Medical device vuln allows hackers to falsify patients' vitals


Tip of the ice berg

Tip of the iceberg. Having worked in healthcare IT for over 10 years i doubt if most medical device companies even know what encryption is.

Hospital IT: "What OS is this running then?"

Supplier: "Ermmmm... Windows XP"

Hospital IT: "Really? Christ... what AV is on it?"

Supplier: "None... and you cant install one because that would mean we need to get FDA approval again for this"

H IT: "... did you just type 'admin admin' in that logon screen"

S: "Yeah... don't change it because its the same on them all... our support guys need them to be all the same"

H IT: "... you ever heard of Wannacry?"

S: "Is that a rapper?"


