From smartwatches to glasses and finger rings – the range of wearable devices are steadily expanding. Combined with the might of Internet of Things, wearable devices have a life transforming effect. While it is fancy and often productive to carry these wearables around, the billion dollar question is, How safe are these wearables?
What if your favourite wearable is just another door that hackers and cybercriminals can break into to make away with the control of your personal and professional life?
Security concerns in wearables are legitimate. A study by Auth0 has confirmed that more than 52% of wearable device users feel that they are provided with inadequate security measures.
VTech, a popular brand that sells wearable for kids suffered a security breach which resulted in the leakage of private information of more than 200,000 children and their parents.
There is no better time to sit back and analyze the security concerns and the ways to negate them, right now, in the present.
Security Concerns in IoT Wearables
Wearables are now being used for purposes that go far beyond calorie counting and fitness tracking. They are now even part of BYOD enterprise work philosophy and are used by remote employees to constantly collaborate and communicate with their peers. Though considered futuristic, the IoT wearable ecosystem is riddled with several security concerns.
Easy to Misplace
IoT wearables are tiny devices that are powered by chips and sensors. Their sheer size makes them easy to be misplaced, lost or even stolen. Along with the misplacement, the data that is contained in the wearable device also stands the chance to fall into the wrong hands. As a result, the first concern is how can physical security of a wireless device, that is half the size of a smartphone, be ensured.
A Rather Inconsistent Platform
IoT wearables are a milieu of devices originating from several manufacturers, each following diverse manufacturing and software installation manoeuvres. The inconsistency is also visible in the attitude taken towards user privacy and security.
While there are brands that consider security as their topmost priority, there are equal number of brands which adopt a laid-back attitude towards installing security features or updating them with changing times.
Multiple Hack-Prone Connectivity Points
IoT wearables now come adaptable for cloud connectivity, NFC, Wi-Fi and several other communication protocols. These increasing connectivity abilities also increase the hack-proneness of these devices. Hackers now can exploit multiple networking points to gain access to other connected devices.
For instance, imagine a home security system that can be controlled via a smartphone which is connected to a wearable device. Breaching the security of the wearable device, gives quick access to the smartphone which in turn opens up the home security system.
Remember the old age saying? Your chain is only as strong as the weakest link. Well, in this case, your IoT wearable can be the weakest link in the chain of connected devices.
Access to Micro-level Personal Information
Primarily, most wearables are used as devices for fitness tracking, receiving notifications and storing music. However, it is not the personal health information and media libraries that hackers are after. They want precious data that will lead to bigger financial gains.
There are wearables which are used almost at par with smartphones. Digital wallets, social media, email, photos; everything can be accessed and retrieved in smart devices. Hackers are after such devices and users who use such devices to steal financial information, personal access controls and much more that the wearables store. This micro-level personal information heightens the level of security concern in using IoT wearables.
Tips to Secure IoT Wearables
Iot wearable security can be reinforced by taking some vital decisions, typically from the user front. Here are some ways to do that:
1. Don’t Make Your Device an Object of Attention
You have a wearable device that is too good? Well, don’t flaunt it. By displaying its ownership you will only be increasing the risk of data stored in the device. Moreover, wearable devices are expensive, often costing a bomb as much as a high-end smartphone itself. As a result, they are also desirable targets for thieves who want to pocket money from its resale.
Despite the cost, the build and the make of these wearables are not anything secure. For instance, smartwatches have straps which are easy to remove by any experienced thief who is a veteran in street pickpocketing. The bottomline is, establish physical security for your device. Conceal it when not in use. Use it responsibly and be aware of the surroundings where its security can be compromised.
2. Invest in the Most Secure Device
Like we said before, IoT wearables do not have a common security protocol. Thus, the burden of picking a wearable that is most secure for personal use falls upon the user.
While buying a wearable, the privacy policy, data collected and sent to manufacturer server, etc. should be considered. Factors like remote data erasing, geo-locating of misplaced device, biometric access, etc. should be considered. In the end, the most secure device, even if it is a tad pricey than the rest, is the safe bet.
3. Set Up Access Controls and Encryption
Patterns, PINs, passwords, etc. can be guessed or duplicated. However, biometric security is irreplaceable. They make it close to impossible for hackers or any other user other than the owner to access the device data. Security concerns in the IoT wearable ecosystem can be mitigated by using unique biometric systems like:
- Finger prints,
- Iris scan
- Palm print
- Face recognition
- Retina scan, etc
The latest batch of wearables and even smartphones come with these security provisions.
4. Limit the Information Shared through Wearables
The present generation of smartwatches can host up to 64GB of internal storage. This makes users to rely on them too much to store information that not necessarily is stored in a smartwatch. The questions worth pondering are:
- How much little can you store on your wearable device?
- How less can you use your wearable for critical tasks?
The less you store and the less you rely will minimize your loss in case of a theft. Limit the information that your wearable device can provide about you. Reduce the usage of apps that require location access, smartphone access, images and things to do. Use them, but be conscious enough to purge them or delete them once the task is done.
5. Update Patches Regularly
Like smartphones, software updates for wearables also happen over-the-air. Users have to enable the security patches to be updated regularly in order to plug the existing security lapses in the device. These security updates also enhance the performance and remove any pre-existing problems in the wearable.
In 2014, the LG Smartwatch ran into some trouble as its rear started corroding. LG was able to fix the same by releasing a firmware update that also removed the irritation and quality issues in the device.
6. Configure Anti-Theft Settings
Apple, the pioneer of smart watches introduced an anti theft system which allowed users to locate their Apple Watch using iPhone. In case the watch is stolen or lost, users can connect to the device through their iPhones and locate its real-time geographical location. There are similar anti theft systems in other wearables too which can be configured by the user for use in a later stage.
7. Install Security Applications
Like antivirus software for laptops and security apps for mobile phones, third party security applications are also available for wearables.Knock, OneID, DuoSecurity, Authy, are some of the security apps presently available for Apple Watches. These security applications help prevent misuse of the wearable device and also helps pairing it up with other owner devices for better control and organization.
8. Keep Sensitive Information Offline
Another simple and effective way to protect your information from hackers is to keep it away from their reach. Storing sensitive information away from the wearables, possibly in offline storage ensures its safety. Of course, the data cannot be always accessed and the real utility of the wearable will be diminished, however, it is better to have limited accessibility than to lose it forever.
9. Set Up Multi-Factor Authentication
Multi-factor authentication (MFA)Â on a wearable device ensures that the user is alerted as soon as there is a suspicious activity from another connected device. It is also a foolproof way to ensure that nobody else other than the sole owner of the device is able to access it. MFA adds a layer of protection on top of the existing security controls thus preventing any possibility of misuse by unauthorized personnel.
10. Set Up Cloud Sync
Cloud connectivity is the bedrock foundation for wearable devices. It paves the way for data transfer from the device to the cloud account of the user. However, there is always the possibility for the user to turn or off cloud sync depending on connectivity and device usage.
In terms of data security, it is always ideal to keep the cloud sync on. That way, even if the device is lost, the data remains intact in the cloud server which can be disconnected from the wearable easily.
In a Nutshell
Security for IoT wearables is a topic that is garnering attention. While tech enthusiasts lap up anything futuristic with excitement, it is important to take a moment and think how the security of these devices can be configured to keep personal data secure.Â