Earlier quoted context omitted.
Not feasible for a single idiot to accomplish, but you're forgetting we live in an age of State-Level Actors who distribute very sophisticated malware to attack enemy nation's infrastructure by borking SCADA controllers in e.g. uranium enrichment plants or petrochemical refineries. One may hypothesize about the feasibility of a router-targeting worm (similar to the Moon router worm, targeting Linksys kit) that has a…
It would be more feasible to just hack industrial controls or the power company rather than create some worm for a specific router and hope that you can find the 50k powerwalls.
Tesla PowerWall 2 Hack
161–170 of 175 posts
Re: Tesla PowerWall 2 Hack
#162Earlier quoted context omitted.
> and anything you can do without blowing that fuse won't damage the grid That's what you'd think. But I have actually done damage to the grid and had that fuse still in one piece. I accidentally connected the -HV line of a neon light installation to ground. After I could see again I realized the power had gone out. I called my boss (landline still worked) who lived more than a kilometer away from the workshop and th…
This is exactly what RCDs are for - with a huge earth leak like that (and therefore L/N imbalance) it would have tripped within milliseconds, before cooking the grid. I am surprised by how infrequently they seem to be used outside of the U.K. - I’ve just rewired my house in Portugal as it was completely unearthed, and just had fuses, no RCDs.
Not sure if that's a national requirement or not, but houses I've lived in in Victoria also had RCDs.
Re: Tesla PowerWall 2 Hack
#163Earlier quoted context omitted.
> and anything you can do without blowing that fuse won't damage the grid That's what you'd think. But I have actually done damage to the grid and had that fuse still in one piece. I accidentally connected the -HV line of a neon light installation to ground. After I could see again I realized the power had gone out. I called my boss (landline still worked) who lived more than a kilometer away from the workshop and th…
I'm sorry, but I don't believe one bit of your story. Ohm's law dictates that it's be impossible for your HV generator (neon transformer) to outpout a HV voltage when connected to the grid (you'd need thousands of kWs). Just impossible
Feel free to contact Riny Assink who was my boss / co-founder at the time for corroboration, I'm pretty sure he will remember because (1) it was a pretty memorable occasion in its own right, (2) the neon installation was intended to be used on a trade show the next day and my action meant we did not get to use one of our nicer eye catchers which really pissed him off, (3) he built the stuff that I blew up in the weeks leading up to the event, which pissed him off even more. I'm sure a bit of googling will turn up contact info for him.
As for Ohm's law, when dealing with large transformers made for 50Hz dumping the full charge of a (pretty beefy) HV power supply into the low end of a circuit looks roughly like a lightning strike would, only with a much lower amount of Joules behind it. So it's not so much Ohm's law but Maxwell. Chances are some protection circuitry said 'better safe than sorry' and disconnected.
FWIW when you receive a bit of data that contradicts your knowledge and assumptions in general the more interesting bits of knowledge are found by asking how things could have happened rather than to disbelieve a priori the facts as presented by eye witnesses. I have fuck all to gain from relating this story, and would happily stake my reputation on it being 100% the truth without any embellishment whatsoever. The whole reason I told it is because the person I replied to made roughly the same claim that you did.
I agree that it should not be possible, and yet it happened.
Re: Tesla PowerWall 2 Hack
#164Earlier quoted context omitted.
> "Responsible disclosure" is an invention of vendors who want you conforming to their policies and timeline No it’s not. It’s an invention of ethical hackers and academic security researchers who are mature enough to realize that dropping 0-days to the public is worse for society than giving the vendor a reasonable opportunity to fix it. “Economics of information security” is a field that publishes some studies abou…
Some interesting commentary: https://news.ycombinator.com/item?id=14010010 https://news.ycombinator.com/item?id=12308246 > That may feel good to say, but as someone whose job it was to find these kinds of bugs in software from companies ranging from tiny startups to financial exchanges to major tech vendors, this is a kind of carelessness shared by virtually everyone shipping any kind of software anywhere. > That sai…
Releasing anything that can be used to harm the public has ethical implications, period. There is no grey area there. Responsible disclosure is entirely about minimizing impact.
People that don’t like the term don’t like it because they don’t like the idea that there are ethical implications for releasing information.
Do you think there is an ethical gray area to releasing a method to the public to gain access to the secure side of an airport terminal without going through security so guns/bombs can be brought in undetected? What if that method is a software vulnerability in the door locks they use?
> The better term is "coordinated disclosure". But uncoordinated disclosure is not intrinsically irresponsible. For instance: if you know there's an exploit in the wild for something, perhaps go ahead and tweet the vulnerability without notice!
FFS, that’s why the term is “responsible disclosure” and not “coordinated disclosure”. Responsible disclosure is the entire process of determining when and how to inform vendors and/or major users or if to inform them at all. Responsible disclosure is entirely about doing disclosure in the least harming way possible to the public.
Re: Tesla PowerWall 2 Hack
#165Earlier quoted context omitted.
> and anything you can do without blowing that fuse won't damage the grid That's what you'd think. But I have actually done damage to the grid and had that fuse still in one piece. I accidentally connected the -HV line of a neon light installation to ground. After I could see again I realized the power had gone out. I called my boss (landline still worked) who lived more than a kilometer away from the workshop and th…
This is exactly what RCDs are for - with a huge earth leak like that (and therefore L/N imbalance) it would have tripped within milliseconds, before cooking the grid. I am surprised by how infrequently they seem to be used outside of the U.K. - I’ve just rewired my house in Portugal as it was completely unearthed, and just had fuses, no RCDs.
Re: Tesla PowerWall 2 Hack
#166Earlier quoted context omitted.
If you were to try this and somehow cause damage to the sub station, would you be held liable? Actually, this brings an interesting question with IoT - if devices damage or otherwise exploit your utility company’s equipment, is it their fault of yours? Presumably doing anything bad is against your utility’s ToS, but if you didn’t do it knowingly...
I would imagine that unless you were a licensed electrician, you would be liable.
Re: Tesla PowerWall 2 Hack
#167"The PW can store up to 13.5kW of electric power..." No, you store energy, not electric power, and energy is Wh, that's why you have your phone battery with 5V and 8000 mAh as units and not 8A. "How does the grid feel about me oscilating this and who will die first, the PW or the sub-station?" Definitely the PW. Sub-stations are made to withstand thousand of households switching all at once their light-bulbs at eveni…
If you were to try this and somehow cause damage to the sub station, would you be held liable? Actually, this brings an interesting question with IoT - if devices damage or otherwise exploit your utility company’s equipment, is it their fault of yours? Presumably doing anything bad is against your utility’s ToS, but if you didn’t do it knowingly...
Re: Tesla PowerWall 2 Hack
#168Earlier quoted context omitted.
>It seems you disapprove of the phrase "responsible disclosure" because it's ambiguous and can be used as a cudgel This is like saying that a glock can be used as a weapon. Yes, it was carefully designed to be one. >We must secure the existence of our people and a future for white children This might also be ambiguous, but we all understand the genocidal connotations.
> This might also be ambiguous, but we all understand the genocidal connotations. Ah yes, because using the term "responsible disclosure" is very clearly analogous to being a white supremacist. There's no need to be so ridiculously dramatic -- "responsible disclosure" was objectively the term-du-jour used by the infosec community until fairly recently. And it's perfectly understandable why the community changed their…
Here's a little historical context https://www.securityfocus.com/columnists/120
I think the 14 words comparison is apt. Without context there's nothing obviously wrong with the 14 words, just like there's nothing obviously wrong with "responsible disclosure".
Re: Tesla PowerWall 2 Hack
#169This is the mythical power-grid attack that people have been talking about since the concept of cyber-warfare was first dreamt up. It’s lucky we caught this now, before there are enough PowerWalls to seriously destabilise the grid if this attack were to occur.
I wouldn't call it mythical. A government red team completely owned our power grid quite a while ago as a test.
Re: Tesla PowerWall 2 Hack
#170Earlier quoted context omitted.
Their customers do, though, and that's the whole point. Without giving people a short, reasonable time to patch, you're part of the problem, not part of the solution. For what it's worth, you are also coming across as something of a zealot, rather than a reasonable person who sees the world in shades of grey.
The burden of proof lies with the person who says publishing research and making it immediately available to those it directly affects is irresponsible. It is not. The side effect that it is available to attackers is also irrelevant to the determination of whether or not it’s irresponsible; it also becomes available to the vendor who shipped it. This notion of “you have to give the vendor time to patch xor you are ir…
Burden of proof? This isn't a court case. The overwhelming majority of users will never see a vulnerability write-up, do not have the education needed to understand such a writeup and - even if they saw the writeup and understood it - lack the tools and information to fix a vulnerability in proprietary software.
The vendor only factors in because they are the only one who can fix the issue.
A disclosure like this only helps hackers and the few consumers who are capable of hacking their own product. It hurts everyone else.
> The vendor releasing the patch (prior to publication of the paper) is just as much a drop of the 0day as publishing the paper is.
Who here is arguing against disclosure? We're arguing for responsible disclosure. Once the vendor distributes patch, consumers can actually do something to protect themselves. At that point, you can put the vendor on blast all you want without harming the consumers.