Live data from Hacker News

Can I drop a pacemaker 0day?

blog.erratasec.com

61–70 of 174 posts

Re: Can I drop a pacemaker 0day?

#61
What do you expect them to do? Even assuming they were 100% concerned with security and did everything right and there was still a bug that allowed a pacemaker to be compromised. Do you expect them to cut open a person and replace the buggy pacemaker?

I don't pretend to be an expert in this area but getting medical equipment approved is a huge undertaking and I don't know what the ramifications of changing anything would be. Say they take your 0day and fix it. Then they have to go through the entire re-certification process again and after however many months or years, NEW patients get the fixed pacemaker. But what about all the old patients?

While I sympathize, the only realistic approach here is to make the consequences for killing someone via a 0day for the "lulz" so drastic that it would certainly legally bleed over into the disclosure. I realize this is the approach we do tend to take here in the US.

Re: Can I drop a pacemaker 0day?

#62

Earlier quoted context omitted.

There's no need to call CNN. We have Youtube now, which would arguably be a more effective medium if the video can achieve any level of virality.

I'd guess the demographic that cares about this does not go on YouTube enough to make it more effective.

Doesn't matter, CNN et al will rebroadcast once it's gone viral.

Re: Can I drop a pacemaker 0day?

#63
post #59

Earlier quoted context omitted.

Don't you need surgery to fix it?

If a pacemaker can be remotely exploited, it can probably be remotely patched as well. Once you have remote root, anything is possible.

It's probably easier to crash than root.

Re: Can I drop a pacemaker 0day?

#65
I don't understand why there is such a debate here. I would absolutely disclose the 0-day if the manufacturer was unresponsive (given sufficient warning, of course). Moreover, if anyone died, I wouldn't feel the least bit guilty about that - the guilt rests firmly on the manufacturer and the individuals who choose to use the exploit.

After all, black-market exploits will come, and people will die, whether you disclose the vulnerability or not. At least with disclosure, the innocent have a chance to protect themselves.

You must weigh the lives lost to silence against the lives lost to disclosure. We practice disclosure in all other areas of computer security because we have seen the cost of silence too many times. There is no reason it should be different here.

Disclosure saves lives.

Re: Can I drop a pacemaker 0day?

#66
post #54

[deleted]

Michael Hastings and Barnaby Jack were not the same person. They weren't in the same industry; they weren't even from the same hemisphere. To my knowledge, there were zero connections between the two.

The death of Barnaby Jack (who was to present at Defcon) was tragic, but not suspicious.

Re: Can I drop a pacemaker 0day?

#68
post #4

This is the most important problem that the internet of things faces. How can we network everything while maintaining at least some scrap of security, especially in the long term? How can we convince people that their toaster is worth patching, and, more importantly, how to we convince vendors that toasters are worth releasing patches for? What if appliance makers go bankrupt and your dishwasher no longer receives pa…

Does this problem (the growing widespread network insecurity of everyday objects) have a specific name, like "security rot"? If it does, I don't know it. I do know that once you give a complex problem a label (like "net neutrality" or "the Internet of Things"), it becomes a catalyst for discussion. People begin to understand and recognize the label, it becomes a brand that journals and conferences and books and blogs can all focus on. This phenomenon needs a label if we're going to make real progress on it.

Re: Can I drop a pacemaker 0day?

#69
"The problem is that dropping a pacemaker 0day is so horrific that most people would readily agree it should be outlawed. But, at the same time, without the threat of 0day, vendors will ignore the problem."

If this is the case, then wouldn't the same most-people (if made aware of the issue) also agree that it should be illegal for a company's management to ignore life-threatening software flaws in their products after being notified?

I mean illegal as in reckless endangerment or manslaughter, not illegal as in lawsuits and golden parachutes.

Re: Can I drop a pacemaker 0day?

#70

Call up CNN and offer to demonstrate how BIOTRONIC is so evil that they refuse to fix their pacemakers. Hook it up to an ECG and use your phone to make it flatline. Then turn to the camera and tell the audience, "because BIOTRONIC doesn't want to pay to fix their product, I can now kill your grandmother just by walking past her on the street." Watch how long it takes them to fix it then, and watch how reactive they b…

Watch how long it takes them to fix it then...

That strikes me as really optimistic. Another scenario:

Medical equipment manufacturing lobby (I'm assuming there is such a thing) pushes to have such disclosures treated as acts of terrorism. Manufacturer issues a patch that fixes your very specific vulnerability in some trivial, meaningless way. Your career is ruined. Pacemakers truly secured: 0.

Post reply on HN