Feeds

Smart meter SSL screw-up exposes punters' TV habits

Also showed researchers WHETHER OR NOT THEY WERE HOME

Intelligent flash storage arrays

White-hat hackers have exposed the privacy shortcomings of smart meter technology.

The researchers said German firm Discovergy apparently allowed information gathered by its smart meters to travel over an insecure link to its servers. The information – which could be intercepted – apparently could be interpreted to reveal not only whether or not users happened to be at home and consuming electricity at the time but even what film they were watching, based on the fingerprint of power usage. The many surprising secrets revealed by some smart meter set-ups were revealed during a presentation by researchers Dario Carluccio and Stephan Brinkhaus at the 28th Chaos Computing Congress (28c3) hacker conference in Berlin late last month.

During the talk, entitled, Smart Hacking for Privacy (YouTube video here), the researchers explained that they came across numerous security and privacy-related issues after signing up with the smart electricity meter service supplied by Discovergy.

Because Discovergy's website's SSL certificate was misconfigured, the meters failed to send data over a secure, encrypted link - contrary to claims Discovergy made at the time before the presentation. This meant that confidential electricity consumption data was sent in clear text. Because meter readings were sent in clear text, the researchers were able to intercept and send back forged (incorrect) meter readings back to Discovergy.

In addition, the researchers discovered that a complete historical record of users' meter usage was easily obtained from Discovergy's servers via an interface designed to provide access to usage for only the last three months. The meters supplied by the firm log power usage in two-second intervals. This fine-grained data was enough not only to determine what appliances a user was using over a period of time – thanks to the power signature of particular devices – but even which film they were watching.

They explained that the fluctuating brightness levels of a film or TV show when displayed on a plasma-screen or LCD TV created fluctuating power-consumption levels. This creates a power/consumption signature for a film that might be determined from the readings obtained by Discovergy's technology. The researchers concluded that the two-second frequency of power readings was unnecessary for Discovergy's stated goal of providing a warning for consumers should they, for example, have left an iron on after leaving the house.

Nikolaus Starzacher, chief exec of Discovergy, was among those who attended the presentation. He thanked the researchers for their work and promised to adapt Discovergy's technology so as to minimise potential security and privacy concerns.

More commentary on the presentation can be found in a blog post by Sophos here.

Smart meters: an ongoing security threat?

Smart meters bring two-way communication between a meter and the central control system of a gas or electricity utility. Suppliers want to introduce the technology not only because it simplifies the process of collecting meter reading, but also because it makes it easier to control supply at times of peak demand. The technology also makes it easier to switch late or unreliable payers onto higher tariffs.

Some security experts, most notably Ross Anderson, professor in security engineering at the University of Cambridge Computer Laboratory, have warned that smart metering introduces a "strategic vulnerability" that might be exploited to remotely switch off elements on the gas or electricity supply grid. Government ministers in the UK have downplayed such fears but the work of the German researchers raise new concerns, related to privacy. ®

Top 5 reasons to deploy VMware with Tegile

More from The Register

next story
Regin: The super-spyware the security industry has been silent about
NSA fingered as likely source of complex malware family
Why did it take antivirus giants YEARS to drill into super-scary Regin? Symantec responds...
FYI this isn't just going to target Windows, Linux and OS X fans
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Home Office: Fancy flogging us some SECRET SPY GEAR?
If you do, tell NOBODY what it's for or how it works
HACKERS can DELETE SURVEILLANCE DVRS remotely – report
Hikvision devices wide open to hacking, claim securobods
'Regin': The 'New Stuxnet' spook-grade SOFTWARE WEAPON described
'A degree of technical competence rarely seen'
Syrian Electronic Army in news site 'hack' POP-UP MAYHEM
Gigya redirect exploit blamed for pop-rageous ploy
Astro-boffins start opening universe simulation data
Got a supercomputer? Want to simulate a universe? Here you go
prev story

Whitepapers

Driving business with continuous operational intelligence
Introducing an innovative approach offered by ExtraHop for producing continuous operational intelligence.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
How to determine if cloud backup is right for your servers
Two key factors, technical feasibility and TCO economics, that backup and IT operations managers should consider when assessing cloud backup.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Internet Security Threat Report 2014
An overview and analysis of the year in global threat activity: identify, analyze, and provide commentary on emerging trends in the dynamic threat landscape.