Skip to main content

Hacking your health (week 5)

In early August, researchers demonstrated at the Black Hat USA convention that pacemakers are still very vulnerable. The researchers asked people with medical implants to leave the are for safety reasons and then began their demonstration. Billy Rios and Jonathan Butts showed how malware can be installed remotely on implants such as pacemakers and insulin pumps. They blamed the lack of encryption and the software delivery methods as the main breaches in security. They also demonstrated that they could breach CareLink 2090 programmer, a program used by doctors to control implanted pacemakers. They showed 2 hacks, one that delivered a large shock and another that stopped the pacemaker from shocking, both could be used for deadly reasons. These attacks are due to firmware not being digitally signed and updates that are sent out are not encrypted in any way. When they asked Medtronic, the creator of the devices and program, about the lack of security they stated that the threat is 'low risk' and that its the doctor's job to ensure the patient's safety.(Smith, 2018)

They also showed how they were able to hack Medtronic insulin pumps. Most pumps work from a wireless connection from a remote to the actual pump. Using software-defined radio, they were able to stop a pump from administering a scheduled dose and they were able to have the pump deliver its entire contents.(Smith, 2018)

At the same convention, Doug McKee demonstrated how devices that show a patients vital signs can be hacked and information can be falsified in real time. He discussed flaws in the RWHAT protocol, a networking protocol used in devices that monitor vitals. He then showed how the information can be modified in transit to then show incorrect information. The demonstration consisted of spoofing a heartbeat to show a flat line and showing a highly elevated heart rate. McKee believes that simply encrypting the encrypting network traffic and adding an authentication process would prevent many attacks.(Smith, 2018)

References

Smith, M. (2018, August 12). Hacking pacemakers, insulin pumps, and patients' vital signs in real time. Retrieved from cso: https://www.csoonline.com/article/3296633/security/hacking-pacemakers-insulin-pumps-and-patients-vital-signs-in-real-time.html


Comments