Live data from Hacker News

The gigantic and unregulated power plants in the cloud

berthub.eu

141–150 of 258 posts

Re: The gigantic and unregulated power plants in the cloud

#141
post #139

The author seems to imply, as if it were generally understood and accepted, that the reason nuclear reactors are heavily regulated is because they produce a lot of energy. Perhaps that's a component, but one really doesn't need to think about it too hard to identify better explanations for why this particular energy source is held to unusually high regulatory standards. I don't have an opinion as to whether other lar…

Here's the critical point:

> In the Netherlands alone, these solar panels generate a power output equivalent to at least 25 medium sized nuclear power plants.

> Because everything runs through the manufacturer, they are able to turn all panels on and off. Or install software on the inverters so that the wrong current flows into the grid. Now, a manufacturer won’t do this intentionally, but it is easy enough to mess this up.

> As an interim step, we might need to demand that control panels stick to providing pretty graphs, and make it impossible to remotely switch panels/loaders/batteries on or off.

Basically, if a hacker were to make all batteries (or panels) suddenly switch between full discharge and full charge every second or so, it would tear down the electric grid. Voltage and frequency would swing rapidly, and whatever plants are riding load would struggle.

This could create a massive power outage; but there is a huge risk that this could damage power plants and other infrastructure.

Re: The gigantic and unregulated power plants in the cloud

#142

Earlier quoted context omitted.

Taking it offline doesn't protect against supply chain attacks in the form of built-in kill switches. A satellite could transmit signed instructions by modulating light below the noise floor, inverters must sense the voltage/current state of the PV panels anyway for MPPT to work. Only deep inspection of the silicon and code can improve the situation. Perhaps Western blocks could develop provably secure silicon IP and…

I'm curious about the feasibility of modulating light onto a solar panel. I feel it would not be feasible, except possibly onto a single panel at a time over a long time period. Just a gut feeling based off radio stuff (GPS).

GPS can provide the coherent reference, if you mean transmitting signal (say sound) while the panel is illuminated by the sun theres youtube videos of people doing that, with a laser pointer, but in sunlight and without information theoretic justified modulation scheme.

Nothing prevents the satellite to transmit the commands at night, if that feels more convincing to you.

Ask yourself what is the active area of a photodiode in your TV/... ? What is the active area of your light-bucket on a roof?

Re: The gigantic and unregulated power plants in the cloud

#143
post #130
post #127

I can make my computer wildly vary the amount of power it is drawing by performing different things in software. Max out the CPU and GPU load and it will instantly change from drawing ~100 watts to 500 or more. There have been plenty of botnets in the past. Some even in the millions of computers. If such a botnet decided to make every node's power draw fluctuate per above, wouldn't this cause the same type of problem…

The Netherlands (about which the article mainly is) has 8.4 million households, let's presume they own average of one such PC you mention. A delta of 400W would mean a total consumption delta of 3.36GigaWatt. That's "peanuts" to cover. And that presumes an attacker can switch on/off all 8.4million computers in a small timeframe. 100% of them would need to be on, online and hacked. I don't think this is a realistic pr…

I don't doubt that that many watts is easy to cover - eventually. The problem is that it can be instantly turned on and off, whereas the grid takes time to shed load or add capacity.

I found a figure on Wikipedia saying that the NL's 4.7GW worth of offshore wind capacity is 16% of their total electricity demand nationwide. 4.7/.16 = 30GW total, so this theorized computer load attack would represent about 10% of their grid's total capacity. Can their grid add and shed that much load that quickly? That's the part I doubt.

Re: The gigantic and unregulated power plants in the cloud

#144
post #98
post #95

Earlier quoted context omitted.

This isn't hundreds of separate sites that have to be hacked individually. This is fewer than 10 clouds with no security to speak of and the ability to push evil firmware to millions of inverters worldwide, where in a few years at the current rate of manufacturing growth, it will be 10s, and then 100s of millions of inverters. Yeah, the potato cannon filled with aluminum chaff or medium caliber semi-automatic rifle c…

> medium caliber semi-automatic rifle Technically, anything that can put a hole in an oil-filled transformer. https://en.m.wikipedia.org/wiki/Transformer_types#Liquid-coo... You don't need to break it... just crack the radiator enough for all the circulating fluid to drain, then it overheats.

Important to point out this isn't just theory, it's actually happened (in the SF Bay Area!) with a regular rifle.

https://en.wikipedia.org/wiki/Metcalf_sniper_attack

https://www.npr.org/sections/thetwo-way/2014/02/05/272015606...

Re: The gigantic and unregulated power plants in the cloud

#145

> It’s also possible to install new software (firmware) on the inverters via the manufacturer, either automatically or manually. As always, the vulnerability of enabling remote updates. When will people learn? Updates should only be possible if there's a physical switch (not a software switch) on the device. If it's "off", no updates are possible. Isn't the most devastating attack vector remotely installing malware?…

That doesn't protect against supply chain attacks.

Neither does remote updating. But you'll still need physical access to the supply chain to compromise it, and that's not possible for some hacker in a basement.

Re: The gigantic and unregulated power plants in the cloud

#147
post #37

Earlier quoted context omitted.

Smartphones don't count?

Apologies, but do not understand the question. Are you suggesting using smart phones should count in "not allowing it in"? Then yes, I try to where possible. I do not depend on a smart phone. All functionality that are operationally necessary can be done elsewhere without major delays or impact.

Interesting. How do you handle MFA, do you have a special device for that? Your bank/brokerage don't require their app?

Re: The gigantic and unregulated power plants in the cloud

#148
Wait what. I don’t know if my inverter does what they say. For one thing the vendor went bankrupt so there is no cloud dashboard anymore. For another there are hundreds of inverter vendors not one single one. And I am highly sceptical the basic dashboard showing solar generation has some sinister inverter backdoor killswitch when the article seems to provide no evidence of such? Seriously?

Edit: did some research and apparently it varies - many modern inverters can be remotely controlled by manufacturers - if they’re setup to allow it and are internet connected.

The article is still sensationalist about the risks though

Re: The gigantic and unregulated power plants in the cloud

#149

Earlier quoted context omitted.

That doesn't protect against supply chain attacks.

Neither does remote updating. But you'll still need physical access to the supply chain to compromise it, and that's not possible for some hacker in a basement.

I never claimed remote updating would prevent supply chain attacks.

I was responding to:

> With a hardware switch, none of that malware will survive a reboot of the device.

A reboot of the inverter would not prevent a supply chain attack using MPPT measurement electronics for an optical backdoor channel.

Re: The gigantic and unregulated power plants in the cloud

#150

Earlier quoted context omitted.

Neither does remote updating. But you'll still need physical access to the supply chain to compromise it, and that's not possible for some hacker in a basement.

I never claimed remote updating would prevent supply chain attacks. I was responding to: > With a hardware switch, none of that malware will survive a reboot of the device. A reboot of the inverter would not prevent a supply chain attack using MPPT measurement electronics for an optical backdoor channel.

So don't put the backdoor channel in without a physical switch.
Post reply on HN