Detail, east Portland photo, courtesy Miles Hochstein / Portland Ground.



For old times' sake
The bojack bumper sticker -- only $1.50!

To order, click here.







Excellent tunes -- free! And on your browser right now. Just click on Radio Bojack!






E-mail us here.

About

This page contains a single entry from the blog posted on January 26, 2011 11:45 AM. The previous post in this blog was The multi-modal mecca ain't always pretty. The next post in this blog is Port guy: No coal through Hayden Island. Many more can be found on the main index page or by looking through the archives.

Archives

Links

Law and Taxation
How Appealing
TaxProf Blog
Mauled Again
Tax Appellate Blog
A Taxing Matter
TaxVox
Tax.com
Josh Marquis
Native America, Discovered and Conquered
The Yin Blog
Ernie the Attorney
Conglomerate
Above the Law
The Volokh Conspiracy
Going Concern
Bag and Baggage
Wealth Strategies Journal
Jim Hamilton's World of Securities Regulation
myCorporateResource.com
World of Work
The Faculty Lounge
Lowering the Bar
OrCon Law

Hap'nin' Guys
Tony Pierce
Parkway Rest Stop
Utterly Boring.com
Along the Gradyent
Dwight Jaynes
Bob Borden
Dingleberry Gazette
The Red Electric
Iced Borscht
Jeremy Blachman
Dean's Rhetorical Flourish
Straight White Guy
HinesSight
Onfocus
Jalpuna
Beerdrinker.org
As Time Goes By
Dave Wagner
Jeff Selis
Alas, a Blog
Scott Hendison
Sansego
The View Through the Windshield
Appliance Blog
The Bleat

Hap'nin' Gals
My Whim is Law
Lelo in Nopo
Attorney at Large
Linda Kruschke
The Non-Consumer Advocate
10 Steps to Finding Your Happy Place
A Pig of Success
Attorney at Large
Margaret and Helen
Kimberlee Jaynes
Cornelia Seigneur
Mireio
And Sew It Goes
Mile 73
Rainy Day Thoughts
That Black Girl
Posie Gets Cozy
{AE}
Cat Eyes
Rhi in Pink
Althouse
GirlHacker
Ragwaters, Bitters, and Blue Ruin
Frytopia
Rose City Journal
Type Like the Wind

Portland and Oregon
Isaac Laquedem
StumptownBlogger
Rantings of a [Censored] Bus Driver
Jeff Mapes
Vintage Portland
The Portlander
South Waterfront
Amanda Fritz
O City Hall Reporters
Guilty Carnivore
Old Town by Larry Norton
The Alaunt
Bend Blogs
Lost Oregon
Cafe Unknown
Tin Zeroes
David's Oregon Picayune
Mark Nelsen's Weather Blog
Travel Oregon Blog
Portland Daily Photo
Portland Building Ads
Portland Food and Drink.com
Dave Knows Portland
Idaho's Portugal
Alameda Old House History
MLK in Motion
LoveSalem

Retired from Blogging
Various Observations...
The Daily E-Mail
Saving James
Portland Freelancer
Furious Nads (b!X)
Izzle Pfaff
The Grich
Kevin Allman
AboutItAll - Oregon
Lost in the Details
Worldwide Pablo
Tales from the Stump
Whitman Boys
Misterblue
Two Pennies
This Stony Planet
1221 SW 4th
Twisty
I am a Fish
Here Today
What If...?
Superinky Fixations
Pinktalk
Mellow-Drama
The Rural Bus Route
Another Blogger
Mikeyman's Computer Treehouse
Rosenblog
Portland Housing Blog

Wonderfully Wacky
Dave Barry
Borowitz Report
Blort
Stuff White People Like
Worst of the Web

Valuable Time-Wasters
My Gallery of Jacks
Litterbox, On the Prowl
Litterbox, Bag of Bones
Litterbox, Scratch
Maukie
Ride That Donkey
Singin' Horses
Rally Monkey
Simon Swears
Strong Bad's E-mail

Oregon News
KGW-TV
The Oregonian
Portland Tribune
KOIN
Willamette Week
KATU
The Sentinel
Southeast Examiner
Northwest Examiner
Sellwood Bee
Mid-County Memo
Vancouver Voice
Eugene Register-Guard
OPB
Topix.net - Portland
Salem Statesman-Journal
Oregon Capitol News
Portland Business Journal
Daily Journal of Commerce
Oregon Business
KPTV
Portland Info Net
McMinnville News Register
Lake Oswego Review
The Daily Astorian
Bend Bulletin
Corvallis Gazette-Times
Roseburg News-Review
Medford Mail-Tribune
Ashland Daily Tidings
Newport News-Times
Albany Democrat-Herald
The Eugene Weekly
Portland IndyMedia
The Columbian

Music-Related
The Beatles
Bruce Springsteen
Seal
Sting
Joni Mitchell
Ella Fitzgerald
Steve Earle
Joe Ely
Stevie Wonder
Lou Rawls

E-mail, Feeds, 'n' Stuff

Wednesday, January 26, 2011

Grid not found

An alert reader asks an interesting, and worrisome, question: What happens when all those "smart meters" on the sides of our abodes get hit by a cyber-attack -- or just pick up a computer virus?

Comments (17)

Undoubtedly you will still be billed for services, utilities will simply revert to your historical average consumption rate.

I would imagine the likelihood of something like that happening is minimal. Smart Meters usually connect via either a voice or data line via and then they communicate to a cluster of servers that are distributed across various data centers for redundancy.

Communication from your smart meter to the cluster is sent via encrypted packets and the technology is FIPS compliant at the very least and then usually will have an extra blanket of security.

However if someone were to compromise the cluster they also would have backup systems and intrusion mitigation that would check the integrity of any store data.

So.... in essence every server would need to be hacked and all the data would need to be cracked and to my knowledge none of the FIPS compliant ciphers have been cracked and there are companies offering millions in rewards to any hacker who can do that so if it were likely or possible it would have been done long ago simply for the reward money.

But lets say the system did get hacked or was under a DDoS and the meters could not communicate well in this situation utility companies also have meter readers who can remotely access your meter from I think 200-300 ft with a special reading device that communicates over the same spectrum and uses encryption as well.

I would imagine the likelihood of something like that happening is minimal.

Hahahahaha....

http://rdist.root.org/2010/02/15/reverse-engineering-a-smart-meter/


http://www.greentechmedia.com/articles/read/hack-your-meter-while-you-can/

Or what about Uncle Sam thinking I have been using too much and turning off my "smart" refrigerator? Or heat?

"Smart Meters usually connect via either a voice or data line via and then they communicate to a cluster of servers that are distributed across various data centers for redundancy."

Actually, Smart Meters are networked over the power line (via a MODEM) to your house, so I'd assume the power company controls access to that path.

However, I thought someone was thinking of making wireless smart meters also (so a guy can just drive by and read your billing) - Which is a more interesting proposition.

The thought of someone being able to spin their meter backwards (like when you wire a solar panel in) would make an interesting science fair project.

Actually, they are wireless.

When mine was installed, the installer walked out to the sidewalk and held up a reader to confirm performance. He explained that this meant they could just drive down the street and read the meter.

Ho boy....

Here's an abbreviated history of hacking:

http://delontin1.wordpress.com/2008/02/27/complete-history-of-hacking/

If the DOD can be hacked repeatedly, a wireless utility network is child's play.

Not mentioned in the link above is a gentleman who spent some time in Federal prision in Sheridan, OR for his antics at an East Coast telco. He and his pals changed people's land line phone numbers at will. Messed up the billing database (including free calling for themselves). I might have worked with him. At the time of his conviction, he owned an ISP in Oregon.

I can hardly wait.....

Smart Meters usually connect via either a voice or data line

Smart Meters are networked over the power line

The meters used by PGE use a wireless radio frequency and a secure, encrypted datastream.

In fact, the meters aren't even fully-capable "smart meters". A meter reader is still required to drive into the neighborhoods with a laptop equipped with a radio receiver, whose range is only a handful of city blocks. The meters also lack two way communication, so there's really nothing that someone can do to it unless they walk up and pull the meter.

Yes, there are more advanced meters out there that do have two-way communication...but not the ones PGE is using.

In Tillamook County, the local PUD there set up a wireless network so they don't even have meter readers...they can literally ping every meter every single day if they wanted to and obtain daily electric consumption. (The benefit of that is in the event of a power outage, they can ping every meter to see which ones respond and which ones don't to know who is with and without power.)

"Actually, they are wireless."

How are they supposed to be smart then? I thought the concept was to be abel to read them (not too smart) and then use them to cycle on/off appliances in your house depending on load?

Here is some information from PGE on the smart meters: http://www.portlandgeneral.com/our_company/news_issues/current_issues/smart_meters.aspx

Note that they are setting up a complete wireless network, so that driving by isn't required, and communication will be two ways.

On of the features listed in their FAQ, http://www.portlandgeneral.com/our_company/news_issues/current_issues/smart_meters_faq.aspx, is "Connect and disconnect meters remotely from office." and "Direct load control: a program in which customers would agree to permit the utility to turn off certain appliances for limited periods when demand is high."

Just because there are a lot of "features" that can be done, doesn't mean they will be implemented right away.

As for load control, a "smart meter" by itself can't do diddly squat. Yes, with a capable two-way meter you can turn on - or off - the power. That's it. To control individual appliances would require additional equipment beyond the meter, and there is no way PGE could force that on anyone.

The good news here is that equipment designers are finally seeing what the threat environment is really like, and we're still pretty early in smart-meter deployment.

The bad news is that security complacency is abundant. Some utility, somewhere, is going to screw it up royally.

Should be interesting!

Oh, and to Mr. Kerensa, some unsolicited yet well-meant advice.* Your faith in technical security controls is charming, but let me suggest that you at least consider the possibility that it is overly optimistic. As a specific example, consider the military-grade FIPS-compliant system allegedly compromised by Mr. Bradley Manning.† More generally, I suggest you start with reading perhaps a dozen random back issues of Crypto-Gram for some inspiration about imagining What Will Go Wrong.

[*: Which, as with all such, may be as welcome as a punch in the nose. Oh, well, that's the internet for ya.]
[†: Or to put it another way, strong encryption is just one component of a security system, and it's usually the easy and straightforward part.]

To control individual appliances would require additional equipment beyond the meter, and there is no way PGE could force that on anyone.

Erik, they wont have to. The capability will be built into the devices themselves. Some are already starting to show up. There are water heaters, washer/dryers, refrigerators, etc.
And eventually, these types of devices will be the only new appliances available to us.

Actually the PLN (Data over powerline) option has not been used for awhile its all on the wireless spectrum now mostly. Smart meters today have upgraded firmware which techs manually flashed whenever they were required to upgrade.

Manning did not hack into or crack any FIPS compliant system.... He had access to the information he gathered.

B.K.: Yes, exactly my point: no cracking needed. Manning (allegedly) used the system as designed, but maliciously. Are commercial power grids less vulnerable to that sort of compromise - or even weak passwords - than military networks? I think not.

The security message here is that technical measures are just one part of the story. Once can read off encryption and authentication standards from the specifications all day long, but they do not automatically make a secure system. Securing a smart grid that's actually smart enough to be really useful is going to be a colossal pain in the arse. (Especially since end users will have physical access to important nodes in the network.)


Sponsors




As a lawyer/blogger, I get
to be a member of:

In Vino Veritas

Charamba, Douro 2008
Horse Heaven Hills, Cabernet 2010
Lorelle, Horse Heaven Hills Pinot Grigio 2011
Avignonesi, Montepulciano 2004
Lorelle, Willamette Valley Pinot Noir 2011
Villa Antinori, Toscana 2007
Mercedes Eguren, Cabernet Sauvignon 2009
Lorelle, Columbia Valley Cabernet 2011
Purple Moon, Merlot 2011
Purple Moon, Chardonnnay 2011
Abacela, Vintner's Blend No. 12
Opula Red Blend 2010
Liberte, Pinot Noir 2010
Chateau Ste. Michelle, Indian Wells Red Blend 2010
Woodbridge, Chardonnay 2011
King Estate, Pinot Noir 2011
Famille Perrin, Cotes du Rhone Villages 2010
Columbia Crest, Les Chevaux Red 2010
14 Hands, Hot to Trot White Blend
Familia Bianchi, Malbec 2009
Terrapin Cellars, Pinot Gris 2011
Columbia Crest, Walter Clore Private Reserve 2009
Campo Viejo, Rioja, Termpranillo 2010
Ravenswood, Cabernet Sauvignon 2009
Quinta das Amoras, Vinho Tinto 2010
Waterbrook, Reserve Merlot 2009
Lorelle, Horse Heaven Hills, Pinot Grigio 2011
Tarantas, Rose
Chateau Lajarre, Bordeaux 2009
La Vielle Ferme, Rose 2011
Benvolio, Pinot Grigio 2011
Nobilo Icon, Pinot Noir 2009
Lello, Douro Tinto 2009
Quinson Fils, Cotes de Provence Rose 2011
Anindor, Pinot Gris 2010
Buenas Ondas, Syrah Rose 2010
Les Fiefs d'Anglars, Malbec 2009
14 Hands, Pinot Gris 2011
Conundrum 2012
Condes de Albarei, Albariño 2011
Columbia Crest, Walter Clore Private Reserve 2007
Penelope Sanchez, Garnacha Syrah 2010
Canoe Ridge, Merlot 2007
Atalaya do Mar, Godello 2010
Vega Montan, Mencia
Benvolio, Pinot Grigio
Nobilo Icon, Pinot Noir, Marlborough 2009
Portuga, Rose 2011
Revelation, Chardonnay, Pays d'Oc 2010
Beaulieu, Cabernet, Rutherford 2005
Monte Alto, Tinto Reserva 2005
Chateau Ste. Michelle, Cabernet, Indian Wells 2009
Espiral, Vinho Rose
Vin-Koru, Pinot Gris 2011
14 Hands, Hot to Trot Red 2009
Rodney Strong, Cabernet, Sonoma 2009
Abacela, Vintner's Blend #11
Portuga, White 2010
La Bourgeoisie, Red 2009
Januik, Red 2009
Three Rivers, River's Red 2008
Kirkland, Alexander Valley Merlot 2008
Muga, Rioja Rose 2010
Quinta das Amoras, Vinho Tinto 2009
Mauro Molino, Barbera d'Alba 2009
Garda Chiaretto Rose
Columbia Crest, Two Vines Vineyard 10 White
Chateau Ste. Michelle, Pinot Gris, Columbia Valley 2009
L'Hortus, Rose de Saignee 2010
Maculan, Pino & Toi 2008
McKinley Springs, Bombing Range Red 2008
Trader Joe's Pinot Gris 2009
Montes Alpha, Cabernet 2007
Gran Sasso, Sangiovese, Terre di Chieti 2009
Garda, Classico Chiaretto Rose
Beaulieu, Cabernet, Rutherford 1999
Picos del Montgo, Tempranillo 2008
Chateau de Montmirail, Vacqueyras 2008
La Granja 360, Syrah 2009
Montgras, Carmenere Reserva 2009
Lange, Pinot Gris 2009
Columbia Crest, Horse Heaven Hills Cabernet 2008
Kirkland, Pinot Grigio 2010
Trader Joe's Coastal Syrah 2009
Columbia Crest, Horse Heaven Hills Merlot 2008
Trader Joe's Coastal Chardonnay 2009
Vieux Papes Red
Domaine de l'Aujardiere, Chardonnay 2009
Santa Rita, Cabernet, Medalla Real 2007
Penfold's, Koonunga Hill Shiraz Cabernet 2008
Guild, Red, Lot #02 2008
Dievole, Dievolino Sangiovese 2008
Laforet, Burgogne Chardonnay 2009
Columbia Winery, Merlot 2007
Bonterra, Cabernet 2008
Elk Cove, Pinot Gris 2009
Maquis Lien 2006
Scott Paul, Pinot Noir, Le Paulee 2007

The Occasional Book

Neil Young - Waging Heavy Peace
Mark Bego - Aretha Franklin, the Queen of Soul (2012 ed.)
Jenny Lawson - Let's Pretend This Never Happened
J.D. Salinger - Franny and Zooey
Charles Dickens - A Christmas Carol
Timothy Egan - The Big Burn
Deborah Eisenberg - Transactions in a Foreign Currency
Kurt Vonnegut Jr. - Slaughterhouse Five
Kathryn Lance - Pandora's Genes
Cheryl Strayed - Wild
Fyodor Dostoyevsky - The Brothers Karamazov
Jack London - The House of Pride, and Other Tales of Hawaii
Jack Walker - The Extraordinary Rendition of Vincent Dellamaria
Colum McCann - Let the Great World Spin
Niccolò Machiavelli - The Prince
Harper Lee - To Kill a Mockingbird
Emma McLaughlin & Nicola Kraus - The Nanny Diaries
Brian Selznick - The Invention of Hugo Cabret
Sharon Creech - Walk Two Moons
Keith Richards - Life
F. Sionil Jose - Dusk
Natalie Babbitt - Tuck Everlasting
Justin Halpern - S#*t My Dad Says
Mark Herrmann - The Curmudgeon's Guide to Practicing Law
Barry Glassner - The Gospel of Food
Phil Stanford - The Peyton-Allan Files
Jesse Katz - The Opposite Field
Evelyn Waugh - Brideshead Revisited
J.K. Rowling - Harry Potter and the Sorcerer's Stone
David Sedaris - Holidays on Ice
Donald Miller - A Million Miles in a Thousand Years
Mitch Albom - Have a Little Faith
C.S. Lewis - The Magician's Nephew
F. Scott Fitzgerald - The Great Gatsby
William Shakespeare - A Midsummer Night's Dream
Ivan Doig - Bucking the Sun
Penda Diakité - I Lost My Tooth in Africa
Grace Lin - The Year of the Rat
Oscar Hijuelos - Mr. Ives' Christmas
Madeline L'Engle - A Wrinkle in Time
Steven Hart - The Last Three Miles
David Sedaris - Me Talk Pretty One Day
Karen Armstrong - The Spiral Staircase
Charles Larson - The Portland Murders
Adrian Wojnarowski - The Miracle of St. Anthony
William H. Colby - Long Goodbye
Steven D. Stark - Meet the Beatles
Phil Stanford - Portland Confidential
Rick Moody - Garden State
Jonathan Schwartz - All in Good Time
David Sedaris - Dress Your Family in Corduroy and Denim
Anthony Holden - Big Deal
Robert J. Spitzer - The Spirit of Leadership
James McManus - Positively Fifth Street
Jeff Noon - Vurt

Road Work

Miles run year to date: 21
At this date last year: 52
Total run in 2012: 129
In 2011: 113
In 2010: 125
In 2009: 67
In 2008: 28
In 2007: 113
In 2006: 100
In 2005: 149
In 2004: 204
In 2003: 269


Clicky Web Analytics