Live data from Hacker News

Can I drop a pacemaker 0day?

blog.erratasec.com

151–160 of 174 posts

Re: Can I drop a pacemaker 0day?

#151

Earlier quoted context omitted.

The oft-recommended prudence of having a lawyer's advice for most any action in the public realm indicates a de facto protection racket. Specifically, the above comment references having a lawyer handle (and moderate) what should be open technical communication with the manufacturer and regulatory agencies, the implication being that simply disclosing facts put you at grave risk from an endlessly complex legal system…

1) You really shouldn't have an open conversation about knowledge that can easily kill people. 2) I'm pretty sure that communication isn't the problem, the problem is that he want's to pressure them into fixing their mess, and that is exactly the point where things get messy from a legal perspective. I can hardly imagine a legal system in which a situation like this would be unproblematic.

>1) You really shouldn't have an open conversation about >knowledge that can easily kill people. I can easily kill someone with a rock. Just hit in the head, repeatedly. Why that should be a secret?

Re: Can I drop a pacemaker 0day?

#153
post #147

Earlier quoted context omitted.

This is a way to kill someone at a distance, with no obvious trace leading to you, and using nothing but an off the shelf laptop or phone. It's significantly more dangerous than any of the other known methods of murder because of the reduced risk to the murderer.

My understanding is that pacemakers, insulin pumps, and such have only limited short-range wireless capability. It's not exactly a 3G connection with a public facing IP address. As long as you still need proximity and individual targeting, I think it's not a paradigm shift in murder.

The short range is to do with the antenna in the device which is (obviously) limited to a certain size.

A larger aerial on the attacking device will allow for communication over a greater range.

The paradigm shift is when you can sit 6 rows back at a baseball stadium and take out someone or walk through their subway car and kill them.

There is no trace evidence and done in a crowd at rush hour essentially no chance of getting caught, heart attacks happen all the damn time.

Re: Can I drop a pacemaker 0day?

#154

Earlier quoted context omitted.

> The only instances of "hacking" a pacemaker [...] // Someone has linked a PDF of an "ICD study" upthread that shows your contention to be at least partially false.

I assume you mean this one: http://www.secure-medicine.org/public/publications/icd-study... You would need to be specific about which one of the linked documents you meant, there were several. All the hacking attempts started off with a manufacturer's programmer and worked back from there. In the example using a software radio, the researchers were able to replay sniffed commands to the device after it had been activ…

Yes. I've not pored over it but they said:

>"We implemented several active [replay] attacks using [only] the USRP and a BasicTX daughterboard to transmit on the 175 kHz band." //

Yes, they used a programmer for reverse engineering purposes but from my - admittedly brief - look at the paper it seemed they performed active attacks (page 8(A) onwards) without using the programmer.

So they previously used a programmer but the attacks were performed without one. Assumed true it seems a reasonable PoC that contradicts the essence of your statement which seemed to say all "hacks" needed a manufacturers programmer to perform.

Re: Can I drop a pacemaker 0day?

#155

Earlier quoted context omitted.

The oft-recommended prudence of having a lawyer's advice for most any action in the public realm indicates a de facto protection racket. Specifically, the above comment references having a lawyer handle (and moderate) what should be open technical communication with the manufacturer and regulatory agencies, the implication being that simply disclosing facts put you at grave risk from an endlessly complex legal system…

1) You really shouldn't have an open conversation about knowledge that can easily kill people. 2) I'm pretty sure that communication isn't the problem, the problem is that he want's to pressure them into fixing their mess, and that is exactly the point where things get messy from a legal perspective. I can hardly imagine a legal system in which a situation like this would be unproblematic.

"an open conversation about knowledge that can easily kill people"

This phrase and the article contain the same fallacy ( ("disclosing 0days when they can kill people"). I may be accused of semantic quibbling here, but I think it is important to state the issues clearly and accurately.

Information cannot kill anyone, nor exert any effects at all, ever. It is not causal. Actions using the information may be enabled by knowledge of the information, but they are human choices and not automatic.

This is not merely a matter of careless expression that does not affect the argument. In fact the fallacy is not only, or not exactly supposing that knowledge is causal, but rather in eliding the whole articulation of what happens between the revealing or acquisition of knowledge and the action that may or may not use it in some way.

The situation has a common element with the gun control issue: if someone has a gun, violence is easier, and this may be considered bad, but it does not excuse conflating the shooter's action with someone else's conduct of merely allowing that person to have a gun. It does not shift any responsibility from a competent adult actor to someone who merely allows a gun to be available.

Note also that the gun-possessor, or the person newly armed with knowledge, need not act on it at all, and those who confuse things by missing these distinctions manage to avoid the fallacy in those cases.

Re: Can I drop a pacemaker 0day?

#156
post #4

This is the most important problem that the internet of things faces. How can we network everything while maintaining at least some scrap of security, especially in the long term? How can we convince people that their toaster is worth patching, and, more importantly, how to we convince vendors that toasters are worth releasing patches for? What if appliance makers go bankrupt and your dishwasher no longer receives pa…

The networking of "things" is not a problem as long as you can opt out of it. Can you stop the toaster of the future from talking to the vendor, the crock pot, Google, the neighbors, your router?

Policy-wise we need a requirement of opt-in: the manufacturer can try to convince you that connecting the device to internet is beneficial for you, but has to let you say no.

And on the technical side, if it needs to be authorized in your router, you already have an opt-in. If it's going to connect by default somehow, maybe by open mesh wireless or somesuch, that's a problem for privacy and security.

Implantables, and particularly life-essential ones like pacemakers, are different. They need remote access to enable updating without surgery, but it must be secured well enough to prevent the sort of vulnerabilty the article describes.

BTW, if you were intent on killing someone, wouldn't it be just as effective to direct a strong RF signal to burn out the electronics, overwhelming any access controls?

Re: Can I drop a pacemaker 0day?

#157
post #92

Earlier quoted context omitted.

Can you elaborate on how lawyers are "member[s] of the protection racket"?

The oft-recommended prudence of having a lawyer's advice for most any action in the public realm indicates a de facto protection racket. Specifically, the above comment references having a lawyer handle (and moderate) what should be open technical communication with the manufacturer and regulatory agencies, the implication being that simply disclosing facts put you at grave risk from an endlessly complex legal system…

This situation isn't the same as a protection racket. In a protection racket, it's the racketeers themselves that hurt you when you don't pay.

In this case, lawyers are more like mercenaries. Yes, you can pay them for protection, as you can a racketeer. The differences are that they don't come to you demanding money, and if you don't pay they won't turn around and hurt you, nor will anybody they're directly working with.

Some other lawyers may cause you grief; however, they will be working on behalf of some other party, not the lawyers you didn't hire.

You could argue that the legal system as a whole is a racket, but that's a different sense of the word.

Re: Can I drop a pacemaker 0day?

#158
post #41

Earlier quoted context omitted.

Terrible advice to pull a media stunt. First, you have no idea what the manufacturer needs to do to fix the problem, alert customers, do recalls and recertifications, and the like. Second, you put yourself directly in the line of fire unnecessarily and for all the wrong reasons. You could find yourself on the end of all kinds of legal trouble, and on top of that you would be morally culpable for any harm. Do it the r…

> get a lawyer Because this is the world we should want to live in? Where you must pay a member of the protection racket to mediate publishing knowledge of someone else's extreme wrongdoing? That is terrible advice. Its road ends with TORified disclosures of weaponized automated exploits, because as pure info sec has shown, that's the only way the message ever gets across when you give people the insulation to not li…

Claiming a medical company's life-saving device will kill your family on national news will almost without a doubt land you on the receiving end of a libel lawsuit, warranted or not. Not having to use lawyers would be nice, but it's not happening in this paradigm. This is a naïve response.

Re: Can I drop a pacemaker 0day?

#159
post #83

How about releasing the vulnerability in stages? The author jumps from unresponsive vendor to releasing exploit code. What if you add steps between the two? For example: - Announcing a vulnerability has been found and identifying the unresponsive vendor. - Announcing what the disclosure timeline will be. - Detailing the product lines known to be affected by the vulnerability. - Publishing communication with the vendo…

This just sounds like responsible disclosure to me. With added steps because the "responsible" part requires you act differently due to the possible risk involved. This is likely the best way to go, and I'd expect to see some legal advice back it up were it to actually happen such an exploit existed.

Re: Can I drop a pacemaker 0day?

#160
post #129

Earlier quoted context omitted.

> 1) You really shouldn't have an open conversation about knowledge that can easily kill people. You mean like guns, toxins, and martial arts?

sigh . This will get boring quite fast because a sizable portion of people participating in threads like that find the idea revolting that actions can have, you know, consequences , but what the heck... If you would find a recipe for a toxin that is deadly, untraceable and can be mixed together from common household items by a talented 14 year old, it's probably a bad fucking idea to post that to 4chan. The same goes…

>If you would find a recipe for a toxin that is deadly, untraceable and can be mixed together from common household items by a talented 14 year old, it's probably a bad fucking idea to post that to 4chan.

Does this count as a straw man argument? Wouldn't the actual scenario would be more like disseminating the information that a deadly toxin that is deadly, untraceable, and can be mixed together from common ingredients exists, not the recipe itself.

Post reply on HN