Join Nostr
2026-06-25 21:53:28 UTC
in reply to

Preston Maness ☭ on Nostr: nprofile1q…9qzwa Really? Inverters? What cybersecurity risks exist for inverters? ...

Really? Inverters? What cybersecurity risks exist for inverters?

>The rationale: China-made inverters are deemed a cybersecurity liability, since manufacturers might be able to remotely manipulate them or even switch them off, destabilising energy grids and potentially causing blackouts.
>
>But the Commission's push to phase out so-called high-risk inverters has alarmed EU officials involved in development projects, as it remains uncertain whether European producers can meet demand.

Uh... how?

/me digs into the references

>The report [by cybersecurity firm Secura] follows a recent probe by investigative journalism platform Follow the Money that shows that a hacker could have gained control of millions of Dutch smart solar panel systems using a backdoor into their online system.
>
>https://www.euronews.com/next/2024/08/21/europes-leading-solar-power-grid-is-vulnerable-to-hackers-this-is-what-a-cyberattack-could

/me looks for the report

>This scenario is a combination of situations which have previously occurred. Vulnerabilities in interfaces of solar panel installations that were connected to the internet were exploited by the Mirai botnet and were then used for financial gain (Brumfield, 2024). In another example, a manufacturer remotely provided 800,000 micro-inverters with a new update on the same day in order to resolve certain problems (Fairley, 2015). A previous investigation by the Dutch Authority for Digital Infrastructure (RDI) (RDI, 2023) also demonstrated that if a malicious actor is able to access an inverter, they are often able to hijack it. The recent attack by anti-Israel hacktivists on PLC systems (Counter threat unit research team, 2023) is another recent example of opportunistic hacktivism, which could also impact the Netherlands even if the Netherlands were not the direct target.
>
>https://www.energy-innovation.nl/documents/1299/2024-Secura_Report-Cybersecurity_threats_and_measures_for_the_solar_power_sector.pdf

Well damn. So those things *do* have network connections. Why? Apart from the obvious "don't connect these devices to a network" approach, the report actually makes a case for requiring the firmware to be open source, which is nice I guess:

>Countermeasures would therefore need to be taken to counteract this – for example, a technically enforced four-eyes principle when issuing new firmware, not simultaneously updating all equipment but using a phased approach, or even making firmware open source so that independent parties can also investigate and contribute to it.