A follow up to my post from December - I got the new OmniPod insulin pump. It still runs Linux. It still violates the GPL.
Original post for people who didn't see it:
https://www.reddit.com/r/linux/comments/1puojsr/the_device_that_controls_my_insulin_pump_uses_the/. tl;dr: Major insulin pump company Insulet used a cheap phone that ran Linux 3.18.19 to control their insulin pump, refused to share the kernel source, violating the GPL.
So, I recently upgraded to Insulet's new pump, the OmniPod 5, and the new OmniPod 5 PDM has a number of improvements compared to the last one. It has Linux 4.9 (congrats omnipod, you're now on par with my 8 year old Pixel 3 XL) USB-C (on par with my 9 year old LG G6), 64-bit processor (on par with my 11 year old Galaxy S6), Android 10 (on par with my 13 year old Nexus 5), and most important for a medical device, a locked bootloader (on par with my 15 year old Motorola XT860 4G)
So again, it's made by Hong Kongese company Nuu, I contacted both Nuu and Insulet, Nuu just said they couldn't provide kernel source, Insulet didn't reply to my email, just like what happened with the OmniPod DASH.
4.9 and Android 10, also both EOL systems, but it's a massive upgrade over the DASH's 3.18 and Android Marshmallow. At least Insulet has implemented an OTA system, so security issues can be fixed if people start exploiting them (of course, if someone decides to start backporting, that does exist for Android 10, not sure about kernel 4.9). Some people in my last thread pointed out that Insulet has to go through FDA, Health Canada, EMA, etc.'s regulatory and testing process which is why it's stuck on such old versions, and that's understandable. At least the OTA system exists now so they can fix things if people start exploiting it (even though it will take months)
How are they on security? Well, still not great. It has a constant Wi-Fi connection now, mine even came with an AT&T SIM (even though i live in canada?) so it can have a connection when I'm not home. Much bigger exploit risk with that. And it still communicates with the pod over Bluetooth, which is a big yikes. As I mentioned earlier, they have locked the bootloader, so that's a major security hole gone, but it can still be easily unlocked with mtkclient. Still not a big issue, as that requires physical access to the PDM and a computer with mtkclient installed, however if a root exploit is discovered, you probably could modify seccfg to unlock the bootloader. Insulet should really do what companies like Samsung and Xiaomi do, if a seccfg modification is detected, instantly flip it back. The biggest issue though, they now store the OmniPod app in userdata. All it takes is a factory reset, and the PDM is bricked for medical purposes. I'm sure there are exploits that can be used to trigger a reset. I'm really not sure why Insulet did this, the old PDM stored it in /system, which can't be modified without root.
Main thing I'm focused on though is again, the GPL violation. I really hate the fact that Insulet is so adamant on protecting their kernel source, it honestly feels really sketchy to me.
A lot of people in my last thread told me to try reaching out to the SFC, I actually did, about a year prior to me making that post, but they never responded. Someone did reach out to me saying that someone at the SFC did want to talk to me, and they provided their email, but I was busy at the time and never got around with it, and I'm not sure if that person is still interested in this.
A lot of people pointed out that Nuu is a Chinese company, so trying to get the kernel source is a lost battle, I don't believe so. The actual pump is made by Insulet, an American company, and so is all the software on the PDM. Later hardware revisions of the DASH PDM also can't load the kernel from earlier DASH PDMs or the Nuu A1+, indicating that Insulet made some sort of modification.
If anyone has any ideas on how I can get the kernel source, please tell me. It is not right for the 2nd largest insulin pump manufacturer in the world to be getting away with