Jump to content
The Inquirer-Home

Killer hackers could target cardiac implants

Emtech Researcher calls for tighter security
Wednesday, 30 September 2009, 13:59

A US RESEARCHER is calling for legislation to enforce tighter security on implanted cardiac devices after he hacked one wirelessly to produce a potentially fatal electric shock.

The scenario may sound like something out of a detective novel or far-fetched thriller movie script but the danger is real and should be taken seriously, says Kevin Fu, an assistant professor of computer science at the University of Massachusetts, who specialises in the security of RFID systems.

Judges at the EmTech conference in Boston took his work seriously enough to give him an Innovator of the Year award.

Doctors can access modern pacemakers and defibrillators over the Internet via a short-range wireless link similar to those used in RFID devices. The system allows them to monitor patients remotely and install software updates.

This means a hacker could access confidential medical information as well as reprogram the devices, Fu says.

He wrote in a recent paper: "Manufacturers point out that IMDs (implanted medical devices) have used radio communication for decades, and that they are not aware of any unreported security problems. Spam and viruses were also not prevalent on the Internet during its many-decade childhood. Firewalls, encryption, and proprietary techniques did not stop the eventual onslaught."

Fu and his team used off-the-shelf components to build a device that could write to a defibrillator and read the signals being sent to it. They deciphered the signals by exploiting the fact that they knew the patient's name.

They could then reprogram the device to give an electric shock. Another possibility is that a hacker could disable the power-saving mode so that the device's battery ran down in days rather than years.

The hacking device could be built into something the size of a cellphone and infect IMDs with malware randomly as the killer walked down the street. Millions of people use pacemaker-defibrillator devices.

Fu points out that such random attacks are not unknown. Vandals can cause people to have seizures by implanting flashing lights on a website used by epileptics; and seven people died when a killer put cyanide-laced painkillers on supermarket shelves in Chicago.

Nevertheless some doctors resisted when Fu first started making inquiries about IMD security. Has he any idea of how many of the devices in use are vulnerable? "That's the point," he said. "We just don't know." µ

 

Share this:

Comments
Umm

"Doctors can access modern pacemakers and defibrillators over the Internet via a short-range wireless link similar to those used in RFID devices."

A short-range wireless link is not the same thing as "over the Internet".

Yes, this is a very real concern and is good that is being brought to light, but it's not as if some script kiddie or Chinese hacker is going to be able to remotely hack it "over the Internet".

posted by : R.E.H, 30 September 2009 Complain about this comment
re: short range

the pacemaker connects via shortrange wireless link to a dock which then connects over the internet to uplaod/download data. knowing the persons name to decrypt the data is pretty cool. Lets say you know a name like Dick Cheney and you happen to know where he lives and you happen to have the patience to wait for him to uplink his pacemaker to send data to his doctor and lets just say you have a personal vendetta. lot of variables there but the name is popular so that increases the odds a bit. egads, the secret service are nocking on the door. help me, they is gonna guantamole me.

posted by : mogwai, 30 September 2009 Complain about this comment
Poor Dick Chenney

Lying low.

posted by : Ling, 30 September 2009 Complain about this comment
Talkin' bout Goob Looks Lot Like YOU....

Until Sheesih Fell from CRAY Dell, Sundays On Phone to Meee.

Should Have QUIT You, Yaaa Long time Ago, I'd Be with My Children On This Skinney Floor.

Should Have Listened. Every time go away, Gives me Blues Straight downdro Lot.

Heres bit from AMD next to Nvidias Conf:
There are three chipsets available, the SR5650, SR5670 and SR5690, all variants of the RS890 chipset, known on desktops as the 785G. While the name is halfway between the 780 and 790 chipsets, this one is based off the next generation 8xx silicon, not the 18-month old 7xx versions. The main difference between the three new SKUs is the PCIe2.0 lanes, with 22 on the -50, 30 on the -70, and 42 on the -90.
My,My,My take it down bit. Keep Worry Baby.
Take'd My Money & Gave It to Another MAP.

DRASHEK Running Implants On Rock 'n Roll.
Purple Haze. Are In My Braid. 'Cuse Me While KISS 'd Scar. Never HAppen or IT Must be. HapMe, Hapme.Don't Know if Its Day or Night. Is IT tomorrow OR JUST END OF TIME. Purple HAZE Is In My Eye.

posted by : Dock Ter...., 30 September 2009 Complain about this comment
My Implants

Man with breast implants very sexy, that would be me. When I smoke my weed things get really fun, all by myself.

HVDD

posted by : hekvondreshdork, 01 October 2009 Complain about this comment
Instant Pre-Crime Execution!

In our fair city, RFID's are a requirement by law for pets [Cats/Dogs].

What would stop a world government, extending this law to humans and applying this application found by this hacker towards crime prevention?

And, a world government bent on controlling populations by electro-attrition?

As Einstein which he would have not said anything, think about it you would be hackers out there.

posted by : Phil, 01 October 2009 Complain about this comment
Chicago cyanide poisonings were in 1982

... and seven people died in 1982 when a killer put cyanide-laced painkillers on supermarket shelves in Chicago.

Omitting the year leaves the reader wondering if the event happened last week.

posted by : responsible-journalism, 01 October 2009 Complain about this comment
TARGETING CARDIAC IMPLANTS?

I am not sure how worthy this item is... whether it is true or not. I do know that if it is true, we who have pacemakers (especially the ones with built-in defibrillators) need to ask our physicians about this. If this article has merit, then we who have these devices implanted in our chests, with the expectation that they function to save our lives, then we definitely need to follow up this story and find out what truth or fiction is involved. Not only Cheney has a cardiac implant! Please don't stab at him because when you do that, you are stabbing at thousands of people, from age 2 weeks of age to those 80+ years old, who are dependent on these devices to keep their hearts pacing at a proper rate, thus keeping them alive. I will be contacting my doctor and will suggest that others do the same. I am not familiar with this particular site, but hopefully I will root out if the info on here is fact or fiction or something in between. Have a blessed day!

posted by : RGValleyGal, 02 October 2009 Complain about this comment
Advertisement
Subscribe to the INQ Newsletter
Sign-up for the INQBot weekly newsletter
Click here to sign up Existing user
Advertisement
INQ Poll

Christmas computer sales

Will you be buying a new computer this Christmas?