Hackers rewrite smart meter power bill

Powered by SC Magazine
 

Energy data shows what movies customers were watching.

Two German researchers have exploited security holes in a smart meter service to alter energy consumption rates, expose privacy flaws and determine what movies consumers had watched.

Dario Carluccio and Stephan Brinkhaus demonstrated the flaws with German energy company Discovergy at the Chaos Computing Congress in Berlin.

The researchers, also customers, learnt that energy consumption data was sent unencrypted because SSL was malfunctioning.

They intercepted and manipulated the data using Fritzbox! and WireShark and returned to the company a negative energy consumption rate of -106610 kWh.

Similar flaws also allowed Carluccio and Brinkhaus to demonstrate that a customer’s entire power consumption history was stored by Discovergy.

Customers could only access a three month time frame under normal circumstances.

A capability that allowed power consumption to be monitored in two-second intervals was also exploited.

The researchers said they could determine if a particular movie had been watched based on two-second relay data held by Discovergy and accessed through HTTP GET requests.

The company offered the services to allow customers to determine if they had left an electrical appliance switched on if they had left their home.

Discovergy CEO Nikolaus Starzacher said customers would have the option to disable the relay feature.

Copyright © SC Magazine, Australia


Hackers rewrite smart meter power bill
 
 
 
Top Stories
Qld Transport to replace core registration system
State's biggest citizen info repository set for overhaul.
 
Innovating in the sleepy super industry
There’s little incentive to be on the bleeding edge, so why is Andrew Todd fighting so hard?
 
How technology will unify Toll
The systems headache formed through 15 years of acquisitions.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
Who do you trust most to protect your private data?







   |   View results
Your bank
  39%
 
Your insurance company
  3%
 
A technology company (Google, Facebook et al)
  7%
 
Your telco, ISP or utility
  7%
 
A retailer (Coles, Woolworths et al)
  2%
 
A Federal Government agency (ATO, Centrelink etc)
  21%
 
An Australian law enforcement agency (AFP, ASIO et al)
  15%
 
A State Government agency (Health dept, etc)
  5%
TOTAL VOTES: 899

Vote