I work in Solar and it is crazy to me that we are installing thousands of Internet connected devices that control megawatts or now even gigawatts of power. Even if we ignore a Chinese adversarial backdoor, one exploit on these and shit goes dark quick. Regulations should be as tight as on smart meters, but it is just the Wild West right now.
Europe
News and information from Europe 🇪🇺
(Current banner: La Mancha, Spain. Feel free to post submissions for banner images.)
Rules (2024-08-30)
- This is an English-language community. Comments should be in English. Posts can link to non-English news sources when providing a full-text translation in the post description. Automated translations are fine, as long as they don't overly distort the content.
- No links to misinformation or commercial advertising. When you post outdated/historic articles, add the year of publication to the post title. Infographics must include a source and a year of creation; if possible, also provide a link to the source.
- Be kind to each other, and argue in good faith. Don't post direct insults nor disrespectful and condescending comments. Don't troll nor incite hatred. Don't look for novel argumentation strategies at Wikipedia's List of fallacies.
- No bigotry, sexism, racism, antisemitism, dehumanization of minorities, or glorification of National Socialism.
- Be the signal, not the noise: Strive to post insightful comments. Add "/s" when you're being sarcastic (and don't use it to break rule no. 3).
- If you link to paywalled information, please provide also a link to a freely available archived version. Alternatively, try to find a different source.
- Light-hearted content, memes, and posts about your European everyday belong in [email protected]. (They're cool, you should subscribe there too!)
- Don't evade bans. If we notice ban evasion, that will result in a permanent ban for all the accounts we can associate with you.
- No posts linking to speculative reporting about ongoing events with unclear backgrounds. Please wait at least 12 hours. (E.g., do not post breathless reporting on an ongoing terror attack.)
(This list may get expanded when necessary.)
We will use some leeway to decide whether to remove a comment.
If need be, there are also bans: 3 days for lighter offenses, 14 days for bigger offenses, and permanent bans for people who don't show any willingness to participate productively. If we think the ban reason is obvious, we may not specifically write to you.
If you want to protest a removal or ban, feel free to write privately to the mods: @[email protected], @[email protected], or @[email protected].
These exploits aren't even purely theoretical anymore. At the 38C3 two security researches have demonstrated, that streetlights and many other devices in Europe, specifically in Germany, can be influenced using very simple methods, like replay attacks, through long-wave radio.
Starting at around 35:00, they've also shown, that some solar power plants use similar vulnerable controllers. If it hasn't been fixed yet, it should be pretty easy to remotely connect or disconnect these plants from the grid, thereby potentially destabilizing it.
The security of Europe's infrastructure really is in dire need of regulation.
As someone working in government IT, the entire sector is focused on compliance, not security. You can install the most obviously backdoored/unsafe device or software, as long as you have a paper trail that someone pinky promised that it's secure. Absolutely bonkers.
In your case, if the manufacturer of devices has all the necessary certifications, nobody will even question the security.
I work in Solar and it is crazy to me that we are installing thousands of Internet connected devices that control megawatts or now even gigawatts of power. Even if we ignore a Chinese adversarial backdoor,
There was that attack Russia did on Viasat systems early in the invasion with the aim of knocking out Ukrainian communications infrastructure where they accidentally knocked out the communications links to a bunch of German wind turbines.
That wasn't even Russia trying to hit Germany, just trying to damage systems and not being very precise in what they targeted.
https://en.wikipedia.org/wiki/Viasat_hack
On February 23, 2022, hackers targeted a VPN installation, in a Turin management center, which provided network access to administrators and operators. The hackers gained access to management servers that gave them access to information about company’s modems. After a few hours, the hackers gained access to another server that delivered software updates to the modems which allowed them to deliver the wiper malware AcidRain.[2]
On 24 February, 2022, the day Russia invaded Ukraine, thousands of Viasat modems went offline.[3] The attack caused the malfunction in the remote control of 5,800 Enercon wind turbines in Germany and disruptions to thousands of organizations across Europe.[4]
Yes!! I have been asking for this since i was 10!! I was not the most normal child...
With regard to forced labour accusations, a new report by the International Labour Organization (ILO) published a couple of days ago criticizes - again - 'China's system of transferring “surplus” rural workers [...] into industries such as the processing of raw materials for the production of solar panels, batteries and other vehicle parts.'