Live data from Hacker News

It’s Easy to Hack Hospital Equipment

wired.com

21–30 of 65 posts

Re: It’s Easy to Hack Hospital Equipment

#21
Definitely not a surprise. I once had to hack a piece of medical equipment in order to make it print to a printer that was manufactured within the previous decade. The only one that it "officially supported" was from about 15 years before that day. The OS version (patches/updates included) was also that old.

Re: It’s Easy to Hack Hospital Equipment

#22
This kind of problems is going to be more prominent as "Internet of Things" starts to take off. I was rather concern about Nest, our cars, Fridges etc being connected to the Internet and, on some devices, the security is quite low. This article is shows an example of it.

Re: It’s Easy to Hack Hospital Equipment

#23

“Many hospitals are unaware of the high risk associated with these devices,” I assure you that while this is the hospital's official stance, many people within the hospital are well aware of the shoddy software on their medical devices and the risks they pose. There are so many opportunities for disruption of every aspect of the healthcare system (from the equipment itself, that this article addresses, to the electro…

TL&DR Regulations need to require interoperability and cross-platform with medical records and images.

As a "Cancer Dad" the electronic medical records and images that are closed and inaccessible between my local hospital where we got our chemotherapy and the Children's Hospital where we did our major surgeries was mind blowingly crazy.

I had to drive my bone cancer child 2.5 hours to use their equipment because there was an issue with the image file format. So I had to give my child enough pain killers to knock out a grown adult just so we could get the same pictures we could get 5 miles down the road.

Re: It’s Easy to Hack Hospital Equipment

#24

To be a dash risk managementy about it; (Risk of being hacked) x (severity of being hacked) (Risk of being hacked): Small. (Severity of being hacked): Very negative, but localised most likely to a single machine, set of machines, or hospital. (Risk of Software not Delivered): Pretty high if we go super-security. We are on a budget. There is competition. Who is paying for it? (Severity of not delivered): Failure to cu…

Whilst true, I can with 100% certainty, state that no-one in the medical profession, or the procurement people in the hospitals ever did that calculation.

NICE (the UK's no-you-cant-spend-ten-million-of-taxpayers-money-per-patient-on-a-drug-to-extend-their-life-by-six-weeks agency which gets it in the neck for such things) might be able to take on such a calculation - but I bet you anything even if they did that calculation every machine maker would treble their security departments anyway.

This is only possible because there was no pressure to deploy secure systems. Now there is, and after the first death from a hacked pacemaker, the outcry will be heard from the moon.

Re: It’s Easy to Hack Hospital Equipment

#25
post #14

In general the security on the equipment is because hideously high acquisition costs keeping most hobbyists out of fooling around with it. And most places with the equipment won't let somebody sit there and fool around with it. It's not quite security through obscurity, but more like security through expense.

Well... I think you should look more often on eBay:

http://www.ebay.com/sch/i.html?_trksid=m570.l3201&_nkw=infus...

=> 49.99$ is not _that_ hideously high.

Re: It’s Easy to Hack Hospital Equipment

#26

They also found surgery robots connected to internal networks. Although the robots generally have software firewalls to block connections to them, Erven and his team found that simply running an off-the-shelf vulnerability scanner against the firewall caused it to turn off and fail open. Wow, just wow. If someone ever hacks an active surgery robot it's going to be Saw meets Snow Crash , and not in a good way.

And with some hospitals still running Win XP, it's easy to get a foothold on their network!

Re: It’s Easy to Hack Hospital Equipment

#27

The thing with equipment like this is that security isn't a priority; "who would hack medical equipment?". A lack of high-profile cases where medical equipment was actively hacked is also not giving any incentive to fix these issues. Worst case, these exploits will suddenly be used to disable or cripple hospitals in case of dirty wars and terrorist campaigns. If the latter is still a problem.

Your comment is a few years out of date. The FDA has recently started caring, and there are high-enough profile cases to be on the industry's radar.

It'll continue to be a mess for years to come, the introduction of new medical hardware and software is slow and I don't know how they plan to handle already deployed items. But not exactly for the reasons you state.

Re: It’s Easy to Hack Hospital Equipment

#28
post #11

How many of these devices are still running Windows XP? Weak default passwords on the web interface is just the icing on the cake, the low-hanging fruit. The entire networking stack is likely to be riddled with unpatched vulnerabilities for anyone to exploit. Relative obscurity and physical security are probably the only things that stand between hospital equipment and certain disaster.

>Relative obscurity and physical security are probably the only things that stand between hospital equipment and certain disaster.

Even then, you can pop on a pair of scrubs and avoid most scrutiny. Keycard systems are there, but those aren't difficult. Sometimes the operating area doesn't have cameras and the area surrounding the 2 million dollar daVinci machines are deserted.

Re: It’s Easy to Hack Hospital Equipment

#29

To be a dash risk managementy about it; (Risk of being hacked) x (severity of being hacked) (Risk of being hacked): Small. (Severity of being hacked): Very negative, but localised most likely to a single machine, set of machines, or hospital. (Risk of Software not Delivered): Pretty high if we go super-security. We are on a budget. There is competition. Who is paying for it? (Severity of not delivered): Failure to cu…

What are the chances that someone would actually doing the hacking? I don't see any monetary reason to do so. Maybe that's one reason why we haven't seen many reports of people hacking medical devices?

Re: It’s Easy to Hack Hospital Equipment

#30
There is much lower hanging fruit (scada systems).

http://en.wikipedia.org/wiki/SCADA

I've seen a couple that used unencrypted UDP with bitfields representing the state of solenoids. Imagine what sending a series of all '1' and all '0' packets would do in terms of damage and panic.

Post reply on HN