Re: [Full-disclosure] Reliable reports on attacks on medical software and IT-systems available?

2010-08-25 Thread Shawn Merdinger
Hi Halfdog, While I have not come across any specific documentation of willful attacks, security (and software quality) issues abound in the medical device space. You might try researching some of the databases at the FDA [1]. In particular, a good place to start is the FDA MAUDE database (Manuf

Re: [Full-disclosure] Reliable reports on attacks on medical software and IT-systems available?

2010-08-13 Thread Jeffrey Walton
On Wed, Aug 11, 2010 at 10:48 PM, wrote: > halfdog wrote: >> Paul Schmehl wrote: >>> --On Tuesday, August 10, 2010 21:03:35 + halfdog >>> wrote: [SNIP] * Medical personal in hospitals with high grade of IT-system usage are so trained and skilled, so that they detect manipulation

Re: [Full-disclosure] Reliable reports on attacks on medical software and IT-systems available?

2010-08-12 Thread Paul Schmehl
--On Wednesday, August 11, 2010 22:48:11 -0400 casp...@random-interrupt.org wrote: > > Some hospitals have a well guarded network. Some Medical IT systems are > secure. Some are not. The Threat Environment for medical institutions is > similar to any other large company, except there's the added r

Re: [Full-disclosure] Reliable reports on attacks on medical software and IT-systems available?

2010-08-12 Thread Caspian
halfdog wrote: > Paul Schmehl wrote: >> --On Tuesday, August 10, 2010 21:03:35 + halfdog >> wrote: >>> * There are reports, but I do not know about them (so I'm asking around) >>> >> Most likely answer. I know about some, but I'm not telling you. Or anyone >> else >> for that matter. :-)

Re: [Full-disclosure] Reliable reports on attacks on medical software and IT-systems available?

2010-08-11 Thread halfdog
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 BMF wrote: > On Tue, Aug 10, 2010 at 2:03 PM, halfdog wrote: >> Possible answers might be (sorted by probability): > > * There is no money in harming or killing patients. Good point, although I guess that there could be quite some money in it. But w

Re: [Full-disclosure] Reliable reports on attacks on medical software and IT-systems available?

2010-08-11 Thread halfdog
Paul Schmehl wrote: > --On Tuesday, August 10, 2010 21:03:35 + halfdog wrote: >> * All hackers keep some sense of ethics, so that they feel it is OK to attack >> "technical" targets but find it inacceptable to attack the health of innocent >> people (if this is the main cause, terrorists might

Re: [Full-disclosure] Reliable reports on attacks on medical software and IT-systems available?

2010-08-10 Thread BMF
On Tue, Aug 10, 2010 at 2:03 PM, halfdog wrote: > Possible answers might be (sorted by probability): * There is no money in harming or killing patients. BMF ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-char

Re: [Full-disclosure] Reliable reports on attacks on medical software and IT-systems available?

2010-08-10 Thread Paul Schmehl
--On Tuesday, August 10, 2010 21:03:35 + halfdog wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > Just to clarify some points from off-list messages: > > I have no knowledge of ongoing or planned attacks. I was just searching for > historic reports of any age. I wonder why powerpl

Re: [Full-disclosure] Reliable reports on attacks on medical software and IT-systems available?

2010-08-10 Thread halfdog
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Just to clarify some points from off-list messages: I have no knowledge of ongoing or planned attacks. I was just searching for historic reports of any age. I wonder why powerplants, telephone systems, corporate IT systems are frequently affected by a

[Full-disclosure] Reliable reports on attacks on medical software and IT-systems available?

2010-08-10 Thread halfdog
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 I am searching for reliable reports on attacks on medical software and infrastructure ___aiming to harm or kill patients___. There are quite a few reports on data theft combined with blackmailing or data disclosure but rather no information if there we