Can I drop a pacemaker 0day?
blog.erratasec.com
Can I drop a pacemaker 0day?
1–10 of 174 posts
Re: Can I drop a pacemaker 0day?
#2It could potentially also depend on how easily the vulnerability can be patched—one that can be patched remotely can be dealt with much more rapidly than one that will require surgery to replace the device. If one assumes that full disclosure will lead to the fixing of the issue, the first class is probably closer to being judged “responsible” than the second.
It is certainly a difficult dilemma. The correct answer can only be known with the benefit of hindsight…
Re: Can I drop a pacemaker 0day?
#3Send that to the company and the media. You are best off also showing documentation that you told the offending company multiple times.
Show don't tell.
Re: Can I drop a pacemaker 0day?
#4This is a very real threat, most notably Belkin [0] has suffered critical security breaches, and this issue won't be going away any time soon. How can security researchers get CVE's patched, and how can we prevent them from occuring in the first place? This should be priority #1 for any company trying to bring internet-connected appliances to the mainstream.
[0]: http://arstechnica.com/security/2014/02/password-leak-in-wem...
Re: Can I drop a pacemaker 0day?
#51.) Responsible disclosure to vendor. Allow reasonable amount of time for a fix to be created and deployed.
2.) (If fix is deployed, release details)
3.) If no fix is deployed in a reasonable amount of time and the vendor is unresponsive, release a PoC that demonstrates exploitability without giving away details. eg: "Here is a pacemaker. Look, I did magic and it stopped!" This is the same idea as releasing the actual vulnerability/exploit, but doesn't put lives at risk. People that could fuzz for any type of a vulnerability would be able to find it on their own anyway.
I agree that ICS and health-sensitive vulnerability disclosure is a trickier field than most. Medical devices, cars, and power plants are much more sensitive than a random kid's iPhone; that's why groups like I Am The Cavalry are trying to address the issue industry-wide.
However, to answer the original question: don't drop a pacemaker 0day at DEF CON. Find a way to fix the problem with the vendor instead. At the very "worst," demo without vulnerability or exploit details.
Re: Can I drop a pacemaker 0day?
#6The only instances of "hacking" a pacemaker (or ICD) have been when researchers used a programmer from the manufacturer to "hack" the device.
So it seems super unlikely you know a blue tooth zero day for a pacer.
Re: Can I drop a pacemaker 0day?
#7If you truly have a pacemaker 0day, contact me (joelparkerhenderson) on most major service and I will connect you with my healthcare policy lawyer. She can rapidly open the doors to the vendors who have the risk.
Re: Can I drop a pacemaker 0day?
#8Don't even get me started about the Nazi analogy...
Re: Can I drop a pacemaker 0day?
#9Absolutely NOT because this could kill people. If you truly have a pacemaker 0day, contact me (joelparkerhenderson) on most major service and I will connect you with my healthcare policy lawyer. She can rapidly open the doors to the vendors who have the risk.