Skip to main content

Hackers can gain control of an insulin pump to inject a harmful dose into patients

When someone mentions hacking, generally it’s about teens breaking into the government’s network or the latest retail/service breach grabbing the personal data of millions of customers. Cracking into an individual’s pacemaker or insulin pump doesn’t really come to mind, but it’s possible and does happen. Johnson & Johnson is actually warning patients now about a security vulnerability found in one of its insulin pumps.

The good news is that the risk of using the affected Animas OneTouch Ping insulin pump is extremely low, so there’s no need for panic. The bad news is that if exploited, hackers could overdose diabetic patients with insulin. Right now there are only around 114,000 patients who actually use this specific medical device.

Recommended Videos

The vulnerability was discovered by researcher Jay Radcliffe of the cybersecurity firm Rapid7 Inc., who also happens to be diabetic. Radcliffe revealed his findings to Johnson & Johnson in April and published the news on the Rapid7 blog on September 28. Johnson & Johnson is just now getting around to informing patients through standard mail.

Please enable Javascript to view this content

According to the product page, the Animas OneTouch Ping provides a Meter Remote so that patients can give themselves an insulin dose without having to touch the pump itself. In addition to checking blood sugar levels, the remote also allows users to remotely control pump functions, calculate how much bolus insulin is needed, and more.

The problem is that the wireless connection between the remote and the pump is not secure. They communicate in the 900MHz band using a proprietary Wi-Fi protocol based on “cleartext” communications. Without encryption, a hacker could potentially fake a Meter Remote connection and give a patient a harmful dose of insulin.

“Due to these insulin vulnerabilities, an adversary within sufficient proximity (which can depend on the radio transmission equipment being used) can remotely harm users of the system and potentially cause them to have hypoglycemic reaction, if he or she does not cancel the insulin delivery on the pump,” Radcliffe reports.

By gaining access to the connection between the pump and the remote, hackers can see the blood glucose results and the insulin dosage data. They gain access by sniffing the 5-packet “key” passed between the pump and remote, which remains the same each time the two devices are paired. This is supposedly to prevent other household remote controls from activating the pump.

“Communication between the pump and remote have no sequence numbers, timestamps, or other forms of defense against replay attacks,” Radcliffe added. “Because of this, attackers can capture remote transmissions and replay them later to perform an insulin bolus without special knowledge, which can potentially cause them to have hypoglycemic reaction.”

So what took so long for Johnson & Johnson to report the problem? The company had to reproduce Radcliffe’s finding before it warned patients of a potential problem. Brian Levy, chief medical officer with Johnson & Johnson’s diabetes unit, told Reuters they discovered a hacker could actually inject patients with a harmful dose of insulin from up to 25 feet away.

In a letter to patients, Johnson & Johnson said that OneTouch Ping owners who are worried about a potential hack can stop using the remote, or program the pump to limit the maximum dose of insulin. Users can also turn on the Vibrating Alert feature to warn of an insulin dose that is about to be initiated via the remote control. Animas provides a letter to patients here.

Kevin Parrish
Former Digital Trends Contributor
Kevin started taking PCs apart in the 90s when Quake was on the way and his PC lacked the required components. Since then…
ChromeOS 134 preview teases accessibility features, quick insert improvements
The back of the Asus Chromebook CX1.

The next ChromeOS update is expected to drop in the coming days and the chromeOS.dev team has once again shared notes of the features scheduled to come with the next version of the Chromebook operating system. According to the team, the initial ChromeOS 134 update will be available starting this coming Monday, March 17th. However, many of the features may arrive at dates beyond the primary rollout. 

The features previewed on ChromeOS 134 developers' notes so far have proven to be very interesting and functional, and this set is no different. The notes share details on improvements for Google’s Quick Insert feature, special enterprise features, more accessibility features, and content manageability tools. Here’s a rundown of what you can expect.   
Slow Keys
ChromeOS 134 has noted its commitment to improvements, including accessibility on its software with each version, and this function is another example. Slow Keys is a feature that can help users who require more time and attention in their typing tasks to press keys with intent. It should especially be helpful for users with conditions that affect their fine motor skills, such as tremors, arthritis, or numbness to the fingertips.

Read more
Report: Apple’s AI plans for Siri hit major roadblocks behind the scenes
Type to Siri being used with Apple Intelligence in macOS Sequoia.

A new report from Bloomberg has claimed that the Apple’s plans for an AI overhaul of its Siri voice assistant have not gone as smoothly as the brand originally hoped, but that plans plans may be subject to a delay.

The publication indicated that the Siri team recently had an all-hands meeting where Apple senior director Robby Walker, discussed the state of the project, calling the delay an “ugly” situation.

Read more
Mobile-based free VR tool is helping people beat speech anxiety
Person wearing a VR kit for speech training.

Virtual Reality was once considered a niche for video games, but over the years, it has found application in many areas. From finding a place in medical education and paving the way for immersive concerts to helping teens and adults deal with psychological distress, the applications of VR are now an ever-expanding domain.
The latest VR innovation comes from the University of Cambridge, and it aims to help people overcome speech anxiety and the fear of public speaking. The institution’s Immersive Technology Lab has launched a free VR training platform that focuses on accessibility and provides expert-curated course material.
Terrified of public speaking? This Cambridge VR solution could eliminate your fear
To that end, the team has created a system that doesn’t necessarily rely on an expensive VR headset. Instead, all it needs is the smartphone in your pocket to provide an immersive experience, fitted atop a mounting kit that can cost as little as $20 a pop.
The training material, on the other hand, is freely available via a website to anyone across the world. Moreover, it is also one of the first products of its kind with a dual-compatible VR player architecture, which means it works just fine with iPhones and Android devices.

“The platform has been built in such a way that whether a participant is using the latest standalone VR headset or an old smartphone inserted into a device mount, they will get the same content and the same experience,” says the team.
The idea is not too different from the Google Cardboard, which cost $15 roughly a decade ago and offered a low-cost route to experiencing VR content by using one’s smartphone. But unlike Google’s approach, we have now entered a market phase where “converter kits” are a lot more polished and use higher quality materials.

Read more