking system
Criss-cross comms – Lumen bets on east-west AI, while the edge keeps north-south in play

© 2026 RCR Wireless News All Right Reserved. Developed by Eight Hats.

Cookie Policy | Privacy Policy

RCR Wireless
  • News
  • Channels
    • 5G
    • 6G
    • BSS OSS
    • Carriers
    • IoT
    • Network Infrastructure
    • Open RAN
    • Private 5G
    • Telco AI
    • Telco Cloud
    • Test & Measurement
  • Resources
    • Reports
    • Webinars
    • White papers
    • AI Fundamentals
    • Analyst Angle
    • Editorial Calendar
    • Fundamentals
      • 5G NR Release 17
      • AI
        • Telco AI in 2025
    • Podcasts
      • Let’s Get Digital with Carrie Charles
      • Wireless Connectivity to Enable Industry 4.0 for the Middleprise
      • Well Technically…
      • Will 5G Change the World
      • Accelerating Industry 4.0 Digitalization
  • AI Infrastructure
  • Programs
  • Events
  • RCRtv
  • Advertise
  • Subscribe
RCR Wireless
  • News
  • Channels
    • 5G
    • 6G
    • BSS OSS
    • Carriers
    • IoT
    • Network Infrastructure
    • Open RAN
    • Private 5G
    • Telco AI
    • Telco Cloud
    • Test & Measurement
  • Resources
    • Reports
    • Webinars
    • White papers
    • AI Fundamentals
    • Analyst Angle
    • Editorial Calendar
    • Fundamentals
      • 5G NR Release 17
      • AI
        • Telco AI in 2025
    • Podcasts
      • Let’s Get Digital with Carrie Charles
      • Wireless Connectivity to Enable Industry 4.0 for the Middleprise
      • Well Technically…
      • Will 5G Change the World
      • Accelerating Industry 4.0 Digitalization
  • AI Infrastructure
  • Programs
  • Events
  • RCRtv
  • Advertise
  • Subscribe
@2020 - All Right Reserved. Designed and Developed by PenciDesign