Buggy smart meters can infect the Smart Grid

June 17, 2009

In a report published June 12th, Register.com's Dan Goodin reports, "The newfangled meters needed to make the smart grid work are built on buggy software that's easily hacked, said Mike Davis, a senior security consultant for IOActive. The vast majority of them use no encryption and ask for no authentication before carrying out sensitive functions such as running software updates and severing customers from the power grid. The vulnerabilities, he said, are ripe for abuse."

In a report published June 12th, Register.com's Dan Goodin reports, "The newfangled meters needed to make the smart grid work are built on buggy software that's easily hacked, said Mike Davis, a senior security consultant for IOActive. The vast majority of them use no encryption and ask for no authentication before carrying out sensitive functions such as running software updates and severing customers from the power grid. The vulnerabilities, he said, are ripe for abuse."

Davis will present at the Black Hat Conference next month, and will demonstrate a worm that he has developed that he claims easily infects the current generation of smart meters. "We can switch off hundreds of thousands of homes potentially at the same time," Davis, who has spent the past few months analyzing a half-dozen smart meters, told The Reg. "That starts providing problems that the power company may not be able to gracefully deal with."

For more details read the rest of the article here.

Is this a surprise to anybody? It certainly isn't a surprise to Unfettered. We've been warning and just waiting for a report like this to surface. I've spoken to many functional security experts who believe that the real benefits of smart grid aren't going to come from household smart meters anyway, but from the generation systems and the transmission and distribution systems and interconnecting them properly.

Most of the functional security experts I know won't have a smart meter in their house for any money-- certainly not now.

Eric Byres warned of this 10 yeas ago when he started developing edge device security appliances, like his Tofino device. If we've known that this was probably going to happen for a decade, there's no excuse for the development of smart meters that are penetrable easily and quickly by the script kiddie who lives in the house, or next door, or around the block.

Sponsored Recommendations

2024 Industry Trends | Oil & Gas

We sit down with our Industry Marketing Manager, Mark Thomas to find out what is trending in Oil & Gas in 2024. Not only that, but we discuss how Endress+Hau...

Level Measurement in Water and Waste Water Lift Stations

Condensation, build up, obstructions and silt can cause difficulties in making reliable level measurements in lift station wet wells. New trends in low cost radar units solve ...

Temperature Transmitters | The Perfect Fit for Your Measuring Point

Our video introduces you to the three most important selection criteria to help you choose the right temperature transmitter for your application. We also ta...

2024 Industry Trends | Gas & LNG

We sit down with our Industry Marketing Manager, Cesar Martinez, to find out what is trending in Gas & LNG in 2024. Not only that, but we discuss how Endress...