{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/101232"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/101232","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"Analysis of privacy protections in fitness tracking applications","abstract":"Mobile fitness tracking apps allow users to track their workouts and share them with friends through online social networks. Although the sharing of personal data is an inherent risk in all social networks, the dangers presented by sharing personal workouts comprised of geospatial and health data may prove especially grave. While fitness apps offer a variety of privacy features, at present it is unclear if these countermeasures are sufficient to thwart a determined attacker, nor is it clear how many of their users are at risk. In this work, we perform a systematic analysis of privacy behaviors and threats in fitness tracking social networks. Collecting a month-long snapshot of public posts to the popular Strava fitness tracking service (21 million posts, 3 million users), we observe that 16.5% of users make use of Endpoint Privacy Zones (EPZs), which conceal fitness activity nearby user-designated sensitive locations (e.g., home, office). We go on to develop an attack against EPZs that infers users’ protected locations from the remaining available information in public posts, discovering that 95.1% of moderately active users are at risk of having their protected locations extracted by an attacker. Finally, we consider the efficacy of state-of-the-art privacy mechanisms through adapting geo-indistinguishability techniques as well as developing a novel EPZ fuzzing technique. Strava has been notified of the discovered vulnerabilities and (at time of submission) is preparing to incorporate our countermeasures into their production system.","abstract_html":"Mobile fitness tracking apps allow users to track their workouts and share them with friends through online social networks. Although the sharing of personal data is an inherent risk in all social networks, the dangers presented by sharing personal workouts comprised of geospatial and health data may prove especially grave. While fitness apps offer a variety of privacy features, at present it is unclear if these countermeasures are sufficient to thwart a determined attacker, nor is it clear how many of their users are at risk. In this work, we perform a systematic analysis of privacy behaviors and threats in fitness tracking social networks. Collecting a month-long snapshot of public posts to the popular Strava fitness tracking service (21 million posts, 3 million users), we observe that 16.5% of users make use of Endpoint Privacy Zones (EPZs), which conceal fitness activity nearby user-designated sensitive locations (e.g., home, office). We go on to develop an attack against EPZs that infers users’ protected locations from the remaining available information in public posts, discovering that 95.1% of moderately active users are at risk of having their protected locations extracted by an attacker. Finally, we consider the efficacy of state-of-the-art privacy mechanisms through adapting geo-indistinguishability techniques as well as developing a novel EPZ fuzzing technique. Strava has been notified of the discovered vulnerabilities and (at time of submission) is preparing to incorporate our countermeasures into their production system.","abstract_has_math":false,"creators":["Hussain, Muhammad Saad"],"institution":"University of Illinois at Urbana-Champaign","degree_name":"M.S.","degree_level":"Thesis","degree_discipline":"Computer Science","degree_department":null,"school":null,"contributors":["Bates, Adam"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2018,"date_issued":"2018-09-04T20:41:58Z","date_published":"2018-09-04T20:41:58Z","updated_at":"2026-07-22T22:24:38Z","subjects":["Location Privacy, Fitness Tracking Applications"],"languages":["en"],"rights":["Copyright 2018 Muhammad Hussain"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"http://hdl.handle.net/2142/101232","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Bates, Adam"]},{"key":"dc:creator","label":"Author","values":["Hussain, Muhammad Saad"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2018-09-04T20:41:58Z","2020-09-05T09:15:09Z","2018-04-26","2018-05"]},{"key":"dc:type","label":"Dc Type","values":["text"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Computer Science"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Thesis"]},{"key":"thesis:degree_name","label":"Degree Name","values":["M.S."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois at Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Location Privacy, Fitness Tracking Applications"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2018 Muhammad Hussain"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["http://hdl.handle.net/2142/101232"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["Mobile fitness tracking apps allow users to track their workouts and share them with friends through online social networks. Although the sharing of personal data is an inherent risk in all social networks, the dangers presented by sharing personal workouts comprised of geospatial and health data may prove especially grave. While fitness apps offer a variety of privacy features, at present it is unclear if these countermeasures are sufficient to thwart a determined attacker, nor is it clear how many of their users are at risk. In this work, we perform a systematic analysis of privacy behaviors and threats in fitness tracking social networks. Collecting a month-long snapshot of public posts to the popular Strava fitness tracking service (21 million posts, 3 million users), we observe that 16.5% of users make use of Endpoint Privacy Zones (EPZs), which conceal fitness activity nearby user-designated sensitive locations (e.g., home, office). We go on to develop an attack against EPZs that infers users’ protected locations from the remaining available information in public posts, discovering that 95.1% of moderately active users are at risk of having their protected locations extracted by an attacker. Finally, we consider the efficacy of state-of-the-art privacy mechanisms through adapting geo-indistinguishability techniques as well as developing a novel EPZ fuzzing technique. Strava has been notified of the discovered vulnerabilities and (at time of submission) is preparing to incorporate our countermeasures into their production system.","Submission published under a 24 month embargo labeled 'U of I Access', the embargo will last until 2020-05-01","The student, Muhammad Hussain, accepted the attached license on 2018-04-25 at 21:03.","The student, Muhammad Hussain, submitted this Thesis for approval on 2018-04-25 at 21:10.","This Thesis was approved for publication on 2018-04-26 at 14:30.","DSpace SAF Submission Ingestion Package generated from Vireo submission #12510 on 2018-08-31 at 17:21:36","Made available in DSpace on 2018-09-04T20:41:58Z (GMT). No. of bitstreams: 3 HUSSAIN-THESIS-2018.pdf: 5289819 bytes, checksum: cc4aaa8bee2598593e9ea49672482d3f (MD5) Saad Thesis.zip: 5556890 bytes, checksum: ea48f0397ef5cfc21d42b1f64055c561 (MD5) LICENSE.txt: 4213 bytes, checksum: 17dca19b5b422ff5a0b4e769d440b003 (MD5) Previous issue date: 2018-04-26","Embargo set by: Seth Robbins for item 107317 Lift date: 2020-09-04T20:42:08Z Reason: Author requested U of Illinois access only (OA after 2yrs) in Vireo ETD system","U of I Only Restriction Lifted for Item 107317 on 2020-09-05T09:15:09Z."]},{"key":"dc:format","label":"Dc Format","values":["application/pdf"]},{"key":"dc:title","label":"Title","values":["Analysis of privacy protections in fitness tracking applications"]}]}],"canonical_facts":{"dc:contributor":["Bates, Adam"],"dc:creator":["Hussain, Muhammad Saad"],"dc:date":["2018-09-04T20:41:58Z","2020-09-05T09:15:09Z","2018-04-26","2018-05"],"dc:description":["Mobile fitness tracking apps allow users to track their workouts and share them with friends through online social networks. Although the sharing of personal data is an inherent risk in all social networks, the dangers presented by sharing personal workouts comprised of geospatial and health data may prove especially grave. While fitness apps offer a variety of privacy features, at present it is unclear if these countermeasures are sufficient to thwart a determined attacker, nor is it clear how many of their users are at risk. In this work, we perform a systematic analysis of privacy behaviors and threats in fitness tracking social networks. Collecting a month-long snapshot of public posts to the popular Strava fitness tracking service (21 million posts, 3 million users), we observe that 16.5% of users make use of Endpoint Privacy Zones (EPZs), which conceal fitness activity nearby user-designated sensitive locations (e.g., home, office). We go on to develop an attack against EPZs that infers users’ protected locations from the remaining available information in public posts, discovering that 95.1% of moderately active users are at risk of having their protected locations extracted by an attacker. Finally, we consider the efficacy of state-of-the-art privacy mechanisms through adapting geo-indistinguishability techniques as well as developing a novel EPZ fuzzing technique. Strava has been notified of the discovered vulnerabilities and (at time of submission) is preparing to incorporate our countermeasures into their production system.","Submission published under a 24 month embargo labeled 'U of I Access', the embargo will last until 2020-05-01","The student, Muhammad Hussain, accepted the attached license on 2018-04-25 at 21:03.","The student, Muhammad Hussain, submitted this Thesis for approval on 2018-04-25 at 21:10.","This Thesis was approved for publication on 2018-04-26 at 14:30.","DSpace SAF Submission Ingestion Package generated from Vireo submission #12510 on 2018-08-31 at 17:21:36","Made available in DSpace on 2018-09-04T20:41:58Z (GMT). No. of bitstreams: 3 HUSSAIN-THESIS-2018.pdf: 5289819 bytes, checksum: cc4aaa8bee2598593e9ea49672482d3f (MD5) Saad Thesis.zip: 5556890 bytes, checksum: ea48f0397ef5cfc21d42b1f64055c561 (MD5) LICENSE.txt: 4213 bytes, checksum: 17dca19b5b422ff5a0b4e769d440b003 (MD5) Previous issue date: 2018-04-26","Embargo set by: Seth Robbins for item 107317 Lift date: 2020-09-04T20:42:08Z Reason: Author requested U of Illinois access only (OA after 2yrs) in Vireo ETD system","U of I Only Restriction Lifted for Item 107317 on 2020-09-05T09:15:09Z."],"dc:format":["application/pdf"],"dc:identifier":["http://hdl.handle.net/2142/101232"],"dc:language":["en"],"dc:rights":["Copyright 2018 Muhammad Hussain"],"dc:subject":["Location Privacy, Fitness Tracking Applications"],"dc:title":["Analysis of privacy protections in fitness tracking applications"],"dc:type":["text"],"thesis:degree_discipline":["Computer Science"],"thesis:degree_level":["Thesis"],"thesis:degree_name":["M.S."],"thesis:institution_name":["University of Illinois at Urbana-Champaign"]},"updated_at":"2026-07-22T22:24:38Z"}