Live data from Hacker News

It’s Easy to Hack Hospital Equipment

wired.com

41–50 of 65 posts

Re: It’s Easy to Hack Hospital Equipment

#41

To be a dash risk managementy about it; (Risk of being hacked) x (severity of being hacked) (Risk of being hacked): Small. (Severity of being hacked): Very negative, but localised most likely to a single machine, set of machines, or hospital. (Risk of Software not Delivered): Pretty high if we go super-security. We are on a budget. There is competition. Who is paying for it? (Severity of not delivered): Failure to cu…

I believe the point of exercises like this is to show that the risk of being hacked is higher than was previously thought. The easier it is to do, the more likely an attacker will pull it off when they attempt it, and for someone whose goal is to wreak havoc rather than defeat an interestingly difficult system, the more likely an attacker will make the attempt in the first place.

Certainly it could be the case that the benefit exceeds the risk, but if such calculations were made, they may need to be reevaluated.

Re: It’s Easy to Hack Hospital Equipment

#42
In a recent hospital visit I noticed that the equipment in the room I was in had bluetooth connectivity enabled. And in fact had all the details you needed to connect to them via bluetooth taped to the sides of the machines. That made me a little worried.

Re: It’s Easy to Hack Hospital Equipment

#43
post #10

Although vendors often tell customers they can’t remove hard coded passwords from their devices or take other steps to secure their systems because it would require them to take the systems back to the FDA for approval afterward, Erven points out that the FDA guidelines for medical equipment includes a cybersecurity clause that allows a post-market device to be patched without requiring recertification by the FDA. Th…

I think you have to always assume that people can't be trusted to do the right thing when it comes to lives of others. The FDA has to employ policies which gives us a reasonable confidence that a vendor's device/test/whatever is safe and effective. Disclaimer: I have worked on FDA cleared medical devices my entire career.

I think most of the time you can trust people to do the right thing when it comes to the lives of others, when the right thing is sufficiently clear, when the fact that it involves the lives of others is sufficiently salient, and when there are not enormous incentives to do otherwise.

Re: It’s Easy to Hack Hospital Equipment

#44
post #23

“Many hospitals are unaware of the high risk associated with these devices,” I assure you that while this is the hospital's official stance, many people within the hospital are well aware of the shoddy software on their medical devices and the risks they pose. There are so many opportunities for disruption of every aspect of the healthcare system (from the equipment itself, that this article addresses, to the electro…

TL&DR Regulations need to require interoperability and cross-platform with medical records and images. As a "Cancer Dad" the electronic medical records and images that are closed and inaccessible between my local hospital where we got our chemotherapy and the Children's Hospital where we did our major surgeries was mind blowingly crazy. I had to drive my bone cancer child 2.5 hours to use their equipment because ther…

As somebody working in healthcare integration, this may be small consolation, but it that's getting better.

The HITECH act[1] (which was part of the stimulus package in 2009) has gone a long way in getting the industry moving. One of the core deadlines we're scrambling to meet at the moment at my hospital is actually data interchange between facilities, including a portal that allows patients to access their records for themselves.

I realize that doesn't help your situation now, but with Medicare penalties looming for not getting that sort of exchange in place, things are starting to happen quickly in an industry that tends to move at a snail's pace.

http://en.wikipedia.org/wiki/HITECH_Act#Electronic_Health_Re...

Re: It’s Easy to Hack Hospital Equipment

#45

This kind of problems is going to be more prominent as "Internet of Things" starts to take off. I was rather concern about Nest, our cars, Fridges etc being connected to the Internet and, on some devices, the security is quite low. This article is shows an example of it.

This is one of the reasons why, as a rule, biomed devices that directly interact with a patient are never connected to the public internet.

Re: It’s Easy to Hack Hospital Equipment

#46
post #11

How many of these devices are still running Windows XP? Weak default passwords on the web interface is just the icing on the cake, the low-hanging fruit. The entire networking stack is likely to be riddled with unpatched vulnerabilities for anyone to exploit. Relative obscurity and physical security are probably the only things that stand between hospital equipment and certain disaster.

>How many of these devices are still running Windows XP?

A lot. I know we have telemetry systems that are all XP based. Granted, they're on a separate VLAN that doesn't touch the public internet or the rest of our internal network, but there are still physical security concerns there.

>Weak default passwords on the web interface is just the icing on the cake, the low-hanging fruit. The entire networking stack is likely to be riddled with unpatched vulnerabilities for anyone to exploit.

A major problem in healthcare is that vendors tend to use generic credentials for support purposes.

Re: It’s Easy to Hack Hospital Equipment

#47
post #11

How many of these devices are still running Windows XP? Weak default passwords on the web interface is just the icing on the cake, the low-hanging fruit. The entire networking stack is likely to be riddled with unpatched vulnerabilities for anyone to exploit. Relative obscurity and physical security are probably the only things that stand between hospital equipment and certain disaster.

>Relative obscurity and physical security are probably the only things that stand between hospital equipment and certain disaster. Even then, you can pop on a pair of scrubs and avoid most scrutiny. Keycard systems are there, but those aren't difficult. Sometimes the operating area doesn't have cameras and the area surrounding the 2 million dollar daVinci machines are deserted.

>Even then, you can pop on a pair of scrubs and avoid most scrutiny. Keycard systems are there, but those aren't difficult. Sometimes the operating area doesn't have cameras and the area surrounding the 2 million dollar daVinci machines are deserted.

I can confirm this.

I can also confirm that those daVinci machines are way less impressive looking in person than they are plastered on roadside billboards. :)

Re: It’s Easy to Hack Hospital Equipment

#49

Earlier quoted context omitted.

The difference being that it's tough to kill people at scale and covertly with a rifle or even poison mail. Exploiting a bug in networked pacemakers could give you the means to kill an entire userbase. For the train comparison, it's the difference between pushing a guy on the rails and derailing a train remotely by accelerating it remotely through a curve and disabling the manual controls. What's the value to the use…

> What's the value to the user of a networked pacemaker? Maybe a lower price? Fewer surgeries to get to the physical device and change settings. Therefore, longer life expectancy. This bug might be a feature.

That is just an (excellent) argument for medical devices to have some kind of connectivity to the outside world, but not for having the actual device ever connected to the Internet.

Strict air gaps would be desirable.

Re: It’s Easy to Hack Hospital Equipment

#50

To be a dash risk managementy about it; (Risk of being hacked) x (severity of being hacked) (Risk of being hacked): Small. (Severity of being hacked): Very negative, but localised most likely to a single machine, set of machines, or hospital. (Risk of Software not Delivered): Pretty high if we go super-security. We are on a budget. There is competition. Who is paying for it? (Severity of not delivered): Failure to cu…

What are the chances that someone would actually doing the hacking? I don't see any monetary reason to do so. Maybe that's one reason why we haven't seen many reports of people hacking medical devices?

It could be done as a murder for hire, or as a terrorist event. It's possible some hackers would do it 'for the lulz' or maybe they just want to test out a hack and accidentally go to far, though these are more unlikely. And there is also extortion, maybe you find everyone that has a vulnerable pacemaker, and demand they pay you or else you stop their heart. Criminals are clever, if they find a way to attack people they can often exploit it.
Post reply on HN