Insulin pump hack delivers fatal dosage over the air
theregister.co.uk
theregister.co.uk
I don't fully understand the problem. Are these things always open to wireless communication? My friend's syncs with USB.
The simplest solution that doesn't make ridiculous assumptions about the time and place is to just do HMAC + replay prevention, as has already been mentioned.
Don't do infosec half-assed, they'll just get in through the other cheek.
It's just capitalism at work, people. Even if someone does use this to kill off a handful of people, the cheaper devices might just have saved 100x more before secure models start appearing. Is it a fair trade-off? People haven't been demanding their insulin pumps be secure, so apparently they think it is (edit: yes yes, ignorance - they don't have to be, ya know. I'd get to know the thing keeping me alive, personally).
I doubt the lack of security provisions is due to the $ matters. It is far more likely to be just the developers' ignorance on the subject... which is entirely unsurprising, totally agree here.
The sectors that need to understand information security the most are the ones that have absolutely no grasp of it.
I see no sign of that changing. Every time an improvement is made to the security of one system, somebody pops up with a new one that has utterly failed to learn the lessons of the last one.
Obviously, there'll be a dose that will be deadly in all cases - the LD100. But the statistical "half the people given this dose" LD50 measure could easily vary by ± 100% or more. Things like metabolic rate, body-weight, route of administration, insulin tolerance, and relative blood-sugar levels could all factor into the dosing system, and I'm guessing the whole point of having it remotely configurable is to minimise the processing effort on the embedded chunk.
This is a new, MUCH worse attack from a different researcher -- one with significant existing credibility, I might add.