logoalt Hacker News

lloekitoday at 8:26 AM1 replyview on HN

Came to see if someone commented on that. I have generally seen Garmin as one of the good ones on several criteria:

- when hit by ransomware, disclosed publicly, bit on the data loss and told them to fsck off

- devices can very much operate without any account, app, or cloud connection (of course you don't get the more advanced "Connect" features)

- plug it in and you have rw access to .FIT files over MTP

- same mechanism to build and sideload apps made with Monkey C

- ANT+ is a fairly open ecosystem (progressively replaced by BLE, often in much less open ways)

I hear that some people are annoyed that devices stop receiving major feature updates after a year or two, and see that as predatory "you must upgrade every year", which is like, ridiculous?

Also in a sense I like that I buy the device and it's mostly "done". Like a mechanical watch it's a utility item I can rely on and it won't ever have a Liquid Ass pulled up on me.


Replies

ssgodderidgetoday at 9:55 AM

Yeah I totally agree with this list. In contrast, Coros had a pretty nonchalant response to their security issues last year. Attackers could:

> Hijacking the vicitim’s COROS account and accessing all data

> – Eavesdropping sensitive data, e.g. notifications

> – Manipulating the device configuration

> – Factory resetting the device

> – Crashing the device

> – Interrupting a running activity and forcing the recorded data to be lost [0]

The security firm disclosed the vulnerability to Coros in Mar 2025. They planned to fix it by the end of 2025, and didn’t address it until the security firm publicly released the finding.

[0]:https://www.dcrainmaker.com/2025/06/coros-confirms-substanti...