40 ms·
As per the other post: tl;dr Scott's most relevant points: 1. "This is a key fob that looks like a car alarm beeper that some pump users use to discretely gi
by timmyd 15y ago
As per the other post:
tl;dr
Scott's most relevant points:
1. "This is a key fob that looks like a car alarm beeper that some pump users use to discretely give themselves insulin doses. However, I feel the need to point out as a pump wearer myself that:
Not every Insulin Pump has a remote control feature. Not every remote-controllable insulin pump has that feature turned on. Mine does not, for example."
2. "all he requires to perpetrate the hack is the target pump's serial number. This is like saying "I can open your garage door with a 3rd party garage door opener. Just give me the numbers off the side of your unit..."
3. If you are a diabetic on a pump who is concerned about this kind of thing, my suggestion is to turn off your pump's remote control feature (which is likely off anyway) and turn off your sensor radio when you are not wearing your CGM. Most of all, don't panic. Call the manufacturer and express your concern. In my experience, pump manufacturers do not mess around with this stuff. I'm not overly concerned.
--
Also - someone asked how much entropy was in the serial ID's on these units ?
Even if entropy is low are - how are you going to randomly select a person, and know their serial ID ? Unless you know what units are distributed to what hospitals/doctors - at exact times - at exact shipments and then from the sample delivered know the exact unit given to any person at any particular time.
Sure, if you know a "set of id's" you could try each one sequentially until you finally get a hit - but even then, you must somehow ensure the person being targeted has remote connection turned on. I'm pretty sure walking up to them and saying "oh, hai 'dere! ... plz turn on ur remotz connetz'n 4 me?" [ said in this voice - http://www.youtube.com/watch?v=xh_9QhRzJEs http://www.youtube.com/watch?v=xh_9QhRzJEs ] - is going to make them pretty suspicious.
There's a lot of "ifs" in there and frankly - if your aim was kill them - it would be a lot faster to do it some other way because to actually get all these things to line up perfectly .... your chances are pretty slim.
I'm a bit of sceptic on this 'hacking' - not to say that it's great that it has been uncovered - but your dealing with minute hardware where every single ms of processing power counts. Simple encryption should be utilized [but then this might be easily hacked anyway ?] but for units placed inside the body [pacemakers and the like] - splitting the units resources between keeping the patient alive vs. encryption for wireless protocols seems to weigh more heavily on the former than the later given how unlikely - for the majority of the world - these 'attacks' are going to be.
- patio11 15y agoWould you trust your life on a computer not being able to count from one to ten billion? From one to ten million? From one to a thousand? Computers can, in fact, trivially do all of these things. Counting to large numbers quickly is what they do best. Accordingly, if "Guess my large number" is sufficient to remote control the machine, then that's a pretty critical finding. And there is no work that the attacker can do which will make his life more difficult. Trivial inspection of any machine establishes the upper bound of how hard it will be to compromise. Any attack he can use to reduce entropy only makes that number shrink, potentially radically. We would worry if you could shrink a 2048 bit keys even by a bit, because it suggests a hidden systemic weakness. The second serial number examined is likely to shrink the keyspace - which will not be 2048 bits to begin with - by tens of bits. There are classes of attackers for whom killing a single named individual is not a goal. "Oh drats, we were only able to kill fifteen people chosen at random from this hospital, Superdome, or session of Congress" would not br a failure condition for them or a victory condition for the public.
- nl 15y agoTo be perfectly clear: a quick Google confirms (at least one type of) insulin pump has 8 digit serial numbers. It also appears the first digit is 1 or 0. Serial numbers usually have a check digit, so it is likely we are down to only 6 digits. That's easily brute-forceable.
- FaceKicker 15y agoStrictly speaking, isn't "guess my large number" sufficient to break most encryption protocols that don't rely on security by obscurity? It's just that the numbers are normally larger by dozens of orders of magnitude.
- gvb 15y agoYes, but you are ignoring the time factor. Assume I'm going to die of natural causes in 60 years. If it takes a minute to guess a 6 digit number, that is really bad. If it takes 1000 years to guess a number that is larger by dozens of orders of magnitude, odds are pretty good I'm going to die of natural causes before the attacker guesses the right number.