this post was submitted on 31 Jan 2025
71 points (96.1% liked)

Cybersecurity

6131 readers
114 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities [email protected] [email protected] [email protected] [email protected] [email protected]

Notable mention to [email protected]

founded 2 years ago
MODERATORS
top 11 comments
sorted by: hot top controversial new old
[–] [email protected] 25 points 3 days ago (2 children)

Those things shouldn't even be connected to the internet.

[–] [email protected] 12 points 3 days ago

Might not be. This could have simply been some IT guy noticing that something kept trying to ping the outside world.

[–] lgmjon64 8 points 3 days ago (1 children)

They connect to allow the vitals to be pulled into the EMR to allow continuous documentation of vitals for the anesthesia record or central patient monitoring. More and more frequently, the database is not onsite and is shared amongst several sites within a hospital system.

[–] [email protected] 10 points 3 days ago* (last edited 3 days ago) (1 children)

But the device itself shouldn't need internet connectivity for this. That networking should be handled by a local master device, the same way access control systems (e.g. Door badge readers, alarm monitoring, etc) work.

Then this device would only use a local, isolated network to access the master device.

[–] Landless2029 3 points 3 days ago

Agreed. Network connected to an isolation vlan without internet access

[–] [email protected] 19 points 3 days ago (1 children)

But I'm sure TikTok is fine and 100% to be trusted.

[–] [email protected] 11 points 3 days ago (1 children)

Or Facebook, fine too... and Instagram, X, Amazon, Microsoft, Google...

[–] WhiteRabbit_33 4 points 2 days ago

Yep, we need broad sweeping data privacy laws and audits in every country for all software. Not just fear mongering over other country's software.

[–] [email protected] 5 points 3 days ago (1 children)
[–] [email protected] 2 points 3 days ago (1 children)

Not sure. If true, prolly just generic data mining?

Would fake news ever report if it was pinging mountain view?

[–] [email protected] 4 points 3 days ago

Might also not be this device that was specifically targeted. The backdoor could have been placed in component firmware for any generic components this device uses, or in some general software library that gets used all over the place.