Security researchers Billy Rios, founder of Whitescope, and Jonathan Butts founder of QED Secure Solutions revealed these shocking vulnerabilities at last week’s Black Hat security conference; the pair claim to have discovered a major weakness in pacemakers and other medical implants such as insulin pumps manufactured by Medtronic, a global leader in medical technology services.
These specific vulnerabilities enable hackers to remotely hijack these widely used health aids and interfere with their behaviour, for example, sending or withholding life-saving shocks from an individual’s peacemaker. According to Rios and Butts, Medtronic’s devices are vulnerable to remote attacks via wireless radio signals and malware installed directly on an implanted device. Using a CareLink 2090 programmer, which is used to control the device once it has been implanted, Butts and Rios were able to demonstrate how a hacker could compromise a medical implant.
The updates for the programmer are not delivered over an encrypted HTTPS connection and firmware isn’t digitally signed, the researchers were able to force it to run malicious firmware that would be hard for most doctors to detect. This means the hacker could easily alter how the device behaves or disable it entirely, thus putting the victim at serious risk of death.
Medtronic’s Slow Response Sparks Criticism
Medtronic spokesperson Erika Winkels said in a statement: “All devices carry some associated risk, and we continuously strive to balance the risks against the benefits our devices provide.”
“Medtronic deploys a robust, coordinated disclosure process and takes seriously all potential cybersecurity vulnerabilities in our products and systems. In the past, WhiteScope, LLC has identified potential vulnerabilities which we have assessed independently and also issued related notifications, and we are not aware of any additional vulnerabilities they have identified at this time.”
According to Butts and Rios, the company took 10 months to vet the submission and subsequently has chosen not to issue a software update that would offer more protection to the individuals fitted with their devices. Rios and Butts both continue to criticise the company over how long it took to take actions to address the vulnerabilities and the lack of comprehensiveness of those updates, saying that it compromises the public’s trust in medical manufacturers.






