You have a coronavirus. How hackers change PCR test results
An internet security researcher has discovered a vulnerability that can easily change the results of a home test for COVID-19. As it turned out, the attacker only needs access to Bluetooth. Gazeta.Ru has found out whether this method of substituting testing will be widespread among cybercriminals. bacobolts
The result of Ellume's home test for coronavirus can be
changed using modern technology, The Verge reports .
The device itself is a nasal swab gadget. The device
analyzes the data and then transmits it via Bluetooth to the corresponding
application in the phone, which displays and saves the test results.
According to Ken Gannon, security researcher at F-Secure, he
was able to intercept and alter the device's signal before the data entered the
application on the user's smartphone.
The researcher used an Android smartphone on which he had
root rights (superuser rights). Gannon connected and analyzed the data sent by
the test to the application.
Then he used two scripts that were able to successfully
change the negative test result to positive. According to him, the described
method works "in both directions".
The kit referred to in the study is an application for a
mobile phone and a special device that performs a COVID-19 test and reports the
test result via Bluetooth in the application, a cybersecurity expert at
Kaspersky Lab told Gazeta.Ru "Boris Larin .
"Judging by the report, the researchers were able to
parse the format of the commands transmitted over Bluetooth, and analyzed which
part of the team is responsible for the status of the test, and also found that
this result is protected only by means of cyclic redundancy code," Larin
said.
It was possible to obtain distorted results thanks to the
open architecture of the Android operating system, says Pavel Adylin, CEO of
Artezio (part of the LANIT group).
“Even without special knowledge, users can get unlimited
access rights to data and hardware of Android devices,” the expert explained.
According to him, the developers of the home testing
protocol simply did not take into account the possibility of using an already
compromised device.
“This kind of counterfeiting is unlikely to be widespread,
since the home testing protocol is likely to be improved to exclude
manipulation of the mobile device. As for the reliability of such testing
methods, there is always a possibility of distortion of the results for one
reason or another, ”Adylin said.
He noted that even when tests are carried out in medical institutions
on accurate and certified equipment, there is the possibility of testing
errors.
“The mentioned method can hardly be used further. The
publicity encourages developers of test protocols to correct errors and, I
think, in the future there will be a tool that can confirm the reliability of
the transfer of test data to a user's smartphone. But this does not mean that
the test results will be reliably protected. The higher the value of fake
testing, the higher the risks, ”Adylin notes.
The head of the information security audit department at
Infosecurity a Softline Company, Sergei Nenakhov, also doubts that this method
of changing the test results for coronavirus will be widespread.
“The device maker was immediately informed about it and,
most likely, a software update will be released. In addition, the procedure is
carried out in the presence of a company representative, who must monitor
compliance with the rules for taking analysis and using the mobile application,
which complicates the imperceptible operation of the modified program,
"the interlocutor of Gazeta.Ru concluded.