Bartek Górkiewicz
Bartek Górkiewicz is a Senior Application Security Engineer at Doyensec and a core maintainer of the InQL GraphQL security scanner. Previously, he worked as a Security Engineer at Idemia, where he gained experience testing systems related to payments and identity. Outside of his main role, he is an active bug bounty hunter who has discovered several vulnerabilities across enterprise platforms which were credited with CVEs. His background is primarily in web and mobile security, but he is actively expanding his research into IoT and embedded device security.
Session
Continuous glucose monitors (CGMs) stream health information over Bluetooth Low Energy from body-worn sensors to smartphones and the vendors’ clouds. Millions of people depend on this communication system every day. However, existing CGM regulations tend to focus on medical-device compliance and operational requirements, while their security posture as connected medical IoT devices is often not fully evaluated.
Over a two-month research effort, we conducted a comparative security assessment of four commercial continuous glucose monitoring (CGM) sensors, covering wireless pairing mechanisms, mobile applications, embedded interfaces, and portions of the supporting cloud infrastructure. Across multiple vendors, we identified recurring architectural weaknesses affecting user device trust, communication security, sensor management functionality, and backend authorization controls.
Guided by a detailed threat model, we analyzed both the design and implementation decisions behind these platforms. In this talk, we will demonstrate how attackers in close proximity can abuse weaknesses in device pairing and trust establishment to impersonate trusted devices, why protocol obscurity at the wireless layer fails as a security boundary, and what manufacturers must change to build secure CGM ecosystems.
Attendees will leave with a clear understanding of the relevant threat scenarios, the technical flaws introduced during the design and manufacturing of these devices, and the broader implications such weaknesses have in today’s always-connected society. The talk will also highlight how insecure wireless connectivity, weak trust assumptions, and poor security engineering practices can directly impact the safety, privacy, and reliability of modern medical ecosystems.