TY - CHAP A1 - Aviram, Nimrod A1 - Schinzel, Sebastian A1 - Somorovsky, Juraj A1 - Heninger, Nadia A1 - Dankel, Maik A1 - Steube, Jens A1 - Valenta, Luke A1 - Adrian, David A1 - Halderman, J. Alex A1 - Dukhovni, Viktor A1 - Käsper, Emilia A1 - Cohney, Shaanan A1 - Engels, Susanne A1 - Paar, Christof A1 - Shavitt, Yuval T1 - DROWN: Breaking TLS Using SSLv2 T2 - 25th Usenix Security Symposium Y1 - 2016 SP - 689 EP - 706 PB - Usenix Association. CY - Austin, TX. ER - TY - CHAP A1 - Puschner, Endres A1 - Saatjohann, Christoph A1 - Willing, Markus A1 - Dresen, Christian A1 - Köbe, Julia A1 - Rath, Benjamin A1 - Paar, Christof A1 - Eckardt, Lars A1 - Haverkamp, Uwe A1 - Schinzel, Sebastian T1 - Listen to Your Heart: Evaluation of the Cardiologic Ecosystem T2 - ARES 2021: The 16th International Conference on Availability, Reliability and Security N2 - Modern implantable cardiologic devices communicate via radio frequency techniques and nearby gateways to a backend server on the internet. Those implanted devices, gateways, and servers form an ecosystem of proprietary hardware and protocols that process sensitive medical data and is often vital for patients’ health. This paper analyzes the security of this Ecosystem, from technical gateway aspects, via the programmer, to configure the implanted device, up to the processing of personal medical data from large cardiological device producers. Based on a real-world attacker model, we evaluated different devices and found several severe vulnerabilities. Furthermore, we could purchase a fully functional programmer for implantable cardiological devices, allowing us to re-program such devices or even induce electric shocks on untampered implanted devices. Additionally, we sent several Art. 15 and Art. 20 GDPR inquiries to manufacturers of implantable cardiologic devices, revealing non-conforming processes and a lack of awareness about patients’ rights and companies’ obligations. This, and the fact that many vulnerabilities are still to be found after many vulnerability disclosures in recent years, present a worrying security state of the whole ecosystem. Y1 - 2021 U6 - http://nbn-resolving.de/urn/resolver.pl?urn:nbn:de:hbz:836-opus-139012 ER -