Live data from Hacker News

Can I drop a pacemaker 0day?

blog.erratasec.com

71–80 of 174 posts

Re: Can I drop a pacemaker 0day?

#71
post #4

This is the most important problem that the internet of things faces. How can we network everything while maintaining at least some scrap of security, especially in the long term? How can we convince people that their toaster is worth patching, and, more importantly, how to we convince vendors that toasters are worth releasing patches for? What if appliance makers go bankrupt and your dishwasher no longer receives pa…

> How can we network everything while maintaining at least some scrap of security, especially in the long term? Another question that we should be asking more is should we network everything that could be? As for a pacemaker, personally I think the answer is a definite NO. It has only one function, to keep someone alive, and any extra functionality only represents an increased risk of malfunction. If there is any fir…

I imagine there's some value in being able to update the firmware on a pacemaker. Maybe a new pacemaking algorithm can save 1% more lives or something. Or it could automatically call an ambulance when you have a heart attack, etc.

Re: Can I drop a pacemaker 0day?

#72
post #28
post #25

Earlier quoted context omitted.

I was a Funeral Director in a previous life. I would remove pacemakers if the deceased was to be cremated. We had bags of them. They are cheap and disposable, don't believe anyone that tells you otherwise. Go ask your local Funeral Director for one.

And you're in tech now? That's an interesting career transition. You might write it up sometime; I love stories like that.

It's a tale of a misspent youth, wasted 20's, and a procrastinating disaffected attempt to reclaim my life as I now begin my 30's.

Re: Can I drop a pacemaker 0day?

#73
post #12

Earlier quoted context omitted.

What does 'fix deployed' mean? How do you actually update pacemaker software? Are you going to wait for 100% of the deployed pacemakers are fixed? What is an acceptable fix rate before you release the exploit?

Pacemaker firmware can almost always be updated using inductive or rf telemetry. In most cases it still requires an appointment with a cardiologist or similar physician though.

And many can now be monitored by the cardiologist from their office as the device uploads data to a server, or can even be reached directly from the physician's console. And both cardiologists and pacemaker companies generally have a pretty good bead on who's walking around with which serial numbered device.

Re: Can I drop a pacemaker 0day?

#74

Call up CNN and offer to demonstrate how BIOTRONIC is so evil that they refuse to fix their pacemakers. Hook it up to an ECG and use your phone to make it flatline. Then turn to the camera and tell the audience, "because BIOTRONIC doesn't want to pay to fix their product, I can now kill your grandmother just by walking past her on the street." Watch how long it takes them to fix it then, and watch how reactive they b…

> Call up CNN and offer to demonstrate how BIOTRONIC is so evil that they refuse to fix their pacemakers

We should probably check first to see if BIOTRONIC is one of their advertisers first, might be an issue.

Re: Can I drop a pacemaker 0day?

#75
post #46

Earlier quoted context omitted.

Yes, but more importantly, medical device makers have broad immunity when their devices go through the PMA process (the most stringent type of FDA approval). Basically, the argument is "hey, the FDA said it was safe".

Then this is where the pressure needs to be applied - at the certification process. It needs to be made a legal requirement to attain certification (if not already), and the certifiers need to follow best practices for vulnerability detection. And it needs to be an ongoing, open process.

Yes, the FDA certification should include something along the lines of "Manufacturer has an ongoing process to evaluate new vulnerabilities and push updates to affected individuals."

Re: Can I drop a pacemaker 0day?

#76

The ONLY people who need to know about this is the manufacturer and their regulatory body FDA, etc. The company can then pull all the inventory that is in and out of the patients and apply fixes or facilitate replacements. If this could kill people, I'd hope the above ideas would be obvious...but well I know they won't be to everyone.

If I had this product implanted in me and it was known for a substantial amount of time that said product was 0dayed, you better believe I have a right to know.

Re: Can I drop a pacemaker 0day?

#77
post #61

What do you expect them to do? Even assuming they were 100% concerned with security and did everything right and there was still a bug that allowed a pacemaker to be compromised. Do you expect them to cut open a person and replace the buggy pacemaker? I don't pretend to be an expert in this area but getting medical equipment approved is a huge undertaking and I don't know what the ramifications of changing anything w…

Someone made a comment above stating that people with pacemakers typically have to go in once or twice a year to get it checked, and the devices can be updated using 'inductive or rf telemetry'. Presumably doctors could update the devices when patients come in.

Re: Can I drop a pacemaker 0day?

#78
post #12

Here's an idea: 1.) Responsible disclosure to vendor. Allow reasonable amount of time for a fix to be created and deployed. 2.) (If fix is deployed, release details) 3.) If no fix is deployed in a reasonable amount of time and the vendor is unresponsive, release a PoC that demonstrates exploitability without giving away details. eg: "Here is a pacemaker. Look, I did magic and it stopped!" This is the same idea as rel…

What does 'fix deployed' mean? How do you actually update pacemaker software? Are you going to wait for 100% of the deployed pacemakers are fixed? What is an acceptable fix rate before you release the exploit?

If a large enough majority of people get their pacemakers fixed, it greatly lowers the chances that you'll encounter someone with a defective pacemaker that you can exploit.
Post reply on HN