
Could someone hack your pacemaker? At TEDxMidAtlantic, Avi Rubin explains how hackers can compromise cars, smartphones, and medical devices, and warns us about the dangers of a growing threat. (Filmed at TEDxMidAtlantic.)
Watch Avi Rubin 's video , the translation follows below.
Avi Rubin 0:11 I'm a computer science professor, and my field of study is computer and information security. When I was a student, I overheard my grandmother describing to an elderly friend of hers what my job was. Apparently, I was responsible for making sure that no one stole the computers from the university. (Laughter) And, you know, that's a perfectly reasonable thing for her to think about, because I told her I worked in computer security, and it was interesting to get her perspective.
Avi Rubin 0:47 But that's not the most ridiculous thing I've ever heard anyone say about my job. The most ridiculous thing I've ever heard, I was at a party, and a woman heard that I work in computer security, and she asked me if -- she said her computer had been infected with a virus and she was very worried that she might get sick from it, that she might catch this virus. (Laughter) I'm not a doctor, but I reassured her that it was extremely unlikely that that would happen, but if she felt more comfortable, she could use latex gloves when she was on the computer, and there would be absolutely no problem with that.
Avi Rubin 1:24 I'm going to go back to this idea of being able to get a virus from your computer, in a serious way. Today I'm going to talk to you about some hacks, some real cyberattacks that people in my community, the academic research community, have done, which I don't think most people know about, and I think it's very interesting and scary, and this discussion is like saying the best hacks from the academic security community. None of this has been done by me. It's all work that my colleagues have done, and I actually asked them for the slides and incorporated them into this talk.
Avi Rubin 1:58 So the first thing I'm going to talk about is implanted medical devices. In our time, medical devices are very technologically advanced. You can see that in 1926, the first pacemaker was invented. In 1960, the first internal pacemaker was implanted, hopefully a little smaller than the one you see there, and the technology continues to evolve. In 2006, we reached a major milestone from a computer security perspective. And why do I say that? Because that's when implantable devices inside people started to have networking capabilities. One thing that's of personal interest to us is the observation of Dick Cheney's device, he had a device that pumped blood from the aorta to another part of the heart, and as you can see, there, at the bottom, it was controlled by a computer, and if you ever think that software responsibility was very important, put one of those inside you.
Avi Rubin 2:52 Now what a research team did was they took what's called an ICD (Implantable Defibrillator). It's a defibrillator, and it's a device that's implanted in a person to control their heart rate, and they've saved a lot of lives. Now so that you don't have to open the person up every time you want to reprogram their device or do some diagnostic tests, they converted it so that it could communicate wirelessly, and what this research team did is they decompiled the wireless protocol, and they built the device that you see here in the picture, with a little antenna, that could talk the protocol to the device, and therefore control it. In order to make their experiment real -- they couldn't find volunteers, so they went and got some ground beef and some bacon and rolled it up to about the size of a human member where the device would fit, and they stuck it inside of it to make their experiment somewhat realistic. They did many, many successful attacks. The one I'm going to highlight here changes the patient's name. I don't know why you would want to do that, but I certainly wouldn't want them to do that to me. And they were able to change treatments, as well as disable the device -- and this is with a real, commercial, off-the-shelf device -- just by decompiling it and sending it wireless messages.
Avi Rubin 4:06 A radio show said that some of these ICDs could be disrupted by simply holding a pair of headphones over them.
Avi Rubin 4:15 Now, wireless connections and the Internet can greatly improve healthcare. There are several examples on screen of situations where doctors are trying to implant devices inside people, and now all of these devices are established to communicate wirelessly, and I think that's fantastic, but without a full understanding of reliable computing power, and without an understanding of what attackers can do and the security risks from the beginning, there's a great deal of risk in that.
Avi Rubin 4:41 Okay, let me change the subject and present you with another goal. I'm going to present you with a few different goals like this, and this is my talk. We're going to look at cars.
Avi Rubin 4:47 This is a car, and today it has a lot of components, a lot of electronics in it. It has many, many different computers inside it, more processors than my lab had when I was in college, and they're connected by a wired network. There's also a wireless network in the car, which is accessible in many different ways. So there's Bluetooth, there's satellite radio, there's actually wi-fi, there's sensors in the wheels that wirelessly transmit tire pressure to a controller in the car. The modern car is a sophisticated multi-computer device.
Avi Rubin 5:25 And what if someone wanted to attack it? Well, that's what the researchers we're going to talk about today did. They basically stuck an attacker on the wired network and the wireless network. Now, they have two areas that they can attack. One is wireless, short-range, where you can communicate with the device in person, either via Bluetooth or wi-fi, and the other is long-range, where you can communicate with the car over the cellular network, or through one of the radio stations. Think about it. When a car receives a radio signal, it's processed by software. This software has to receive and decode a radio signal, and then figure out what to do with it, even if it's just the music that needs to play on the radio, and the software that does this decoding, if it has any bugs, could create a vulnerability and someone could hack the car.
Avi Rubin 6:12 The way the researchers did this work is, they read the software in the integrated computer systems that were in the car, and then they used sophisticated decompilation tools to figure out what that software was doing, and then they found vulnerabilities in that software, and then they built special programs to exploit those vulnerabilities. And they did their attacks in real time. They bought two cars, and I guess they have a better budget than I do. The first threat model was to see what someone could do if an attacker got access to the car's internal network. Okay, think about it this way, someone goes to your car, messes with it, and then they leave, and now, what kind of problems do you have? The other threat model is that they communicate with you in real time over one of the wireless networks like a cell phone, or something like that, without ever having physical access to your car.
Avi Rubin 7:05 This is what the setup looks like for the first model, where you can access the car. They put a laptop in, and they connected to the diagnostic unit on the car's network, and they did all this nonsense, like here's a picture of the speedometer showing 140 miles per hour, while the car is parked. Once you have control of the car's computers, you can do anything. Now you might say, "Okay, that's stupid." So what if you make the car always show that it's going 30 kilometers per hour slower than it's actually going? You might get a lot of speeding tickets.
Avi Rubin 7:33 Then they went to an abandoned runway with two cars, the target car and the car chasing it, and they did other attacks. One of the things they were able to do from the attack car is make the other car brake, just by hacking the computer. They were able to disable the brakes. They were also able to install malware that wouldn't start and wouldn't activate until the car did something like go over 30 kilometers per hour, or something like that. The results are amazing, and when they gave this talk, even though they gave this talk at a conference to computer security researchers, everyone was shocked. They were able to take over several critical computers inside the car: the brakes, the lighting, the engine, the dashboard, the radio, etc., and they were able to do it in real commercial cars that they bought using the radio network. They were able to access every single piece of software that controlled every single wireless feature of the car. All of this was implemented successfully.
Avi Rubin 8:35 How would you steal a car in this model? Well, you take control of the car by a cache overflow due to a software vulnerability, something like that. You use the GPS in the car to locate it. You remotely unlock the doors through the computer that controls them, you start the engine, you bypass the immobilizer, and you have a car.
Avi Rubin 8:53 The tracking was really interesting. The authors of the study have a video where they seem to take control of a car and then turn on the microphone in the car, and listen to the car while they locate it via GPS on the map, and so this is something that the drivers of the car would never know was happening.
Avi Rubin 9:11 Did I scare you? I have a few more of these interests. These are from a conference I went to, and they amazed me, and I said, "I have to share this with other people.".
Avi Rubin 9:21 This was Fabian Monrose's lab at the University of North Carolina, and what they did was something that was kind of intuitive when you look at it, but also kind of amazing. They videotaped people on a bus, and then they processed the video. What you see here, in number one, is the reflection in someone's glasses from their smartphone as they type. They wrote software to stabilize -- even if they were on a bus and maybe someone was holding their phone at an angle -- to stabilize the phone, to process it, and you might know that on your smartphone, when you type a password, the keys bounce a little bit, and they were able to use that to represent what they were typing, and they had a language model to detect the typing. What was interesting about the videotaping on a bus is that they were able to produce exactly what people were typing on their smartphones, and then they had an amazing result, which is that their software did it, not only for their target, but also for others who happened to be in the image by accident, they were able to produce what those people had typed, and that was kind of like an accidental feat of what their software did.
Avi Rubin 10:26 I'll show you two more. One is the P25 radios. The P25 radios are used by police and various government agencies and people in combat to communicate, and there's an encryption option on these phones. This is what this phone looks like. It's not really a phone. It's more of a two-way radio. Motorola makes the most common one, and you can see them being used by intelligence agencies, they're used in combat, they're very common in the United States and elsewhere. So one thing that researchers wondered was can they block it, right? You could do a denial of service attack, because they're the first responders? So, would a terrorist organization want to block police and fire communications in an emergency? They found that there's a GirlTech text messaging device that happens to operate on the exact same frequency as the P25, and they made what they call My First Jammer. (Laughter) If you look closely at this device, it has a switch for encryption or plain text. Let me move the slide forward, and now I'm going to go back. Can you see the difference? This is plain text. This is encrypted. There's a little dot that appears on the screen, and a little tiny flip of the switch. And so the researchers asked themselves, "I wonder how many times very secure, important, sensitive conversations are happening on these wireless phones, where they forget to decrypt and don't notice that they're not encrypting?"
Avi Rubin 11:50 So, they bought a scanner. These are completely legal and they run on the P25 frequency, and what they did is they would go around the frequencies and write software to listen to them. If they found encrypted communication, they would stay on that channel and make a note, this is a channel that these people, these police departments, communicate on, and they went to 20 metropolitan areas and listened to conversations that were happening on those frequencies. They found that in each metropolitan area, they could pick up over 20 minutes a day of plain text communication. And what kind of things were they talking about? Well, they found names and information about secret informants. They found information that had been recorded on wiretaps, various crimes that they were discussing, sensitive information. It was mostly police and criminal. They went and reported it to law enforcement after they anonymized it, and the vulnerability here is simply that the user interface wasn't good enough. If you're talking about something really secure and sensitive, you should be really clear that this conversation is encrypted. That's pretty easy to fix.
Avi Rubin 12:56 The last thing I thought was really, really cool, and I just had to show you, it's probably not something you're going to lose sleep over like cars or defibrillators, but it records keystrokes. Now, we've all seen smartphones before and after. Every security expert wants to hack a smartphone, and we tend to look at the USB port, the GPS for tracking, the camera, the microphone, but no one had ever looked at the accelerometer. The accelerometer is what determines the vertical orientation of the smartphone. And so they had a simple setup. They put a smartphone next to a keyboard, and they had someone type, and then their goal was to use the vibrations created by the typing to measure the changes in the accelerometer readings to determine what was typed. Now, when they tried this on an iPhone 3GS, this is a graph of the disturbances created by typing, and you can see that it's very difficult to tell when someone was typing or what they were typing, but the iPhone 4 has greatly improved the accelerometer, and so the same measurement produced this graph. Now this gave you a lot of information as long as someone was typing, and what they did is they used advanced artificial intelligence techniques, called machine learning, to have a training phase, and so they probably had students type different things, and learn, have the system use the machine learning tools that were available to learn what they were typing and match it to the accelerometer readings. And then there's the attack phase, where you have someone type something, you don't know what it was, but you use the model that you created in the training phase to figure out what they typed. They were very successful. This is an article from USA Today. They typed, "The Illinois Supreme Court has ruled that Rahm Emanuel can run for mayor of Chicago" -- see, I linked it to the previous speech -- "and ordered him to stay on the ballot." Now, the system is interesting because it produced "The Illinois Supreme" and then it wasn't certain. The model produced a few choices, and that's the beauty of some artificial intelligence techniques, is that computers are good at some things, humans are good at other things, take the best of both and let humans figure it out. Don't waste computational cycles. A human is not going to think they're the ultimate power. It's the Supreme Court, right? And so, together, we're able to replicate typing just by measuring the accelerometer. Why is that important? Well, with the Android platform, for example, the developers have a manifest where every device there, the microphone, etc., has to be registered if you're going to use it so that hackers can't take control, but nobody controls the accelerometer.
Avi Rubin 15:36 So what's the point? You can leave your iPhone next to someone's keyboard, and just walk out of the room, and then you can retrieve whatever they were doing, even without using the microphone. If someone can put malware on your iPhone, they can then access what you type every time you put your iPhone next to your keyboard.
Avi Rubin 15:51 There are several other notable attacks that I unfortunately don't have time to mention, but the one I wanted to highlight was a team from the University of Michigan who were able to take voting machines, Sequoia AVC Edge DREs that were going to be used in the New Jersey election, that had been left in a hallway, and they put Pac-Man on them. And they ran the Pac-Man game.
Avi Rubin 16:10 What does all this mean? Well, I think society tends to adopt technology really quickly. I love the next new gadget. But it's really important, and these researchers are showing, that the developers of these things need to consider security from the beginning, and they need to realize that they may have a threat model, but the attackers may not be so good at limiting themselves to that threat model, and so you need to think differently, unconventionally.
Avi Rubin 16:35 What we can do is know that devices can be compromised, and anything that has software in it is going to be vulnerable. It's going to have bugs. Thank you very much. (Applause)
