Become a fan of Slashdot on Facebook

 



Forgot your password?
typodupeerror
Security Government Medicine

FDA Calls On Medical Devicemakers To Focus On Cybersecurity 40

alphadogg writes "Medical device makers should take new steps to protect their products from malware and cyberattacks or face the possibility that U.S. Food and Drug Administration won't approve their devices for use, the FDA said. The FDA issued new cybersecurity recommendations for medical devices on Thursday, following reports that some devices have been compromised. Recent vulnerabilities involving Philips fetal monitors and in Oracle software used in body fluid analysis machines are among the incidents that prompted the FDA to issue the recommendations."
This discussion has been archived. No new comments can be posted.

FDA Calls On Medical Devicemakers To Focus On Cybersecurity

Comments Filter:
  • Simple standard? (Score:4, Interesting)

    by Okian Warrior ( 537106 ) on Friday June 14, 2013 @06:41PM (#44012013) Homepage Journal

    Network security is an add-on, largely viewed as an externality by corporations.

    I think that it's largely because of this (and that mostly due to Microsoft) that people don't use good security features.

    Suppose the socket layer had a function to generate a key pair, and a function call to set the key used for encoding and decoding. (Possibly a bit in the protocol to send a message using or not-using encryption). If it was that simple most products would use it, certainly safety-certified products would use it.

    (There's Transport Layer Security [wikipedia.org], but it's not really simple to use.)

    Since there is no simple universal way to use good security, everyone ends up having to implement their own version, which costs time and money.

    Simple secure communications should be an OS feature.

  • by Relic of the Future ( 118669 ) <dales&digitalfreaks,org> on Friday June 14, 2013 @07:31PM (#44012273)
    Since I helped write a system that pulled live data from medical devices (during surgery) to update patient records on the fly, and that, eventually, those records have to be sent to someone else (using the internet): No. You can't just run an internal network with no access to the internet.

    Build layers of security. Don't use hard-wired passwords. I.e., Stop being stupid about security. But no, you can't just air gap.

Real Users never know what they want, but they always know when your program doesn't deliver it.

Working...