> Would you use a computer who's only ability was to manage an intravenous pump?
Yes, I would prefer exactly such a thing for my IV pump.
> Even with medical devices being highly audited, not running Flash or WebGL & not being on the Internet,
There absolutely are many many medical devices running Windows XP embedded plugged in to hospital LANs around the country as we speak.
In fact, I used to work on such a system. It was a total PoS from a security perspective. The mechanical engineers who designed it seriously didn't expect anyone would plug it into the LAN. Maybe they've improved it since then, I don't know. I no longer associate with those people.
Summary: Adobe Flash Player before 10.3.183.11 and 11.x before 11.1.102.55 on Windows, Mac OS X, Linux, and Solaris and before 11.1.102.59 on Android, and Adobe AIR before 3.1.0.4880, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-2445, CVE-2011-2451, CVE-2011-2452, CVE-2011-2453, CVE-2011-2454, CVE-2011-2455, and CVE-2011-2459. CVSS Severity: 10.0 (HIGH) Published: 11/11/2011
So I had to look back only 11 days for my example, and that's not to mention the 15 other Adobe bugs with CVEs published that week.
Still medical devices, like SCADA systems, do usually tend to suck because they're computer systems designed by people who've never secured a computer before. Guess what! Did you know you can kill someone wirelessly if they have a Medtronic insulin pump? http://www.reuters.com/article/2011/10/26/us-medtronic-idUST...
But that doesn't have much to do with my reasons for being wary of allowing WebGL.
Yes, I would prefer exactly such a thing for my IV pump.
> Even with medical devices being highly audited, not running Flash or WebGL & not being on the Internet,
There absolutely are many many medical devices running Windows XP embedded plugged in to hospital LANs around the country as we speak.
In fact, I used to work on such a system. It was a total PoS from a security perspective. The mechanical engineers who designed it seriously didn't expect anyone would plug it into the LAN. Maybe they've improved it since then, I don't know. I no longer associate with those people.
> they still can end up with life threatening bugs. http://en.wikipedia.org/wiki/Therac-25
Bonus points for knowing your history, but note that you're going back 25 years for such a bug.
Adobe, lets see ... http://web.nvd.nist.gov/view/vuln/search-results?query=adobe...
There we go CVE-2011-2460:
Summary: Adobe Flash Player before 10.3.183.11 and 11.x before 11.1.102.55 on Windows, Mac OS X, Linux, and Solaris and before 11.1.102.59 on Android, and Adobe AIR before 3.1.0.4880, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-2445, CVE-2011-2451, CVE-2011-2452, CVE-2011-2453, CVE-2011-2454, CVE-2011-2455, and CVE-2011-2459. CVSS Severity: 10.0 (HIGH) Published: 11/11/2011
So I had to look back only 11 days for my example, and that's not to mention the 15 other Adobe bugs with CVEs published that week.
Still medical devices, like SCADA systems, do usually tend to suck because they're computer systems designed by people who've never secured a computer before. Guess what! Did you know you can kill someone wirelessly if they have a Medtronic insulin pump? http://www.reuters.com/article/2011/10/26/us-medtronic-idUST...
But that doesn't have much to do with my reasons for being wary of allowing WebGL.