Live data from Hacker News

It’s Easy to Hack Hospital Equipment

wired.com

61–65 of 65 posts

Re: It’s Easy to Hack Hospital Equipment

#61

This kind of problems is going to be more prominent as "Internet of Things" starts to take off. I was rather concern about Nest, our cars, Fridges etc being connected to the Internet and, on some devices, the security is quite low. This article is shows an example of it.

This is one of the reasons why, as a rule, biomed devices that directly interact with a patient are never connected to the public internet.

Which works until one of the devices networked with said biomed device uses a wireless link and someone brings in a cell phone.

Airgaps are really hard to do correctly, as they have so many single points of failure.

Re: It’s Easy to Hack Hospital Equipment

#62

They also found surgery robots connected to internal networks. Although the robots generally have software firewalls to block connections to them, Erven and his team found that simply running an off-the-shelf vulnerability scanner against the firewall caused it to turn off and fail open. Wow, just wow. If someone ever hacks an active surgery robot it's going to be Saw meets Snow Crash , and not in a good way.

And with some hospitals still running Win XP, it's easy to get a foothold on their network!

I'm working in that space, and sampling from the ones I've dealt with, I'd replace some with most.

Some of the ones I deal with are also running those XPs with old IE versions, 6 & 7. This is because they bought, then never upgraded, systems that won't run right with newer browsers.

Re: It’s Easy to Hack Hospital Equipment

#63

Earlier quoted context omitted.

Whilst true, I can with 100% certainty, state that no-one in the medical profession, or the procurement people in the hospitals ever did that calculation. NICE (the UK's no-you-cant-spend-ten-million-of-taxpayers-money-per-patient-on-a-drug-to-extend-their-life-by-six-weeks agency which gets it in the neck for such things) might be able to take on such a calculation - but I bet you anything even if they did that calc…

> after the first death from a hacked pacemaker, the outcry will be heard from the moon // Isn't the problem that there will always be a way to kill people, even remotely without touching them (sniper, poison mail, gas bomb, massive microwave in a van that you park next to them, ...). You perhaps don't want to make it easy but it's also not necessarily sensible to waste money on an arms race that you'll never win. Si…

I had not thought of the rise of microwave terrorism (perhaps with the skin-burning crowd disperser (citation not found) it's already on us).

But my basic tenant is that we / society has an acceptable balance of risk and benefit. Maybe not a rational one but one that is understood by most people. For cars it's pretty high on the risk tolerance. For medical drugs it's really low. For computer hacking it's low too - cf Aaron Schwartz. I would say that medical devices combine low risk tolerance of drugs and low risk tolerance of hacking - making the spectre of hacked implanted devices front page news.

I expect it will be pretty simple to defeat however - only allow networking of a device over near field radio (RFID style). that way there is no remote access in a body, and do a similar thing for any robots or monitors - the only way to connect a surgical robot to the Internet is with a doctors own personal RFID - tcpip convertor, that he takes away with him or is counts back into stores next to the nurses. Massively dropping the risk ratio with a few simple rules.

we can do this - we just need to be sensible about it

Ps Westminster and canary wharf do have enclosed tube platforms so people cannot jump / be pushed. Because we cannot have bankers or politicians delayed by poverty stricken depressives ...

Re: It’s Easy to Hack Hospital Equipment

#64

Earlier quoted context omitted.

Whilst true, I can with 100% certainty, state that no-one in the medical profession, or the procurement people in the hospitals ever did that calculation. NICE (the UK's no-you-cant-spend-ten-million-of-taxpayers-money-per-patient-on-a-drug-to-extend-their-life-by-six-weeks agency which gets it in the neck for such things) might be able to take on such a calculation - but I bet you anything even if they did that calc…

> after the first death from a hacked pacemaker, the outcry will be heard from the moon // Isn't the problem that there will always be a way to kill people, even remotely without touching them (sniper, poison mail, gas bomb, massive microwave in a van that you park next to them, ...). You perhaps don't want to make it easy but it's also not necessarily sensible to waste money on an arms race that you'll never win. Si…

The difference is that snipers et al require targeted effort. Hacking hospital equitment allows for mass destruction.

Re: It’s Easy to Hack Hospital Equipment

#65

Earlier quoted context omitted.

Whilst true, I can with 100% certainty, state that no-one in the medical profession, or the procurement people in the hospitals ever did that calculation. NICE (the UK's no-you-cant-spend-ten-million-of-taxpayers-money-per-patient-on-a-drug-to-extend-their-life-by-six-weeks agency which gets it in the neck for such things) might be able to take on such a calculation - but I bet you anything even if they did that calc…

They don't need to do the calculation because their intuition already leads them to the right decision. This is just economics. What is the payoff for the evildoer hacking a pacemaker? Oh right, he's a contract killer? Too many movies for you. It's just more profitable to replace the payment processing app with your own payment skimming app at some big store.

Re intutition, there are several statistically observable anomalies in human decision-making.

http://www.investopedia.com/university/behavioral_finance/

(note the article is in several sections)

Post reply on HN