KILL SWITCH
http://venturebeat.com/2008/08/08/defcon-excuse-me-while-i-turn-off-your-pacemaker/
Defcon: Excuse me while I turn off your pacemaker
BY Dean Takahashi / August 8th, 2008
The Defcon conference is the wild and woolly version of Black Hat for
the unwashed masses of hackers. It always has its share of unusual
hacks. The oddest so far is a collaborative academic effort where
medical device security researchers have figured out how to turn off
someone’s pacemaker via remote control. They previously disclosed the
paper at a conference in May. But the larger point of the
vulnerability of all wirelessly-controlled medical devices remains a
hot topic here at the show in Las Vegas.
Let’s not have a collective heart attack, at least not yet. The people
on the right side of the security fence are the ones who have figured
this out so far. But this has very serious implications for the 2.6
million people who had pacemakers installed from 1990 to 2002 (the
stats available from the researchers). It also presents product
liability problems for the five companies that make pace makers.
Kevin Fu, an associate professor at the University of Massachusetts at
Amherst and director of the Medical Device Security Center, said that
his team and researchers at the University of Washington spent two
years working on the challenge. Fu presented at Black Hat while Daniel
Halperin, a graduate student at the University of Washington,
presented today at Defcon.
Getting access to a pacemaker wasn’t easy. Fu’s team had to analyze
and understand pacemakers for which there was no available
documentation. Fu asked the medical device makers, explaining his
cause fully, but didn’t get any help.
William H. Maisel, a doctor at Beth Israel Deaconess Hospital and
Harvard Medical School, granted Fu access for the project. Fu received
an old pacemaker as the doctor installed a new one in a patient. The
team had to use complicated procedures to take apart the pacemaker and
reverse engineer its processes. Halperin said that the devices have a
built-in test mechanism which turns out to be a bug that can be
exploited by hackers. There is no cryptographic key used to secure the
wireless communication between the control device and the pacemaker.
A computer acts as a control mechanism for programming the pacemaker
so that it can be set to deal with a patient’s particular
defribrillation needs. Pacemakers administer small shocks to the heart
to restore a regular heartbeat. The devices have the ability to induce
a fatal shock to a heart.
Fu and Halperin said they used a cheap $1,000 system to mimic the
control mechanism. It included a software radio, GNU radio software,
and other electronics. They could use that to eavesdrop on private
data such as the identity of the patient, the doctor, the diagnosis,
and the pacemaker instructions. They figured out how to control the
pacemaker with their device. “You can induce the test mode, drain the
device battery, and turn off therapies,” Halperin said.
Translation: you can kill the patient. Fu said that he didn’t try the
attack on other brands of pacemakers because he just needed to prove
the academic point. Halperin said, “This is something that academics
can do now. We have to do something before the ability to mount
attacks becomes easier.”
The disclosure at Defcon wasn’t particularly detailed, though the
paper has all of the information on the hack. The crowd here is mostly
male, young, with plenty of shaved heads, tattoos and long hair. The
conference is a cash-only event where no pictures are allowed without
consent. It draws thousands more people from a much wider net of
security researchers and hackers than the more exclusive Black Hat.
Similar wireless control mechanisms are used for administering drugs
to a patient or other medical devices. Clearly, the medical device
companies have to start working on more secure devices. Other hackers
have figured out how to induce epileptic seizures in people sensitive
to light conditions. The longer I stay at the security conferences
here in Las Vegas, the scarier it gets.
CONTACT
Kevin Fu
http://www.cs.umass.edu/~kevinfu/
email : kev...@cs.umass.edu
Daniel Halperin
http://www.cs.washington.edu/homes/dhalperi/
email : dhal...@cs.washington.edu
ABSTRACT
http://www.secure-medicine.org/icd-study/icd-study.pdf
Our study analyzes the security and privacy properties of an
implantable cardioverter defibrillator (ICD). Introduced to the U.S.
market in 2003, this model of ICD includes pacemaker technology and is
designed to communicate wirelessly with a nearby external programmer
in the 175 kHz frequency range. After partially reverse-engineering
the ICD’s communications protocol with an oscilloscope and a software
radio, we implemented several software radio-based attacks that could
compromise patient safety and patient privacy. Motivated by our desire
to improve patient safety, and mindful of conventional trade-offs
between security and power consumption for resource-constrained
devices, we introduce three new zero-power defenses based on RF power
harvesting. Two of these defenses are human-centric, bringing patients
into the loop with respect to the security and privacy of their
implantable medical devices (IMDs). Our contributions provide a
scientific baseline for understanding the potential security and
privacy risks of current and future IMDs, and introduce human-
perceptible and zero-power mitigation techniques that address those
risks. To the best of our knowledge, this paper is the first in our
community to use general-purpose software radios to analyze and attack
previously unknown radio communications protocols.
SEE ALSO : DEFCON / BLACKHAT
http://www.defcon.org/
http://www.hackaday.com/category/cons/
http://www.blackhat.com/
http://blog.wired.com/27bstroke6/2008/08/audio-from-subw.html
http://defcon.stotan.org/faq/survival.htm
http://defcon.stotan.org/faq/fullmonty.htm
PICTURES OF DEFCON'S TEMPORARY NETWORK OPERATIONS CENTER
http://blog.wired.com/27bstroke6/2008/08/a-first-ever-lo.html
Las Vegas -- "Over 9,000 hackers, freaks, feds and geeks are gathered
in Las Vegas for Defcon, the world's largest computer security
convention. The temporary wireless network that serves the Defcon
attendees is the most hostile on the planet. Defcon's network is put
together and run by a group of dedicated volunteers, known as Goons.
These red badge-sporting Network Goons work hard to make the network
robust enough to handle the endless stream of dangerous traffic.
Threat Level got the first ever photo tour of the Defcon Network
Operations Center. Here are the photos for your viewing pleasure."
DEFCON 16
http://news.cnet.com/8301-1009_3-10012612-83.html
http://news.cnet.com/8301-1009_3-10013156-83.html
Defcon ends with researchers muzzled, viruses written
BY Elinor Mills / August 10, 2008
LAS VEGAS -- The Defcon hacker conference ended its 16th year on
Sunday, sending about 8,000 attendees home from a weekend of virus
writing, discussion of Internet attacks, and general debauchery. The
highlight was most definitely the restraining order which prevented
three MIT students from presenting their research on how to hack the
Boston subway system. The students attended the event and even gave a
news conference after the order came down on Saturday, but did not
present their highly anticipated talk.
Instead, journalist and security expert Brenno de Winter took their
empty spot and discussed how the cards used in transit system in The
Netherlands and London can be hacked just like the ones used in
Boston. Both systems, and many around the world, use the Mifare
Classic chip technology, whose cryptography was cracked by researchers
last year. "I was advised by several lawyers not to go into details of
the Mifare Classic, but anybody who has access to Google...," de
Winter said.
Breaking the rules is always a theme at Defcon, but while irreverence
for established corporate and government protocols is condoned if not
exactly encouraged, breaking Defcon rules definitely has its
consequences. Defcon officials said they were considering banning film
crews from future events after ejecting a team from the G4 cable
network on Saturday for allegedly videotaping a crowd. Photographers
and videographers are required to get permission to shoot anyone, even
from behind, and are forbidden from shooting crowds.
There was a report that police were called in to investigate a Windows-
based kiosk that was hacked to display pornographic images in the
lobby. And the usual rowdiness and late-night drinking were a nightly,
if not daily, activity. However, things did not seem to reach the
level of tomfoolery they did in in the early and mid-1990s when
elevators were hacked and cement was poured down toilets. Of course,
many of the script kiddies from that era are now married with
children.
There were, of course, a range of sessions, including ones on
evaluating the risks of "good viruses," hijacking outdoor billboard
networks, and compromising Windows-based Internet kiosks. Members of
SecureState, a company that does penetration testing of corporate
networks, gave a live demo in one session of an automated attack on
Microsoft SQL Server-based computer that left the machine vulnerable
to attackers installing viruses and other malware. The team used new
tools they are offering for download, SA Exploiter and Fast-Track.
One of the more controversial events at the event was a "Race to
Zero," in which teams modified samples of viruses and tested them
against antivirus software. Four teams managed to complete all the
levels and get through the antivirus software. There were less
technical contests as well. "Mike" from Chicago won $3,000 for
spending 30 straight hours listening to pitches and marketing buzz
from security company Configuresoft and correctly answering questions
on periodic quizzes on the presentations. After the announcement, he
jumped out of his seat with his arms in the air. Asked how he felt,
Mike, who declined to give a last name, said he "felt smelly."
The contest, called "Buzzword Survivor," was not without scandal.
Several contestants claimed--and submitted a cell phone photo as
evidence to organizers--that one of the contestants had fallen asleep
at one point. However, he was allowed to remain in the contest and
made it to the very end with all the others, winning $200. The second
prize was $1,000. Gartner analyst Paul Proctor came up with the idea
on a whim. It was originally intended to have 10 contestants competing
for 36 hours for a $10,000 prize, but the prize was reduced when only
one sponsor stepped up.
The contestants had 10 minute breaks every hour, but otherwise were in
their seats listening to detailed talks about the company, its
products, and the industry. "We've submitted them to pain," Andrew
Bird, a Configuresoft vice president, who served as MC at the end of
contest, said mischievously. "We played recorded Webinars at 4 a.m."
Note: In the video below, Defcon founder Jeff Moss, alias "Dark
Tangent," discusses the ethics of hacking and disclosure issues that
provoke debate, and often lawsuits, at the event:
http://www.youtube.com/watch?v=_krUUAU_3ZA
THE BADGES
http://blog.wired.com/27bstroke6/2008/08/exclusive-defco.html
http://www.hackaday.com/2008/08/05/defcon-16-badge-details-released/
http://www.grandideastudio.com/
One of the more popular gadgets from the previous two Defcons were the
hackable convention badges. This year, we convinced Defcon's founder
Jeff Moss, aka Dark Tangent, and badge-designer Joe "Kingpin" Grand,
to give Wired.com an exclusive sneak preview of the Defcon 16 badge.
Keep in mind that the badge in the photo is a prototype; the actual
badges will be a different color, won't have the USB and debug ports
soldered on, nor include an SD card (so bring one, seriously).
Threat Level: Defcon 15's badge was exponentially more complicated and
functional than Defcon 14's badge. How does this year's badge compare
to the DC 15 badge?
Joe Grand: Last year's badge was sort of an over-engineered project.
We wanted to do something that was cool and different than the year
before, but it ended up getting more complicated because of design
problems along the way ... I was really aiming to have something a
little less complicated and a little less over-engineered than Defcon
15, but still more complicated then Defcon 14 and have enough hackable
features to make it interesting enough for people. It's more simple
than last year but also more powerful.
TL: Why did you choose a Freescale microprocessor, and why did you
choose the MC9S08JM60 over the MC9S08QG8?
JG: The guys at Freescale have been super supportive throughout both
the Defcon 15 and this Defcon 16 badge. One of their things is that
they have a lot of engineers who truly love engineering and they love
coming up with new products that use their technologies. They
understand that it is a hacker gathering and the hackers are
ultimately the ones who are creating the cutting-edge products and
they're messing around with technology and doing things that haven't
been done before. They love the concept and they love being involved
with Defcon ...
The JM60 was a new product that they just launched ... We looked at
the processor and said the JM60 has support for USB so let's use USB.
It has support for a Secure Digital card so let's add SD in there ...
I rarely come across companies that are as passionate as I am about a
project and these guys are, so it's a total thrill to be able to work
with them.
TL: What components and other fun stuff does the badge have?
JG: The artistic elements and the PC board design tricks that I did
this year [are] some of my favorite parts of doing the badge. Ping and
Dark Tangent don't necessarily understand the engineering constraints
of making circuit boards so they really push me ... In turn I get to
learn a lot of new techniques ... We're doing stuff that's totally
crazy and nonstandard for circuit boards.
TL: Are they the same batteries as last year?
JG: No, different batteries. One of the things I ran into last year
that I was pretty embarrassed about was the battery life. Depending on
how much you used the badge, the batteries didn't even last the
weekend. For me one of my major design goals is making sure that the
badge lasted longer than Defcon. This year I went with a larger
battery, something that's way more robust and will just last a long
time for people who really want to hack on the badge. It's one of the
CR123A batteries. These things will last a long time, weeks if not
months. It's a little bigger than I would have like, but I placed it
in away that hopefully will not get too annoying for people.
TL: Did you see the RFID badges at The Last HOPE? Will yours also
include some kind of unique ID for buddy/hacker tracking?
JG: I didn't [see the HOPE badges] ... We talked about the badges
being able to either track each other or have some kind of unique
identifier, but I think that shit is just way too big brother. Most
people at Defcon don't even use their real name. Forcing them to wear
a badge that has features like that, to me is crap. I wouldn't want to
wear one of them.
TL: What were the biggest challenges in the badge development this
time around?
JG: This badge ... ended up taking 200 hours to design, versus the 170
from last year ... Most of that was because I was trying new things
I'd never done before ... During the process every time I had an
engineering problem or I stayed up late ... I just kept thinking the
pain's going to be worth it. Once the badge is done and it gets into
people's hands and they just love the way it looks and they have fun
with it and they hack on it it makes all of the trouble worthwhile to
get people interested into this type of thing.
TL: How are you going to top this badge next year?
JG: I have a few ideas for what I want to do next year assuming we do
it ... I won't say what they are yet, but it's going to be cool.
TL: What other projects are you working on right now?
JG: I just started a new apparel line called Kingpin Empire ... I am
going to donate a portion of the proceeds to hacker related charities
and health related charities: EFF, ACLU, American Heart Association.
Things that have personally affected me or personally saved me in some
way.
It's a way for me to spread the hacker message to the masses ... to
educate people as to what hacking is about, support hacker and health
related causes and give back to the community that shaped my entire
life.
TL: Anything else you want to say about the badge?
JG: I just hope people like it. It's a labor of love. The more people
that hack on it the better. I want people to modify it, I want people
to fix any problems they might see with it and just make it their own.
If I can inspire just one person out of the 8,500 people that have a
badge to start hacking on things and maybe even become and engineering
then I've done my part.
WALL OF SHEEP
http://www.g4tv.com/attackoftheshow/exclusives/64949/Def-Con-Convention.html
http://www.infoworld.com/article/08/08/11/Wall_of_Sheep_Coming_to_your_company_1.html
http://www.infoworld.com/archives/t.jsp?N=s&V=108591
Wall of Sheep: Coming to your company?
Defcon displays a long list of details showing who at the hacker
conference has sent readable data using insecure wireless connections
BY Robert McMillan / August 11, 2008
The Wall of Sheep has become a fixture of the Defcon hacker
conference: a wall with a long list of details showing who at the
conference has sent readable data using insecure wireless connections.
For Brian Markus, better known to conference attendees as "Riverside,"
it just may become a line of business.
Last month, Markus and three of his fellow volunteers incorporated a
company called Aries Security, which they bill as an education and
security awareness consultancy that can come in and identify risky
behavior on corporate networks. The company is still in an
experimental state, meaning that none of the partners have actually
quit their day jobs, Markus said. They don't expect companies to start
projecting their own Wall of Sheep displays in their lobbies, but they
say the network analysis tools they've developed could be helpful when
aimed at corporate networks. "We can go into a company if they need
help with a security awareness program," Markus said. "There are an
amazing amount of things that we could see by watching the traffic go
by."
Wall of Sheep got its start in 2002, when Markus and friends were
sniffing wireless LAN traffic at Defcon. It turned out there were
plenty of people putting their data out on those networks. "We were
saying there are so many of them, they are everywhere." Inspired by a
T-shirt, they decided to call the people they could observe "sheep,"
and they started sticking paper plates on the wall with some of the
user details they'd found. They list login names, domain or Internet
Protocol addresses and partial passwords. Hotel management wasn't
crazy about the idea of paper plates being stuck to the walls, so the
Wall of Sheep was soon using a projector.
They've seen some pretty crazy stuff revealed on open wireless LANs
over the years, including fake usernames and passwords, brand-new
computer attacks, a tax return and what Markus calls "nontypical adult
material." Today the project attracts dozens of volunteers at the
conference who spend hours hunched over computers analyzing data
before it's put up on the wall. "It's a tremendous amount of human
labor," Markus said.
Wall of Sheep made its first appearance ever at Defcon's less chaotic
sister conference Black Hat this year, and it got a lot of attention
when French journalists tried to post sensitive information on the
wall that was culled from a Black Hat network set up for reporters.
Because the journalists had illegally sniffed the Black Hat network
without permission, Markus refused, and eventually the journalists
were ejected from the conference. "We said, 'No way,'" he said. "It's
completely against what all of us are trying to do."
http://www.wallofsheep.com/
http://www.wallofsheep.com/tools/
About the Wall of Sheep
Our mission is to raise security awareness. Computer crime and
identity theft loom large in most people's unconscious fears because
they do not know:
1. How they are at risk, and
2. The steps they can take to protect themselves.
We explain both, but the way we do it is unconventional . . .
What We Do
The Wall of Sheep is an interactive demonstration of what can happen
when network users let their guard down. We passively observe the
traffic on a network, looking for evidence of users logging into
email, web sites, or other network services without the protection of
encryption. Those we find get put on the Wall of Sheep as a good-
natured reminder that a malicious person could do the same thing we
did . . . with far less friendly consequences. More importantly, we
strive to educate the "sheep" we catch—and anyone who wants to learn—
how to use free, easy-to-use tools to prevent leaks in the future.
Some Background
Nearly every time a network is accessed, an email account is checked,
a web application is logged into, or a message is sent, some form of
identification is passed between systems. By simply listening to this
network traffic and sorting out the interesting bits, ill-intentioned
third parties can often steal a password or other credentials with
little to no effort. In reality, on average, the occurrence of such
eavesdroppers is infrequent, but that does not diminish the
consequences if they are listening. Why risk a chance when you don't
have to? Awareness and education is the key. The tools and knowledge
to protect yourself are freely available. Most of the time, they are
built into your current system.
Our Approach
The Wall of Sheep shows what happens when there are eavesdroppers on
your network. If you access a network we are listening to without
protecting yourself, we will see your username and password. Then we
will post identifying elements* of your transaction on the the Wall in
front of all of your friends and colleagues. At that point, we hope
you will come to us and learn how to avoid such mistakes in the
future.
The Bottom Line
A potential attacker might maliciously and criminally use your
mistakes against you. We do the opposite by raising security awareness
and providing education on how to be defensive. It is very easy to
become a "sheep," but it is just as easy to learn how to avoid turning
into one.
*but never the whole thing
PREVIOUSLY ON SPECTRE --- PACEMAKER HACK
http://groups.google.com/group/spectre_event_horizon_group/browse_thread/thread/10b89d544726e9c9/b78c38b3c629b544