Live data from Hacker News

Can I drop a pacemaker 0day?

blog.erratasec.com

51–60 of 174 posts

Re: Can I drop a pacemaker 0day?

#51
post #4

This is the most important problem that the internet of things faces. How can we network everything while maintaining at least some scrap of security, especially in the long term? How can we convince people that their toaster is worth patching, and, more importantly, how to we convince vendors that toasters are worth releasing patches for? What if appliance makers go bankrupt and your dishwasher no longer receives pa…

> How can we network everything while maintaining at least some scrap of security, especially in the long term?

Another question that we should be asking more is should we network everything that could be?

As for a pacemaker, personally I think the answer is a definite NO. It has only one function, to keep someone alive, and any extra functionality only represents an increased risk of malfunction. If there is any firmware in it then that firmware should be as simple as it can be. Preferably open-source and subject to being reviewed/corrected by many, before it gets permanently embedded in a device.

> how can we prevent them from occuring in the first place?

The obvious way is by doing it right the first time. Sadly, this is something that seems to have fallen out of fashion, as the prevalent mentality is more like "we can always issue an update, so it doesn't matter that much". A dangerous mentality indeed, when it's in truly safety-critical applications. Companies are increasingly pushing for "smartness" in their products, espousing all the ostensible advantages, while not giving much exposure to the possible downsides too.

Re: Can I drop a pacemaker 0day?

#52
post #41

Earlier quoted context omitted.

Terrible advice to pull a media stunt. First, you have no idea what the manufacturer needs to do to fix the problem, alert customers, do recalls and recertifications, and the like. Second, you put yourself directly in the line of fire unnecessarily and for all the wrong reasons. You could find yourself on the end of all kinds of legal trouble, and on top of that you would be morally culpable for any harm. Do it the r…

I think OP is suggesting reveal the effect, but don't reveal the cause. That's what makes the suggestion different from releasing an 0day

If it's as easy as using 'strings', then isn't that no different than releasing a 0day?

Re: Can I drop a pacemaker 0day?

#55
It's not quite "this could kill people" but rather "this could be used to kill someone." But there are a lot of things that one person could use against another person to kill them, ethically, what does adding this thing to the list change?

If you discovered / disclosed a particular way the unit could malfunction and kill someone it seems like that's put in a different class; in that case you're a hero saving lives. But if you report on a technique someone could use to cause the device to malfunction, it's treated completely differently.

I think a related and important message is that pacemaker "malfunctions" should be treated as possibly suspicious.

Re: Can I drop a pacemaker 0day?

#56
post #48
post #41

Earlier quoted context omitted.

Terrible advice to pull a media stunt. First, you have no idea what the manufacturer needs to do to fix the problem, alert customers, do recalls and recertifications, and the like. Second, you put yourself directly in the line of fire unnecessarily and for all the wrong reasons. You could find yourself on the end of all kinds of legal trouble, and on top of that you would be morally culpable for any harm. Do it the r…

And who pays the lawyer?

I expect that any savvy lawyer would be happy to take this pro bono. Think of how much free publicity they'd get for their practice.

Re: Can I drop a pacemaker 0day?

#57

Call up CNN and offer to demonstrate how BIOTRONIC is so evil that they refuse to fix their pacemakers. Hook it up to an ECG and use your phone to make it flatline. Then turn to the camera and tell the audience, "because BIOTRONIC doesn't want to pay to fix their product, I can now kill your grandmother just by walking past her on the street." Watch how long it takes them to fix it then, and watch how reactive they b…

There's no need to call CNN. We have Youtube now, which would arguably be a more effective medium if the video can achieve any level of virality.

I'd guess the demographic that cares about this does not go on YouTube enough to make it more effective.

Re: Can I drop a pacemaker 0day?

#58
post #12

Earlier quoted context omitted.

What does 'fix deployed' mean? How do you actually update pacemaker software? Are you going to wait for 100% of the deployed pacemakers are fixed? What is an acceptable fix rate before you release the exploit?

Pacemaker firmware can almost always be updated using inductive or rf telemetry. In most cases it still requires an appointment with a cardiologist or similar physician though.

Anyone who uses a pacemaker will need to have it checked at least a couple of times a year anyway.

Re: Can I drop a pacemaker 0day?

#59

Call up CNN and offer to demonstrate how BIOTRONIC is so evil that they refuse to fix their pacemakers. Hook it up to an ECG and use your phone to make it flatline. Then turn to the camera and tell the audience, "because BIOTRONIC doesn't want to pay to fix their product, I can now kill your grandmother just by walking past her on the street." Watch how long it takes them to fix it then, and watch how reactive they b…

Don't you need surgery to fix it?

If a pacemaker can be remotely exploited, it can probably be remotely patched as well. Once you have remote root, anything is possible.

Re: Can I drop a pacemaker 0day?

#60
post #41

Call up CNN and offer to demonstrate how BIOTRONIC is so evil that they refuse to fix their pacemakers. Hook it up to an ECG and use your phone to make it flatline. Then turn to the camera and tell the audience, "because BIOTRONIC doesn't want to pay to fix their product, I can now kill your grandmother just by walking past her on the street." Watch how long it takes them to fix it then, and watch how reactive they b…

Terrible advice to pull a media stunt. First, you have no idea what the manufacturer needs to do to fix the problem, alert customers, do recalls and recertifications, and the like. Second, you put yourself directly in the line of fire unnecessarily and for all the wrong reasons. You could find yourself on the end of all kinds of legal trouble, and on top of that you would be morally culpable for any harm. Do it the r…

> get a lawyer

Because this is the world we should want to live in? Where you must pay a member of the protection racket to mediate publishing knowledge of someone else's extreme wrongdoing?

That is terrible advice. Its road ends with TORified disclosures of weaponized automated exploits, because as pure info sec has shown, that's the only way the message ever gets across when you give people the insulation to not listen.

Publicly demonstrating these exploits to an amicable media is the best idea I've heard yet, as they have straightforward real-world effects that can be easily illustrated. If certain manufacturers choose to send goons after you rather than fix their buggy products, then the community-accepted custom for them can change to psuedonymous press releases accompanied by a video with a (mock) live human subject.

Post reply on HN