Hacked Gadgets Forum

August 14, 2008

Pacemaker Wireless Power Off Exploit and Countermeasure

at 10:26 am. Filed under Insane Equipment, What Were They Thinking

 

A recent study by Kevin Fu, an associate professor at the University of Massachusetts at Amherst and director of the Medical Device Security Center, has uncovered a weakness in some pacemakers. It turns out that pacemakers communicate with a computer during initial configuration. This wireless communication channel is not encrypted and provides test functions that can turn off the device! The research team has developed a countermeasure which allows the wearer of the pacemaker an alert when someone is attempting to interact with their device. I hope these devices are upgraded to prevent this attack and future models keep this hack in mind…

Read published study (PDF)

"Our prototype of zero-power notification wirelessly drives a piezo-element that can audibly warn a patient of security-sensitive events. The prototype builds upon revision 1.0 of the Wireless Identification and Sensing Platform (WISP) [27], a postage stamp-sized embedded system that contains RFID circuitry and a Texas Instruments MSP430F1232 microcontroller with 256 bytes of RAM and 8 KBytes of flash memory. The WISP harvests energy from a 915 MHz RF signal generated by the Alien ALR-9640 nanoscanner, a UHF RFID reader running the EPC Class 1 Gen 1 protocol. Although we prototyped at 915 MHz, it may be possible to create similar hardware that operates at the frequency of current ICD programmers. WISPer adds to the WISP’s base code a 30-line C program that activates a piezo-element which we attached to the general-purpose I/O (GPIO) ports of the WISP. After WISPer receives a sequence of wireless requests from the RFID reader, it emits constant chirping, thereby informing the patient of the wireless interaction. A future version of WISPer could set a separate GPIO high after buzzing for a certain number of cycles, and the IMD could allow remote communications only after that GPIO is raised. WISPer satisfies our zero-power notification design constraints: it draws no energy from a battery and can issue alerts for all reprogramming activity."

Via: Gearfuse and Defcon


 


Related Posts

Wireless Power Transfer and Magnetic Levitation
Is this real or What?
Levitating Light Bulb
Guitar Hero Goes Wireless
Wireless GPS Project
Vibration-Powered Generator
Hack: Cell phone + wireless router = Mobile hotspot
Wireless Impact Guardian - But can you find good sushi with it?

 


 

7 Responses to “Pacemaker Wireless Power Off Exploit and Countermeasure”

  1. miky Says:

    oh no this things are not also protected against solar storms
    if the strong solar storm will hit the earth this devices will become out of control

  2. The voice in your head Says:

    An alert? “Warning, warning, you are about to die.” How about some authentication?

  3. Mr. Maigo Says:

    Next we’ll find out that prosthetic arms have a “stop hitting your self” function

  4. Day Trading Computers Says:

    I wonder if it beeps like a truck backing up. I guess it’s good to know if you’re about to die, so you can avoid it…lol

  5. Robs NSFW Blog Says:

    Wow.. “miky” — learn some English, please… “Day Trading Computers” — you can’t be serious… Can you? Other than that — this is ridiculous. Why would someone want to have control over a pacemaker? Seriously, it’s not like the person isn’t about to die anyways…

  6. miky Says:

    [Robs NSFW Blog] if someone has total control of Pacemaker he can stop the hurt for a short time
    you would have question how is that possible? it is possible because Pacemaker works when the hurt starts working irregularly
    or stops working completely when that happens Pacemaker will hit the hurt with electricity and hurt will stop working and it will start again (hitting hurt with electricity it is like a reset button which we have on computers)

    hacker which is in bed mode and he is a bad person can kill human
    sorry for bad English

  7. Amiya Sarkar Says:

    That chink in the armor is one thing I feared, now there’s something that will act like a sentry.

Leave a Reply

 

Internal Links:


Categories:

Search:

Google
Hacked Gadgets
Web

Site Sponsors:

 

Recent Comments:

Rich on Name the Thing Contest - 69

Monica on Popcorn Popper made from a Tin Can

George on Waldic - Water Cooled Laptop

GEARFUSE » The Evolution Control Committee In Action on Mashup Mixing using a Wiimote

Curtisbeef on Name the Thing Contest - 68

Vintagepc on Name the Thing Contest - 69

ECC mashup touchscreen hacked with Wiimotes: Video demo - SlashGear on Mashup Mixing using a Wiimote

Bike Art : Orologi « Geeketto on Motorcycle Models made from Watches

daftness on Christmas Lights controlled with the .NET Micro Framework

Desozza on LEGO Marble Carousel

Alan Parekh on Name the Thing Contest - 69

Zack on Christmas Lights controlled with the .NET Micro Framework

Alan Parekh on Name the Thing Contest - 68

Ice_Cubes on Propeller Clock

pro on Floor Cavity Subwoofer Install

Site Rating:

Technology blogs

Technology Blogs - Blog Flare

Technology Blogs - Blog Top Sites

Top Technology blogs

Technology Blogs

Best blogs on Technology and Science

More RSS Feed Options

Most Popular This Month:

1100 Paintballs Shoot to instantly make a Picture
In-Vehicle Blind Spot Detection System
Xr-B3 - Trossen Robotics Project
ArduGame - Arduino Based Handheld Game
Waterfall Display
Hard Drive Clock - 18f252 Microcontroller Based
Tachometer made from a Bicycle Computer
Stonehenge Robotic Digital Clock
High-speed Magnetic Levitation
Airsoft Gun Turret

Site Sponsors:

 

Interesting Sites:

Sony Vaio SZ
ThinkGeek
Apple TV Hacks
Gadget India
Top HDTV Reviews
VoIP Phone
Technology Blog
Free Phone Number Trace
How To Hack

 

Site Videos:

Incoming Links:

Recent Readers:

Forum Activity:

Get this widget!