Heart-Stopper: Could Hackers Hit Pacemakers, Other Medical Implants?

Researchers warn that implantable medical devices could be vulnerable to cyber strikes















Share on Tumblr

Security problems will continue to plague new technologies as they come into the mainstream and attract the attention of devious computer hackers; it is a problem that has dogged PCs, mobile devices and radio-frequency identification tags throughout their maturation, says Gadi Evron, a security researcher who specializes in assessing computer vulnerability. Evron raised the issue at last year's Chaos Communication Camp international hacker gathering in Berlin, Germany, via a presentation entitled, "Hacking the Bionic Man: Science fiction or security in 2040?"

"All of the same security mistakes are made again and again," Evron says. "As long as people write [software], there will be bugs and vulnerabilities because secure design is never really followed."

Protecting implanted medical aids is tricky because manufacturers must avoid security measures that could cause the devices' batteries to run down or otherwise impede their lifesaving functions. The researchers propose that makers incorporate "zero-power" defenses into future designs, such as radio-frequency identification tags that create vibrations or audibly alert the patient of possible tampering without sapping battery power.

"The first thing to do is not scare people," Evron says, noting that such mischief is unlikely at this point. But he says it's important to keep on top of the issue, given the potential for trouble. "We should bring computer and security development into the realm of medical devices," he says, "so we aren't faced with security risks 10 or 15 years from now."



4 Comments

Add Comment
View
  1. 1. mikecimerian 03:59 AM 3/15/08

    Making public such a potential flaw is irresponsible. Work on solutions ...don't provoke malicious people with a new challenges.

    Reply | Report Abuse | Link to this
  2. 2. Go Yoshida 07:59 AM 3/16/08

    Balancing security and privacy with safety and efficacy will become increasingly important as implanted medical device technologies evolve.
    Remoted-control is a potential danger some of the cases of which patients with the mentioned devices should be harmed by a malicious security attack.

    Reply | Report Abuse | Link to this
  3. 3. Marian 02:23 PM 3/16/08

    It would also be extremely easy to set up special encryption so that the devices could only be accessed by authorized devices and authorized users, and had extremely limited range. Adjustable shunts (for example) are only adjustable at extremely close range, and the adjustments made would never be lethal, only problematic if done incorrectly.

    Currently anyone with a medical implant faces more problems from a microwave oven than any 'malicious hacker'.

    Reply | Report Abuse | Link to this
  4. 4. Omnivirus 12:29 AM 3/17/08

    It would be extremely easy to hack a special encryption to for a hacker psycho enough to do this. Also making this public... ha ha. This is old news to any hacker. Do u really think they never would of thought of this on their own. Its a scary world out there. Just hope no one would do it, bc its entirely possible (as the research shows)

    Reply | Report Abuse | Link to this
Leave this field empty

Add a Comment

You must sign in or register as a ScientificAmerican.com member to submit a comment.
Click one of the buttons below to register using an existing Social Account.

More from Scientific American

See what we're tweeting about

Scientific American Editors

More »

Free Newsletters


Get the best from Scientific American in your inbox

Solve Innovation Challenges

Powered By: Innocentive

  SA Digital

Latest from SA Blog Network

  SA Digital

Science Jobs of the Week

Email this Article

Heart-Stopper: Could Hackers Hit Pacemakers, Other Medical Implants?

X
Scientific American Magazine

Subscribe Today

Save 66% off the cover price and get a free gift!

Learn More >>

X

Please Log In

Forgot: Password

X

Account Linking

Welcome, . Do you have an existing ScientificAmerican.com account?

Yes, please link my existing account with for quick, secure access.



Forgot Password?

No, I would like to create a new account with my profile information.

Create Account
X

Report Abuse

Are you sure?

X

Institutional Access

It has been identified that the institution you are trying to access this article from has institutional site license access to Scientific American on nature.com. To access this article in its entirety through site license access, click below.

Site license access
X

Error

X

Share this Article

X