News: 1705051806

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Your pacemaker should be running open source software

(2024/01/12)


Opinion Software Freedom Conservancy's (SFC) Executive Director Karen Sandler was last year awarded an honorary doctorate by Belgium's Katholieke Universiteit Leuven for her work for open source and software freedom.

There was only one problem. Her heart was beating strangely, and she [1]couldn't get the data out of her implanted pacemaker/defibrillator proprietary software to find out what was going on.

She was forced to make a life-or-death decision that would have been much easier were it not for proprietary software being the only option for heart devices. Sandler ended up going, and all went well. It easily could have gone terribly wrong.

[2]

You see, Sandler has a heart condition, [3]Hypertrophic Cardiomyopathy (HCM). It's a condition that generally has no discernible symptoms unless it kills you. A serious thing.

[4]

[5]

This time, however, she had a symptom, an irregular heartbeat, that was getting worse. Clearly, the first thing to do was pull the data from the device so that her cardiologist would have more data for the treatment.

One of the reasons why people get these devices is so they and their doctor can track their condition. So it was easy right? Wrong.

[6]

Remember, this runs proprietary software. It turned out that no one but a company representative could pull data from it. And, no one - and I mean no one - was available who could get the information.

This is not a rare problem. Sandler, aka the cyborg lawyer, has been following the use of proprietary software in medical devices for years. It's an ugly picture.

All Implantable Medical Devices (IMDs)- and I mean all - run proprietary software. Why is this a problem? Can't you trust them?

[7]

As Sandler has told me, "All software has bugs, and all software is vulnerable." On average, according to the Software Engineering Institute, there is one bug for every 100 lines of software and that pacemaker in your chest? It has about [8]70,000 lines of code .

"Free and open software tends to be better and safer over time," observed Sandler. Proprietary software is a black box. Unless you're the manufacturer, you have no idea what's actually in the code, or, as Sandler found out in this latest episode, how to get data out of the device if you're not a company representative.

Don't think, by the way, that this is some kind of theoretical problem. It's not. In 2017, MedSec, a medical technology security company, found that [9]Abbott Laboratories' St Jude Medical defibrillators could be remotely attacked by hackers. As a result, the US Food and Drug Administration (FDA), issued a [10]recall of of 465,000 of these devices .

At about the same time, Johnson & Johnson admitted one of its [11]insulin pumps had a security vulnerability , which could be exploited to overdose diabetics with insulin.

On top of that, the [12]FBI warns that unpatched medical devices run on outdated software with known security problems and that the devices often lack adequate security features. In addition, the manufacturer's default configurations are often easily exploitable, and the devices themselves aren't designed with security in mind. Their makers assume, foolishly, that medical devices aren't exposed to security threats.

On TV shows, people have been killed by someone hacking their IMDs. That's not far-fetched. Indeed, it may have already happened. How would we ever know? A proof of concept for [13]hacking a medcial devices was shown off at RSA previously .

It's not just people, like Sandler, that are open source and security savvy, who worry about these issues. Former US VP Dick Cheney had his defibrillator's wireless feature disabled to prevent hacking attempts in 2017.

How would an attacker know that you have an IMD? Well, it turns out that besides being proprietary, they're chatty devices. They're often broadcasting remotely without any real security.

That's a real problem. It's bad enough that [14]wireless key fobs can be hacked so someone can start your car, I don't need anyone revving up my pacemaker, thank you very much.

[15]I'm diabetic. I'd rather risk my shared health data being stolen than a double amputation

[16]New York City latest to sue Hyundai and Kia claiming their cars are too easy to steal

[17]If we have self-healing bio robots in 2053, it started here with mouse muscle cyborgs

[18]Tesla owner gets key fob chip implanted in his hand

So, before you volunteer to have Elon Musk's brain-computer [19]Neuralink interface implanted in your head, you may want to think long and hard about your decision. Besides the Physicians Committee of Responsible Medicine (PCRM)'s warning of the company's invasiveness and rushed actions in animal testing, the code itself is a riddle wrapped in a mystery inside an enigma.

Sandler is understandably "not comfortable with the idea of having proprietary software literally screwed into her heart." Who would be?

For years, she's tried to get the medical device industry to open up its code with little success. All we can do is support her in this struggle.

As she wrote, "The ways we rely on our software are not theoretical. They pervade every aspect of our lives, and we must make our decisions carefully — knowing that there will be immediate and long-term consequences of those choices." ®

Get our [20]Tech Resources



[1] https://sfconservancy.org/blog/2023/dec/19/a-note-from-karen-2023/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZaEb1EHegN1th4caYXaACwAAAU8&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://www.mayoclinic.org/diseases-conditions/hypertrophic-cardiomyopathy/symptoms-causes/syc-20350198

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZaEb1EHegN1th4caYXaACwAAAU8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZaEb1EHegN1th4caYXaACwAAAU8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZaEb1EHegN1th4caYXaACwAAAU8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZaEb1EHegN1th4caYXaACwAAAU8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[8] https://www.economist.com/technology-quarterly/2012/06/02/when-code-can-kill-or-cure

[9] https://www.theregister.com/2017/08/30/st_jude_pacemaker_patch_approved/

[10] https://www.nytimes.com/2017/04/13/health/st-jude-medical-defibrillator-abbot-fda.html

[11] https://www.reuters.com/article/us-johnson-johnson-cyber-insulin-pumps-e/jj-warns-diabetic-patients-insulin-pump-vulnerable-to-hacking-idUSKCN12411L

[12] https://www.ic3.gov/Media/News/2022/220912.pdf

[13] https://www.youtube.com/watch?v=OpyYLJOLwpA

[14] https://www.cbsnews.com/boston/news/aaa-key-fob-hack-car-thefts/

[15] https://www.theregister.com/2021/10/13/healthcare_privacy_debate_wednesday/

[16] https://www.theregister.com/2023/06/08/new_york_city_hyundai_kia/

[17] https://www.theregister.com/2023/01/21/mouse_muscle_cyborg_light/

[18] https://www.theregister.com/2022/08/24/tesla_owner_gets_hand_fob/

[19] https://www.theregister.com/2023/09/20/neuralink_human_trials/

[20] https://whitepapers.theregister.com/



The CEOs ....

KittenHuffer

.... of the companies involved should be forced to have at least one of their IMDs fitted to them. Just to show that they are sure that they are safe from hacking!

Re: The CEOs ....

Wellyboot

And required to attend certain security conferences that have a practical application leaning?

Going nowhere but there are alternatives

Charlie Clark

It's difficult to see any real path to success here: legally, there's no difference between a medical device and anything else we buy the software can be considered the IP of the manufacturer.

But the data collected by the device is another matter entirely. This should be clearly documented and the patient and/or their clinician should be given the means to access it and control who else has access. This is much easier to legislate and implement.

Functional safety

Mishak

What is needed is the proper enforcement of functional safety standards on these devices - the current medical standards are not fit for purpose, and (some of) the medical device companies are lobbying to prevent there being any changes.

And then there are the user interfaces - there were (are?) infusion pumps that give orders of magnitude different doses for what appear to be the same settings (and this has lead to serious accidents).

On its own, opensource will not help as the code is generally not compatible with a number of the objectives that have to be satisfied when functional safety is required (where are the formal requirements, test plans, etc. ?). However, there is nothing to stop an open source project from being created that does tick all of the boxes, though many will not what to take part because of the amount of (tedious) supporting documentation that needs to be provided.

Certifications for Medical Devices

Sir Sham Cad

Part of the issue re: security of Medical Devices generally is that they are shipped to the Clinicians essentially as a Black Box that has a Certification for use as a Medical Device. Usually certified several years previously. Any "change" to the state of that device, for example: patching the underyling OS, deviates from the original specification meaning the device is no longer certified and can't be used.

Essentially, Medical Devices are a huge security problem because they, and the whole ecosystem is designed for a point-in-time configuration not security.

gnasher729

Independent of open source or not, it should be easily possible to extract data from these devices. Say some Bluetooth interface that can send the data to my iPhone. Or android phone.

For security, having a gut repository with public read-only access would be a great way if you don’t want to open source it. I mean I’d love to have this software safe, but I really don’t think having different versions would be a good idea.

Deprive a mirror of its silver and even the Czar won't see his face.