[Hack.lu 2015] Geek usages for your Fitbit Flex Tracker

This talk was presented at Hack.lu in October 2015. Fitness Flex are fitness wristbands which record your fitness activity: walking, running and also sleep efficiency. In this talk we show alternate ways to use your fitness tracker:

  • Have the tracker blink (to impress kids?)
  • Use your tracker as a random number generator
  • Lock your screen with your fitbit USB dongle, or by walking away with your tracker
  • Digitally tatoo your tracker
Video of Digital Tatoo/Infection PoC:


Fitness Flex is a fitness wristband which records your fitness activity: walking, running - and also sleep efficiency. Since prior infamous security and privacy issues - such as public web disclosure of sexual activity - Fitbit has made significant progress. While reverse engineering, we noticed trackers now use end to end encryption for their communications with Fitbit servers. Is this good? or bad? What happens if Fitbit servers are unreachable ? What can we possibly do with the wristband besides activity tracking?

References

Hack.lu conference Talk slides Malware injection and infection PoC