BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Wand Protocol: Full-Chain Attack on an FDA-Listed Fe
 rtility\n   Analyzer\n   Tags: Biohacking Village | Creator Talk/Panel\n  
  When: Sunday\, Aug 9\, 10:30 - 10:59 PDT\n   Where: LVCCW Level 1 Hall 3 
 1104 (Creator Stage 4) - [1]Map\n\n   Description:\n\n   This year's BHV t
 heme is access. This talk is about what happens when\n   access is granted
  to everyone who should not have it\, and about what\n   happens to patien
 t data once it leaves the device. We conducted a full\n   security assessm
 ent of a shipping consumer fertility hormone analyzer\n   — an FDA-liste
 d device used by millions of people to track LH\, FSH\,\n   estrogen\, and
  progesterone. In a post-Dobbs environment\, those\n   measurements are no
 t just health data. In 14 states\, they are\n   potential legal evidence. 
 We found no authentication anywhere in the\n   stack. From BLE proximity\,
  any attacker within approximately 30 meters\n   can silently rebind the d
 evice to an attacker-controlled account in\n   under 15 seconds using a ~$
 10 dongle and open-source tools. No\n   credentials. No pairing prompt. No
  notification to the user. The\n   protocol works exactly as designed. The
  companion app identifies\n   hardware by a substring check on the BLE adv
 ertisement name. Any\n   peripheral advertising a matching name receives t
 he user's live API\n   session token during the app's own handshake. That 
 token grants access\n   to the complete hormone history\, miscarriage stat
 us\, PCOS diagnosis\,\n   and fertility treatment records of any user whos
 e phone comes within\n   range. The cloud login endpoint issues session to
 kens without\n   verifying the password. Email address alone grants full a
 ccount\n   access. A hardcoded API key in the distributed APK grants read 
 and\n   write access to approximately 659\,000 user health profiles with n
 o\n   per-object authorization. Reproductive health data — including\n  
  miscarriage history — transmits to analytics vendors\, an advertising\n
    pixel\, and a customer data platform headquartered in Russia on every\n
    session open. This talk presents the full attack chain with live\n   de
 mos\, maps each finding to FDA's February 2026 premarket\n   cybersecurity
  guidance\, and closes with three concrete implementation\n   decisions th
 at would have prevented all of it. Coordinated disclosure\n   submitted to
  vendor\, FDA CDRH\, and CISA. All testing on\n   researcher-owned hardwar
 e and accounts.\n\n   SpeakerBio:  Gigi Xiaoqing Liu\n\n   Gigi Liu is a g
 raduate security researcher at Northeastern's Security\n   And Privacy Res
 earch (SPQR) Group under Professor Kevin Fu\, where her\n   work covers em
 bedded systems security\, medical device attack surfaces\,\n   and AI-gene
 rated media detection. She interns at Lila Sciences as a\n   Security and 
 Cloud Engineer\, building enterprise-wide agentic AI\n   security infrastr
 ucture and detection capabilities for unauthorized AI\n   activity across 
 cloud and SaaS environments.\n\n   Her technical work spans wireless proto
 col reverse engineering\, binary\n   exploitation\, web and mobile reverse
  engineering\, cloud and AI\n   security. She has applied these skills acr
 oss medical hardware\,\n   automotive platforms\, and enterprise cloud env
 ironments — from BLE\n   command injection on FDA-listed devices to CarP
 lay API exploitation to\n   building agentic AI detection controls at scal
 e. As a UCLA\n   psychobiology alum with a consulting background\, she bri
 ngs a\n   multidisciplinary lens to every system: understand what it's des
 igned\n   to do first\, then find where it breaks.\n\n   '\n\n   1. #LVCCW
 _Level1_Hall3\n\n\n
DTEND:20260809T175900Z
DTSTART:20260809T173000Z
LOCATION:Biohacking Village - LVCCW Level 1 Hall 3 1104 (Creator Stage 4)
SUMMARY:Wand Protocol: Full-Chain Attack on an FDA-Listed Fertility Analyze
 r
END:VEVENT
END:VCALENDAR
