5 ms·
> Of course, those insulin pumps are running insecure firmware allowing for adjustments to be made remotely by an sbc (Raspberry Pi) where the OpenAPS software
by disabled 5y ago
> Of course, those insulin pumps are running insecure firmware allowing for adjustments to be made remotely by an sbc (Raspberry Pi) where the OpenAPS software lives and takes measurements from a GCM. Without the insecure remote interface on those insulin pumps, OpenAPS might not exist.
This is the issue here, with a cyber to physical attack, which is bound to happen at some point, with some medical device, and this project is a huge target for something like that. This project was specifically mentioned in the book "Click Here to Kill Everybody" by renowned cybersecurity expert Bruce Schriener, too.
OpenAPS was also designed to circumvent government laws, and is not-as-legal as the creators portray it to be. For example, one of the main "advocates" calls OpenAPS an "off-label qualification" for use (in the USA), when in order for that to apply, the specific device intended to be used must be FDA approved. As you know, OpenAPS cannot be FDA approved at this point of time. This individual also illegally markets unapproved medical devices across the United States, Europe, Australia, and New Zealand, plus online, with various gatherings for it. If you look at the specific laws of those lands, it is pretty clear cut what is going on is illegal. Plus, the new EU Medical Devices Regulation applies now.
Yes, it is illegal. I am astonished that this individual has not gotten in trouble with the FDA yet.