Live data from Hacker News

It’s Easy to Hack Hospital Equipment

wired.com

31–40 of 65 posts

Re: It’s Easy to Hack Hospital Equipment

#31

To be a dash risk managementy about it; (Risk of being hacked) x (severity of being hacked) (Risk of being hacked): Small. (Severity of being hacked): Very negative, but localised most likely to a single machine, set of machines, or hospital. (Risk of Software not Delivered): Pretty high if we go super-security. We are on a budget. There is competition. Who is paying for it? (Severity of not delivered): Failure to cu…

Whilst true, I can with 100% certainty, state that no-one in the medical profession, or the procurement people in the hospitals ever did that calculation. NICE (the UK's no-you-cant-spend-ten-million-of-taxpayers-money-per-patient-on-a-drug-to-extend-their-life-by-six-weeks agency which gets it in the neck for such things) might be able to take on such a calculation - but I bet you anything even if they did that calc…

>after the first death from a hacked pacemaker, the outcry will be heard from the moon //

Isn't the problem that there will always be a way to kill people, even remotely without touching them (sniper, poison mail, gas bomb, massive microwave in a van that you park next to them, ...). You perhaps don't want to make it easy but it's also not necessarily sensible to waste money on an arms race that you'll never win.

Similarly we don't have enclosed station platforms (in the UK) despite people having been pushed in front of trains in the past.

Re: It’s Easy to Hack Hospital Equipment

#32
post #9

Earlier quoted context omitted.

Calm down, they just removed an adverb whose only function was to exaggerate.

What's the point of rules if you don't follow them? So what if some one feels "insanely" exagerates it. Its the journalists opinion that it is insanely easy. That should be the title. I don't care if an hn moderator feels it is insanely easy or just easy to hack a hospital. IF he has an opinion on the difficulty to hack topic there is a comment section. The op is not a comment section for mods

Hear, hear!

Re: It’s Easy to Hack Hospital Equipment

#33
I was actually at the conference talk this guy gave about the subject last week and was talking to him about it the night before. If anyone has questions I can attempt to answer them.

Also interesting to think about is if these devices are getting hacking and people are blaming it on malfunctions.

Re: It’s Easy to Hack Hospital Equipment

#34
I was actually at the conference talk this guy gave about the subject last week and was talking to him about it the night before. If anyone has questions I can attempt to answer them.

Also interesting to think about is if these devices are getting hacking and people are blaming it on malfunctions.

Re: It’s Easy to Hack Hospital Equipment

#35
post #14

In general the security on the equipment is because hideously high acquisition costs keeping most hobbyists out of fooling around with it. And most places with the equipment won't let somebody sit there and fool around with it. It's not quite security through obscurity, but more like security through expense.

I'm pretty sure this has less to do with high acquisition costs and more to do with the fact that you can basically kill someone if you start tinkering with hospital equipment.

Re: It’s Easy to Hack Hospital Equipment

#36

Earlier quoted context omitted.

Whilst true, I can with 100% certainty, state that no-one in the medical profession, or the procurement people in the hospitals ever did that calculation. NICE (the UK's no-you-cant-spend-ten-million-of-taxpayers-money-per-patient-on-a-drug-to-extend-their-life-by-six-weeks agency which gets it in the neck for such things) might be able to take on such a calculation - but I bet you anything even if they did that calc…

> after the first death from a hacked pacemaker, the outcry will be heard from the moon // Isn't the problem that there will always be a way to kill people, even remotely without touching them (sniper, poison mail, gas bomb, massive microwave in a van that you park next to them, ...). You perhaps don't want to make it easy but it's also not necessarily sensible to waste money on an arms race that you'll never win. Si…

The difference being that it's tough to kill people at scale and covertly with a rifle or even poison mail. Exploiting a bug in networked pacemakers could give you the means to kill an entire userbase.

For the train comparison, it's the difference between pushing a guy on the rails and derailing a train remotely by accelerating it remotely through a curve and disabling the manual controls.

What's the value to the user of a networked pacemaker? Maybe a lower price? There would be better ways for it to 'speak' to a network to collect data, I should think.

Re: It’s Easy to Hack Hospital Equipment

#37

Earlier quoted context omitted.

Whilst true, I can with 100% certainty, state that no-one in the medical profession, or the procurement people in the hospitals ever did that calculation. NICE (the UK's no-you-cant-spend-ten-million-of-taxpayers-money-per-patient-on-a-drug-to-extend-their-life-by-six-weeks agency which gets it in the neck for such things) might be able to take on such a calculation - but I bet you anything even if they did that calc…

> after the first death from a hacked pacemaker, the outcry will be heard from the moon // Isn't the problem that there will always be a way to kill people, even remotely without touching them (sniper, poison mail, gas bomb, massive microwave in a van that you park next to them, ...). You perhaps don't want to make it easy but it's also not necessarily sensible to waste money on an arms race that you'll never win. Si…

The risk is exactly that you can't tell it was hacked. Then the manufacturer might end up being liable.

Re: It’s Easy to Hack Hospital Equipment

#38

Earlier quoted context omitted.

> after the first death from a hacked pacemaker, the outcry will be heard from the moon // Isn't the problem that there will always be a way to kill people, even remotely without touching them (sniper, poison mail, gas bomb, massive microwave in a van that you park next to them, ...). You perhaps don't want to make it easy but it's also not necessarily sensible to waste money on an arms race that you'll never win. Si…

The difference being that it's tough to kill people at scale and covertly with a rifle or even poison mail. Exploiting a bug in networked pacemakers could give you the means to kill an entire userbase. For the train comparison, it's the difference between pushing a guy on the rails and derailing a train remotely by accelerating it remotely through a curve and disabling the manual controls. What's the value to the use…

> What's the value to the user of a networked pacemaker? Maybe a lower price?

Fewer surgeries to get to the physical device and change settings. Therefore, longer life expectancy.

This bug might be a feature.

Re: It’s Easy to Hack Hospital Equipment

#39

Earlier quoted context omitted.

The difference being that it's tough to kill people at scale and covertly with a rifle or even poison mail. Exploiting a bug in networked pacemakers could give you the means to kill an entire userbase. For the train comparison, it's the difference between pushing a guy on the rails and derailing a train remotely by accelerating it remotely through a curve and disabling the manual controls. What's the value to the use…

> What's the value to the user of a networked pacemaker? Maybe a lower price? Fewer surgeries to get to the physical device and change settings. Therefore, longer life expectancy. This bug might be a feature.

Excellent point.

Re: It’s Easy to Hack Hospital Equipment

#40
post #20

“Many hospitals are unaware of the high risk associated with these devices,” I assure you that while this is the hospital's official stance, many people within the hospital are well aware of the shoddy software on their medical devices and the risks they pose. There are so many opportunities for disruption of every aspect of the healthcare system (from the equipment itself, that this article addresses, to the electro…

There's a market for disruption with some things, but it's mostly about doing more/better for less money. Security isn't really what most people are interested in paying for in many cases.

In the medical space (at least in the U.S.), there's much less room for disruption relative to other markets. The market is significantly regulated / restricted; the law is structured so that even if the vendor and their potential patients both consent to a given transaction or procedure, the government can still step in and deny it.

In essence, the laws are structured under the (not necessarily wrong) assumption that the consumer is too stupid to identify snake-oil. All an incumbent has to do to block a newcomer to the market is make a hard-to-deny snake-oil accusation.

Post reply on HN