Go Back  Bike Forums > Bike Forums > Road Cycling
Reload this Page >

What is going on with Garmin Connect?

Search
Notices
Road Cycling “It is by riding a bicycle that you learn the contours of a country best, since you have to sweat up the hills and coast down them. Thus you remember them as they actually are, while in a motor car only a high hill impresses you, and you have no such accurate remembrance of country you have driven through as you gain by riding a bicycle.” -- Ernest Hemingway

What is going on with Garmin Connect?

Thread Tools
 
Search this Thread
 
Old 07-26-20 | 11:12 AM
  #51  
msu2001la's Avatar
Senior Member
 
Joined: Mar 2006
Posts: 2,914
Likes: 1,502
From: Chicago, IL, USA
Originally Posted by GlennR
Come on guys... it's just personal cycling statistics. It's not like your retirement account or medical records.

And if the data is so critical to you, you should have a backup in a secure location and not rely on any 3rd party to be the only source and to protect it. The larger the collective data, the larger the target.

If I lost all of my Garmin history, it wouldn't make a difference in my life.
I'm not worried about losing my data, nor am I worried about losing access to Garmin's online services for a few days.These are mild inconveniences at best.

What worries me is who else might have access to the trove of personal data that Garmin has.

In addition to the standard online account stuff like phone numbers, IP addresses, billing addresses, email addresses, passwords, credit card info there are some more unique things in the data that Garmin collects via devices and uploads:
Age, height, weight, gender, heart rate, fitness history, power meter readings, GPS verified location tracks, lists of bikes and equipment that we all own, how frequently/far we ride them, who else we ride with, etc. In some cases, emergency contact info. Some devices collect additional data like sleep schedules, VO2 numbers, and so on.

All of that personal data may or may not be in the hands of Russian hackers.
msu2001la is offline  
Reply
Old 07-26-20 | 12:54 PM
  #52  
Senior Member
15 Anniversary
Community Builder
 
Joined: Sep 2007
Posts: 15,273
Likes: 1,764
From: Far beyond the pale horizon.
Originally Posted by msu2001la
I'm not worried about losing my data, nor am I worried about losing access to Garmin's online services for a few days.These are mild inconveniences at best.

What worries me is who else might have access to the trove of personal data that Garmin has.

In addition to the standard online account stuff like phone numbers, IP addresses, billing addresses, email addresses, passwords, credit card info there are some more unique things in the data that Garmin collects via devices and uploads:
Age, height, weight, gender, heart rate, fitness history, power meter readings, GPS verified location tracks, lists of bikes and equipment that we all own, how frequently/far we ride them, who else we ride with, etc. In some cases, emergency contact info. Some devices collect additional data like sleep schedules, VO2 numbers, and so on.

All of that personal data may or may not be in the hands of Russian hackers.
It doesn't seem like the ransomware scum care about the data.

Since backups might be compromised, a fair amount of data might be unrecoverable.

Why would Russian hackers care about sleep schedules and VO2 numbers?
njkayaker is online now  
Reply
Old 07-26-20 | 01:06 PM
  #53  
Bah Humbug's Avatar
serious cyclist
 
Joined: Apr 2009
Posts: 21,147
Likes: 3,687
From: Austin

Bikes: S1, R2, P2

If they were after the data itself, they wouldn't announce themselves by encrypting it and demanding ransm; they'd be silently siphoning it off for as long as possible.
Bah Humbug is offline  
Reply
Old 07-26-20 | 01:30 PM
  #54  
Senior Member
 
Joined: Apr 2008
Posts: 68
Likes: 18
Originally Posted by msu2001la
I'm not worried about losing my data, nor am I worried about losing access to Garmin's online services for a few days.These are mild inconveniences at best.

What worries me is who else might have access to the trove of personal data that Garmin has.

In addition to the standard online account stuff like phone numbers, IP addresses, billing addresses, email addresses, passwords, credit card info there are some more unique things in the data that Garmin collects via devices and uploads:
Age, height, weight, gender, heart rate, fitness history, power meter readings, GPS verified location tracks, lists of bikes and equipment that we all own, how frequently/far we ride them, who else we ride with, etc. In some cases, emergency contact info. Some devices collect additional data like sleep schedules, VO2 numbers, and so on.

All of that personal data may or may not be in the hands of Russian hackers.
If you're worried about that information being compromised, you shouldn't upload it to Garmin, or any other service.
Wooderson is offline  
Reply
Old 07-26-20 | 02:05 PM
  #55  
msu2001la's Avatar
Senior Member
 
Joined: Mar 2006
Posts: 2,914
Likes: 1,502
From: Chicago, IL, USA
Originally Posted by Wooderson
If you're worried about that information being compromised, you shouldn't upload it to Garmin, or any other service.
Of course I know that there's always a risk of data being compromised. That doesn't mean I have to forego any discussion or opinion on it, or accept it as a given outcome.
msu2001la is offline  
Reply
Old 07-26-20 | 02:10 PM
  #56  
msu2001la's Avatar
Senior Member
 
Joined: Mar 2006
Posts: 2,914
Likes: 1,502
From: Chicago, IL, USA
Originally Posted by njkayaker
It doesn't seem like the ransomware scum care about the data.

Since backups might be compromised, a fair amount of data might be unrecoverable.

Why would Russian hackers care about sleep schedules and VO2 numbers?
Hackers probably don't care about any of it, but they might think it's something they can sell to someone who does.
It doesn't seem like a huge stretch to think that other companies, not to mention health/life insurance companies might be interested in getting their hands on data like this.
msu2001la is offline  
Reply
Old 07-26-20 | 02:43 PM
  #57  
Senior Member
 
Joined: Apr 2008
Posts: 68
Likes: 18
Originally Posted by msu2001la
That doesn't mean I have to forego any discussion or opinion on it, or accept it as a given outcome.
I don't think I suggested that you "forego any discussion or opinion", at least I didn't mean to.
Wooderson is offline  
Reply
Old 07-26-20 | 03:04 PM
  #58  
Senior Member
15 Anniversary
Community Builder
 
Joined: Sep 2007
Posts: 15,273
Likes: 1,764
From: Far beyond the pale horizon.
Originally Posted by msu2001la
Hackers probably don't care about any of it, but they might think it's something they can sell to someone who does.
If they could sell it, they'd care about it. Who would buy sleep schedules and VO2 numbers?

Originally Posted by msu2001la
It doesn't seem like a huge stretch to think that other companies, not to mention health/life insurance companies might be interested in getting their hands on data like this.
Actually, it's kind of nutty to think that insurance companies are going to buy this information from hackers.
njkayaker is online now  
Reply
Old 07-26-20 | 03:04 PM
  #59  
Chi_Z's Avatar
Senior Member
 
Joined: Dec 2013
Posts: 507
Likes: 69

Bikes: Niner RLT 9 RDO

Originally Posted by Marcus_Ti
Well I would lose track of how many miles I have on the present chain...
try probikegarage, it syncs with starva and you can track every little thing on a bike and setting up service reminders
Chi_Z is offline  
Reply
Old 07-26-20 | 05:22 PM
  #60  
kcblair's Avatar
Old Legs
5 Anniversary
 
Joined: Nov 2016
Posts: 1,212
Likes: 33
From: Mass.

Bikes: '80 Strayvaigin, '84 Ciocc Aelle-Shimano 105, '90 Concorde Astore /Campy Triple ,85 Bridgestone 500/Suntour, 2005 Jamis Quest, 2017 Raleigh Merit 1, Raleigh Carbon Clubman

Originally Posted by Chi_Z
try probikegarage, it syncs with starva and you can track every little thing on a bike and setting up service reminders
Yep, great app. KB
kcblair is offline  
Reply
Old 07-26-20 | 07:55 PM
  #61  
GeneO's Avatar
Senior Member
Titanium Club Membership
15 Anniversary
 
Joined: May 2010
Posts: 2,528
Likes: 152
From: midwest

Bikes: 2018 Roubaix Expert Di2, 2016 Diverge Expert X1

Originally Posted by Bah Humbug
If they were after the data itself, they wouldn't announce themselves by encrypting it and demanding ransm; they'd be silently siphoning it off for as long as possible.
Or they can just sell it on the dark web for additional money besides the ransom or to punish Garmin for not paying it.
GeneO is offline  
Reply
Old 07-26-20 | 11:10 PM
  #62  
Senior Member
 
Joined: Jun 2009
Posts: 468
Likes: 173
From: Land of Enchantment

Bikes: Domane SLR7 Project One

Looks like things are back online and no data loss that I can see. Able to upload saved files from memory on my Edge.
August West is offline  
Reply
Old 07-27-20 | 04:25 AM
  #63  
Senior Member
15 Anniversary
Community Builder
 
Joined: Sep 2007
Posts: 15,273
Likes: 1,764
From: Far beyond the pale horizon.
Originally Posted by GeneO
Or they can just sell it on the dark web for additional money besides the ransom or to punish Garmin for not paying it.
Beyond things like credit card info, data like sleep schedules and how fast you ride is worthless to other people.

===============================

Ransomware is like threatening to burn your house down. It’s easy and nonspecific

Stealing data is like needing to know where the jewels and money are hidden.

Last edited by njkayaker; 07-27-20 at 04:34 AM.
njkayaker is online now  
Reply
Old 07-27-20 | 04:38 AM
  #64  
Senior Member
15 Anniversary
Community Builder
 
Joined: Sep 2007
Posts: 15,273
Likes: 1,764
From: Far beyond the pale horizon.
Originally Posted by scott967
Garmin used to have a windows program that you could load all your rides into, also had mapping and could display your routes.

Good info on what happened here: https://www.bleepingcomputer.com/new...omware-attack/

scott s.
.
BaseCamp?

That still exists (but there isn’t much active work being done on it now).

There are programs from other people too.

The data is just files (which you can store on your computer).
njkayaker is online now  
Reply
Old 07-27-20 | 05:46 AM
  #65  
roth rothar's Avatar
Senior Member
 
Joined: Jul 2020
Posts: 57
Likes: 21
From: Massachusetts

Bikes: Raleigh Technium, Cannodale SR600,Trek 520, Specialized Rock Hopper, Scott CR1 Pro

Originally Posted by August West
Looks like things are back online and no data loss that I can see. Able to upload saved files from memory on my Edge.
Yes I connected with the server this morning. It is a a little slow and I had to try twice, probably because of heavy traffic.
roth rothar is offline  
Reply
Old 07-27-20 | 06:19 AM
  #66  
Marcus_Ti's Avatar
FLIR Kitten to 0.05C
 
Joined: Sep 2014
Posts: 5,331
Likes: 409
From: Lincoln, Nebraska

Bikes: Roadie: Seven Axiom Race Ti w/Chorus 11s. CX/Adventure: Carver Gravel Grinder w/ Di2

Originally Posted by njkayaker
Beyond things like credit card info, data like sleep schedules and how fast you ride is worthless to other people.

===============================

Ransomware is like threatening to burn your house down. It’s easy and nonspecific

Stealing data is like needing to know where the jewels and money are hidden.
People have used Strava data to pinpoint which houses to hit for bike grand larceny.

Where you live and how many bikes you have is all thieves need to know to case your house. One of my riding mates lost $6K of tools and bikes out of their garage--no one else in their area was hit and everything was locked. Because GPS data plus knowing there are valuable bikes there is all you need.

Originally Posted by August West
Looks like things are back online and no data loss that I can see. Able to upload saved files from memory on my Edge.
Well that was shortlived....nothing here as of now.

Last edited by Marcus_Ti; 07-27-20 at 06:24 AM.
Marcus_Ti is offline  
Reply
Old 07-27-20 | 06:53 AM
  #67  
Hypno Toad's Avatar
meh
10 Anniversary
 
Joined: Jul 2014
Posts: 4,742
Likes: 1,129
From: Hopkins, MN

Bikes: 23 Cutthroat, 21 CoMotion Java; 21 Bianchi Infinito; 15 Surly Pugsley; 11 Globe Daily; 09 Kona Dew Drop; 96 Mondonico

People are targeted by thieves using social media and GPS platforms, this is nothing new. Based on analysis available, I highly double Russian or Chinese hackers are interested in stealing your bike stash. They would love your passwords, credit cards, and use your Garmin data to social engineer breaches into other organizations. Frankly, social engineering is the top of my threat lists, Garmin is very popular and could easily give hackers a path into more critical systems around the world.

EDIT - additional info (I've added the bold to the quote to the point of the post above):"WastedLocker is a new kind of ransomware, detailed by security researchers at Malwarebytes in May, operated by a hacker group known as Evil Corp. Like other file-encrypting malware, WastedLocker infects computers, and locks the user’s files in exchange for a ransom, typically demanded in cryptocurrency.

Malwarebytes said that WastedLocker does not yet appear to have the capability to steal or exfiltrate data before encrypting the victim’s files, unlike other, newer ransomware strains. That means companies with backups may be able to escape paying the ransom. But companies without backups have faced ransom demands as much as $10 million."
https://techcrunch.com/2020/07/25/ga...mware-sources/

Last edited by Hypno Toad; 07-27-20 at 07:00 AM. Reason: adding info
Hypno Toad is offline  
Reply
Old 07-27-20 | 06:54 AM
  #68  
Senior Member
15 Anniversary
Community Builder
 
Joined: Sep 2007
Posts: 15,273
Likes: 1,764
From: Far beyond the pale horizon.
Originally Posted by Marcus_Ti
People have used Strava data to pinpoint which houses to hit for bike grand larceny.

Where you live and how many bikes you have is all thieves need to know to case your house. One of my riding mates lost $6K of tools and bikes out of their garage--no one else in their area was hit and everything was locked. Because GPS data plus knowing there are valuable bikes there is all you need.
None of these are sleep schedules or VO2 data.

​​​I didn't say none of the data has value (I even listed some!)

The location data might be useful but it's usefulness is local. Which reduces the value of it being sold.

​​​​​​

It's also possible that the theives who hit your friend didn't use GPS data.

Last edited by njkayaker; 07-27-20 at 09:07 AM.
njkayaker is online now  
Reply
Old 07-27-20 | 08:53 AM
  #69  
NoWhammies's Avatar
Senior Member
 
Joined: Jul 2017
Posts: 1,992
Likes: 513
From: Pacific Northwest

Bikes: Argon 18 Gallium, BH G7, Rocky Mountain Instinct C70

Looks like the server is back online. I was able to log in this morning. Still no word though on the nature / extent of the breach. I'd like to know if all of my information is out there and what, if anything, is being done about it.
NoWhammies is offline  
Reply
Old 07-27-20 | 09:32 AM
  #70  
GlennR's Avatar
On Your Left
 
Joined: Nov 2011
Posts: 8,373
Likes: 2,440
From: Long Island, New York, USA

Bikes: Trek Emonda SLR, Sram eTap, Zipp 303

Originally Posted by NoWhammies
Looks like the server is back online. I was able to log in this morning. Still no word though on the nature / extent of the breach. I'd like to know if all of my information is out there and what, if anything, is being done about it.
Nope... still down.
GlennR is offline  
Reply
Old 07-27-20 | 09:59 AM
  #71  
msu2001la's Avatar
Senior Member
 
Joined: Mar 2006
Posts: 2,914
Likes: 1,502
From: Chicago, IL, USA
Originally Posted by njkayaker
None of these are sleep schedules or VO2 data.

​​​I didn't say none of the data has value (I even listed some!)

The location data might be useful but it's usefulness is local. Which reduces the value of it being sold.

​​​​​​

It's also possible that the theives who hit your friend didn't use GPS data.
My post also noted many other data points that Garmin collects, that hackers may have accessed.

The focus on VO2 and sleep schedules as specific items from my post to nitpick was your choice, but I agree that those two items would have less value than others, and may not have any actual value at all.

None of this makes it any less concerning that lots of personal user data was potentially compromised, which was my entire point.
msu2001la is offline  
Reply
Old 07-27-20 | 10:12 AM
  #72  
msu2001la's Avatar
Senior Member
 
Joined: Mar 2006
Posts: 2,914
Likes: 1,502
From: Chicago, IL, USA
Originally Posted by Marcus_Ti
People have used Strava data to pinpoint which houses to hit for bike grand larceny.

Where you live and how many bikes you have is all thieves need to know to case your house. One of my riding mates lost $6K of tools and bikes out of their garage--no one else in their area was hit and everything was locked. Because GPS data plus knowing there are valuable bikes there is all you need.
Good example.
Although we can set up "privacy zones" within Strava/Garmin, and keep equipment descriptions somewhat vague as basic security measures, the raw data still includes the actual start/stop points. The privacy zone just prevents it from being broadcast to other users.

In the event of a data breach, it would be very easy for someone to sort through GPS data to single out and pinpoint the location of high-mileage/frequency riders that log rides on multiple bikes. Combine that with day/time info on when they're typically out riding...
msu2001la is offline  
Reply
Old 07-27-20 | 11:07 AM
  #73  
GlennR's Avatar
On Your Left
 
Joined: Nov 2011
Posts: 8,373
Likes: 2,440
From: Long Island, New York, USA

Bikes: Trek Emonda SLR, Sram eTap, Zipp 303

You guys are obsessing over Garmin data, imagine if they got your Google or Apple data. Everywhere you go, everything you look at.

As it was said, George Orwell would be shocked at the amount of personal information we give away for free. And the interweb never forgets.

Anyone pay any of those DNA services?
GlennR is offline  
Reply
Old 07-27-20 | 11:45 AM
  #74  
Hypno Toad's Avatar
meh
10 Anniversary
 
Joined: Jul 2014
Posts: 4,742
Likes: 1,129
From: Hopkins, MN

Bikes: 23 Cutthroat, 21 CoMotion Java; 21 Bianchi Infinito; 15 Surly Pugsley; 11 Globe Daily; 09 Kona Dew Drop; 96 Mondonico

Originally Posted by msu2001la
Good example.
Although we can set up "privacy zones" within Strava/Garmin, and keep equipment descriptions somewhat vague as basic security measures, the raw data still includes the actual start/stop points. The privacy zone just prevents it from being broadcast to other users.

In the event of a data breach, it would be very easy for someone to sort through GPS data to single out and pinpoint the location of high-mileage/frequency riders that log rides on multiple bikes. Combine that with day/time info on when they're typically out riding...
Quoting my post earlier today (I've added the bold to highlight the point):

Originally Posted by Hypno Toad
People are targeted by thieves using social media and GPS platforms, this is nothing new. Based on analysis available, I highly double Russian or Chinese hackers are interested in stealing your bike stash. They would love your passwords, credit cards, and use your Garmin data to social engineer* breaches into other organizations. Frankly, social engineering is the top of my threat lists, Garmin is very popular and could easily give hackers a path into more critical systems around the world.

EDIT - additional info (I've added the bold to the quote to the point of the post above):"WastedLocker is a new kind of ransomware, detailed by security researchers at Malwarebytes in May, operated by a hacker group known as Evil Corp. Like other file-encrypting malware, WastedLocker infects computers, and locks the user’s files in exchange for a ransom, typically demanded in cryptocurrency.

Malwarebytes said that WastedLocker does not yet appear to have the capability to steal or exfiltrate data before encrypting the victim’s files, unlike other, newer ransomware strains. That means companies with backups may be able to escape paying the ransom. But companies without backups have faced ransom demands as much as $10 million."
https://techcrunch.com/2020/07/25/ga...mware-sources/
For reference: Social Engineering
Hypno Toad is offline  
Reply
Old 07-27-20 | 12:17 PM
  #75  
Senior Member
15 Anniversary
Community Builder
 
Joined: Sep 2007
Posts: 15,273
Likes: 1,764
From: Far beyond the pale horizon.
Originally Posted by msu2001la
The focus on VO2 and sleep schedules as specific items from my post to nitpick was your choice, ...
I focused on them because they where especially nutty nits! They are your nits!

If it bothers you that somebody pointed that out, maybe, you shouldn't have mentioned them!

Originally Posted by msu2001la
... but I agree that those two items would have less value than others, and may not have any actual value at all.
Again, you mentioned them. And you suggested that insurance companies would illegally buy the info from criminals.

They don't have any value to anybody. Why mention them?

Originally Posted by msu2001la
None of this makes it any less concerning that lots of personal user data was potentially compromised, which was my entire point.
It exaggerates the risk in a meaningless way. And it's funny!

Last edited by njkayaker; 07-27-20 at 12:33 PM.
njkayaker is online now  
Reply


Contact Us - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service -

Copyright © 2026 MH Sub I, LLC dba Internet Brands. All rights reserved. Use of this site indicates your consent to the Terms of Use.