Live data from Hacker News

The gigantic and unregulated power plants in the cloud

berthub.eu

81–90 of 258 posts

Re: The gigantic and unregulated power plants in the cloud

#81
post #31
post #13

Earlier quoted context omitted.

They already can by simply turning open some power mosfets in their fleet of EVs.

Yeah. I'm not sure everyone is really thinking clearly here. Don't get me wrong, they should get rid of this practice of cloud monitoring. A consumer should be able to access monitoring over the internet without an intermediary. They should, of course, be allowed to contract with an intermediary if that is their desire. But the security argument? Yeah, that ship has sailed. Total war, means total war. Your power grid…

You're turning war into a black-and-white "total war" situation. Total war is rare, and no -- no ships have sailed.

It's easy to imagine a scenario where something happens between China and Taiwan, Europe gets involved in a way that majorly pisses off China, and China decides to sabotage Europe's grid in response.

Nothing about that is "total war" with Europe, and it's not like Europe is going to escalate with nukes either because that would be wildly disproportionate.

But it's a major vulnerability that should be fixed as quickly as possible. It's negligent for that to even be an option for China, because it certainly doesn't seem like Europe can do anything similar to the grid in China.

Your idea that security vulnerabilities don't matter, that "that ship has sailed", is false and irresponsible.

Re: The gigantic and unregulated power plants in the cloud

#82
post #58

Earlier quoted context omitted.

In some areas like cameras there are a decent number of cloud-free alternatives. Hopefully as the IOT market grows we'll get cloud-free versions of everything. I think you're too optimistic about costs though. Providing any support at all, even one-time during the install, is expensive and cloud-free IOT is going to require support due to home networks being broken.

Yes, support is expensive, but what I am proposing will, if anything, reduce support. I'm imagining something where, if I opt into local control, I am giving up all rights to any support that is not related to the core functionality of the device. For example the solar panels/inverters in the article. If I opt in to local control, then the only support I am entitled to is the solar panels stop generating power or if…

Consumer electronics doesn't work that way. If people can't get a product to work they will return it to the retailer and when the retailer gets a lot of returns they will penalize the company or drop them completely.

Re: The gigantic and unregulated power plants in the cloud

#83
post #59
post #51

> In the Netherlands alone, these solar panels generate a power output equivalent to at least 25 medium sized nuclear power plants. Since this didn't pass the smell test: the author is looking at nameplate capacity, which is a completely useless metric for variable electricity production sources (a solar panel in my sunless basement has the same nameplate capacity as the same panel installed in the Sahara desert). Lo…

For the purposes of information security, the nameplate capacity is the correct number to consider for a very simple reason: we must defend as if hackers will pick the absolute worst moment to attack the grid. That is the moment when the sun is shining and it's absolutely cloudless across Netherlands, California, Germany, or wherever their target grid is. At that moment, the attacker will not only blast the grid with…

While I agree that the important metric to consider is peak output and not average output, I would still guess that in a country like the Netherlands that peak output is nowhere near nameplate capacity.

Re: The gigantic and unregulated power plants in the cloud

#84
> It’s also possible to install new software (firmware) on the inverters via the manufacturer, either automatically or manually.

As always, the vulnerability of enabling remote updates. When will people learn? Updates should only be possible if there's a physical switch (not a software switch) on the device. If it's "off", no updates are possible.

Isn't the most devastating attack vector remotely installing malware? With a hardware switch, none of that malware will survive a reboot of the device.

I remember when hard disk drives came with a write-enable jumper. Then, once you've made a backup, the jumper is removed. Then it is impossible to accidentally or maliciously write over your precious backup.

Re: The gigantic and unregulated power plants in the cloud

#85
Related to this topic, some research results about cybersecurity of solar inverters:

https://github.com/veganmosfet/Balcony_in_the_cloud

https://github.com/veganmosfet/SolarFlareSec

https://github.com/veganmosfet/CyberEclipse

https://github.com/veganmosfet/SecureWatt

A big mess, but it's getting slowly better...

Re: The gigantic and unregulated power plants in the cloud

#86
post #59
post #51

> In the Netherlands alone, these solar panels generate a power output equivalent to at least 25 medium sized nuclear power plants. Since this didn't pass the smell test: the author is looking at nameplate capacity, which is a completely useless metric for variable electricity production sources (a solar panel in my sunless basement has the same nameplate capacity as the same panel installed in the Sahara desert). Lo…

For the purposes of information security, the nameplate capacity is the correct number to consider for a very simple reason: we must defend as if hackers will pick the absolute worst moment to attack the grid. That is the moment when the sun is shining and it's absolutely cloudless across Netherlands, California, Germany, or wherever their target grid is. At that moment, the attacker will not only blast the grid with…

This is wildly overstating the issue. Hackers are not going to break into hundreds of separate sites, compromise inverters, compromise relay protection, compromise SCADA systems, and execute a perfectly timed attack. Even if they did, these are distributed resources, they don't all go through a single substation and I doubt any one site could cause any major harm to any one substation.

Instead, they're going to get a few guys with guns and shoot some step of transformers and drive away.

The problem with infosec people is they tend to wildly overestimate cyber attack potential and wildly underestimate the equivalent of the 5 dollar wrench attack.

Re: The gigantic and unregulated power plants in the cloud

#88
post #63

> 0.002 MW - Small set of technical standards, no diplomas or certificates required Be careful with this language, especially when you're involving politicians and the non-technical. The current atrocity of criminally negligent IT infrastructure right now is mostly created and driven by people with diplomas, including from the most prestigious schools. (And a top HN story over the weekend was one of the most famous t…

Punishment is not the answer, you'll just drive out of the industry lots of competent people. Punishment also means that nobody will admit to mistakes, will not fix mistakes (because that implies guilt), and the covering up of mistakes. Punishment for mistakes is what led to the Chernobyl disaster.

Flight safety works so well because the personnel are aligned with safety and professionalism, and the FAA has an important program in place to protect people from being punished for behaving professionally. And IIRC you're familiar with aircraft manufacturer alignment with safety.

But I'm concerned about the entire field of software, which doesn't have that sense of responsibility, and I don't see how it would get it. However, software industry -- both companies and workers -- are guided almost entirely by money. To the point that it's often hard to explain to many people in HN discussions on why it would be good to behave in any other way than complete mercenary self interest. So I don't see any way to get alignment other than to link money to it. If people see that as punishment, so be it.

Re: The gigantic and unregulated power plants in the cloud

#89
post #55
post #26

Earlier quoted context omitted.

Cloudflare absolutely does not control 80% of internet traffic. I have no idea where you got that number from.

This article says 80% of known websites, which are 19% of all websites. Probably where it came from. https://w3techs.com/technologies/details/cn-cloudflare

That's still the number of websites, not their traffic. A personal blog hosted on Cloudflare and google.com are not both the same.

Re: The gigantic and unregulated power plants in the cloud

#90
post #59

Earlier quoted context omitted.

For the purposes of information security, the nameplate capacity is the correct number to consider for a very simple reason: we must defend as if hackers will pick the absolute worst moment to attack the grid. That is the moment when the sun is shining and it's absolutely cloudless across Netherlands, California, Germany, or wherever their target grid is. At that moment, the attacker will not only blast the grid with…

While I agree that the important metric to consider is peak output and not average output, I would still guess that in a country like the Netherlands that peak output is nowhere near nameplate capacity.

[deleted]
Post reply on HN