firstfrost: (Default)
[personal profile] firstfrost
A conversation at lunch:

[livejournal.com profile] mjperson: Let me tell you about the stupidest idea I ever heard. I was watching NCIS, and someone died, and they were investgating it, and he died of tachycardia, which was weird because he had a pacemaker for low heart rate. And it turned out that someone hacked into his pacemaker. How stupid an idea is that, pacemakers being just accessible via your wireless and remote hacking? Bah."
Me: "... well, pacemakers probably don't have IP addresses, but you know that the ones controlled by wireless don't really have any security, right?"
Mike: That can't be right. They have to be encrypted, you can't just let people hack in and control your pacemaker.
Me: (google google google) "Well, here's an ABC News article. Okay, look, they say it's not a problem, because the number of attackers in wireless range of you is pretty small. "Within wireless distance of you, the number of attackers is necessarily pretty small," Kaminsky said. "It's not to say the devices can't be attacked. They can be. ... It is something for the implant device [user] to think about it."
Mike: ARGH! What do they mean, it's something for the user to think about? Why is it not something for the implant device *maker* to think about? How could they not worry about that? Just stick in a private key...!
Me: Welcome to the real future. It's not as smart as the science fiction future.

Date: 2012-03-15 06:34 pm (UTC)
desireearmfeldt: (Default)
From: [personal profile] desireearmfeldt
And yet, someone *did* it, which I'd say makes Mike right: this is a problem someone ought to be worrying about... :)

Date: 2012-03-15 06:47 pm (UTC)
From: [identity profile] chenoameg.livejournal.com
Clearly Mike is not reading his tech reviews magazines, or he would already know about this problem (I'm pretty sure that's where I read about it.)

Date: 2012-03-16 12:50 am (UTC)
dcltdw: (Default)
From: [personal profile] dcltdw
+1 on "yeah, I recently read about people researching ways to mess with medical devices". I could dig through my RSS reader if you wanted links, but I'm currently too lazy to do so unless poked. :)

Date: 2012-03-17 02:17 pm (UTC)
From: [identity profile] shaggy-man.livejournal.com
Does all of this say "massive wrongful death suit" to anybody else?

Date: 2012-03-21 12:01 pm (UTC)
From: [identity profile] nakor.livejournal.com
It's not that easy. Public key crypto eats silly amounts of power... So much that if you add it, an attacker can still turn off your pacemaker by spamming requests.

Availability is a major goal of these; even if it's just the comms battery that dies, not the pacemaker itself, it still takes major surgery to replace it.

Profile

firstfrost: (Default)
firstfrost

May 2025

S M T W T F S
    123
45678910
11121314151617
18192021222324
25262728293031

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags
Page generated Jun. 19th, 2025 06:54 am
Powered by Dreamwidth Studios