Live data from Hacker News

Can I drop a pacemaker 0day?

blog.erratasec.com

141–150 of 174 posts

Re: Can I drop a pacemaker 0day?

#141
post #52

Earlier quoted context omitted.

I think OP is suggesting reveal the effect, but don't reveal the cause. That's what makes the suggestion different from releasing an 0day

If it's as easy as using 'strings', then isn't that no different than releasing a 0day?

If it's that simple he or she has, in effect, already released it.

Re: Can I drop a pacemaker 0day?

#142
post #92

Earlier quoted context omitted.

> get a lawyer Because this is the world we should want to live in? Where you must pay a member of the protection racket to mediate publishing knowledge of someone else's extreme wrongdoing? That is terrible advice. Its road ends with TORified disclosures of weaponized automated exploits, because as pure info sec has shown, that's the only way the message ever gets across when you give people the insulation to not li…

Can you elaborate on how lawyers are "member[s] of the protection racket"?

Like estate agents and recruiters, they create an inefficiency and exploit it.

Re: Can I drop a pacemaker 0day?

#143

Call up CNN and offer to demonstrate how BIOTRONIC is so evil that they refuse to fix their pacemakers. Hook it up to an ECG and use your phone to make it flatline. Then turn to the camera and tell the audience, "because BIOTRONIC doesn't want to pay to fix their product, I can now kill your grandmother just by walking past her on the street." Watch how long it takes them to fix it then, and watch how reactive they b…

"I can now kill your grandmother" - very bad phrasing for TV...

Re: Can I drop a pacemaker 0day?

#144
post #129

Earlier quoted context omitted.

1) You really shouldn't have an open conversation about knowledge that can easily kill people. 2) I'm pretty sure that communication isn't the problem, the problem is that he want's to pressure them into fixing their mess, and that is exactly the point where things get messy from a legal perspective. I can hardly imagine a legal system in which a situation like this would be unproblematic.

> 1) You really shouldn't have an open conversation about knowledge that can easily kill people. You mean like guns, toxins, and martial arts?

sigh. This will get boring quite fast because a sizable portion of people participating in threads like that find the idea revolting that actions can have, you know, consequences, but what the heck...

If you would find a recipe for a toxin that is deadly, untraceable and can be mixed together from common household items by a talented 14 year old, it's probably a bad fucking idea to post that to 4chan. The same goes for hypothetical weapon blue prints or martial arts techniques that would allow to kill with a microscopic risk.

Re: Can I drop a pacemaker 0day?

#145
post #6

What pacemaker communicates via blue tooth? Last I checked they all used induction telemetry (which requires the telemetry wand to be within several inches of the device) or MICS band radio for distance telemetry. I think some Boston Scientific devices used 900MHz at one time, but how many of those are still in the wild? The only instances of "hacking" a pacemaker (or ICD) have been when researchers used a programmer…

> The only instances of "hacking" a pacemaker [...] // Someone has linked a PDF of an "ICD study" upthread that shows your contention to be at least partially false.

I assume you mean this one:

http://www.secure-medicine.org/public/publications/icd-study...

You would need to be specific about which one of the linked documents you meant, there were several. All the hacking attempts started off with a manufacturer's programmer and worked back from there. In the example using a software radio, the researchers were able to replay sniffed commands to the device after it had been activated by the programmer.

Which of the reports talked about a device being compromised without using a manufacturers programmer?

Re: Can I drop a pacemaker 0day?

#146
post #25

Earlier quoted context omitted.

Now THAT is how you do it. Grab a "shock of the week" angle and play it for anyone that wants to watch. Only issue is getting a "non-defective" pacemaker. Those things aren't cheap or easy to come by without ordering it from the manufacturer. Whatever profit you could have shorting the stock you'd lose almost immediately by having to purchase the devise.

I was a Funeral Director in a previous life. I would remove pacemakers if the deceased was to be cremated. We had bags of them. They are cheap and disposable, don't believe anyone that tells you otherwise. Go ask your local Funeral Director for one.

I'm sure this is true, but all of the manufacturers provide postage paid biohazard boxes for the explanted devices to be returned to the manufacturer and properly disposed of. All you have to do is call the customer service number and ask for some to be sent to you.

Re: Can I drop a pacemaker 0day?

#147
post #55

It's not quite "this could kill people" but rather "this could be used to kill someone." But there are a lot of things that one person could use against another person to kill them, ethically, what does adding this thing to the list change? If you discovered / disclosed a particular way the unit could malfunction and kill someone it seems like that's put in a different class; in that case you're a hero saving lives.…

This is a way to kill someone at a distance, with no obvious trace leading to you, and using nothing but an off the shelf laptop or phone. It's significantly more dangerous than any of the other known methods of murder because of the reduced risk to the murderer.

My understanding is that pacemakers, insulin pumps, and such have only limited short-range wireless capability. It's not exactly a 3G connection with a public facing IP address.

As long as you still need proximity and individual targeting, I think it's not a paradigm shift in murder.

Re: Can I drop a pacemaker 0day?

#148
You can play moral white hat hacker when you are disclosing vulns in some shitty Chinese router, or participating in one of bug bounty programs, but NOT when you play against big boys (AT&T, MBTA, Juniper, Adobe, etc). You will get crushed, jailed and humiliated.

Disclose fully, but anonymously.

Re: Can I drop a pacemaker 0day?

#149

Here's an idea: 1.) Responsible disclosure to vendor. Allow reasonable amount of time for a fix to be created and deployed. 2.) (If fix is deployed, release details) 3.) If no fix is deployed in a reasonable amount of time and the vendor is unresponsive, release a PoC that demonstrates exploitability without giving away details. eg: "Here is a pacemaker. Look, I did magic and it stopped!" This is the same idea as rel…

This will stop at #1 after vendor sends you DMCA and informs feds that you are planning to kill people by hacking their product.

Re: Can I drop a pacemaker 0day?

#150

- Contact the FDA, or other regulatory bodies. - Contact the customers. They'll likely have standing to sue (they were sold a defective product). - Class-action attorneys may be interested for this reason. - Did you know you can pay a very, very modest amount of money to file a press release saying anything you want? - Contact some investors. Short sellers will have a vested interest in making sure the information ge…

I agree that the FDA would be a good place to start. I only know people on the Drug side, so I am not sure who to have you talk to about devices.

I would start with Josh Simms who is in charge of Cardio Devices in the Division of Manufacturing and Quality at 301-796-5540, or maybe someone in the Office of Device Evaluation. Mark Feliman at 301-796-5630 is in charge of Cardiac Electrophysiology Devices, but I think he works more on the approval side.

The appropriate contact info for all of CDRH can be found here: http://www.fda.gov/AboutFDA/CentersOffices/OfficeofMedicalPr...

Post reply on HN