Credit: Unsplash/CC0 Public Domain
Despite efforts to anonymize user data, fitness app Strava allows anyone to discover personal information — including home addresses — about some users. The finding, which is detailed in a new study, raises significant privacy concerns.
“Strava users expect their personal information to be secure, and our work shows that is not always the case,” says Anupam Das, senior author of a paper on the work and assistant professor of computer science at North Carolina State University. “This can be especially problematic for users who are concerned about stalkers or have other reasons why their location data should be kept from the public.”
Strava is a mobile fitness-tracking app that allows users to track their exercise activities, but also includes features designed to help users connect with each other. These facilities can be used to organize clubs around shared interests such as hiking or bicycling. For example, the app includes a “heatmap” feature that collects user data. While all user data is anonymized, the heatmap feature allows users to see how many other Strava users are hiking, running, or cycling in a given area.
“Strava insisted that the heatmap feature only use aggregated data, which should make it impossible to gain access to private information about any specific user,” says Das. “However, we found a loophole.”
Specifically, the researchers found that it is possible for anyone to view all Strava users in a given area. It is also possible for users to view aggregated data on a heatmap and see where each anonymous user’s routes begin and end.
“In a densely populated area, with lots of routes and lots of users, there is so much data that it would be extremely difficult to track down a specific individual,” says Das. “However, in areas where there are few users and/or few routes, this becomes a simple process of elimination – particularly if the person one is looking for is a highly active Strava user. Even users who have Marking your accounts as private shows up when someone searches for a list of all users in a given municipality, so marking an account private doesn’t necessarily provide additional protection against this tracking technology.”
“We reached out to Strava about this, and the company has said it doesn’t share heatmap data unless many users are active in a given area,” says Kevin Childs, first author of the paper and a former undergraduate at NC State. ” “However, we were still able to identify the home addresses of some users in certain areas using heatmaps, and confirmed those identifications using voter registration data.”
However, there is something users can do to protect their privacy.
“Users can go to their Strava account settings and opt in to contribute data to the ‘aggregated data usage’ feature, which will completely remove their routes from the heatmap,” says Das.
paper, “Heat Mark the Spot: De-anonymizing users’ geographic data on Strava heatmaps,” was presented at the 7th Workshop on Technology and Consumer Protection on 25 May (Conpro ’23) in San Francisco.
Citation: Fitness app loophole allows access to home address (2023, 7 June) Retrieved 7 June 2023
This document is subject to copyright. No part may be reproduced without written permission, except in any fair dealing for the purpose of private study or research. The content is provided for information purposes only.











