Live data from Hacker News

Can I drop a pacemaker 0day?

blog.erratasec.com

81–90 of 174 posts

Re: Can I drop a pacemaker 0day?

#81

Call up CNN and offer to demonstrate how BIOTRONIC is so evil that they refuse to fix their pacemakers. Hook it up to an ECG and use your phone to make it flatline. Then turn to the camera and tell the audience, "because BIOTRONIC doesn't want to pay to fix their product, I can now kill your grandmother just by walking past her on the street." Watch how long it takes them to fix it then, and watch how reactive they b…

Everything except shorting their stock. If you wrote a hard-hitting exposé or a John Stossel-type broadcast you aren't likely to be branded a terrorist. Make sure you don't reveal how it's actually done, but the fact that it can be.

In short - media showing the potential results (and dramatizing them) puts heat on the company to fix it.

Re: Can I drop a pacemaker 0day?

#82
post #41

Call up CNN and offer to demonstrate how BIOTRONIC is so evil that they refuse to fix their pacemakers. Hook it up to an ECG and use your phone to make it flatline. Then turn to the camera and tell the audience, "because BIOTRONIC doesn't want to pay to fix their product, I can now kill your grandmother just by walking past her on the street." Watch how long it takes them to fix it then, and watch how reactive they b…

Terrible advice to pull a media stunt. First, you have no idea what the manufacturer needs to do to fix the problem, alert customers, do recalls and recertifications, and the like. Second, you put yourself directly in the line of fire unnecessarily and for all the wrong reasons. You could find yourself on the end of all kinds of legal trouble, and on top of that you would be morally culpable for any harm. Do it the r…

Oh fucking yawn, this is absurd advice. Can you even be serious?

Re: Can I drop a pacemaker 0day?

#83
How about releasing the vulnerability in stages? The author jumps from unresponsive vendor to releasing exploit code. What if you add steps between the two?

For example:

- Announcing a vulnerability has been found and identifying the unresponsive vendor.

- Announcing what the disclosure timeline will be.

- Detailing the product lines known to be affected by the vulnerability.

- Publishing communication with the vendor so far with any details about the vulnerability redacted.

- Private disclosure to professionals (doctors & journalists) to have them independently verify that the vulnerability exists and help with raising awareness.

- Full details about the vulnerability, but no exploit code.

Re: Can I drop a pacemaker 0day?

#84
This is clearly something where a regulatory agency that can and will apply penalties to manufacturers that do not fix bugs that are physically possible to fix without ill effect in a timely manner is appropriate. You simply report to that agency.

These problems are serious enough that failing fast and hard is not a good way to go about it. This is software meets physical reality. In software land, we've developed radically different approaches to engineering problems because of the incredibly cheap costs. This is one place where we have to borrow from other disciplines that have more experience with safety issues.

Re: Can I drop a pacemaker 0day?

#85

Call up CNN and offer to demonstrate how BIOTRONIC is so evil that they refuse to fix their pacemakers. Hook it up to an ECG and use your phone to make it flatline. Then turn to the camera and tell the audience, "because BIOTRONIC doesn't want to pay to fix their product, I can now kill your grandmother just by walking past her on the street." Watch how long it takes them to fix it then, and watch how reactive they b…

If you attempt a stunt like this, please first consider the people who have these pacemakers in their bodies. Put yourself in their shoes as they're watching the news broadcast or getting a frantic call from a family member.

Let's say one of them panics out of fear, has a heart attack, and dies. The family reports this to the media. Now the news media is hunting you down. The authorities want to have a word with you, and you're the target of several lawsuits. Not to mention, you just killed someone with your flippant remarks. Technically speaking, the device manufacturer hasn't hurt anyone at this point. But you've contributed to the death of a person. Is that really what you're after?

Contacting a lawyer to understand the protocol for disclosure and the ramifications won't cost you anything for the initial consultation. Contact the EFF or ACLU and ask for advice. Ask them who you should contact next.

Re: Can I drop a pacemaker 0day?

#86

- Contact the FDA, or other regulatory bodies. - Contact the customers. They'll likely have standing to sue (they were sold a defective product). - Class-action attorneys may be interested for this reason. - Did you know you can pay a very, very modest amount of money to file a press release saying anything you want? - Contact some investors. Short sellers will have a vested interest in making sure the information ge…

I believe this comes closest to the proper answer. Eventually, we need technology literate courts, and a law that criminalizes failure to fix disclosed vulnerabilities. Until that day, the process you describe best achieves the same result.

Re: Can I drop a pacemaker 0day?

#87
post #41

Earlier quoted context omitted.

Terrible advice to pull a media stunt. First, you have no idea what the manufacturer needs to do to fix the problem, alert customers, do recalls and recertifications, and the like. Second, you put yourself directly in the line of fire unnecessarily and for all the wrong reasons. You could find yourself on the end of all kinds of legal trouble, and on top of that you would be morally culpable for any harm. Do it the r…

> get a lawyer Because this is the world we should want to live in? Where you must pay a member of the protection racket to mediate publishing knowledge of someone else's extreme wrongdoing? That is terrible advice. Its road ends with TORified disclosures of weaponized automated exploits, because as pure info sec has shown, that's the only way the message ever gets across when you give people the insulation to not li…

> Because this is the world we should want to live in? Where you must pay a member of the protection racket to mediate publishing knowledge of someone else's extreme wrongdoing?

Might be useful to distinguish between the ideal and the actual: in an ideal world, you of course shouldn't need a lawyer and the manufacturers should smilingly thank anyone who discovers an exploit and tells them. In this less-than-perfect world I'd suggest getting a lawyer and then going to the media.

Re: Can I drop a pacemaker 0day?

#88
post #71

Earlier quoted context omitted.

> How can we network everything while maintaining at least some scrap of security, especially in the long term? Another question that we should be asking more is should we network everything that could be? As for a pacemaker, personally I think the answer is a definite NO. It has only one function, to keep someone alive, and any extra functionality only represents an increased risk of malfunction. If there is any fir…

I imagine there's some value in being able to update the firmware on a pacemaker. Maybe a new pacemaking algorithm can save 1% more lives or something. Or it could automatically call an ambulance when you have a heart attack, etc.

Implanted medical devices do seem like the ideal situation for wireless access, albeit you probably don't want to overburden the thing with features either.

Re: Can I drop a pacemaker 0day?

#89

Call up CNN and offer to demonstrate how BIOTRONIC is so evil that they refuse to fix their pacemakers. Hook it up to an ECG and use your phone to make it flatline. Then turn to the camera and tell the audience, "because BIOTRONIC doesn't want to pay to fix their product, I can now kill your grandmother just by walking past her on the street." Watch how long it takes them to fix it then, and watch how reactive they b…

Then they cut to an ad of Watch_Dogs.

Re: Can I drop a pacemaker 0day?

#90
I remember reading that Cheney had them remove all wireless functionality from his pacemaker because they were afraid of the potential of someone using it for assassination.[1]

[1]http://abcnews.go.com/US/vice-president-dick-cheney-feared-p...

EDIT: Also, no you shouldn't release a pacemaker 0day. As others have said, expose it without releasing details. Makes for a nice demo.

Post reply on HN