Two Different Studies Find Thousands of Bugs In Pacemakers, Insulin Pumps and Other Medical Devices
Two studies are warning of thousands of vulnerabilities found in pacemakers, insulin pumps and other medical devices. "One study solely on pacemakers found more than 8,000 known vulnerabilities in code inside the cardiac devices," reports BBC. "The other study of the broader device market found only 17% of manufacturers had taken steps to secure gadgets." From the report: The report on pacemakers looked at a range of implantable devices from four manufacturers as well as the "ecosystem" of other equipment used to monitor and manage them. Researcher Billy Rios and Dr Jonathan Butts from security company Whitescope said their study showed the "serious challenges" pacemaker manufacturers faced in trying to keep devices patched and free from bugs that attackers could exploit. They found that few of the manufacturers encrypted or otherwise protected data on a device or when it was being transferred to monitoring systems. Also, none was protected with the most basic login name and password systems or checked that devices they were connecting to were authentic. Often, wrote Mr Rios, the small size and low computing power of internal devices made it hard to apply security standards that helped keep other devices safe. In a longer paper, the pair said device makers had work to do more to "protect against potential system compromises that may have implications to patient care." The separate study that quizzed manufacturers, hospitals and health organizations about the equipment they used when treating patients found that 80% said devices were hard to secure. Bugs in code, lack of knowledge about how to write secure code and time pressures made many devices vulnerable to attack, suggested the study.
Companies used to building medical hardware have discovered microcontrollers and hired the cheapest programmer or two they could find to program it. Companies not used to software, hiring low skilled programmers, probably giving them unreasonable schedules and requirements. Color me shocked.
Love to hear from one of the programmers who programmed one of these things, hear what they have to say.
going dowwwwnnnnnn!
killing off the less fit?
Honestly, if you have 8000 bugs in your system then you haven't just done a bad job of securing your code, you have done a bad job of architecting your software and hardware. Bottom line, they should fire the people in charge of designing this shit and everyone in management who pushed these devices out before they were ready. Alternatively, start holding individuals inside corporations personally liable for things like criminal negligence and you'll find devices will get properly secured instead of being pushed out the door.
Anons need not reply. Questions end with a question mark.
If the FDA had to approve all these devices, even at the cost of making the price of everything exorbitant, their rigorous testing would ensure that the firmware wouldn't be riddled with all these bugs.
Oh, wait --
Jay Minder knew how to design chip-sets light years ahead of his day and in his spare time he invented pacemaker technology. It worked back then and would still work today.
Please understand that money is the reason that companies make this devices. When security concerns raise their ugly head, they get slapped down. Ego, we have devices that are open for exploitation. Security will also be ignored when $$$ are you objective. If customers stop buying these devices because they are insecure then, and only then will manufactures add the cost of security into the price of these devices.
I hope this caused some synapses to fire.
For a couple seconds I thought of literal bugs, and the title was slightly more nightmare fuel-ish.
No question the CIA knows all about these bugs, this vector is an ideal assassination technique. Just think if they had this tech in the 60's and Fidel had had a pacemaker or other medical device like one of these. The bar for political assassinations for Western nations has risen (a little), but the Russians would be all over this as well.
If you want news from today, you have to come back tomorrow.
Considering how expensive medical devices are right now, I am going to say I prefer the current somewhat buggy software, over the higher cost it would take to fix the bugs.
The cost of the software development is probably negligible compared to the cost of regulations.
Which models and companies are in the 17% that can be secured, or even better, the 9% of device makers that review security annually? And why isn't security being monitored constantly? A lot can happen in a year.
If one were to patch all of these vulnerabilities, it would undermine every effort we have placed into pushing for devices to become part of the Internet of Things.
Leave hole enough alone.
I'm working with some other folks to start a company to develop, manufacture, and market open-source medical devices. We all have extensive experience in developing commercial medical devices - defibrillators, radiation therapy for tumors, etc - and we're convinced that getting more eyeballs to review software and hardware will substantially increase safety and reduce costs.
Yes, we know how to work with the FDA and so forth.
Stay tuned...
Coming from the auto industry, I mean we're cowboys (compare to aviation and defense). But the medical guys. Jesus, they're hatchetjobs.
Linux is the Kernel. The Kernel isn't the issue, it's all the crap written on top of it.
So how is the manufacturer supposed to diagnose devices that malfunctioned out in the field? If you lock the debugging interfaces, they can usually only be reactivated by completely clearing the devices flash memory - or even not at all.
Are third-party libraries used in software development?
What kind of question is that?
Ok, I've seen code without any third party libraries. It was all assembly, only available in hardcopy, written for an 8051 and about 30 years old.
Is the firmware image for the implantable cardiac device mapped into protected memory to prevent arbitrary writing to memory addresses?
I would guess the implantable device doesn't use a microcontroller beefy enough to have an MPU. That would reduce battery lifetime.
Which in turn is probably negligible when compared to the 5,000% markup imposed by the medical device manufacturer...
Any sect, cult, or religion will legislate its creed into law if it acquires the political power to do so.
You say open-source, but will your organisation commit explicitly and non-retractably that ALL the code and hardware (including any ASIC HDL) will be published in a way that any individual can duplicate any design independently without agreeing to any contract, such as NDA?
In which case, how does your business model work?
I can guarantee you there isn't a single pacemaker in the world running Linux. I certainly hope you are not so phenomenally clueless as to not know that, and are simply so stupid you think that was a good troll.
Guns don't kill people; Physics kills people! - John Lithgow as Dick Solomon on Third Rock From The Sun
I hear that Test-Driven Development is better than Death-Driven Development (according to Robert C Martin, but he may be biased... Given that he's a living person, we should check with corporate persons too, so as not to discriminate against any group.)