Live data from Hacker News

The gigantic and unregulated power plants in the cloud

berthub.eu

101–110 of 258 posts

Re: The gigantic and unregulated power plants in the cloud

#101
post #51

> In the Netherlands alone, these solar panels generate a power output equivalent to at least 25 medium sized nuclear power plants. Since this didn't pass the smell test: the author is looking at nameplate capacity, which is a completely useless metric for variable electricity production sources (a solar panel in my sunless basement has the same nameplate capacity as the same panel installed in the Sahara desert). Lo…

you are splitting hairs about the wrong issue. When it is sunny in the netherlands, it is likely sunny everywhere in NL because of how small the country is. This is the situation where having so much solar power capacity (kW) is dangerous. The risk scales with energy output but it would not term nameplate capacity a "completely useless metric".

> When it is sunny in the netherlands, it is likely sunny everywhere in NL because of how small the country is.

Often friends of mine who live in my city report rain when I see none, or no rain when it's raining outside my window. That's to say nothing of a location 30km away, where basically anything can happen. Do we live on the same planet?

Re: The gigantic and unregulated power plants in the cloud

#103

Earlier quoted context omitted.

What's the reasoning for not allowing both control paths, via cloud but also locally? So that people who can and want to, will use the local control.

Often there are two control paths. Sometimes more! Plenty of inverters will quite happily give you an RS232 port specification and you can create your own dongle! However, for purpose of the security of the nation's power grid, I don't just need my inverter to be secure, I need pretty much everyone's inverter to be secure. If an attack bricks 95% of solar inverters, the fact the nerdiest 5% of users have their invert…

> RS232 port specification and you can create your own dongle!

This is just a way of pretending to give access while making it as hard as possible. We are talking about a device that is already connected to the network. The local path is not some rest services, but a serial port for which I need to fabricate some hardware? Don't piss on me and tell me it's raining.

Re: The gigantic and unregulated power plants in the cloud

#104
post #80

Q: Are there no regulatory requirements for power plants of any kinds in EU, specially around cybersecurity? I do not allow any system into my environments (at home and at work) that requires a third party data connection function. There are way too many incidents where a provider, cloud or otherwise which required connection failed for various reasons. (e.g., Cisco Spark Board, Xerox ConnectKey, Google Cloud Print,…

How would one practically verify and certify cybersecurity of a product? Even payment smartcards sometimes come with non-malicious maintenance backdoors. There seem to be little to no academic theoretical basis to this whole software security thing.

Given the challenges of techniques like TLS interception (i.e. through pinning and other good security features), about the only measure I can see left is network isolation.

You can set up a local network that has no WAN connectivity on it. About anything else is difficult to verify even the most basic of security properties. Certifying is another step up (although you could argue certifying is just a third party saying something passed a finite list of tests) - the real challenge is defining a meaningful certification scheme.

There has been some good work towards consumer IoT device security (i.e. the 13 steps approach from the UK), that covers some of the lowest hanging fruit - https://www.gov.uk/government/publications/code-of-practice-...

The trouble is that these set out principles, but it's hard to validate those principles without having about the same amount of knowledge as required to build an equivalent system in the first place.

If you at least know the system is not connected to a WAN, you can limit the assurance required (look for WiFi funcitonality, new SSIDs, and attempts to connect to open networks), but at a certain point you need to be able to trust the vendor (else they could put a hard-coded "time bomb" into the code for the solutions they develop).

I don't see much value in the academic/theoretical approaches to verification (for a consumer or stakeholder concerned by issues like these), as they tend to operate on an unrealistic set of assumptions (i.e. source code or similar levels of unrealistic access) - the reality is it could take a few days for a good embedded device hacker to even get binary firmware extracted from a device, and source code is likely a dream for products built to the lowest price overseas and imported.

Re: The gigantic and unregulated power plants in the cloud

#105

Earlier quoted context omitted.

What's the reasoning for not allowing both control paths, via cloud but also locally? So that people who can and want to, will use the local control.

Cheapness. It would require to be at least semi secure, application on phone would need to find those devices locally and it should be synchronized with cloud anyway, synchronization is error prone and we had problems with devices sometimes responding twice or very slowly through local interface (through cloud was much faster, no idea why, not our firmware). Also not enough people requesting that feature, most don't…

I have some shelly devices which manage to do all that, and cost next to nothing. Work with local rest services or cloud, password protection, TLS. Sure, it costs more than zero, but not much.

In the end, freedom goes away because we could not be arsed to ask for it at least, let alone fight.

Re: The gigantic and unregulated power plants in the cloud

#106

This article repeatedly cites the need for personnel to have diplomas, certificates, and other ceremonial bits of paper. This focus on paper qualification to mitigate risk seems a very European approach. Not saying it is wrong - it is just not emphasized as strongly elsewhere. And while it seems like a good fit for a slow-moving industry with high expectations of safety, the solar/wind world is not a slow-moving indu…

A good point - perhaps the focus is too heavy on paperwork or "measurable compliance".

From experience in this sector though, I think the real issue is a lack of technical awareness and competency with enough breadth to extend into the "digital" domain - often products like these are developed by people from the "power" domain (who don't necessarily recognise off the top of their head that 512-bit RSA is a #badthing and not enough to use to protect aggregated energy systems that are controllable from a single location).

Clearly formal diplomas/certificates are not needed for that - some practical hands-on knowledge and experience would help a lot there.

When a product gets a network interface on it, or runs programmable firmware, we should hear discussions about A/B boot, signatures, key revocation, crypto agility to enable post quantum cryptography algorithms, etc. Instead, the focus will be on low-cost development of a mobile app, controlled via the lowest-possible-cost vendor server back-end API that gets the product shipped to market quickly.

Let's not even go near the "embedded system" mindset of not patching and staying up to date - embedded systems are a good place to meet Linux 2.4 or 2.6, even today... Vendors ship whatever their CPU chipset vendor gives them as a board support package, generally as a "tossed over the wall" lump of code.

I doubt many of these issues (which seem to be commercial/price driven) will be resolved through paperwork, as you say.

Re: The gigantic and unregulated power plants in the cloud

#107
post #14
post #6

I live off-grid, power and water wise, and it really irked me that the monitoring coming with my inverter is only available online. Even when there is a network available the app will not work. I fixed this by getting a raspberry pi connected and reading it from there, but if I disconnect the inverter from the internet it will create a new network so now there is always an open network in the middle of nowhere with n…

The high-voltage side should be separated from the electronics, so it shouldn't be dangerous if you are observant. It may be sufficient to just disconnect the antennas from the WiFi module, that will help prevent any network connections.

Disclaimer, ymmw, if you have no clue about these systems (average people), you can still easily kill yourself in the process.

Re: The gigantic and unregulated power plants in the cloud

#108

Does anyone know of an inverter manufacturer that doesn't require this? Ideally, one that offers micro inverters for each panel.

In greater scale, meaning power plants not the PV installed at houses, these things are taken more seriously and after purchase of equipment the control and automation of plant are in your hands. For example, Woodward, ABB have products with capacity up to 0.5 MW of single inverter.

Micro inverter for each panel would be very costly. In 1 MW plant you will have around 4000 panels, communicating with that amount electronic devices would be a headache.

Re: The gigantic and unregulated power plants in the cloud

#109
post #59

Earlier quoted context omitted.

For the purposes of information security, the nameplate capacity is the correct number to consider for a very simple reason: we must defend as if hackers will pick the absolute worst moment to attack the grid. That is the moment when the sun is shining and it's absolutely cloudless across Netherlands, California, Germany, or wherever their target grid is. At that moment, the attacker will not only blast the grid with…

The failure mode is much simpler: you don't need to physically break anything, you just need to drop 10GW of production from the grid (send a "turn off" command to all solar inverters) leading to a cascade of failures. Getting the grid back online is a laboreous manual process which will take (a lot of) time. Think https://en.wikipedia.org/wiki/Northeast_blackout_of_2003 or https://en.wikipedia.org/wiki/2021_Texas_po…

> Getting the grid back online is a laboreous manual process which will take (a lot of) time. Think...

It would be even more laborious and take more time to bring things back online if the attacker manages to damage or destroy equipment with an overload like the GP describes.

Re: The gigantic and unregulated power plants in the cloud

#110
post #59

Earlier quoted context omitted.

For the purposes of information security, the nameplate capacity is the correct number to consider for a very simple reason: we must defend as if hackers will pick the absolute worst moment to attack the grid. That is the moment when the sun is shining and it's absolutely cloudless across Netherlands, California, Germany, or wherever their target grid is. At that moment, the attacker will not only blast the grid with…

> We must consider the worst case, which is that the attacker is trying to not only physically break the inverters, but the batteries, solar panels, blow fuses, and burn out substations. Power transformers have a loooooooot of thermal wiggle room before they fail in such a way and usually have non-computerized triggers for associated breakers, and (at least if done to code, which is not a given I'll admit) so do inve…

This is true, especially for low frequency (high mass) inverters. The inverters that are covered here are overwhelmingly high frequency (low mass) inverters. We hope that they practiced great electrical engineering and layered multiple layers of physical safeguards on top of the software based controls built into the firmware.

Of course a company that skimped to the point of total neglect on software security would never skimp anywhere else, right? Right?

:crossed-fingers: And even if they did all the right things with their physical safety, the attackers can still brick the inverters with bad firmware and make them require a high skill firmware restore at a minimum and turn them into e-waste and require an re-install from a licensed electrician at a maximum.

Post reply on HN