Showing posts with label IoT. Show all posts
Showing posts with label IoT. Show all posts

Sunday, March 24, 2024

Medical Device Connectivity

 

With our new technology advancing so rapidly on different fronts, the nuances in applications are growing. One of these is connectivity. Most of the public is aware of connectivity in vehicles. We see this as we’re driving with the infotainment system, making calls, or following a map. This is not by far the only industry embracing connectivity.

Another is the medical device field. Globally, this is estimated to triple its value by 2028. This may take the form of home health monitors, or cardiac monitors reporting data to the backend or receiving updates.

There are several factors driving this massive increase. One of these includes telehealth. Our population has endured much through the pandemic and post-pandemic. This has shaped how we shop, gather information, and utilize healthcare. The need and want for home healthcare has assisted in the growth. If the patients didn’t want it, there wouldn’t be the need or market for this. Related to this is remote patient monitoring. This may involve cardiac or other monitoring. This advance allows the patient to stay in their home while the device collects the data and uploads it to the doctor or other device.

While this works great for the patient and doctor, this also adds to the attack surface and provides another point to test. This is another area to secure, test, and maintain through the SDLC. 

Services 

Enterprise and Embedded System Cybersecurity Engineering & Architecture


Red Team Product Pentesting   |   HW & SW BoMs  |   CBoM  | 

Vulnerability Management   |   Tabletop Exercises (TTX)   | 

Embedded Systems Architecture   |   Threat Intelligence   | 

TARA (Threat Assessment and Remediation Analysis) |

Supply Chain Cybersecurity Review 

Reverse Engineering


 charles.parker@mielcybersecurity.net 810-701-5511


IoT Devices Need Cybersecurity Attention

 IoT devices have evolved and expanded into commercial, and consumer uses. These appear throughout people’s homes with refrigerators, ovens, thermostat, light bulbs, and many other pieces of equipment.

Smart thermostats have become more prevalent in residences in the last few years. These are a nice addition in that these are trained to learn your optimal temperature, when you on average are in the house, and other useful assists.

While these have beneficial aspects with this, let’s not forget about detriments. When smart thermostats have not included cybersecurity through their dev cycle and SDLC, you can be answering many questions from clients, federal agencies, and other interested persons and stakeholders when something goes wrong (i.e., a significant compromise).

Recently two models for smart thermostats have been noted to have multiple security vulnerabilities. When successfully exploited, the bad actors would be executing the code they wanted on the device. The device could be weaponized with modified or rogue firmware.

The vulnerability allows an unauthenticated connection from a local network. The attack point is the WIFI microcontroller. This acts as a network gateway. This has been corrected, but only after the vulnerability had been known and open. This emphasizes the need for cybersecurity to be applied through the dev cycle, with security being at each gate. This also requires staff being comfortable in working with embedded systems, and all the nuances associated with these. Embedded systems require a different set of skills, different than the traditional IT.


Services 

Enterprise and Embedded System Cybersecurity Engineering & Architecture


Red Team Product Pentesting   |   HW & SW BoMs  |   CBoM  | 

Vulnerability Management   |   Tabletop Exercises (TTX)   | 

Embedded Systems Architecture   |   Threat Intelligence   | 

TARA (Threat Assessment and Remediation Analysis) |

Supply Chain Cybersecurity Review 

Reverse Engineering


 charles.parker@mielcybersecurity.net 810-701-5511


 

Medical IoT Devices

 The technology with medical devices and the protocols continue to improve. For example, we started with WIFI, moved to BlueTooth, and improved to BLE (BlueTooth Low Energy). There are many other examples throughout the products. One of the latest pushes is for AI integration. This has vast potential to improve the entire device’s operations and security. The full integration of IoT into medical devices cannot be overlooked.

There are several factors driving this. There is an increasing demand for remote patient monitoring. Our population is aging. The demographics are clear. The aging population has more chronic diseases, which tends to need more of this remote patient monitoring. These can provide real-time monitoring for the patient’s vital signs, for example. This allows for ease of collecting data and proactive management for chronic diseases.

The connectivity has also been beneficial. The updated protocols allow for the ease of data transmission. These also have greater security, which likewise is a bonus.

With the vast amount of data collected, the patient’s doctors can provide a much more specialized level of patient care. The diagnosis and treatment have the potential to be specifically tailored for them.

With the ease of use, functionality, and improved security, these may be used in many more types of facilities. This includes hospitals, rehabilitation centers, homes, and other facilities.

 



Services 

Enterprise and Embedded System Cybersecurity Engineering & Architecture


Red Team Product Pentesting   |   HW & SW BoMs  |   CBoM  | 

Vulnerability Management   |   Tabletop Exercises (TTX)   | 

Embedded Systems Architecture   |   Threat Intelligence   | 

TARA (Threat Assessment and Remediation Analysis) |

Supply Chain Cybersecurity Review 

Reverse Engineering


 charles.parker@mielcybersecurity.net 810-701-5511



Saturday, July 21, 2018

California Consumer Privacy Act of 2018 Applicability

California recently passed an aggressive data privacy law. The California legislature passed AB375 (The California Consumer Privacy Act of 2018), which by most accounts, is a strong push for consumer privacy. The law, in summary, requires companies collecting consumer data to disclose to the consumer the types of data collected and allowing the consumer the option of opting out from allowing the companies to sell the consumer’s data.

The new California law is a step towards the GDPR. This has much of the same intent, however, does not have the like exact goals, parameters, or negative reinforcement for not complying. Interestingly, the law requires the company to disclose the “category” of the third party receiving the consumer’s data, versus the name of the third party.

Consumers in California will, beginning on January 1, 2020 (the point at which the law takes effect), have the right to know all the data that has been collected for the individual consumer, to not allow their data to be sold, know what type of companies are receive the data, have their data deleted, the sources of the consumer data being sold, and other pertinent, germane facets of their data.

The headlines do indeed portray this as a far-reaching and direct victory for consumer rights. The general consumer thought is of this bringing the Google, Yahoo, and other internet-oriented companies to comply and be more transparent with their wishes. One should actually read the statute to garner a better understanding of the statute’s parameters. The California Consumer Privacy Act of 2018 does indeed affect businesses. As an example, section 1798.105 references a consumer’s right to request a business to delete any of the consumer’s personal information. On the initial reading, this would appear to affect all businesses collecting the personal information of a California citizen.

With this law, in general as it pertains to consumer’s data privacy, a business “...collects consumer’s personal information” (1798.140(c)(1)), has annual gross revenues greater than $25M (1798.140(c)(1)(A)), buys or receives the personal data of at least 50K consumers, households, or devices (1798.140(c)(1)(B), or derives 50% or more of the annual revenue from selling consumer’s personal information (1798.140(c)(1)(C)). As the statute is presently written, the “or” is important. Although this does narrow the potential field of companies having to comply to the statute, this would include the massive companies that comprise most of the work done in this endeavor. This statute also covers any device, which is any equipment that may connect to the internet or another device.

Embedded Devices
Embedded devices are throughout many industries and utilized with many devices consumers are in contact with daily, including vehicles. The connected vehicles have many opportunities to collect a consumer’s private information. If the person were to connect their cell phone to the vehicle with an app, the person’s contact list, smartphone call history, locations visited previously, credit card numbers, and other relevant data could be collected or in the least pass through the modules. With IoT devices, there may be present a portion of this data and other data points deemed confidential. These are only two examples of the many possible scenarios. In the present capacity, there is no legal advice and this is my opinion only, however, seemingly this new statute would apply to the embedded systems in vehicles, IoT devices, and other like devices collecting, processing, or managing a consumer’s private information and data in California. At this junction, this point is more of conjecture and to begin the thought process.

Is this were to be applicable to these systems, there would need to be completed much updating to the code for the present and future hardware, the affected policies, and noticing functions for the consumers.


Resources
California Legislative Information. (2018). Bill text - AB-375 Privacy: personal information: business. Retrieved from https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=201720180AB375

California Privacy. (n.d.). Californians for consumer privacy applauds successful passage of groundbreaking legislation. Retrieved from https://www.caprivacy.org/

Lecher, C. (2018, June 28). California just passed one of the toughest data privacy laws in the country. Retrieved from https://www.theverge.com/2018/6/28/17509720/california-consumer-privacy-act-legislation-law-vote