I'm sort of glad, in a twisted way, that this has finally happened. Better the light get cast on this now than in a few years once the criminal(/nation-state...) equivalents have had time to go through it themselves.
Can I drop a pacemaker 0day?
11–20 of 174 posts
Re: Can I drop a pacemaker 0day?
#12Here's an idea: 1.) Responsible disclosure to vendor. Allow reasonable amount of time for a fix to be created and deployed. 2.) (If fix is deployed, release details) 3.) If no fix is deployed in a reasonable amount of time and the vendor is unresponsive, release a PoC that demonstrates exploitability without giving away details. eg: "Here is a pacemaker. Look, I did magic and it stopped!" This is the same idea as rel…
Re: Can I drop a pacemaker 0day?
#13What pacemaker communicates via blue tooth? Last I checked they all used induction telemetry (which requires the telemetry wand to be within several inches of the device) or MICS band radio for distance telemetry. I think some Boston Scientific devices used 900MHz at one time, but how many of those are still in the wild? The only instances of "hacking" a pacemaker (or ICD) have been when researchers used a programmer…
Re: Can I drop a pacemaker 0day?
#14Watch how long it takes them to fix it then, and watch how reactive they become to responsible disclosure next time.
Also, short their stock before you go on TV. A little something for your troubles.
Re: Can I drop a pacemaker 0day?
#15The company can then pull all the inventory that is in and out of the patients and apply fixes or facilitate replacements.
If this could kill people, I'd hope the above ideas would be obvious...but well I know they won't be to everyone.
Re: Can I drop a pacemaker 0day?
#16Call up CNN and offer to demonstrate how BIOTRONIC is so evil that they refuse to fix their pacemakers. Hook it up to an ECG and use your phone to make it flatline. Then turn to the camera and tell the audience, "because BIOTRONIC doesn't want to pay to fix their product, I can now kill your grandmother just by walking past her on the street." Watch how long it takes them to fix it then, and watch how reactive they b…
Re: Can I drop a pacemaker 0day?
#17[article]: http://www.wired.com/2014/04/hospital-equipment-vulnerable/
[hn thread]: https://news.ycombinator.com/item?id=7684291
Re: Can I drop a pacemaker 0day?
#18Personally, I think it's completely unacceptable the way many technologies critical to keeping people alive are so vulnerable. Especially if the vulnerabilities are as widespread as the article suggests (30%!), find a list of 10-20 that vary in importance. List all the products, and list the consequences of each vulnerability.
Then start dropping 0-days one at a time until the industry realizes you are serious. Start with the less severe ones, but if the pacemaker vulnerability hasn't been addressed after a few months of weekly vulnerability releases, don't hold back. The more publicity you can get the more likely a company is to patch vulnerabilities.
If _teenagers_ are capable finding vulnerabilities that can end lives using a script they downloaded online, then we need to be ready to take drastic action. The industry is in a terrible state and we aren't safe, and decreasingly so as these gaping holes continue to sit there and be discovered.
Re: Can I drop a pacemaker 0day?
#19Call up CNN and offer to demonstrate how BIOTRONIC is so evil that they refuse to fix their pacemakers. Hook it up to an ECG and use your phone to make it flatline. Then turn to the camera and tell the audience, "because BIOTRONIC doesn't want to pay to fix their product, I can now kill your grandmother just by walking past her on the street." Watch how long it takes them to fix it then, and watch how reactive they b…
Re: Can I drop a pacemaker 0day?
#20Disclosure of critical vulnerabilities in implantable devices is far more fraught than your normal critical software 0-day. These devices require surgery for replacement, and a small number of those surgeries will have possibly fatal complications. The cost of immediately replacing all existing vulnerable devices could literally be measured in lives. (And that's even assuming that the device manufacturer fixed the problem!)
Implantable software is already a very tricky area, and there's no signs that it'll get any easier.
[1] Pacemakers and Implantable Cardiac Defibrillators: Software Radio Attacks and Zero-Power Defenses, http://www.secure-medicine.org/public/publications/icd-study...