Medical device maker Medtronic finally fixes its hackable pacemaker

Medtronic, a maker of medical devices and implants, has pulled the plug on its internet-based software update system, which security researchers had found had a dangerous security vulnerability

The company said in a notice this week that it’s switching off the software distribution network after researchers found that a hacker could update the pacemaker’s software with malicious software that could manipulate the impulses that regulate a patient’s heartbeat. The researchers, Jonathan Butts and Billy Rios, revealed the vulnerability at the Black Hat conference in August, more than a year after first reporting the vulnerability to Medtronic.

The bug isn’t within the pacemaker itself but the devices that are used by doctors to connect to the pacemaker to check its battery and status. These “programmer” devices weren’t checking if downloaded software hadn’t been tampered with.

Medtronic issued several updates throughout the year to try to mitigate the vulnerability, but only this month shut down the internet updating feature, per a security advisory issued by the Federal Drug Administration.

Now, patients with one of the 34,000 CareLink affected pacemakers will have to receive the update over USB from their doctor when new software is released, according to Medtronic’s statement.

It’s a turnaround from how the medical device maker reacted when the flaws were first reported. Butts said at the time that the company “spent more time trying to twist the story than fixing it.”

Medtronic said that it’s not received any reports to date of anyone exploiting the vulnerabilities.



from www.tech-life.in
Share:

No comments:

Post a Comment

Search This Blog

Blog Archive

Powered by Blogger.

Edo raises $12M from Breyer Capital to measure TV ad effectiveness

Edo , an ad analytics startup founded by Daniel Nadler and actor Edward Norton, announced today that it has raised $12 million in Series A f...

Blog Archive

Recent Posts

Unordered List

  • Lorem ipsum dolor sit amet, consectetuer adipiscing elit.
  • Aliquam tincidunt mauris eu risus.
  • Vestibulum auctor dapibus neque.

Sample Text

Lorem ipsum dolor sit amet, consectetur adipisicing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation test link ullamco laboris nisi ut aliquip ex ea commodo consequat.

Pages

Theme Support

Need our help to upload or customize this blogger template? Contact me with details about the theme customization you need.