Slashdot Mirror


FBI Says Smart Meter Hacks Are Likely To Spread

tsu doh nimh writes "A series of hacks perpetrated against so-called 'smart meter' installations over the past several years may have cost a single U.S. electric utility hundreds of millions of dollars annually, the FBI said in cyber intelligence bulletin first revealed today. The law enforcement agency said this is the first known report of criminals compromising the hi-tech meters, and that it expects this type of fraud to spread across the country as more utilities deploy smart grid technology."

19 of 189 comments (clear)

  1. Re:So how come they are "smart" meters? by cayenne8 · · Score: 3, Interesting
    I dunno...but the simple use a powerful magnet trick to cut the usage tracking down sounds fantastic to me!!

    Simple, just put the magnet on at night...take it off during the day when at work....

    I've been wanting to get some rare earth magnets to play with...hmm...now, maybe I have even more justification?

    {BAEG}

    --
    Light travels faster than sound. This is why some people appear bright until you hear them speak.........
  2. No fraud checking? by dj245 · · Score: 4, Interesting

    Besides the fact that you don't need to mess with dangerous line-voltages, this is no different than normal meter fraud. I can't imagine anything other than incompetence being the reason this was not found. A utility buys electricity, or makes it, and the amount they put on the grid is a known quantity and easily measured. If the amount that they are billing for is less than that, something is wrong. You can do the numbers on a per-line or a per-substation basis, possibly even more granular than that. All the major HV lines and substations have their own meters which report back to HQ. A single person stealing electricity is somewhat hard to catch, but if substantial amounts of people got away with this for an extended period of time, someone was not doing their job.

    --
    Even those who arrange and design shrubberies are under considerable economic stress at this period in history.
    1. Re:No fraud checking? by Sarten-X · · Score: 5, Funny

      You can do the numbers on a per-line or a per-substation basis, possibly even more granular than that.

      That's brilliant! To get specific enough information for legal recourse, we'll need maximum granularity, which means tracking the usage for each customer! We can put their meter right on their house for convenience!

      --
      You do not have a moral or legal right to do absolutely anything you want.
    2. Re:No fraud checking? by arth1 · · Score: 5, Informative

      A utility buys electricity, or makes it, and the amount they put on the grid is a known quantity and easily measured. If the amount that they are billing for is less than that, something is wrong.

      Yes, like Ohm's law and Joule's law. Any electrical cable and transformer converts electricity into heat, so what the users pull out can never equal what is put on the grid.

      Electricity is also not a resource like water, where if you don't pump it out one second, you can pump it out the next second. Use it or lose it. Converted to DC, it can be stored in capacitors or batteries, but at a very high cost.

    3. Re:No fraud checking? by icebike · · Score: 5, Interesting

      Besides the fact that you don't need to mess with dangerous line-voltages, this is no different than normal meter fraud. I can't imagine anything other than incompetence being the reason this was not found. A utility buys electricity, or makes it, and the amount they put on the grid is a known quantity and easily measured. If the amount that they are billing for is less than that, something is wrong. You can do the numbers on a per-line or a per-substation basis, possibly even more granular than that. All the major HV lines and substations have their own meters which report back to HQ. A single person stealing electricity is somewhat hard to catch, but if substantial amounts of people got away with this for an extended period of time, someone was not doing their job.

      But take your average mid size city, and the substations cover huge areas. HV feeders typically feed entire neighborhoods and step down to lower voltage on the neighborhood feed without any such meter. Line loss is variable, not a constant you can be assured of over time. Your mom's current frugality binge can make a significant difference in usage month to month.

      So how do you find the 6 houses out of 100 that reduce their consumption by some amount less than the average variance? Especially if they ratchet it down slowly in the high use season?

      And even if you statistically isolate a few suspects, how do you prove it? About the only way to do so is to put another meter upstream of each suspect house. Expensive, and not at all stealthy, so the suspect can drop the hack.

      A power company in an area I lived in, where power was still distributed with overhead wires, would put the meter at the top of the off-property pole as a way of advertising people they had caught tampering with meters. The entire neighborhood knew what that meant. They could still read them remotely, so it didn't involve any additional work load on their staff once installed.

      --
      Sig Battery depleted. Reverting to safe mode.
    4. Re:No fraud checking? by slimjim8094 · · Score: 4, Interesting

      They do tend to have meters per transformer ("pole pig"), which is pretty granular, as well as at other points in the distribution network. They use them to diagnose flaws in the system, but they're also used for finding fraud.

      --
      I have developed a truly marvelous proof of this comment, which this signature is too narrow to contain.
  3. Business model by Dunbal · · Score: 4, Insightful
    So the power company says "I know, let's make a bunch of money by using smart meters. That way we can fire all the people we used to send out to go read meters, and we can maximize our profits by having variable billing throughout the day."

    "Oh, and let's make sure to contract these meters out to the lowest bidder because after all, people are morons and if they don't realize that we're shafting them by getting them to pay more for their electricity, certainly they will never be smart enough to figure out our meters"

    "Oh shit, our meters can be hacked! These guys are CRIMINALS help help government HELP come save us!". That way we don't have to invest in more secure meters, or go back to the old meters. No, we can continue with minimal staff, continue with crappy hackable meters, and stick the cost of our broken business model to the government, the court system, and of course the prison system. Why should we have to share any of these unforseen costs from a business model we forgot to think through properly? Maximum profit is our GOD GIVEN RIGHT.

    --
    Seven puppies were harmed during the making of this post.
    1. Re:Business model by tomhath · · Score: 3, Informative

      The primary purpose is to provide an incentive for customers to shift energy use to non-peak hours. By doing that the peak load is reduced, which is a big cost saver for the utilities (less total generation and transmission capacity required).

  4. Obviously. by Reverand+Dave · · Score: 4, Insightful

    The problems started when we deregulated this industry. The smart meter debacle is just another symptom of a system that is rotten to the core. Where I live, power rates were heavily affected by the Enron fueled energy crisis and the rates have scarcely dropped since they were artificially driven up. Year after year the power company has been asking for $0.20 rate hikes because they know they can talk the PUC into giving them at least half of what they want. All the while claiming to be losing money while the parent company of the utility is making record profits.

    If the Utilities were regulated then they might have to spend a little more on the secure tech instead of the cheapest crap available. They would have a more vested interest in it since their single motivating factor is to provide service instead of to make as much money as possible.

    --
    I got here through a series of tubes
  5. The "other" hacking? by Anonymous Coward · · Score: 5, Interesting

    What about thieves who regularly intercept wireless signals from the meters to determine occupancy patterns, then come back and break in when no one's home?

    Do these meters have end-to-end encryption? Inquiring minds want to know.

    captcha: quality

    1. Re:The "other" hacking? by jessehager · · Score: 3, Informative

      Saw this gizmo earlier today: http://www.gridinsight.com/

      Since anyone can buy a receiver to read their own meters, I'm going to say "probably not."

  6. Re:So how come they are "smart" meters? by QuantumRiff · · Score: 3, Funny

    You're electric bill would be directly proportional to the number of quiet afternoons I had to listen to you music in my house :) Damn kids! you call that music?!!? Get off my lawn!

    --

    What are we going to do tonight Brain?
  7. Re:So how come they are "smart" meters? by mhajicek · · Score: 3, Interesting

    The law enforcement agency said... that it expects this type of fraud to spread across the country...

    Especially now that the vulnerabilities have been announced.

  8. Re:So how come they are "smart" meters? by LoRdTAW · · Score: 5, Interesting

    Smart meters do not use the old electro-mechanical method to measure power consumption. They are solid state and have no moving parts or coils that can be tampered with by a magnetic field.

    Little story:
    Back in high school I took electrical installation, basically you were taught to become an electrician for residential, commercial and industrial. We had an amazing teacher, a master electrician who told us how he cheated the meter to cut his bill down. Basically most older electric meters were "5-jaw" meaning that they had 5 contacts, two incoming hot legs from the street, one neutral and two outgoing hot legs to your panel box. If you cut the neutral leg the meter stopped spinning. So he "obtained" a forged matching utility seal (the numbered plastic thing that seals the meter to detect tampering) and ran two wires stealthily into the meter pan. Instead of the neutral leg of the meter going strait to the main neutral bus bar, it first went into his home to a timer switch hidden in a closet and back to the meter pans neutral bus bar. He said if you looked in the pan and didn't poke around, you would never see that the wires were diverted.
    So over the period of a few years he finally got it to the point where he would only pay 20-30 dollars a month in electricity because he lowered it very very slowly over time. If you suddenly half your electric bill the uitility's billing software would flag you and send an investigation team out who will pull your meter and take it to a lab for diagnosis and inspect your meter pan. Well he was sitting pretty paying next to nothing while running air conditioners and pool filters but one day the timer burnt out completely shutting the meter off. He didnt notice and said it could have been that way for well over a month. The utility came to his house on a day when he happened to be home and pulled the meter. The lights went out and he decided to look out the window and saw the utility truck in front of his house. He ran out and with some quick thinking started screaming at the utility workers "What the fuck are you doing! My wife was carrying laundry down the stairs and she fell. I think she broke her leg. Im calling 911, and im going to sue your asses!" before he could get back in the house the utility crew plugged the meter back in and ran. He then removed his modifications and covered his trail. The next day an inspector came and rang his bell informing him they had to remove the meter for inspection and that they were sorry for any problems the previous crew caused. Well they took his old mechanical meter and installed an electronic meter that had a clock and a light sensor (from his description). It was a "4-jaw" meter (no neutral) and could not be disabled without physically unplugging it. He never heard back from the utility as he covered his tracks and they couldn't prove he tampered with the meter since he replaced the seal with one of the same serial number. He never tried to tamper with the meter again.

    Goes to show you how easy it was to cheat the electric bill with a little skill, resources and patience.

  9. Re:So how come they are "smart" meters? by LiMikeTnux · · Score: 3, Interesting

    Most analog meters I have seen (I do residential) are 4 blades. You can actually pull them out and flip them upside down, and they will run backwards!

    --
    yap
  10. Re:So how come they are "smart" meters? by Anonymous Coward · · Score: 4, Insightful

    Smart meters have other advantages you just don't hear often about. The reason you don't hear about them is because it invades your privacy.

    With smart meters, they can tell people when you're home, likely which holidays you observe, if you watch TV, if you work at night or day, so on and so. They sell your demographic information.

    Likewise, police and other officials are now working with utility companies to determine if you are growing pot, running a business out of your garage, so on and so.

    The fact they hope to reduce their billing costs associated with meters is their primary goal but the field is ripe for secondary profit avenues.

    If you are against smart meters you are against industry invading your privacy and are therefore evil.

  11. Re:So how come they are "smart" meters? by gmanterry · · Score: 4, Informative

    I'm retired from two different electrical utilities. I can tell you that one of the things that was checked on old analog meters was the wear on the contact legs. It doesn't take many repetitions of flipping the meter in it's socket to wear off the plating on the copper legs. It's pretty obvious.

    --
    Since when is "public safety" the root password to the Constitution?
  12. Re:So how come they are "smart" meters? by Grizzley9 · · Score: 3, Insightful

    Goes to show you how easy it was to cheat the electric bill with a little skill, resources and patience and lack of ethics.

    Fixed that for you.

  13. Bullshit by Anonymous Coward · · Score: 3, Informative

    On a 200 amp feed the common leg has to be at least 2/0 copper or 4/0 aluminum. That shit is about as thick as a human thumb, requires a radius of several inches to make any kind of turn, and you're suggesting that he "stealthily" diverted it from the meter (one thumb-sized wire) and then routed it back into the meter with a second thumb-sized wire. Not a chance that this happened unless this "master electrician" created a severe fire and electrical hazard by using severely undersized wire.

    Never mind the fact this this scenario seems to indicate that a common day-timer was placed serially into a 200 amp circuit, which is just utter bullshit all by itself.

    Nice story though.