Friday, February 14, 2014

Embedded Software, Malware, and Medical Devices

I've occasionally heard from the lips of well meaning but uninformed persons that a medical device is secure because it uses embedded software. I'd like to introduce you to self-replicating malware for embedded firmware in routers.


I'd also like to take this opportunity to draw attention to a quote regarding the router's embedded firmware:
Unfortunately, no update is available for E1000 models, since they are no longer supported.
Sound familiar? Oh yes, Microsoft is ending all support for Windows XP Professional on April 8th of this year (2014).  No more patches, no more security updates.  Hope there aren't too many XP-based medical devices out there.



Wednesday, February 12, 2014

Security and Privacy for Telehealth, Invoking the FTC

Joe Hall and Deven McGraw from the Center for Democracy and Technology have published a thought provoking article, "For Telehealth To Succeed, Privacy And Security Risks Must Be Identified And Addressed" in the journal of Health Affairs.  They argue for the Federal Trade Commission to ensure health data privacy is protected on medical devices and apps.  The authors have considerable experience and success in explaining such nuanced arguments with federal policy makers and legislators.

Friday, January 10, 2014

NPR on the Security and Privacy of Health-Related Devices


Weight, weight, don't hack me!
This morning NPR broadcast an interview from CES that highlights the growing pains of security and privacy for health-related devices. It highlights the paradox: you can't bolt on security after the fact; you need to build it in. But what happens to a fledgling startup more worried about basic survival and getting their first customers? I think it's foolish to say one cannot think about cybersecurity at all just because a company is struggling to stay in existence. Instead, one must innovate and make frugal yet wise choices for cybersecurity risk management. A product's core architecture should not preclude security properties. A threat model is as essential as a specification of software behavior. Here's to 2014. May your product not become a cybersecurity admonition when it finally takes off in the marketplace. Be frugal, not cheap.

Startups Often Focus On Data Security Too Late, If At All

http://www.npr.org/2014/01/10/261271818/startups-often-focus-on-data-security-too-late-if-at-all