Smart grids may be rife with dumb security bugs

subscribe

New “smart” electricity meters, beginning to be rolled out across the country, may be rife with bugs that could pose security risks.

The new meters create a smart communication network between the user and the local power plant. The software that powers some of the smart meters, however, is coming under fire from security experts for its lack of adequate protections against malicious hacks.

One expert, hoping to illustrate the risks involved, claims to have created a worm program that infects one of the popular meters, taking control of its functionality and propagating itself further throughout the grid.

The new meters supposedly require no authentication or encryption whenever running functions such as software updates. These vulnerabilities are what the worm, written by the security firm IOActive as a proof of concept, will exploit using peer-to-peer technology to spread. Using it, hackers could potentially control the workings of the grid, turning on and off power to users, or even reconfiguring the entire systemÂ’s settings.

These smart meters were a result of a $4.5 billion stimulus plan by the Obama administration to update electrical grids across the country to make them smarter and more efficient. This could allow meter values to be sent directly to the company rather than requiring a meter reader to stop off at each userÂ’s house. It also can shift, in real-time, the demands on the power grid to provide electricity where needed and change rates based on the electricity being used and what is available.

However, in order to receive larger chunks of the stimulus money, companies raced each other to create a smart meter that worked. Perhaps in the rush, the amount of testing needed was reduced and security issues may have been compromised.

Several companies have created their own smart meter products and it is as yet unclear which ones, if any, are affected by a lack of security. The worm described will only be shown at a security conference occurring next month, so weÂ’ll have to wait to see if the claims are true and on what scale.

Related News

PG&E

US judge orders PG&E to use dividends to pay for efforts to reduce wildfire risks

LOS ANGELES - A U.S. judge said on Tuesday that PG&E may not resume paying dividends and must use the money to fund its plan for cutting down trees to reduce the risk of wildfires in California, stopping short of more costly measures he proposed earlier this year.

The new criminal probation terms for PG&E are modest compared with ones the judge had in mind in January and that PG&E said could have cost upwards of $150 billion.

The terms will, however, keep PG&E under the supervision of Judge William Alsup of the U.S. District Court for the Northern District of California…

READ MORE

N.B. Power hits pause on large new electricity customers during crypto review

READ MORE

oeb chart

Electricity rates are about to change across Ontario

READ MORE

weed zapper

A robot is killing weeds by zapping them with electricity

READ MORE

Battery-electric buses hit the roads in Metro Vancouver

READ MORE