On 29/12/2009, at 10:07 PM, Crispin Harris wrote:
> Ohhh, the Potential Joys that are Smart Meters.
> Ahhh, the World of FAIL that is the in-world deployment of these things!
> On Tue, Dec 29, 2009 at 2:57 PM, <stephen at melbpc.org.au> wrote:
>> Hmm .. seems to me that if every home, workplace and powered structure
>> will soon have an always-on smart meter point for home/work/car energy
>> metering..
> <groans> Oh Ghod, I hope not.  There is some good academic literature about
> the dangers of so-called smart-meters, and the (incredibly) insecure
> wireless protocol that is being used for remote management and update for
> these devices.
> Prof Caig Valli (
> http://www.scss.ecu.edu.au/staff/staffinfo.php?staffid=craigv) { Head of
> School, School of Computer and Security Science, Edith Cowan University
> c.valli at ecu dot edu dot au }, presented some interesting findings on
> Smart metering at the recent Australian Security and Inteligence Conference
> (http://ocs.scss.ecu.edu.au/index.php/asic/ASIC09).
> His findings are summarised thusly:
> 1) the wireless communications protocol most often used is riddled with
> holes,
> 2) low cost commodity equipment can compromise the wireless networks
> 3) the devices do not do even the most minimal validity checks on firmware
> updates (not even a simple CRC check)
> 4) Malware propogation through the network is exponential. Further,
> simulations of metropolitan deployment showed that the network was
> unrecoverable within a very short time (15-30 minutes IIRC) after initial
> infection.

And in this week's "Patch Monday" podcast at ZDNet.com.au, Crispin and I chat further about these security risks.

or, for those with brain-deaf email clients,


