The HAPI Connected scale shows several privacy and security issues which should be considered. Mostly these are related to HAPI's mobile application.
sensor | Connected Scale |
WiFi | ✗ |
Bluetooth | ✅ |
mobile app | com.hapiconnect |
app release date | Jul, 2016 |
app install base | 100k |
app version | 1.2.8_us_server |
The most severe is the missing encryption of communication between the mobile application and the HAPI web servers. The user is not able to apply adequate counter measures as this can only be fixed by the developers. The version we analyzed might even leak your email address and the password you are using. Hence usage of that application should be avoided.
We strive to discuss the mentioned issues and more with HAPI. At this point in time we are waiting for any response, but will be happy to help on request.