Home Business IT Security The latest tools for hacking Smart Meters
The latest tools for hacking Smart Meters Featured
Get all your tech news delivered to your mail box five days a week
iTWire UPDATE - it's FREE!


For a category of devices intended to operate for 20 - 50 years, we sure are seeing a lot of early security problem with Smart Meters.

When it comes to guaranteeing resistance against determined, long-term intruders, most security experts will shy violently away from any substantive predictions of long-term viability. And that doesn't matter whether you're talking about hardware or software applications (how long did DES last?)

In mid 2009, iTWire spoke with Gabriel d'Eustachio, Security Consulting Lead at CSC to gain his thoughts on the state of play with Smart metering (also known as Advanced Metering Infrastructure) - this conversation happened a little after the Victorian Government had called a halt to the meter roll-out avalanche; Gabriel was speaking more generally on the overall project.

The Victorian Government has made a bold decision in this space. They have mandated the implementation of one of the most advanced systems in the world. This is a double edged proposition: this system will give Victoria a long-term edge in both energy efficiency and reliability; on the other hand, something this complex brings on incredible amounts of risk. The standards and guidelines for security and privacy are not formally defined to any detail, and the power companies are compelled to fly "seat-of-the-pants" until some standards are produced. Very interesting time to be involved in this industry.

I agree with you that consumers have a valid concern that their privacy will be respected with this new technology. Step 1 of enforcing privacy is strong security controls. In my opinion, decisions regarding privacy and consumer protections should be made prior to the implementation of this technology. I would advocate including key stakeholders (this could be facilitated by the National Smart Metering Program) and also including independent consumer and privacy advocates in the decision making process.

In the weeks before d'Eustachio spoke with iTWire, there were three presentations at BlackHat (the Las Vegas hackers' conference) dealing with how to break into Smart Meters - not bad for brand-new technology intended to survive for a generation or more.

At around the same time, iTWire reached out to the Victorian Department of Primary Industry - the department responsible for Smart Meter roll-out for their thoughts on the various security issues already announced.

iTWire: Every meter is essentially a computer; what will be done to ensure that these meters are installed untampered and also are provided with regular security updates (should later 'issues' be identified)?

Read on for DPI's response and also the latest ways to cause mischief to Smart Meters.

RECRUITMENT & RETENTION REPORT 2013

HIRE OR FIRE? BUY OR BUILD

2013 is well underway and Australian companies need to know whether they should invest in IT skills training or pay a premium for the people they need.

If you want to know which choices are being made in your sector, what skills are hard to find, which sectors intend to hire or fire and where the IT spend is going, this free report is must have.

GET YOUR REPORT NOW

David Heath

joomla statistics

David Heath has over 25 years experience in the IT industry, specializing particularly in customer support, security and computer networking. Heath has worked previously as head of IT for The Television Shopping Network, as the network and desktop manager for Armstrong Jones (a major funds management organization) and has consulted into various Australian federal government agencies (including the Department of Immigration and the Australian Bureau of Criminal Intelligence). He has also served on various state, national and international committees for Novell Users International; he was also the organising chairman for the 1994 Novell Users' Conference in Brisbane. Heath is currently employed as an Instructional Designer, building technical training courses for industrial process control systems.

Connect

http://bs.serving-sys.com/BurstingPipe/adServer.bs?cn=tf&c=19&mc=imp&pli=5460041&PluID=0&ord=[2000]&rtu=-1