# Bad security can kill (Hacking a pacemaker)

**URL:** <https://boards.straightdope.com/t/bad-security-can-kill-hacking-a-pacemaker/441117>\
**Category:** Miscellaneous and Personal Stuff I Must Share\
**Created:** [March 12, 2008, 3:35pm UTC](https://boards.straightdope.com/t/bad-security-can-kill-hacking-a-pacemaker/441117 "2008-03-12T15:35:09Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![Typo\_Knig](https://avatars.discourse-cdn.com/v4/letter/t/cdc98d/32.png) [@Typo\_Knig](https://boards.straightdope.com/u/Typo_Knig)\
**Post date:** [March 12, 2008, 3:35pm UTC](https://boards.straightdope.com/t/bad-security-can-kill-hacking-a-pacemaker/441117/1 "2008-03-12T15:35:09Z")

</div>

A research team was able to hack into a pacemaker/heart defibrillator, in a laboratory setting. :eek:

[NY Times article](http://www.nytimes.com/2008/03/12/business/12heart-web.html?_r=2&oref=slogin&oref=slogin) (subscription required, I believe)

[Medical device Security Center Web site](http://www.secure-medicine.org/) where the paper is posted.

[FAQ about the paper](http://www.secure-medicine.org/icd-study/icd-faq.html)

and finally,

[Text of the paper (PDF)](http://www.secure-medicine.org/icd-study/icd-study.pdf)

This was a laboratory based attack on a device that was NOT in a patient. Never the less, this is scary stuff. Oh, and hackers could get private medical info as well as forcing the pacemaker/defibrillator to fire when they want. Or they could just run down the batteries, which require a surgical replacement.

Scary stuff.

---

<div class="post-metadata">

**Author:** ![Really\_Not\_All\_That\_Bright](https://avatars.discourse-cdn.com/v4/letter/r/e8c25b/32.png) [@Really\_Not\_All\_That\_Bright](https://boards.straightdope.com/u/Really_Not_All_That_Bright)\
**Post date:** [March 12, 2008, 5:12pm UTC](https://boards.straightdope.com/t/bad-security-can-kill-hacking-a-pacemaker/441117/2 "2008-03-12T17:12:52Z")

</div>

I don’t know much about pacemakers. I always assumed you had to be hardwired to one to fiddle with it… so wouldn’t it be a mite tricky once the pacemaker is implanted?

---

<div class="post-metadata">

**Author:** ![Typo\_Knig](https://avatars.discourse-cdn.com/v4/letter/t/cdc98d/32.png) [@Typo\_Knig](https://boards.straightdope.com/u/Typo_Knig)\
**Post date:** [March 12, 2008, 5:46pm UTC](https://boards.straightdope.com/t/bad-security-can-kill-hacking-a-pacemaker/441117/3 "2008-03-12T17:46:24Z")

</div>

[QUOTE=Really Not All That Bright]  
I don’t know much about pacemakers. I always assumed you had to be hardwired to one to fiddle with it… so wouldn’t it be a mite tricky once the pacemaker is implanted?  
[/QUOTE]

Oh, **Really Not All That Bright** , you know that wires are just soooo Twentieth Century. It’s all wireless now.

Wireless communications allows doctors to make adjustments to the devices, or download records from the devices, without opening up the patient. There are proposed devices which allow remote access, for patients in rural areas. The remote access devices may actually exist - I wasn’t clear on that part.

A part of the FAQ that I thought was clever was the author’s proposal of security methods for implantable medical devices that (the authors claim) use the RF power of the hacking signal to run the security measures, rather than drawing down the batteries. Often the batteries have to be replaced via surgery, so discharging the batteries is a form of attack.

---

<div class="post-metadata">

**Author:** ![Doctor\_Jackson](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/doctor_jackson/32/32_2.png) [@Doctor\_Jackson](https://boards.straightdope.com/u/Doctor_Jackson)\
**Post date:** [March 12, 2008, 8:38pm UTC](https://boards.straightdope.com/t/bad-security-can-kill-hacking-a-pacemaker/441117/4 "2008-03-12T20:38:49Z")

</div>

Future newspaper headline:

\*\*“Octagenarian Hacker Makes Woman’s Heart Go Pitter-Pat” \*\*  
“I thought it was love”, she said, “but it was just bad code.”

---

<div class="post-metadata">

**Author:** ![Tim\_T-Bonham.net](https://avatars.discourse-cdn.com/v4/letter/t/46a35a/32.png) [@Tim\_T-Bonham.net](https://boards.straightdope.com/u/Tim_T-Bonham.net)\
**Post date:** [March 13, 2008, 12:36am UTC](https://boards.straightdope.com/t/bad-security-can-kill-hacking-a-pacemaker/441117/5 "2008-03-13T00:36:53Z")

</div>

[QUOTE=Really Not All That Bright]  
I don’t know much about pacemakers. I always assumed you had to be hardwired to one to fiddle with it… so wouldn’t it be a mite tricky once the pacemaker is implanted?  
[/QUOTE]  
I have a friend who has one (actually, a fairly new one – it was inserted last fall, to replace one from 13 years ago).

She has a small pad she holds next to the pacemaker (near her shoulder) and it wirelessly communicates with the pacemaker, and can download recorded date on how it has been working and any problems it encountered. Then she can connect that to a phone modem, and upload it to her cardiologist. And the data must be stored with date/time on it; they’ve told her to write down the date/time when she has an incident where it isn’t working as she wants, then they can look back to find the pacemaker data from that time and see just what was happening.

The doctor has a similar device, but his can also re-program the pacemaker parameters. I think they even have the technical capability to able to send a reprogramming ‘update’ over the phone to her, which she could use to re-program her pacemaker. But they don’t do that; they always do that when she has come in to the office for a checkup.

But her reading device has to be held right against her body to work, and kept still. Wouldn’t a ‘hacking’ device also have to be held up against the patient for it to work?

---

<div class="post-metadata">

**Author:** ![Zeriel](https://avatars.discourse-cdn.com/v4/letter/z/58956e/32.png) [@Zeriel](https://boards.straightdope.com/u/Zeriel)\
**Post date:** [March 13, 2008, 4:09pm UTC](https://boards.straightdope.com/t/bad-security-can-kill-hacking-a-pacemaker/441117/6 "2008-03-13T16:09:09Z")

</div>

[QUOTE=t-bonham@scc.net]  
But her reading device has to be held right against her body to work, and kept still. Wouldn’t a ‘hacking’ device also have to be held up against the patient for it to work?  
[/QUOTE]

Not necessarily–the max power and range of the device for receiving commands is dependent on the antenna size, not the typical power used–that is, if the hackers use a bigger broadcast antenna and reception dish than the standard programming apparatus, the viable range of hacking attempts will be correspondingly increased.

---

<div class="post-metadata">

**Author:** ![tdn](https://avatars.discourse-cdn.com/v4/letter/t/94ad74/32.png) [@tdn](https://boards.straightdope.com/u/tdn)\
**Post date:** [March 13, 2008, 4:41pm UTC](https://boards.straightdope.com/t/bad-security-can-kill-hacking-a-pacemaker/441117/7 "2008-03-13T16:41:59Z")

</div>

I find it not so much scary as really neat. Not only do I work in technology, but I work in cardiac surgery. I had no idea we did stuff this cool. And now that Medtronic knows about the security hole, they can do something to fix it.

I was wondering who would actually go to the immense amount of trouble to screw with someone’s VAD and why. Then the article mentioned Dick Cheney.

---

<div class="post-metadata">

**Author:** ![rjk](https://avatars.discourse-cdn.com/v4/letter/r/ed655f/32.png) [@rjk](https://boards.straightdope.com/u/rjk)\
**Post date:** [March 14, 2008, 5:19am UTC](https://boards.straightdope.com/t/bad-security-can-kill-hacking-a-pacemaker/441117/8 "2008-03-14T05:19:06Z")

</div>

“Twice up to overload and back down dead” - Cordwainer Smith, in _Scanners Live in Vain_.

The story should be in any collection of his short stuff. Go [here](http://www.cordwainer-smith.com/rediscovery.htm) to read the first paragraph.

---

<div class="post-metadata">

**Author:** ![Really\_Not\_All\_That\_Bright](https://avatars.discourse-cdn.com/v4/letter/r/e8c25b/32.png) [@Really\_Not\_All\_That\_Bright](https://boards.straightdope.com/u/Really_Not_All_That_Bright)\
**Post date:** [March 14, 2008, 1:36pm UTC](https://boards.straightdope.com/t/bad-security-can-kill-hacking-a-pacemaker/441117/9 "2008-03-14T13:36:13Z")

</div>

[QUOTE=tdn]  
And now that Medtronic knows about the security hole, they can do something to fix it.

[/QUOTE]

Tools —\> Windows Update ----\> Custom Install -----\> “Now searching for latest available updates for your pacemaker”…

---

<div class="post-metadata">

**Author:** ![Zebra](https://avatars.discourse-cdn.com/v4/letter/z/c0e974/32.png) [@Zebra](https://boards.straightdope.com/u/Zebra)\
**Post date:** [March 14, 2008, 1:52pm UTC](https://boards.straightdope.com/t/bad-security-can-kill-hacking-a-pacemaker/441117/10 "2008-03-14T13:52:15Z")

</div>

From the times article.

[QUOTE=NYTimes]  
The report, to published at [www.secure-medicine.org](http://www.secure-medicine.org), makes clear that the hundreds of thousands of people in this country with implanted defibrillators or pacemakers to regulate their damaged hearts — they include Vice President Dick Cheney — **have no need yet to fear hackers**. The experiment required more than $30,000 worth of lab equipment and a sustained effort by a team of specialists from the University of Washington and the University of Massachusetts to interpret the data gathered from the implant’s signals. And the device the researchers tested, a combination defibrillator and pacemaker called the Maximo, **was placed within two inches of the test gear**.  
[/QUOTE]

Bolding mine

So if you kidnapped a person and made them stand still long enough you could hack the device.

Of course you could just shoot them, or throw them in a tank full of sharks with laser beams attached to their heads.

---

<div class="post-metadata">

**Author:** ![Zeriel](https://avatars.discourse-cdn.com/v4/letter/z/58956e/32.png) [@Zeriel](https://boards.straightdope.com/u/Zeriel)\
**Post date:** [March 14, 2008, 2:33pm UTC](https://boards.straightdope.com/t/bad-security-can-kill-hacking-a-pacemaker/441117/11 "2008-03-14T14:33:04Z")

</div>

Or you could invite them over for coffee and seat them near the computer.

---

<div class="post-metadata">

**Author:** ![Zebra](https://avatars.discourse-cdn.com/v4/letter/z/c0e974/32.png) [@Zebra](https://boards.straightdope.com/u/Zebra)\
**Post date:** [March 14, 2008, 5:23pm UTC](https://boards.straightdope.com/t/bad-security-can-kill-hacking-a-pacemaker/441117/12 "2008-03-14T17:23:29Z")

</div>

2 inches from the sensors, hooked to your $30,000 while a whole team of guys work on the problem.

I wonder how long a ‘sustained’ effort takes.

Hours? Days? Weeks?

---

<div class="post-metadata">

**Author:** ![tdn](https://avatars.discourse-cdn.com/v4/letter/t/94ad74/32.png) [@tdn](https://boards.straightdope.com/u/tdn)\
**Post date:** [March 14, 2008, 6:05pm UTC](https://boards.straightdope.com/t/bad-security-can-kill-hacking-a-pacemaker/441117/13 "2008-03-14T18:05:41Z")

</div>

[QUOTE=Really Not All That Bright]  
Tools —\> Windows Update ----\> Custom Install -----\> “Now searching for latest available updates for your pacemaker”…  
[/QUOTE]

_snerk_

I was just telling my boss about this.

He already knew. He was on the team that worked on it.

---

<div class="post-metadata">

**Author:** ![Sleel](https://avatars.discourse-cdn.com/v4/letter/s/73ab20/32.png) [@Sleel](https://boards.straightdope.com/u/Sleel)\
**Post date:** [March 17, 2008, 3:18am UTC](https://boards.straightdope.com/t/bad-security-can-kill-hacking-a-pacemaker/441117/14 "2008-03-17T03:18:19Z")

</div>

Featured in the triller [Hard Rain](http://www.amazon.com/Hard-Rain-John-Thrillers/dp/0451212460/ref=ed_oe_p) published back in 2002. Not that big of a logical leap considering that pacemakers haven’t been wired for a long time, and that the general public have been warned about microwave or cell phone interference. Frankly, I’m surprised that this is considered big news rather than being looked at as just a demonstration of a theoretical vulnerability.
