Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Re: source code release, it seems like that could get rather messy for anyone using third party source code that isn't open.

Also, right away any sort of law like that would become incredibly nuanced. I have a pacemaker and there's an optional BLE app for it. Security through obscurity is lame, but I'd rather that app's source code not be dumped on the internet if the pacemaker company stops supporting it. The source code wouldn't keep the app going because it is dependent on the cloud, and would only be of value to folk trying to reverse engineer the diagnostic protocol. Personally that sounds like a lot of fun, but it's also hardwired into my heart...



On the other hand, something wired into your heart probably shouldn't rely on a proprietary app from a for-profit company that could drop support at any time...


It is what it is. As far as I know, there aren't any viable open source pacemakers. The existence of pacemakers is a wonderful modern marvel, and for-profit companies made it happen. It's likely $100 in materials, but my insurance probably paid at least $30K for the device and two leads. Considering how much engineering went into building it, I think it's a fair price. I once heard that there's roughly a 2:1 ratio between requirements and lines of code.


BLE strapped to one's heart sounds incredibly dystopic to me for some reason.

Source code for such products shouldn't be a problem because devices like these should definitely come with the necessary signature checks out of the box. Such key material shouldn't be released for anything important to one's health (medical devices, emergency devices, etc.). If you're at risk of having a heart attack when someone beats some kind of app code obfuscation then you're in for a bad time.

The cloud won't save you either. When the company disappears, their domain name expires eventually. Someone malicious could record and analyse API traffic and buy the domain to set up their own evil API server.

There are so many attack vectors for such a setup that I'm worried about how tech-ingrained such crucial devices are.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: