What to do to prevent security from becoming a PR disaster

How would you react if someone told you that your product could be hacked to such an extent that it could lead to fatalities? This question is not out of the question: Pacemaker manufacturer Medtronic was warned and failed to act for 18 months. Is this irresponsible behavior, or is the situation described by the security researchers completely exaggerated?
This is not the first time that such situations have arisen, even if they rarely involve human lives so directly. And Attack safety is more relevant today than ever. But no matter what the facts are: If management, the legal department, product development and the PR department do not communicate properly with each other, the threat to the company may be greater than the threat to users.
The facts
To understand the Medtronic case, let's first look at the position of the two parties:
The research results
Researcher Billy Rios published this case with his colleague Jonathan Butts at the Black Hat security conference in Las Vegas. The researchers showed that a pacemaker and an insulin pump offer the company several points of attack for manipulation. These included, among other things unencrypted HTTP connections and readable VPN login data embedded in the program.
The researchers notified the company and have now gone public with the findings, as the company has not secured these vulnerabilities via an update in 18 months.
The answer from Medtronic
Medtronic has responded to the researchers. However - according to the researchers - very slowly and with little enthusiasm. In the end, Medtronic came to the conclusion that "the gap has no impact on the well-being of patients. Therefore, there is no need to close the gap with an update."
With more detail, Medtronic addresses the warning in their Security Bullet one. A technically sound risk analysis is presented there. The result of this is that "these vulnerabilities do not represent a new potential security risk". One of the reasons given is that the login data identified by the researchers only allows read-only access. Measures are also recommended, but these only concern handling. For example, access to the (physical) writing device should be protected.
Who is right?
It is the wrong question to ask who is right. There are several reasons for this:
First of all harmless points of attack often used for further attacks. Simply having read access to a system can be the first step towards gaining write access. How exactly this could happen is usually not even foreseeable. For this reason, vulnerabilities that are classified as unproblematic should also be eliminated in the case of security issues.
The second point is Liability. If the vulnerability is misused after all, this could be expensive for Medtronic. The liability is certainly mitigated by the fact that a risk analysis was carried out. Nevertheless, securing the vulnerability would have been the better alternative in terms of liability risk.
The third point is reputation, the reputation of the company. A case like this has the potential to Streisand effect to fall victim. When this case is covered in the mainstream press, many readers will not understand the details. They will remember that Medtronik failed to remove a potentially fatal software vulnerability.
Ethics
I have deliberately put ethical issues on the back burner. It would be desirable for companies to act ethically, especially in the medical environment. However, this is difficult to demand. Nevertheless, it would be desirable for companies to build safe products not only out of fear of liability, but also out of conviction.
What to do?
The developments in the Medtronic case point to inadequate communication within the company. The authors of the risk analysis certainly acted to the best of their knowledge and belief. However, it is astonishing that Medtronic's PR department published it in this way. It is also astonishing that the management did not demand a software update that at least cosmetically covers the gaps, or more desirably closes the gaps in depth.
Safety is a matter for the boss. Period. [tweetthis]Safety is a matter for the boss. Period.[/tweetthis]
The last aspect in particular is important: in companies where human lives are at stake, safety must be a top priority. Apart from ethics, this also makes business sense. After all, security weaknesses are dangerous even if they have not yet been exploited (PR disaster). And if they are exploited, it can mean the end of the company.






