this post was submitted on 11 Jul 2026
273 points (93.9% liked)

Technology

86538 readers
2983 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
 

cross-posted from: https://scribe.disroot.org/post/10061950

Security researchers from the Chaos Computer Club (CCC) have exposed critical vulnerabilities in Hoymiles solar inverters that allow attackers to remotely control, manipulate, or destroy hundreds of thousands of solar installations across Europe. The Chinese manufacturer holds roughly 20 percent of the European microinverter market, making the security flaw a widespread threat to balcony power plants and small rooftop solar systems.

...

During experimental tests, a modified handheld scanner located two dozen foreign inverters and their identification numbers within 20 minutes. In Augsburg, Hunz identified 42 hackable systems within just one hour. The radio signals can travel several hundred meters, making it feasible to mount attack equipment on drones for systematic scanning of residential areas.

Once attackers have the serial numbers, they can switch inverters on or off, alter power limits, and inject malware through an unprotected firmware update command. Tampering with sensitive network parameters or erasing bootloader memory could lead to fires, electrical accidents, or device destruction requiring physical repair.

...

The CCC informed Hoymiles [which is headquartered in China] about the vulnerability in February but received no initial response. Only after the German Federal Office for Information Security contacted the Chinese authority CNCERT did Hoymiles react at the end of June. The company announced a security update for mid-October.

...

Archived

you are viewing a single comment's thread
view the rest of the comments
[–] Jason2357@lemmy.ca 7 points 1 week ago* (last edited 1 week ago) (2 children)

Did they break this story? Looks like this is a copy-paste article on hundreds of shitty sites: https://duckduckgo.com/?t=fpas&q=chaos+computer+club+solar+vulnerability+remote+chinese&ia=web

The Chaos Computer Club is real, and awesome, but I cand find anything on their site or YouTube about this yet. It was probably not in English though so thats on me: https://www.ccc.de/en/home

Edit, I just had to scroll down: https://lemmy.ca/post/67687895/24241020

[–] yggstyle@lemmy.world 6 points 1 week ago* (last edited 1 week ago)

I imagine the feat itself is possible and plausible - though I couldn't speculate further without digging into the specifics.

What left me feeling wary was, at least in the US, theres been a massive push to limit the spread and use of renewables... and normally when sowing fear and doubt you generally want to tie in your preferred boogie man. Presently that would be China.

Misinformation campaigns and astro turfing frequently will rely on half truths as it is FAR easier to sow dissent in a community. A half truth becomes opinion - an easily disproven lie can backfire and unify communities.

Tons of Chinese equipment is exploitable. Most of the time its simply a product of "cheap, fast, stable/secure" pick 2. I promise you it won't be the thing that costs time and money.

I won't speculate further on something I noticed in passing but... very frequently the third play in the trifecta is to accuse your boogie man of something that you are doing as well. It weakens the opposing observation, true or not, by increasing difficulty in finding data (similar search terms... two different parties) and lizard brain "feels" like your arguement is weaker because its copying the opposition.

Either way - I'd hesitate to take an organization seriously if they fucked up their own.distribution platform that badly and didnt IMMEDIATELY fix it. Either they are inept or unaware... and unaware implies lack of traffic who might @ a dev.