Live data from Hacker News

Can I drop a pacemaker 0day?

blog.erratasec.com

11–20 of 174 posts

Re: Can I drop a pacemaker 0day?

#11
And so it begins. I was wondering when we'd finally start seeing the InfoSec guys get to this. The more recent stuff branching into CAN on cars and before that SCADA systems seemed to be the last sort of stepping stone from a traditional PC network to the internet of things networks.

I'm sort of glad, in a twisted way, that this has finally happened. Better the light get cast on this now than in a few years once the criminal(/nation-state...) equivalents have had time to go through it themselves.

Re: Can I drop a pacemaker 0day?

#12

Here's an idea: 1.) Responsible disclosure to vendor. Allow reasonable amount of time for a fix to be created and deployed. 2.) (If fix is deployed, release details) 3.) If no fix is deployed in a reasonable amount of time and the vendor is unresponsive, release a PoC that demonstrates exploitability without giving away details. eg: "Here is a pacemaker. Look, I did magic and it stopped!" This is the same idea as rel…

What does 'fix deployed' mean? How do you actually update pacemaker software? Are you going to wait for 100% of the deployed pacemakers are fixed? What is an acceptable fix rate before you release the exploit?

Re: Can I drop a pacemaker 0day?

#13
post #6

What pacemaker communicates via blue tooth? Last I checked they all used induction telemetry (which requires the telemetry wand to be within several inches of the device) or MICS band radio for distance telemetry. I think some Boston Scientific devices used 900MHz at one time, but how many of those are still in the wild? The only instances of "hacking" a pacemaker (or ICD) have been when researchers used a programmer…

> So let's say

Re: Can I drop a pacemaker 0day?

#14
Call up CNN and offer to demonstrate how BIOTRONIC is so evil that they refuse to fix their pacemakers. Hook it up to an ECG and use your phone to make it flatline. Then turn to the camera and tell the audience, "because BIOTRONIC doesn't want to pay to fix their product, I can now kill your grandmother just by walking past her on the street."

Watch how long it takes them to fix it then, and watch how reactive they become to responsible disclosure next time.

Also, short their stock before you go on TV. A little something for your troubles.

Re: Can I drop a pacemaker 0day?

#15
The ONLY people who need to know about this is the manufacturer and their regulatory body FDA, etc.

The company can then pull all the inventory that is in and out of the patients and apply fixes or facilitate replacements.

If this could kill people, I'd hope the above ideas would be obvious...but well I know they won't be to everyone.

Re: Can I drop a pacemaker 0day?

#16

Call up CNN and offer to demonstrate how BIOTRONIC is so evil that they refuse to fix their pacemakers. Hook it up to an ECG and use your phone to make it flatline. Then turn to the camera and tell the audience, "because BIOTRONIC doesn't want to pay to fix their product, I can now kill your grandmother just by walking past her on the street." Watch how long it takes them to fix it then, and watch how reactive they b…

Now THAT is how you do it. Grab a "shock of the week" angle and play it for anyone that wants to watch. Only issue is getting a "non-defective" pacemaker. Those things aren't cheap or easy to come by without ordering it from the manufacturer. Whatever profit you could have shorting the stock you'd lose almost immediately by having to purchase the devise.

Re: Can I drop a pacemaker 0day?

#18
I think that there are a lot of ways to approach this. The Heartbleed disclosure was very well done and has a lot of lessons, perhaps there's something to learn from that.

Personally, I think it's completely unacceptable the way many technologies critical to keeping people alive are so vulnerable. Especially if the vulnerabilities are as widespread as the article suggests (30%!), find a list of 10-20 that vary in importance. List all the products, and list the consequences of each vulnerability.

Then start dropping 0-days one at a time until the industry realizes you are serious. Start with the less severe ones, but if the pacemaker vulnerability hasn't been addressed after a few months of weekly vulnerability releases, don't hold back. The more publicity you can get the more likely a company is to patch vulnerabilities.

If _teenagers_ are capable finding vulnerabilities that can end lives using a script they downloaded online, then we need to be ready to take drastic action. The industry is in a terrible state and we aren't safe, and decreasingly so as these gaping holes continue to sit there and be discovered.

Re: Can I drop a pacemaker 0day?

#19

Call up CNN and offer to demonstrate how BIOTRONIC is so evil that they refuse to fix their pacemakers. Hook it up to an ECG and use your phone to make it flatline. Then turn to the camera and tell the audience, "because BIOTRONIC doesn't want to pay to fix their product, I can now kill your grandmother just by walking past her on the street." Watch how long it takes them to fix it then, and watch how reactive they b…

[deleted]

Re: Can I drop a pacemaker 0day?

#20
This sort of 0-day has been known in the academic literature for some time[1].

Disclosure of critical vulnerabilities in implantable devices is far more fraught than your normal critical software 0-day. These devices require surgery for replacement, and a small number of those surgeries will have possibly fatal complications. The cost of immediately replacing all existing vulnerable devices could literally be measured in lives. (And that's even assuming that the device manufacturer fixed the problem!)

Implantable software is already a very tricky area, and there's no signs that it'll get any easier.

[1] Pacemakers and Implantable Cardiac Defibrillators: Software Radio Attacks and Zero-Power Defenses, http://www.secure-medicine.org/public/publications/icd-study...

Post reply on HN