Earlier quoted context omitted.
For the purposes of information security, the nameplate capacity is the correct number to consider for a very simple reason: we must defend as if hackers will pick the absolute worst moment to attack the grid. That is the moment when the sun is shining and it's absolutely cloudless across Netherlands, California, Germany, or wherever their target grid is. At that moment, the attacker will not only blast the grid with…
The risk is not turning all solar installations "on maximum". That happens nearly every summer day between 1 and 2pm. Automatic shutoff when the grid voltage is rising can be disabled, but more than 9 out of 10 consumer solar installations in the Netherlands deliver their maximum output on such a day for most of the summer, not running into the maximum voltage protections. The big risk is turning them all off at the…
The gigantic and unregulated power plants in the cloud
161–170 of 258 posts
Re: The gigantic and unregulated power plants in the cloud
#162This article repeatedly cites the need for personnel to have diplomas, certificates, and other ceremonial bits of paper. This focus on paper qualification to mitigate risk seems a very European approach. Not saying it is wrong - it is just not emphasized as strongly elsewhere. And while it seems like a good fit for a slow-moving industry with high expectations of safety, the solar/wind world is not a slow-moving indu…
A good point - perhaps the focus is too heavy on paperwork or "measurable compliance". From experience in this sector though, I think the real issue is a lack of technical awareness and competency with enough breadth to extend into the "digital" domain - often products like these are developed by people from the "power" domain (who don't necessarily recognise off the top of their head that 512-bit RSA is a #badthing…
How someone would wave a 20 year old piece of paper as evidence that they know how to use solar tech that was developed last year, I don’t know.
Re: The gigantic and unregulated power plants in the cloud
#163Earlier quoted context omitted.
Most(more or less all of them) grid operators can operate their network remotely from a single control room. I suspect most grids are extremely easy to hack(never tried, don't bite the hand that feed you etc). Info sec is just a hobby of mine. I install high voltage switch gear for a living.
> I suspect most grids are extremely easy to hack I’d expect the opposite. All companies controlling equipment that is part of the “Bulk Electric System” have to be NERC CIP compliant and are audited regularly with large fines for non-compliance. Doesn't guarantee perfect (or even good security) but it’s more likely to be a priority.
Re: The gigantic and unregulated power plants in the cloud
#164Earlier quoted context omitted.
This is wildly overstating the issue. Hackers are not going to break into hundreds of separate sites, compromise inverters, compromise relay protection, compromise SCADA systems, and execute a perfectly timed attack. Even if they did, these are distributed resources, they don't all go through a single substation and I doubt any one site could cause any major harm to any one substation. Instead, they're going to get a…
Most(more or less all of them) grid operators can operate their network remotely from a single control room. I suspect most grids are extremely easy to hack(never tried, don't bite the hand that feed you etc). Info sec is just a hobby of mine. I install high voltage switch gear for a living.
Re: The gigantic and unregulated power plants in the cloud
#165Earlier quoted context omitted.
> I suspect most grids are extremely easy to hack I’d expect the opposite. All companies controlling equipment that is part of the “Bulk Electric System” have to be NERC CIP compliant and are audited regularly with large fines for non-compliance. Doesn't guarantee perfect (or even good security) but it’s more likely to be a priority.
How do fines make things better? They confiscate resources that could be used to improve.
A fine is a black eye for a utility where people pride themselves on the reliability of the service they provide
Re: The gigantic and unregulated power plants in the cloud
#166Earlier quoted context omitted.
This is wildly overstating the issue. Hackers are not going to break into hundreds of separate sites, compromise inverters, compromise relay protection, compromise SCADA systems, and execute a perfectly timed attack. Even if they did, these are distributed resources, they don't all go through a single substation and I doubt any one site could cause any major harm to any one substation. Instead, they're going to get a…
Hurray! I have experience that may shed some insights. I worked on SCADA software (3 different ones), for about 15 years, started off as a Systems Engineer for an Industrial Power Metering company (but writing software), built drivers for various circuit breakers and other power protection devices, and wrote drivers and other software for IEC61850 (substation modelling and connectivity standard). I’ve been the techni…
Re: The gigantic and unregulated power plants in the cloud
#167Earlier quoted context omitted.
This isn't hundreds of separate sites that have to be hacked individually. This is fewer than 10 clouds with no security to speak of and the ability to push evil firmware to millions of inverters worldwide, where in a few years at the current rate of manufacturing growth, it will be 10s, and then 100s of millions of inverters. Yeah, the potato cannon filled with aluminum chaff or medium caliber semi-automatic rifle c…
> medium caliber semi-automatic rifle Technically, anything that can put a hole in an oil-filled transformer. https://en.m.wikipedia.org/wiki/Transformer_types#Liquid-coo... You don't need to break it... just crack the radiator enough for all the circulating fluid to drain, then it overheats.
Re: The gigantic and unregulated power plants in the cloud
#168> In the Netherlands alone, these solar panels generate a power output equivalent to at least 25 medium sized nuclear power plants. Since this didn't pass the smell test: the author is looking at nameplate capacity, which is a completely useless metric for variable electricity production sources (a solar panel in my sunless basement has the same nameplate capacity as the same panel installed in the Sahara desert). Lo…
If memory serves, and I’ll admit it’s pretty fuzzy, the US tends to make ridiculously large nuclear reactors and Europe has an easier regulatory situation so they make more of them and smaller. So in addition to the other stuff people mentioned, you might be off by another factor of 2 there. They also said “medium sized” so let’s call it 3.
The only new (non-Russian) European design built in the past 15 years is the EPR at 1600 MW. The only new American design built in the past 15 years is the AP1000 which as the name suggests is 1000 MW (technically 1100). AP1000 uses a massively simplified design to try and be much safer than other designs (NRC calculations say something like an order of magnitude) but is not cost competitive against most other forms of power generation. Which is why after Vogtle 3 and 4 there are no plans for more of them in the US.
It's not that EPR is any better- they are actually doing worse in terms of money and time slippage than Vogtle did. Flamanville 3 had it's first concrete poured in 2007 and still hasn't generated a single net watt!
It turns out that the pause in building nuclear reactors in the west from about 1995-2005- both US (which actually was longer, from the early 1980's, after 3 Mile Island things still under construction were finished but nothing new was built) and Western Europe (after Chernobyl following a similar path) basically gutted the nuclear construction industries in both, and they haven't built back up. The Russians kept at it, and the South Koreans have moved in to the market (and China is building a huge number domestically, though I don't think they've built any internationally), but Western Europe and the US are far behind, and after Fukushima Daiishi I strongly suspect the Japanese are in the same boat. Without the trained workers you can't build these in any predictable way, and when you pause construction for a decade you lose all of the trained workers and it's really hard to build that workforce back up again.
Re: The gigantic and unregulated power plants in the cloud
#169Earlier quoted context omitted.
A good point - perhaps the focus is too heavy on paperwork or "measurable compliance". From experience in this sector though, I think the real issue is a lack of technical awareness and competency with enough breadth to extend into the "digital" domain - often products like these are developed by people from the "power" domain (who don't necessarily recognise off the top of their head that 512-bit RSA is a #badthing…
In the rest of the tech industry, what you did to get your diploma gives you about 18 months of momentum. If you haven’t learned multiple new technologies by that point, you’re in trouble. Success in this industry means perpetually redeveloping your own skills, and liking it. How someone would wave a 20 year old piece of paper as evidence that they know how to use solar tech that was developed last year, I don’t know…
Re: The gigantic and unregulated power plants in the cloud
#170It irks me endlessly that we live in the worst timeline, where the computer equivalent of fuses and circuit breakers are almost completely unknown. Instead we trust code blindly. This results in almost all of the situations threads here address. In a better timeline, everyone has stable and secure OSs on all their devices, and the default is for everything to be locally networked, with optional monitoring from the ou…
it's incredibly hard to implement a data diode for PV systems, enemy satellites can modulate light (like a TV remote, but lower baudrate to stay below the noise floor) and an inverter could decode it and respond accordingly. They measure the PV panels anyway for MPPT.
A data diode applies to a specific connection. It's easy to have a serial port that goes one way.
Preventing any possible input to an already compromised device is much harder. But if your device isn't already compromised then it won't be looking at the input light levels for commands.