Slashdot Mirror


US Government Task Force Urges Cash Incentives For Ditching Insecure Medical Devices (securityledger.com)

chicksdaddy shares this report from The Security Ledger: The healthcare sector in the U.S. is in critical condition and in dire need of an overhaul to address widespread and systemic information security weakness that puts patient privacy and even safety at risk, a Congressional Task Force has concluded... On the controversial issue of medical device security, the report suggests that the Federal government and industry might use incentives akin to the "cash for clunkers" car buyback program to encourage healthcare organizations to jettison insecure, legacy medical equipment...

The report released to members of both the U.S. Senate and House of Representatives on Friday concludes that the U.S. healthcare system is plagued by weaknesses, from the leadership and governance of information security within healthcare organizations, to the security of medical devices and medical laboratories to hiring and user awareness. Many of the risks directly affect patient safety, the group found. It comes amid growing threats to healthcare organizations, including a ransomware outbreak that affected scores of hospitals in the United Kingdom.

Joshua Corman, the Director of the Cyber Statecraft Initiative at The Atlantic Council, argues that currently "Healthcare is target rich and resource poor," adding a special warning about the heavy usage of internet-connected healthcare equipment. "If you can't afford to protect it, you can't afford to connect it."

64 comments

  1. Re:This just in by Anonymous Coward · · Score: 0

    That isn't fair. What he SAID was "If she wasn't my daughter I'd grab her by the pussy with my little tiny hands". BIGLY difference.

  2. fines? by Anonymous Coward · · Score: 1

    How about we start fining these irresponsible companies when they negligently use known insecure devices and have security breaches?

    1. Re:fines? by fluffernutter · · Score: 1

      I'd say, "you can't do that to a medical institution!", but then I remember that they are there for profit like everyone else and I'm totally fine with it.

      --
      Laws are rules for the court, but merely a bottom bar to hit for life. Think beyond laws in your actions always.
  3. If you need a medical device to live by Anonymous Coward · · Score: 0

    And then you die, you've saved more money and carbon emissions for the world. My recommendation is to be healthy

    1. Re: If you need a medical device to live by Anonymous Coward · · Score: 0

      Where is Jessica Hyde?

  4. Re: This just in by Anonymous Coward · · Score: 0

    Still butt-hurt, eh? Better luck in 8 years!

  5. Re: I have an IoT medical device by Anonymous Coward · · Score: 0

    I'm not gay

  6. Of course, the lengthy and expensive cert process by Salgak1 · · Score: 4, Informative

    .. . . makes even PATCHING existing gear for security holes an extended and tedious process.

    Consider, my eldest daughter was working as a ward admin, IT relied on her for backup, because for an entire 445 bed hospital. . . was two junior techs. The password on everything EXCEPT the email and timecard system. . .was "password".

    And, of course, that didn't even include the systems you could physically exploit. . . like a "Pyxis" supply dispenser. The tool needed to "hack" it. . . is a flat-head screwdriver. . .

  7. Resource poor? BS by whoever57 · · Score: 1

    Resource poor? When I have to pay over $300 for a simple doctor appointment, or over $600 for an appointment with a specialist?

    No, there are plenty of resources. It's the priorities that are the problem.

    --
    The real "Libtards" are the Libertarians!
    1. Re:Resource poor? BS by sabbede · · Score: 1

      All those resources are dedicated to filing paperwork or paying for the shiny, new, hi-tech, connected medical equipment that now has to be updated or replaced at no small cost. To patients.

  8. Re: Of course, the lengthy and expensive cert proc by Anonymous Coward · · Score: 0

    Is your eldest daughter hot?

  9. Re: I have an IoT medical device by Anonymous Coward · · Score: 0

    Why don't you give it a try for a while? You can always switch back if you decide you don't like it. C'mon, haven't you ever wondered what it would be like to have a cock buried in your ass? Not even a little? I know a lot of guys like you who weren't gay before, but boy o boy they sure are fabulous now!

  10. Re:I have an IoT medical device by Anonymous Coward · · Score: 0

    It's a special vibrating buttplug to stimulate my sphynxster. It uses a location aware app that stimulates my anus whenever certain criteria are met - like when I'm in a gayborhood or near a gay bar. Because it was prescribed by a doctor to relieve my "Dry Rectum" (DR for short) condition, Medicare paid for it. Thanks Obama!

    +1 Informative

  11. We could just hire more people by rsilvergun · · Score: 1

    I hear there's a shortage of good jobs. But then we'd have to train them. And feed and house and cloth them while they train (don't kid yourself, you can't do intensive training like that while working full time to support yourself, that's why college drop out rates are so high, higher if you consider the ones that didn't get in in the first place).

    Once again, this is a problem that could be solved but we'll be damned if we're gonna do it because nobody wants to pay for it. He'll, when you suggest they do they call you a thief for raising their taxes.

    --
    Hi! I make Firefox Plug-ins. Check 'em out @ https://addons.mozilla.org/en-US/firefox/addon/youtube-mp3-podcaster/
    1. Re:We could just hire more people by Anonymous Coward · · Score: 0

      Capitalism!

      What is the maximally efficient cost-effective solution to job X?

      Don't do it at all.

      This is the result of an economy that focuses only on cost vs. profit.

    2. Re:We could just hire more people by PixelPusher1532 · · Score: 2

      don't kid yourself, you can't do intensive training like that while working full time to support yourself

      Good thing I did not read your post before I did exactly that.

  12. Re: I have an IoT medical device by Anonymous Coward · · Score: 0

    no dilz in my ass!

  13. How it ought to go, but won't by Anonymous Coward · · Score: 0

    "How much cash do you give us if we upgrade our machines to secure ones?"

    "Absolutely none at all."

    "How's that a cash incentive then?"

    "You get to keep the large amounts of money you're otherwise going to be fined for keeping your customers details on shitty, insecure systems."

  14. You can thank our healthcare system for that by rsilvergun · · Score: 1

    most of the money goes to the top. Not your Doctors or the infrastructure to support them. Then there's the little matter of 'deductibles', meaning you pay for 'insurance' then you pay for care until you hit your deductible then you pay 80/20 if you're lucky and 60/40 if you're not.

    This is what happens when you let middle men run your healthcare system.

    --
    Hi! I make Firefox Plug-ins. Check 'em out @ https://addons.mozilla.org/en-US/firefox/addon/youtube-mp3-podcaster/
    1. Re:You can thank our healthcare system for that by whoever57 · · Score: 1

      most of the money goes to the top. Not your Doctors or the infrastructure to support them.

      Isn't that what I said? "priorities".

      --
      The real "Libtards" are the Libertarians!
  15. just reduce regulations blocking updates by Anonymous Coward · · Score: 0

    There's no need to provide cash incentives, all that's needed is to reduce the barriers that over-regulation causes (like the need to completely recertify the entire device to apply a patch)

    Once you lower the barriers, then other pressures (audits, etc) can take effect and push for the devices to be updated.

    Right now, there is no ability to patch the devices because the vendors don't release patches, because the cost to certify a patch is so high.

    The FDA needs to be able to separate out the medical functionality of a device from the software, and setup tests that test the software for changes in the desired functionality (while letting bugfixes, UI fixes, even OS updates and changes go through easily)

    1. Re: just reduce regulations blocking updates by Anonymous Coward · · Score: 0

      Lots of claims that tjis is happening but still no one can produce proofs that patches to the os means you loose the certification.

      It also begs the question of why tjese vendors use general purpose operating systems for their specilalized machines if this where the case.

  16. Poor healthcare companies by mspohr · · Score: 2

    US healthcare is more expensive than anywhere in the world. Profits of healthcare companies are higher in the US than anywhere. There are no limits to what they charge.
    Now they are saying they can't afford to fix the crap they've been foisting on the public?
    Crocodile tears...

    --
    I don't read your sig. Why are you reading mine?
    1. Re:Poor healthcare companies by Anonymous Coward · · Score: 0

      Now they are saying they can't afford to fix the crap they've been foisting on the public? Crocodile tears

      Fine, but you're the one who's privacy and security suffers while they keep raking in the profits. How's that working for you?

    2. Re:Poor healthcare companies by Anonymous Coward · · Score: 0

      The only way this plan would actually work is if they deny sales to the military unless they comply.

  17. Re:Of course, the lengthy and expensive cert proce by Anonymous Coward · · Score: 0

    The thing is, medical devices have by far the biggest bang-per-buck as far as per-device profit in the medical field. So as much as my gut reaction to the "cert process ... an extended and tedious process" is to suggest reduced regulation, I think the more obvious truth is that instead of "cash for clunkers" we should have "recalls for clunkers" because the whole point of the "extended and tedious process" is that device makers don't want to have to go through the costly process again.

    The alternative is the mess we see with Windows PCs, where we've just come to accept the whole notion of patching monthly, running [often ineffective] antivirus software, and accepting we're going to get hacked eventually. It's precisely the argument that it'd be astronomically expensive to make things right the first time is why we accept it: the risk vs cost isn't worth it. When it comes to a PC, a person's life isn't on the line.

    Plan B? Since clearly all tort suits, which is going to happen when people DO die--and it's going to happen--from these insecure device, do to businesses is make them roll the problem into the cost of doing business--and as I discussed above, medical device makers are prepared for it--, start holding CEOs, engineers, etc criminal liable for negligent homicide. As much as people bitch about the whole GM ignition switch scandal, it's actually a relatively minor thing* precisely because the Transportation Safety Admin has gotten the industry to accept the notion of "voluntary" recalls to avoid direct government regulation which would be much, much worse all around.

    PS - Cash for clunkers is a horrible comparison. ICEs suck for the environment. The "solution" was to simply "trade" worse ICEs for slightly better ICEs. But insecure IoT or otherwise insecure medical devices is because of shitty design, coding, etc. It's not an inherent part of what a medical device is. ICEs can't be "fixed". Medical devices can be. But what's the promise that they will be? In the end, it's more "cash for clunkers for another [possible] clunker because we can't trust medical device makers". That's no solution. Hell, the new device might be even worse. At least "cash for clunkers" actually improved things because of CAFE standards--ignore the whole VW mess which is worth a whole other post.

    * Put in perspective, 10-15% of traffic accidents are due to mechanical failure. That we find a specific cause in one instance that could have been corrected is both good (we can fix it) and bad (it should have been noticed and fixed sooner, probably). But, it's near the level of noise given all the other things that can happen in a car. "Potential failure" is the core of what ICE is all about--more of an internal explosion engine. Another example of people who lack perspective are those that take the Bin Ladin Determined to Strike in US briefing.as some idea 9/11 should have been stopped. The best answer is probably to just be more diligent next time and get industry to be involved.

  18. Buyback? by bestweasel · · Score: 1

    Why should these highly profitable corporations receive public money to do the right thing to protect themselves and the patients? If they won't do it voluntarily, the law should make them.

    1. Re:Buyback? by Anonymous Coward · · Score: 1

      Yes, the incentive should be to not punish them for failures to adhere to the HIPPA law, not to give them cash for the bad decisions they've made without regard to privacy!

    2. Re:Buyback? by dargaud · · Score: 2

      And in addition, nothing so far shows that the new devices are anymore secure than the old ones: they still run on Windows, versions of which don't receive any updates for various reasons, passwords are kept the same forever and everywhere, all ports are open so that various equipment can communicate 'easily', etc...

      --
      Non-Linux Penguins ?
  19. Re: Of course, the lengthy and expensive cert proc by Anonymous Coward · · Score: 0

    wow u typed a lot of words har nobody will read but congrats on getting a +5 from mods that don't want to read your bullshit

  20. Wrong reward by Anonymous Coward · · Score: 0

    This isn't rewarding citizens for doing the right thing, it's avoiding the punishing of manufacturers that ignored good security practices and US HIPPA laws. Medical devices aren't shoved onto the market as soon as possible, they're manufactured to a strict standard: There's no excuse for leaving the job half-done. Maybe the government should be punishing itself for not updating and enforcing that strict standard.

  21. More Information, Please by bill_mcgonigle · · Score: 1

    Where can I find out which of the local hospitals and surgical suites uses up-to-date secure stuff and which ones don't give a damn?

    Because I will vote with my wallet.

    --
    My God, it's Full of Source!
    OUTSIDE_IP=$(dig +short my.ip @outsideip.net)
  22. Re:Of course, the lengthy and expensive cert proce by bill_mcgonigle · · Score: 1

    That's surprising - Pyxis machines are frequently used to dispense Schedule II drugs.

    Maybe they changed out the stock screws ... one can hope.

    --
    My God, it's Full of Source!
    OUTSIDE_IP=$(dig +short my.ip @outsideip.net)
  23. This idea brought to you by Draining The Swamp(TM) by Anonymous Coward · · Score: 0

    "Here's a good one: let's pick out those contractors who've made absolutely no effort to keep their IT up to date, and reward them with taxpayers' money!"

    Another great idea from our friends in Congress. Keep it up, guys.

  24. Re: This just in by fluffernutter · · Score: 0

    As opposed to you, whose butt doesn't hurt and wants it again, and again, and again because Donnie uses the good lube paid for by the Amarican public on you. Yeah I'll pick butt-hurt.

    --
    Laws are rules for the court, but merely a bottom bar to hit for life. Think beyond laws in your actions always.
  25. Re: This just in by Anonymous Coward · · Score: 0

    What is the female version of a cuckold? I need to know because calling her Hillary has gotten old.

  26. Re: I have an IoT medical device by KGIII · · Score: 1

    Well, not with that attitude, you won't!

    --
    "So long and thanks for all the fish."
  27. More bailouts?? WTF! by Anonymous Coward · · Score: 0

    The manufacturers of the insecure medical devices should be held civilly and criminally liable!!

    1. Re:More bailouts?? WTF! by rholtzjr · · Score: 1

      Currently they are in the event that the device causes the harm and the flaw was proven to cause said harm. If it is "user" error, then it is not the responsibility of the maker, but the hospital. Most medical devices I was involved with creating utilized standard security practices and if setup properly they would be a reliable secure device, but only as secure as the network in which it is placed.

  28. Re:Of course, the lengthy and expensive cert proce by Anonymous Coward · · Score: 0

    And, of course, that didn't even include the systems you could physically exploit. . . like a "Pyxis" supply dispenser. The tool needed to "hack" it. . . is a flat-head screwdriver. . .

    I work in embedded systems security, and we generally don't worry too much about things like the "screwdriver" example (as a matter of public policy, if I were doing security architecture, I would certainly worry about that). We have laws to take care of that. You can also walk into a hospital and poison someone, and there's no computer security mechanism against that. Sure, it'd be great if everything was secure, but hacks that require physical access, are limited to physical access in the damage caused and leave a trace behind are really not worth spending much effort on.

  29. Re:Of course, the lengthy and expensive cert proce by rholtzjr · · Score: 1

    As a developer in the medical device area, the biggest obstacle of creating the devices was the FDA. So the regulations that were attached were daunting. Not only was their an audit annually with respect to every device we created, we had to have detailed design, creation, maintenance and release of each object. This produced quite a bit of paperwork. At the time, the FDA would not accept electronic documents that could have (at the time) be put on a CD for every device. Every change or enhancements also had to be tracked in this manner as well. So less regulations could probably help, but we are talking medical devices.

    We also designed into said devices security as well, so as long as they had a competent admin person the devices could be secured. As a matter of fact, it was actually quite difficult to get the admins from different hospitals to setup secure networks in the event they needed to share patient information between hospitals. I ran into a couple that would only allow a temporary connection and only open it on request for a set time period. But I could see the complaint of not having a competent system administrator is their real problem.

  30. Re: Of course, the lengthy and expensive cert pro by orlanz · · Score: 1

    I read it all. GP has good points. GASP.. are you wrong on the internet? Go go, log off right now, go hide.

  31. Re: This just in by Anonymous Coward · · Score: 0

    Well, his user name (fluffernutter) does sound like he is in the porn industry.

  32. Politics..Again by oakgrove · · Score: 1

    I like this site and I really liked it when the byline used to be "News for nerds Stuff that matter". Is there an extension or bookmarklet or something that I can use to filter out stories based on keywords? Keywords like Comey, Trump, Government, Clinton, Democrat, Republican, Brexit, and on and on? I sure would like that. I really would.

    --
    The soylentnews experiment has been a dismal failure.
  33. HORRIBLE IDEA by Anonymous Coward · · Score: 0

    Paying people to do what they should do is plain wrong. This is nothing more than aid to big corporations. Passing money from tax payers to CEOs and other officers of large corporations that give big $$$ in pay and bonuses. They CAN afford to fix their mess and they should be forced to do so.

    Don't believe that none of that is true because that's exactly how big business works with the government. CORRRRRUPTION!

  34. Need a similar buy back ... by CaptainDork · · Score: 1

    ... program for the NSA.

    --
    It little behooves the best of us to comment on the rest of us.
  35. Re:Of course, the lengthy and expensive cert proce by drinkypoo · · Score: 1

    Maybe they changed out the stock screws ... one can hope.

    You probably have to go to Harbor Freight and buy a $3.99 security bit set, now.

    --
    "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
  36. Re:Of course, the lengthy and expensive cert proce by radarskiy · · Score: 1

    What does the certification process for equipment have to due to size of the IT staff?

  37. Dare they be patients in their own hospitals? by tychoS · · Score: 2

    I once spoke to (tried to pull) a smart, bright, knowledgeable, beautiful female programmer, who worked in the software development department of a very large well known manufacturer of hospital equipment. The sort of equipment you hook up to patients and use to monitor their well-being, or interconnect to their bodies in various ways.

    She told me she had been admitted to hospital once and been hooked up to such a machine. She had felt very relieved when she saw it was made by a competing manufacturer and not her own employer, as she knew full well how crappy the software in the machines made by her employer was made.

    She relaxed in the hospital bed, hoping thee competitors had better software that her own employer.

    1. Re:Dare they be patients in their own hospitals? by dargaud · · Score: 1

      She relaxed in the hospital bed, hoping thee competitors had better software that her own employer.

      ...but they didn't and when the insulin pump started running a DDOS botnet, a bitcoin fab, a spam spewer and a ransomware distributor, it unfortunately also started dispensing too much insulin. Hence she's been in a coma ever since. And the popup asking for an update to the WinXP antivirus is routinely ignored as medical staff press on Cancel at every reboot. Which happens multiples times per day.

      --
      Non-Linux Penguins ?
  38. Re:Of course, the lengthy and expensive cert proce by Anonymous Coward · · Score: 0

    As a developer in the medical device area, the biggest obstacle of creating the devices was the FDA.

    So, your medical device was a trivial fob? Or are you undermining the notion of how difficult it is to create a well-designed device?

    So the regulations that were attached were daunting. Not only was their an audit annually with respect to every device we created, we had to have detailed design, creation, maintenance and release of each object.

    For "each object" do mean "each model" or "each produced unit"? Even if it's the latter, well, it makes the change/enhancement part later rather moot. In any case, it's just duplicate paperwork.

    This produced quite a bit of paperwork. At the time, the FDA would not accept electronic documents that could have (at the time) be put on a CD for every device.

    And? I mean, I can see wanting it all on a CD and complaint about all the printing, but and?

    Every change or enhancements also had to be tracked in this manner as well. So less regulations could probably help, but we are talking medical devices.

    Seriously, what's so onerous about any of this? You should already be tracking this stuff. It's actually better for your development to be tracking this stuff. The only bad part is the literal paperwork but it sounds like they've got electronic so that part should be trivial as well.

    We also designed into said devices security as well, so as long as they had a competent admin person the devices could be secured.

    And this I really doubt. If you think following FDA rules was "the biggest obstacle", it's hard to believe your medical device was competently designed unless it was a very simple fob. But, since you mention "networks", I know it's not.

    As a matter of fact, it was actually quite difficult to get the admins from different hospitals to setup secure networks in the event they needed to share patient information between hospitals. I ran into a couple that would only allow a temporary connection and only open it on request for a set time period. But I could see the complaint of not having a competent system administrator is their real problem.

    No, that's a separate complaint. The concern is that medical devices that shouldn't crash, require physical access, etc often fail at all these things and more. That the FDA requires you to document everything doesn't mean much because the FDA isn't out to painstakingly figure out all possible failure modes. That's your job.

    I don't want to sound overly harsh, but I really wonder if you understand the issue at hand. I mean, as a developer in the medical device area, I would hope you would. But it really sounds to me that you don't. You think it's enough to presume that there aren't hostile actors and that your security is top notch. I hope I'm wrong.

  39. I complained back then by Anonymous Coward · · Score: 0

    slashdot doesn't talk about Linux distros, or microprocessors anymore, and politics was nonexistent. I miss that slashdot.

    1. Re: I complained back then by Anonymous Coward · · Score: 0

      We need a Debian LTS flavor for medical devices.

  40. none of this stuff has to connect to the internet by Anonymous Coward · · Score: 0

    I don't see why medical devices have to connect to a giant network. It should just be connected to a LAN for the building. If you want to sabotage, just come in with a knife, or gun. No computer skills needed.

    Therefore, to keep medical device costs down, use code that is mediocre in the right way.

  41. Re: Of course, the lengthy and expensive cert proc by Anonymous Coward · · Score: 0

    You miss how painstakingly anal the FDA is about things like software. You are correct, they don't "know" what they're approving do the just heap paperwork on the problem. You either stick to an approved "canned" system (that probably won't get upgraded) or implement your own stuff like security. But if you need to do things like security patches you can get the WHOLE DEVICE reviewed just to change the login protocol. Devices take five-ten years to design and bosses don't want to keep paying for intensive reviews because something like OpenSSL changes monthly.

  42. Here's a cash incentive by Khyber · · Score: 1

    Ditch your insecure shit or face HIPPA fines and fees.

    --
    Still waiting on Serviscope_minor to wake up to fucking reality and realize that Jessica Price isn't going to fuck him.
  43. Medical Costs by unixcorn · · Score: 1

    With the money I (my insurance company) am paying to hospitals and doctors, I can see no reason for the Federal Government to subsidize ANYTHING medical related. However, with the difficulty of certification, red tape and long durations of testing new or upgraded devices, I can understand why hospitals and doctors are resistant to replacing equipment that seems to work perfectly. Once again the Feds create a problem and then go back to taxpayers for more money to fix it.

  44. Re:Of course, the lengthy and expensive cert proce by jpschaaf · · Score: 1

    As far as I'm concerned, the commenter whose posting was broken apart line-by-line knows exactly what he/she is talking about, and their engineering judgment should not be questioned.

    In the medical device arena, an obvious two line of code change can easily take 3-4 days to complete the necessary reviews and documentation updates; the testing can take a week or two. Now imagine that a patch was made in the networking subsystem of a real-time operating system to deal with a security hole. Completing the relevant documentation/testing turns into a three to six month process. By the time the patch has gone through the necessary regulatory rigmarole, it's arriving so late in the field that any malware that targets the exploit will have long-ago infected the device. Medical device manufacturers are still scrambling to complete the paperwork/testing required to authorize patching their devices for eternalblue/Wannacry, in spite of the fact that it's truly a top priority for both hospitals and the manufacturers.

    Without a question of a doubt, generating paperwork that will withstand FDA audit is at least as big of a challenge as engineering the device itself.

  45. Re:Of course, the lengthy and expensive cert proce by Salgak1 · · Score: 1

    . . . which would be a configuration change, and require yet ANOTHER audit and paper trail. . . Not that it would fix the actual problem, which is a latch that is easily and tracelessly jimmied with a simple screwdriver. . .

  46. Re: Of course, the lengthy and expensive cert proc by Anonymous Coward · · Score: 0

    In which case you have an easy answer. Make the security update, take out an ad in the paper claiming the FDA has demanded $1,xxx,xxx dollars to approve the security update. Watch the problem get fixed.

  47. Re:Of course, the lengthy and expensive cert proce by Anonymous Coward · · Score: 0

    As far as I'm concerned, the commenter whose posting was broken apart line-by-line knows exactly what he/she is talking about, and their engineering judgment should not be questioned. ... Now imagine that a patch was made in the networking subsystem of a real-time operating system to deal with a security hole.

    This is precisely my point. You can't say I shouldn't question their judgment then imply they have security holes in their code. How about designing the device right first, then submitting the finished device to the FDA?

    Medical device manufacturers are still scrambling to complete the paperwork/testing required to authorize patching their devices for eternalblue/Wannacry, in spite of the fact that it's truly a top priority for both hospitals and the manufacturers.

    That's why the went with Windows. Where security (and by extension, patient lives) is #1!

    Without a question of a doubt, generating paperwork that will withstand FDA audit is at least as big of a challenge as engineering the device itself.

    Given the quality of the engineering presented, I agree. But as another poster had suggested, if the issue really is that making trivial changes is such a burden or that you can't group changes and engage in a thorough testing at set times to deal with the documentation and regulation in a predictable fashion, present actual examples to the American people and to Congress. My personal guess is, it's not nearly as bad as you think and a lot less critical engineering is put to similar standards which are considered reasonable.

    Feel free to prove me wrong with examples. A big hint that eternalblue doesn't count precisely because it's a shitty engineering practice to rely upon a consumer OS as a core of a medical device.