FDA Issues Warning about Security Vulnerabilities in Pacemaker Programmers
news.softpedia.com
news.softpedia.com
Medtronic is also the company that made vulnerable insulin pumps that could be wirelessly instructed to stop all insulin delivery, or inject a fatal dose into the user.
Oh, dear. Is this the same kind of decades-old TCP/IP stacks that crash if you ping them the wrong way?
I recently worked on an insulin pump that was both wirelessly controlled and potentially internet connected. Unit tests and communications security seemed to be an more of an afterthought than anything.
The older designs that used magnetic coupling to communicated required holding a bulky device right next to where the pacemaker was implanted may have been annoying to use, but that kind of roadblock is a feature for pacemakers and other devices where changing the battery requires major surgery.
Also, for anybody that missed it: Karen Sandler gave a very good followup talk[2] earlier this year where she discusses her attempts to get the source code for her own pacemaker.
Right, not so unexpectedly, physically limiting access to devices (air gapped) remains the safer practice.
As a side note - there isn't even need for a motive, otherwise vandalism would never happen.