5 ms·
This sort of 0-day has been known in the academic literature for some time[1]. Disclosure of critical vulnerabilities in implantable devices is far more fraugh
by kmowery 12y ago
This sort of 0-day has been known in the academic literature for some time[1].
Disclosure of critical vulnerabilities in implantable devices is far more fraught than your normal critical software 0-day. These devices require surgery for replacement, and a small number of those surgeries will have possibly fatal complications. The cost of immediately replacing all existing vulnerable devices could literally be measured in lives. (And that's even assuming that the device manufacturer fixed the problem!)
Implantable software is already a very tricky area, and there's no signs that it'll get any easier.
[1] Pacemakers and Implantable Cardiac Defibrillators:
Software Radio Attacks and Zero-Power Defenses, http://www.secure-medicine.org/public/publications/icd-study.pdf http://www.secure-medicine.org/public/publications/icd-study...