Open Source Smart Meter Hacking Framework Released
wiredmikey writes "A researcher specializing in smart grids has released an open-source tool designed to assess the security of smart meters. Dubbed 'Termineter,' the framework would allow users, such as grid operators and administrators, to test smart meters for vulnerabilities. Termineter uses the serial port connection that interacts with the meter's optical infrared interface to give the user access to the smart meter's inner workings. The user interface is much like the interface used by the Metasploit penetration testing framework. It relies on modules to extend its testing capabilities. Spencer McIntyre, a member of SecureState's Research and Innovation Team, is scheduled to demonstrate Termineter in a session 'How I Learned to Stop Worrying and Love the Smart Meter,' at Security B-Sides Vegas on July 25. The Termineter Framework can be downloaded here." As the recent lucky winner of a smart meter from the local gas company, I wish householder access to this data was easy and expected.
Or just my meter !!
As someone who writes drivers for various smart meters to do AMR, I am surprised it took this long. Most protocols are childishly simple with little in the way of encryption or authentication. Often the passwords are sent in plain text. Check metering might be a simpler way to secure your meters. Catch them at it rather than get into an arms race...
I have determined that my sig is indeterminate.
One of the main reasons for installing smart gas meters is to not have to deal with customers like you. The meters are accurate and can be read from a distance. Meter readers who used to read 200 to 300 meters a day can now read 3000 a day, and they don't have to deal with your fences, holly bushes, mean dogs, and bad attitude.
Doesn't help me on my job because I have to physically walk over your service line and be able to touch the meter. I check for leaks, and if I can't do my job because of the bloody obstacle course you've made your yard into, then I just write it down as uncheckable and you're on your own.
Nobody is out to cheat you. The gas company gets cheated way more often than the customer does.
Soon, the meters will be smart enough to connect to your bank account.
rewriting history since 2109
Nobody is out to cheat you. The gas company gets cheated way more often than the customer does.
In other words, "the $FOSSILFUELCORP I worked at is honest, as far as I know, though I don't know everyone personally and didn't launch an investigation or anything ... therefore it should be obvious that every employee at every other $FOSSILFUELCORP is equally honest." Sheesh, with such impeccable logic I don't know why so many people just won't believe you...
I witnessed an old electrician use a fragment of a standard household item to mitigate his monthly payment to the electricity provider. This was 20 years ago and obviously on a dumber meter. The new meters will not stop theft, though they will change the perp's resume` from HS dropout to 'sum book larnin'.
Happiness in intelligent people is the rarest thing I know.
Ernest Hemingway
The meter is not your property and hacking it without authorization is illegal. You don't use Metasploit on other people's systems and you shouldn't use this on the utility's meter either. Buy your own meter if you want to run some experiments.
One of the main reasons for installing smart gas meters is to not have to deal with customers like you. The meters are accurate and can be read from a distance. Meter readers who used to read 200 to 300 meters a day can now read 3000 a day, and they don't have to deal with your fences, holly bushes, mean dogs, and bad attitude.
Doesn't help me on my job because I have to physically walk over your service line and be able to touch the meter. I check for leaks, and if I can't do my job because of the bloody obstacle course you've made your yard into, then I just write it down as uncheckable and you're on your own.
Nobody is out to cheat you. The gas company gets cheated way more often than the customer does.
The problem I have with smart meters for gas & electricity isn't a worry about the utility company somehow "cheating" me.
It's a number of things.
First, it allows real-time rationing on an individual level, allowing for all kinds of possible discrimination and other shenanigans. For instance, you get identified at a protest against your utility company, a politician your utility company supports, or some piece of legislation, and then suddenly, and completely coincidentally of course, all sorts of bad things happen to your service and your billing.
Second, it also provides a pool of very granular and detailed data that I don't particularly care to to have in the hands of either the utility or the government/LEAs, especially without strict rules that we as citizens and consumers get to vote on. How about a spouse using the data in a divorce to prove another person was there? Or a LEA using that blip in usage when you pulled out that old broken toaster-oven/microwave/etc to try to fix it as evidence of criminal activity.
Third, it's another set of data points that allow a more thorough profiling of individual habits, schedules, and activities. It's data that's also sure to be stolen/hacked at some point, either directly from the meters or from the utility database. Hack the smart meter of somebody you don't like and get them raided by a paramilitary SWAT team looking for a grow operation, maybe even getting them or their family members killed.
Sorry that your job is difficult. However, I'm not about to allow myself to be put into the above scenarios just to make your job easier. Get another job if it's that bad.
Strat
Progressivism (aka US 'Liberalism'): Ideas so good they need a police/surveillance-state to enforce.
Please, They have us CALL IN the numbers. so sorry you don't have to come in my house, walk on my grass or be licked to death by my friendly dog that loves everyone. I don't let strangers in my house anyway, you might be a serial killer or rapist!
This person gets it.
To the meter reader guy: Sorry you have to leave the office once every couple months and go door to door asking to read meters, at a time of day that most people are at work so you just drop a slip in the mail box so they call the numbers in. That sounds rough dude. SARCASM-> I feel really bad you have such a hard job -SARCASM
It would be rather catastrophic if all this 'connectedness' suddenly became disconnected. Many networks (finance, supply chain, electricity, gas, water, etc) are interconnected and interdependent in a number of ways.
One of the main reasons for installing smart gas meters is to not have to deal with customers like you. The meters are accurate and can be read from a distance. Meter readers who used to read 200 to 300 meters a day can now read 3000 a day, and they don't have to deal with your fences, holly bushes, mean dogs, and bad attitude.
You clearly don't understand what a "smart reader" is. What you describe is drive-by meter reading and it has been deployed for years now. Smart readers don't make the meter readers more efficient, they eliminate the entire job category by sending the meter data all the way back home over their own network.
Among most of his tin foil hat nonsense there were some valid concerns mainly with access to your usage times. That can be used as a crime tool
Third, it's another set of data points that allow a more thorough profiling of individual habits, schedules, and activities.
First, that data can be usefull to you. You might want to adjust your usage in periods when electricity prices are high.
Second, I agree that that data shouldn't be in the hands of anyone besides you.
This can be accomplished by letting the meter log data in 2 places:
- The first place only logs the tariff and the cumulative usage while that tariff was in effect.
- The second place logs the tariff, and usage over time (e.g. every minute the applied tariff and the usage in that last minute is logged)
Again, the utility doesn't need to know when you used the electricity, they only need to know how expensive the electricity was at that moment.
Well, why not to opt-out? Yes, it costs a bit extra, but who said that piece of mind is free? Just click http://t.co/CY8crRXY and opt-out.
I check for leaks, and if I can't do my job because of the bloody obstacle course you've made your yard into, then I just write it down as uncheckable and you're on your own.
So what you're saying is now nobody checks for leaks? Somehow I don't think this will end well, especially with electronics in close proximity.
So no smart meters to keep the luddites and those with "radiation allergies" happy? At the very least it will keep the coal mining industry happy.