Live data from Hacker News

The gigantic and unregulated power plants in the cloud

berthub.eu

71–80 of 258 posts

Re: The gigantic and unregulated power plants in the cloud

#71

If solar panels can be turned off, why are utility companies having to sell excess power at a loss? Why can’t they tell the solar farms to reduce their output by the required amount?

It's worst actually, at least in France, if you inject to the grid you have to pay an "energy transport fee", even if you inject for free (only recently self-made systems are allowed to sell energy, before they can only donate or not inject at all) and the injected energy is now paid less than the cheapest price to the customers (6 cent/kWh for ground based p.v., 10 cent for on-roof p.v.). So well, we do not harm large utility business.

What harm on scale is the variable output especially from small p.v. utilities built out of incentives NOT personal power plants, the grid is sized with some large power plants serving a large set of customers, their absorption vary but if the grid is vast (and not too vast) enough variation tend to be slow on average, let's say 50MW PP experience 100-200kW demand variation in very short time. They can compensate easily keeping the grid frequency stable. With a significant amount of grid injecting p.v. variation might be MUCH bigger creating significant stability issues where injection goes up too quickly making the frequency skyrocketing and large PP can't decrease their output fast enough risking disconnection witch in turn might put large p.v. plants offline suddenly creating a cascading effect of large blackouts.

That's the real issue with grid-connected and tied renewables and another reason why we need to go toward self-consumption NOT injection.

Re: The gigantic and unregulated power plants in the cloud

#72
post #51

> In the Netherlands alone, these solar panels generate a power output equivalent to at least 25 medium sized nuclear power plants. Since this didn't pass the smell test: the author is looking at nameplate capacity, which is a completely useless metric for variable electricity production sources (a solar panel in my sunless basement has the same nameplate capacity as the same panel installed in the Sahara desert). Lo…

If memory serves, and I’ll admit it’s pretty fuzzy, the US tends to make ridiculously large nuclear reactors and Europe has an easier regulatory situation so they make more of them and smaller.

So in addition to the other stuff people mentioned, you might be off by another factor of 2 there. They also said “medium sized” so let’s call it 3.

Re: The gigantic and unregulated power plants in the cloud

#73
post #5

>The owner of the panels and inverters can meanwhile establish a connection with that manufacturer using an app or website, and via the manufacturer see how their own panels are doing > It wasn’t necessary from a technical standpoint to let everything run through the manufacturer’s servers, but it was chosen to do it this way. (emphasis from article) I'm working on IoT cloud system. It was chosen to be done this way…

Also administering a bunch of IOT systems is a pain. If something is an open source community project, ok, I’ll play. If somebody is selling a product they are responsible for making sure it works.

You could put an sql database on a local device and just access it remotely like anything else. But you are correct you're stuck with administering each and everyone one of them.

The standard go to a raz pi solution will up and die every few months. And half the time you'll need physical access to get it back. It takes a lot of work to develop an embedded system that has enough reliability.

Re: The gigantic and unregulated power plants in the cloud

#74
post #63

> 0.002 MW - Small set of technical standards, no diplomas or certificates required Be careful with this language, especially when you're involving politicians and the non-technical. The current atrocity of criminally negligent IT infrastructure right now is mostly created and driven by people with diplomas, including from the most prestigious schools. (And a top HN story over the weekend was one of the most famous t…

Put another way: it’s far too easy and common for certification to encourage rote memorization. And only rote memorization. No higher order reasoning is imparted.

Knowledge without reasoning is how you get mired in bureaucracy.

Re: The gigantic and unregulated power plants in the cloud

#75
post #63

> 0.002 MW - Small set of technical standards, no diplomas or certificates required Be careful with this language, especially when you're involving politicians and the non-technical. The current atrocity of criminally negligent IT infrastructure right now is mostly created and driven by people with diplomas, including from the most prestigious schools. (And a top HN story over the weekend was one of the most famous t…

Punishment is not the answer, you'll just drive out of the industry lots of competent people. Punishment also means that nobody will admit to mistakes, will not fix mistakes (because that implies guilt), and the covering up of mistakes.

Punishment for mistakes is what led to the Chernobyl disaster.

Re: The gigantic and unregulated power plants in the cloud

#76
post #5

>The owner of the panels and inverters can meanwhile establish a connection with that manufacturer using an app or website, and via the manufacturer see how their own panels are doing > It wasn’t necessary from a technical standpoint to let everything run through the manufacturer’s servers, but it was chosen to do it this way. (emphasis from article) I'm working on IoT cloud system. It was chosen to be done this way…

What's the reasoning for not allowing both control paths, via cloud but also locally? So that people who can and want to, will use the local control.

Often there are two control paths. Sometimes more! Plenty of inverters will quite happily give you an RS232 port specification and you can create your own dongle!

However, for purpose of the security of the nation's power grid, I don't just need my inverter to be secure, I need pretty much everyone's inverter to be secure. If an attack bricks 95% of solar inverters, the fact the nerdiest 5% of users have their inverters airgapped won't stop the grid having a lot of problems.

Re: The gigantic and unregulated power plants in the cloud

#77
post #51

> In the Netherlands alone, these solar panels generate a power output equivalent to at least 25 medium sized nuclear power plants. Since this didn't pass the smell test: the author is looking at nameplate capacity, which is a completely useless metric for variable electricity production sources (a solar panel in my sunless basement has the same nameplate capacity as the same panel installed in the Sahara desert). Lo…

> the author is looking at nameplate capacity, which is a completely useless metric for variable electricity production sources

For solar panels, the nameplate capacity is usually also the power generated at the peak production time, which is the moment when an attacker turning off all inverters at the same time would have the most impact.

That is: for an attack (or any other failure), the most important metric is not the total power produced, but the instantaneous power production, which is the amount which has to be absorbed by the "spinning reserve" of other power plants when one power plant suddenly goes offline.

Re: The gigantic and unregulated power plants in the cloud

#78
post #74
post #63

> 0.002 MW - Small set of technical standards, no diplomas or certificates required Be careful with this language, especially when you're involving politicians and the non-technical. The current atrocity of criminally negligent IT infrastructure right now is mostly created and driven by people with diplomas, including from the most prestigious schools. (And a top HN story over the weekend was one of the most famous t…

Put another way: it’s far too easy and common for certification to encourage rote memorization. And only rote memorization. No higher order reasoning is imparted. Knowledge without reasoning is how you get mired in bureaucracy.

I think the larger problem is alignment.

BS gatekeeping rituals and compliance-for-sale theatre are arguably just symptoms -- of companies and individuals not being aligned with developing trustworthy systems.

Re: The gigantic and unregulated power plants in the cloud

#79
post #51

> In the Netherlands alone, these solar panels generate a power output equivalent to at least 25 medium sized nuclear power plants. Since this didn't pass the smell test: the author is looking at nameplate capacity, which is a completely useless metric for variable electricity production sources (a solar panel in my sunless basement has the same nameplate capacity as the same panel installed in the Sahara desert). Lo…

you are splitting hairs about the wrong issue. When it is sunny in the netherlands, it is likely sunny everywhere in NL because of how small the country is. This is the situation where having so much solar power capacity (kW) is dangerous. The risk scales with energy output but it would not term nameplate capacity a "completely useless metric".

I dunno. I lived next to a small inland sea most of my adult life. The number of times someone on the other side of town asserted it was raining when in fact it was not was quite high.

Every adult in Seattle eventually has to learn that if you have an activity planned on the other side of town, if you cancel it because it’s raining at your house you’re not going to get anything done. You have to phone a friend or just show up and then decide if you’re going to cancel due to weather.

Now to be fair, in the case of Seattle, there’s a mountain that multiplies this effect north versus south. NL doesn’t have that, but if you look at the weather satellite at the time of my writing, there are long narrow strips of precip over England that are taller but much narrower than NL.

Re: The gigantic and unregulated power plants in the cloud

#80

Q: Are there no regulatory requirements for power plants of any kinds in EU, specially around cybersecurity? I do not allow any system into my environments (at home and at work) that requires a third party data connection function. There are way too many incidents where a provider, cloud or otherwise which required connection failed for various reasons. (e.g., Cisco Spark Board, Xerox ConnectKey, Google Cloud Print,…

How would one practically verify and certify cybersecurity of a product? Even payment smartcards sometimes come with non-malicious maintenance backdoors. There seem to be little to no academic theoretical basis to this whole software security thing.
Post reply on HN