Live data from Hacker News

Can I drop a pacemaker 0day?

blog.erratasec.com

1–10 of 174 posts

Re: Can I drop a pacemaker 0day?

#2
If it’s an obvious vulnerability, is there value in withholding the details? There is a strong case to be made for the argument that the people who would be willing to use such a 0day maliciously (sociopaths) would find it anyway.

It could potentially also depend on how easily the vulnerability can be patched—one that can be patched remotely can be dealt with much more rapidly than one that will require surgery to replace the device. If one assumes that full disclosure will lead to the fixing of the issue, the first class is probably closer to being judged “responsible” than the second.

It is certainly a difficult dilemma. The correct answer can only be known with the benefit of hindsight…

Re: Can I drop a pacemaker 0day?

#3
Make a YouTube video of the hack actually working on a pacemaker (preferably one that is not in a person). Show how it can be executed from a smart phone while walking down the street or sitting at Starbucks.

Send that to the company and the media. You are best off also showing documentation that you told the offending company multiple times.

Show don't tell.

Re: Can I drop a pacemaker 0day?

#4
This is the most important problem that the internet of things faces. How can we network everything while maintaining at least some scrap of security, especially in the long term? How can we convince people that their toaster is worth patching, and, more importantly, how to we convince vendors that toasters are worth releasing patches for? What if appliance makers go bankrupt and your dishwasher no longer receives patches? How will devices be updated if another Heartbleed-esque situation occurs? It's easier for a user to protect themselves from a 0-day in an app they use, for example, compared to vital home appliances such as dishwashers, refrigerators or washing machines, which cannot merely be uninstalled.

This is a very real threat, most notably Belkin [0] has suffered critical security breaches, and this issue won't be going away any time soon. How can security researchers get CVE's patched, and how can we prevent them from occuring in the first place? This should be priority #1 for any company trying to bring internet-connected appliances to the mainstream.

[0]: http://arstechnica.com/security/2014/02/password-leak-in-wem...

Re: Can I drop a pacemaker 0day?

#5
Here's an idea:

1.) Responsible disclosure to vendor. Allow reasonable amount of time for a fix to be created and deployed.

2.) (If fix is deployed, release details)

3.) If no fix is deployed in a reasonable amount of time and the vendor is unresponsive, release a PoC that demonstrates exploitability without giving away details. eg: "Here is a pacemaker. Look, I did magic and it stopped!" This is the same idea as releasing the actual vulnerability/exploit, but doesn't put lives at risk. People that could fuzz for any type of a vulnerability would be able to find it on their own anyway.

I agree that ICS and health-sensitive vulnerability disclosure is a trickier field than most. Medical devices, cars, and power plants are much more sensitive than a random kid's iPhone; that's why groups like I Am The Cavalry are trying to address the issue industry-wide.

However, to answer the original question: don't drop a pacemaker 0day at DEF CON. Find a way to fix the problem with the vendor instead. At the very "worst," demo without vulnerability or exploit details.

Re: Can I drop a pacemaker 0day?

#6
What pacemaker communicates via blue tooth? Last I checked they all used induction telemetry (which requires the telemetry wand to be within several inches of the device) or MICS band radio for distance telemetry. I think some Boston Scientific devices used 900MHz at one time, but how many of those are still in the wild?

The only instances of "hacking" a pacemaker (or ICD) have been when researchers used a programmer from the manufacturer to "hack" the device.

So it seems super unlikely you know a blue tooth zero day for a pacer.

Re: Can I drop a pacemaker 0day?

#7
Absolutely NOT because this could kill people.

If you truly have a pacemaker 0day, contact me (joelparkerhenderson) on most major service and I will connect you with my healthcare policy lawyer. She can rapidly open the doors to the vendors who have the risk.

Re: Can I drop a pacemaker 0day?

#8
This is an incredibly sensational piece. All of the sane suggestions are dismissed as "doesn't work" by giving one example where it didn't work. It's not that easy - going to the media won't solve the problem 100% of the time but it sure as hell would if it were a life and death 0day and wasn't fixed with urgency.

Don't even get me started about the Nazi analogy...

Re: Can I drop a pacemaker 0day?

#9
post #7

Absolutely NOT because this could kill people. If you truly have a pacemaker 0day, contact me (joelparkerhenderson) on most major service and I will connect you with my healthcare policy lawyer. She can rapidly open the doors to the vendors who have the risk.

Do most medical device manufacturers carry insurance against lawsuits? If so, historically, how high has the bar been before the insurers pay out? If there is a strong relationship between a device manufacturer getting sued and an insurer losing money then this could be a great contact to try.
Post reply on HN