It’s Easy to Hack Hospital Equipment
21–30 of 65 posts
Re: It’s Easy to Hack Hospital Equipment
#22Re: It’s Easy to Hack Hospital Equipment
#23“Many hospitals are unaware of the high risk associated with these devices,” I assure you that while this is the hospital's official stance, many people within the hospital are well aware of the shoddy software on their medical devices and the risks they pose. There are so many opportunities for disruption of every aspect of the healthcare system (from the equipment itself, that this article addresses, to the electro…
As a "Cancer Dad" the electronic medical records and images that are closed and inaccessible between my local hospital where we got our chemotherapy and the Children's Hospital where we did our major surgeries was mind blowingly crazy.
I had to drive my bone cancer child 2.5 hours to use their equipment because there was an issue with the image file format. So I had to give my child enough pain killers to knock out a grown adult just so we could get the same pictures we could get 5 miles down the road.
Re: It’s Easy to Hack Hospital Equipment
#24To be a dash risk managementy about it; (Risk of being hacked) x (severity of being hacked) (Risk of being hacked): Small. (Severity of being hacked): Very negative, but localised most likely to a single machine, set of machines, or hospital. (Risk of Software not Delivered): Pretty high if we go super-security. We are on a budget. There is competition. Who is paying for it? (Severity of not delivered): Failure to cu…
NICE (the UK's no-you-cant-spend-ten-million-of-taxpayers-money-per-patient-on-a-drug-to-extend-their-life-by-six-weeks agency which gets it in the neck for such things) might be able to take on such a calculation - but I bet you anything even if they did that calculation every machine maker would treble their security departments anyway.
This is only possible because there was no pressure to deploy secure systems. Now there is, and after the first death from a hacked pacemaker, the outcry will be heard from the moon.
Re: It’s Easy to Hack Hospital Equipment
#25In general the security on the equipment is because hideously high acquisition costs keeping most hobbyists out of fooling around with it. And most places with the equipment won't let somebody sit there and fool around with it. It's not quite security through obscurity, but more like security through expense.
http://www.ebay.com/sch/i.html?_trksid=m570.l3201&_nkw=infus...
=> 49.99$ is not _that_ hideously high.
Re: It’s Easy to Hack Hospital Equipment
#26They also found surgery robots connected to internal networks. Although the robots generally have software firewalls to block connections to them, Erven and his team found that simply running an off-the-shelf vulnerability scanner against the firewall caused it to turn off and fail open. Wow, just wow. If someone ever hacks an active surgery robot it's going to be Saw meets Snow Crash , and not in a good way.
Re: It’s Easy to Hack Hospital Equipment
#27The thing with equipment like this is that security isn't a priority; "who would hack medical equipment?". A lack of high-profile cases where medical equipment was actively hacked is also not giving any incentive to fix these issues. Worst case, these exploits will suddenly be used to disable or cripple hospitals in case of dirty wars and terrorist campaigns. If the latter is still a problem.
It'll continue to be a mess for years to come, the introduction of new medical hardware and software is slow and I don't know how they plan to handle already deployed items. But not exactly for the reasons you state.
Re: It’s Easy to Hack Hospital Equipment
#28How many of these devices are still running Windows XP? Weak default passwords on the web interface is just the icing on the cake, the low-hanging fruit. The entire networking stack is likely to be riddled with unpatched vulnerabilities for anyone to exploit. Relative obscurity and physical security are probably the only things that stand between hospital equipment and certain disaster.
Even then, you can pop on a pair of scrubs and avoid most scrutiny. Keycard systems are there, but those aren't difficult. Sometimes the operating area doesn't have cameras and the area surrounding the 2 million dollar daVinci machines are deserted.
Re: It’s Easy to Hack Hospital Equipment
#29To be a dash risk managementy about it; (Risk of being hacked) x (severity of being hacked) (Risk of being hacked): Small. (Severity of being hacked): Very negative, but localised most likely to a single machine, set of machines, or hospital. (Risk of Software not Delivered): Pretty high if we go super-security. We are on a budget. There is competition. Who is paying for it? (Severity of not delivered): Failure to cu…
Re: It’s Easy to Hack Hospital Equipment
#30http://en.wikipedia.org/wiki/SCADA
I've seen a couple that used unencrypted UDP with bitfields representing the state of solenoids. Imagine what sending a series of all '1' and all '0' packets would do in terms of damage and panic.