Live data from Hacker News

“I Want to Know What Code Is Running Inside My Body”

backchannel.com

71–80 of 217 posts

Re: “I Want to Know What Code Is Running Inside My Body”

#71
post #48

Earlier quoted context omitted.

No. Tell me, how many vulnerabilities are running wild on Linux, the software that powers... well, pretty much anything (including the servers through which you read this content)? Even if you find a vulnerability, it gets patched within hours and it may take a day or two for it to be distributed to everyone. > Security by obscurity [...] does raise the barrier to entry for script kiddies. Which script can help you f…

If the same vulnerability is present across a large range of devices, a public exploit has a much larger impact. I'm not advocating for security by obscurity in the slightest because on balance I think it's bad, but we should acknowledge that publishing your source does change the potential cost of mounting an attack in various scenarios, and some of them might actually favor obscurity. Nobody except the most determi…

> This doesn't work for embedded devices.

This is patently incorrect. Even the underpowered Z80-clone micros with 18kB RAM I was writing firmware for 15 years ago had trivially updated firmware; modern devices are even easier.

The article even mentions that wireless firmware updates is a feature:

    Then she bought a pacemaker programmer online,
    and she and other hackers figured out that it
    could be used to update the code on her implant.
> Nobody except the most determined attacker will attack

Relying on the laziness and ignorance of the attacker is a terrible idea.

> Hence why it might not be a great idea to publish their vulnerabilities

This is why any it's important to practice responsible disclosure. The manufacturer should have a reasonable time to make their patch before telling the internet.

Re: “I Want to Know What Code Is Running Inside My Body”

#72
post #28

Earlier quoted context omitted.

With or without a warrant...? EDIT: Not sure what's up w/ the downvotes. There are well-established ways for regulatory agencies (whether FDA, FCC, etc) to obtain firmware for devices -- and it almost always involves a warrant under extraneous circumstances -vs- proactively receiving proprietary code.

What if they had to subpoena a tomato grown in a field next to the toxic waste dump? What if they opted not to examine that tomato because they didn't have the resources to issue, process, and support, the lengthy bureaucratic process involved in such things?

Who owns the tomato? Who owns the land that the tomato is grown on? You can't just willy nilly confiscate other's property...

Re: “I Want to Know What Code Is Running Inside My Body”

#73
post #72

Earlier quoted context omitted.

What if they had to subpoena a tomato grown in a field next to the toxic waste dump? What if they opted not to examine that tomato because they didn't have the resources to issue, process, and support, the lengthy bureaucratic process involved in such things?

Who owns the tomato? Who owns the land that the tomato is grown on? You can't just willy nilly confiscate other's property...

But the government can and should have the right to inspect a tomato (not necessarily a specific tomato) if all the tomatoes in that field are slated to go direct to consumers, right?

Similarly, what about testing for drug quality? You could even extrapolate it out to the SEC's right to examine a private financial transaction in order to determine legality. Or the IRS's right to inspect one's taxes to determine compliance.

Point is (IMO) there is a need put on government by society to bypass some of our "Inalienable" rights. In most cases this societal decision is necessary and makes sense, and I'm arguing that code inspection of life-critical systems is a reasonable example of such a case.

Re: “I Want to Know What Code Is Running Inside My Body”

#74
post #14

Earlier quoted context omitted.

> If your company takes ~2 years to develop a pacemaker's software, it's not to your advantage to let your competitors catch up. Why should the patient who has the pacemaker implanted care? This seems like a clear situation in which the patient's interests trump everybody else's. Pacemaker manufacturers should be competing in how well their devices meet patient needs. Closed source doesn't meet a key patient need.

Medical device software is subject to a level of rigor in development process that little else is. Exactly what patient need do you believe open source would meet that is not being met by the current closed-source development process?

> Medical device software is subject to a level of rigor in development process that little else is.

How do you know this?

Re: “I Want to Know What Code Is Running Inside My Body”

#75

I saw a talk about medical device security (or lack thereof) at the Eleventh Hope a few weekends ago. Very scary. They started off with a story about patients in a hospital who became horribly addicted to morphine because they were able to hack the machine from resources found online ( http://www.massdevice.com/hospital-patient-hacks-his-own-mor... ). Go on Shodan and search for medical devices and terminology (e.g.…

The sad part is that the companies will use this security by obscurity argument against open sourcing.

Re: “I Want to Know What Code Is Running Inside My Body”

#76
post #14

Earlier quoted context omitted.

> If your company takes ~2 years to develop a pacemaker's software, it's not to your advantage to let your competitors catch up. Why should the patient who has the pacemaker implanted care? This seems like a clear situation in which the patient's interests trump everybody else's. Pacemaker manufacturers should be competing in how well their devices meet patient needs. Closed source doesn't meet a key patient need.

Medical device software is subject to a level of rigor in development process that little else is. Exactly what patient need do you believe open source would meet that is not being met by the current closed-source development process?

> what patient need do you believe open source would meet that is not being met by the current closed-source development process?

The need to know, and be able to control if necessary, what a device that affects your life and health is doing.

I'll give an example from my own experience. I have sleep apnea and have to use a CPAP machine. There is a nice little SD card in the machine that records detailed data from every use--which means it records how long I sleep, how soundly I sleep, how many (if any) apnea episodes I have, etc. This would be very useful information to me, but I have no way of getting it, because the software and data inside the device is proprietary. The only way for me to have anyone look at this data is to pull the SD card out and take it to a sleep therapy doctor, and even then I won't see the actual raw data; the best I'll get is some proprietary analysis report designed by the device manufacturer.

Furthermore, the ostensible use for the data is to be able to adjust the pressure the CPAP machine is set at in order to improve the therapy. If I had access to the data and the settings inside the machine, I could easily do this myself. Instead, if I want any adjustment made, again, I have to go see a sleep therapy doctor--which means I need to make an appointment, which usually means waiting weeks or months, and I need to take off from work to go to the appointment, etc., etc.

It should be obvious how open source would greatly improve this situation.

Re: “I Want to Know What Code Is Running Inside My Body”

#77
post #61

By extension should every device I own require me to have access to the source code and output data? Not a rhetorical question.

Y'know, back in the early 2000's and the days of Slashdot, it was quite common to find people who advocated for free software everywhere. Now we find people who like yourself have to specify that the radical position that all software should be free is something worthy of serious consideration. That they're not joking or trying to be deliberately provocative. What happened to us? Why did we go from boasting about ins…

Because Linux was supposed to become a great thing, but instead it remained a paradise for geeks to do what they think is best. Software built to make money, on the other hand, was built to improve things like ease of use, aesthetics, and buyer's happiness, because that's what buyers were looking for. The open-source people never really cared about the dumb people and lay folks, the ignoramuses that didn't care to learn how to compose commands and figure out regular expressions. And that Linux was supposed to be the shining example of open-source software, one that so many people installed and tried, only to find out it blows and is effectively unusable for their needs.

Re: “I Want to Know What Code Is Running Inside My Body”

#78

Does anyone know if at least the FDA is allowed to review the source code for pacemakers? Or is it a complete blackbox? Personally I would be appalled if even the FDA is not allowed to.

I know. Nope.

The FDA probably doesn't even know what source code is. They have vague regulations on how medical devices should be tested, which by tradition has been interpreted in a particular way to mean certain kinds of documents have to be prepared. There are auditors that check that those documents are written. Nobody checks that what the documents say about the software is in fact true because neither those writing the regulations nor those auditing the documents really know anything about computers.

Re: “I Want to Know What Code Is Running Inside My Body”

#79
post #71

Earlier quoted context omitted.

If the same vulnerability is present across a large range of devices, a public exploit has a much larger impact. I'm not advocating for security by obscurity in the slightest because on balance I think it's bad, but we should acknowledge that publishing your source does change the potential cost of mounting an attack in various scenarios, and some of them might actually favor obscurity. Nobody except the most determi…

> This doesn't work for embedded devices. This is patently incorrect. Even the underpowered Z80-clone micros with 18kB RAM I was writing firmware for 15 years ago had trivially updated firmware; modern devices are even easier. The article even mentions that wireless firmware updates is a feature: Then she bought a pacemaker programmer online, and she and other hackers figured out that it could be used to update the c…

Even if embedded devices are updatable in principle, in practice how often do they receive security patches? Pointing to a feature list isn't a realistic evaluation of what actually happens.

We live in a world where even phones don't get patched as frequently as they should; you expect end users to patch their pacemakers?

Putting them online and allowing auto-patching would probably be worse since it also increases their attack surface drastically.

> This is why any it's important to practice responsible disclosure.

Right, and fact is that 'responsible disclosure' ends up looking a lot like obscurity in a world where you can't guarantee that devices will be patched before an attacker would be interested in exploitation.

Re: “I Want to Know What Code Is Running Inside My Body”

#80

Does anyone know if at least the FDA is allowed to review the source code for pacemakers? Or is it a complete blackbox? Personally I would be appalled if even the FDA is not allowed to.

In general, you do not submit source code for review - just all your procedures and results for testing. In normal auditing, they will not inspect your source code - they may inspect everything around your source code (what you procedures for changes are, how you do your testing, etc etc). However, I believe there's a general understanding that if you fuck up, your source code will be open to inspection - along with…

> However, I believe there's a general understanding that if you fuck up, your source code will be open to inspection

Hold it right there, Karl Marx. We can't just be giving the proletariat access to the means of software production because of one little boo-boo. That could totally bankrupt a company and would be a theft of IP. Rest assured that the proper procedures will be followed and the flaws corrected, but under no circumstances can we take the lawful property of entrepreneurs and daring businessmen.

Post reply on HN