This is a failure of regulators and manufacturer, the media will spin it and next thing you know flipper zeros will be banned and smart meters will be as shitty as this one.
This is a failure of regulators and manufacturer, the media will spin it and next thing you know flipper zeros will be banned and smart meters will be as shitty as this one.
To rate limit switching would be a no brainer here.
These devices are not built to be operated by the general public. Anyone who operates these devices knows to reduce the load first.
I don't see the sense in saying "these devices, built for a specific industry with specific, exacting specs, should instead have been built with different specs that were never meant to occur".
Everywhere in industry we train operators to know how to operate machinery that can be made to break itself, because it's cheaper to train the operator than to make the machine unable to break itself.
The remote sends a signal to the chip in the device, and that chip decides what to do, often ignoring the signal if it's currently busy or otherwise doesn't want to.
There is no force here. Even if it wants to turn off on request in case of dangerous external circumstances, it doesn't need to turn back on so easily and rapidly.
You're looking at a $500K farming tractor and complaining that it doesn't have collision avoidance.
Now, smart meter being able to shut power off is somewhat expected. But I would also expect it to be protected command.
Guess where you don't have that? When you accept inputs via radio. The least you could do then is rate limit the input, better even would be authentication. This doesn't even has to be misuse. It could just be some wonky device sending the "wrong" sequence of zeros and ones on the right frequency and boom.
Guarding against this kind of interference is totally the task of the manufacturer. Designing the device in such a way, that you cannot turn a load switch into a makeshift dimmer for a short moment as well.
Still, maybe they should have better security. Specially as there is radio interface.
Seriously? The device has no authentication. By the design, anyone within range is authorised.
And it wasn't "forced". There's no code execution here. It was sent commands, it accepted them.
And comparing it to industrial applications with trained workers is just absurd. This is not some hugely complicated industrial system. I really don't see how logic for designing heavy machinery for industrial applications can be uncritically applied to consumer devices. It's just a different space, with different requirements and it's much less complicated.
Citation?
How? This is a system for remotely opening a circuit. The user can’t reduce the load first. At best they can (likely with too much latency to be at all reliable) wait for the meter to report a small load.
How does it enforce that? Is it just based on signal strength?
> The intended user can switch off or unplug the load in person then operate the meter.
This is just the wrong way to think about it. The "intended user" is all nice, but what can an attacker do? That is how these problems need to be analysed.
If a technician were on site, they could physically remove the meter or open the main breaker.
But if you use a smart meter (which by definition is in the path of the load) to switch something on/off it should not break as long as the load is within the spec of the meter. If it is out of spec of the meter, see above.
On a electrical component level the switching element they are using is rated for a maximal temperature. If they continue switching when it is outside of that temperature, because they did not observe a cooldown phase or don't guard against overheating in any other way, it is totally on them. They are operating the switching element outside of the scope, and they should never do that, even if some input tells them to do so.
1. Disconnect circuit 1 2. Connect circuit 2
Bypass step 1 by only sending 2 and bad things happen.
That is what this is about. It's not necessarily the fault of the manufacturer if a device can be harmed by deliberate RF-based (mis)use.
I am not too familiar with the FCC as I am from Europe, but even the linear motor of a standing desk will rate limit the amount of movement you can make it do within a given time frame (those linear motors are not designed for permanent operation).
If your meter is rated to switch a certain current, that rating is made under the assumption of a certain ambient temperature and temperature of the switching element. Switching it heats it up, so there has to be a cooldown period if you plan to still operate it within spec. Operating components within spec is the task of the manufacturer, and checks to avoid going out of spec should be one of the first things to design into such a product to prevent house fires or malfunction.
Guard mechanisms like rate limiting are cool because they can protect you against liabilty if your programmer makes an error, but they become more important the more exposed the controls are. There is a reason why e.g. a RCD cannot be permanently be fixed in the on-position (the switch is not tied to the lever internally), because you want it to switch off even in the case of misuse in order to save lives. This is magnitudes more important if your controls are exposed to external inputs (e.g. via radio, or over the network/internet), as accidental or malicious misuse might be more prevalent there.
Note: I am not saying there is a strict legal requirement to do this, I say that this is what I expect from a modern design made by professional electrical engineers.
"you" is the manufacturer of the device that bricks itself if touched wrong by arbitrary (untrained) personnel.
The owner has no way to know the thermal limits of some unknown internal switching component, and even if they have who says the radio signals are emitted by the owner?
This is one step removed from even that - a third party device designed for hackers being intentionally used for destructive purposes.
Do you even know how much regulation exists behind meters and electrical equipment?
What's next, complaining that the meter can't handle a sledgehammer?
You call weakness I call vandalism
Same as the brats who go and do a "tiktok challenge" of robbing an easily accessible car than finding out they're not immune to handcuffs and jail cells
Edit: and while a self-protection/rate limiting would be good, this could as well as easily be turned into a denial-of-service attack by causing the switch to be off. Better than failure, sure, but still an issue.
My freaking standing desk has protection if I go up and down too much within a certain period of time.
Like I said, I have zero trust this meter is accurate when it doesn't even have simple protective circuitry.
The desk controllers I have seen check for that limit (as one should).
Every controller should reject input that leads to destruction, especially if the input is wireless or comes over network.
--
[0] - The shredder is of the cheaper kind, and shows zero indication of any computer on board, so I'm assuming overheating shutoff is charging up some capacitor that's grounded via a high-resistance path and discharges at a known rate.
I actually had a dangerous situation here once in a big compressor motor that had a faulty soft-start circuit, that caused the bi-metal contacts to fuse so the protection no longer worked. By the time I noticed the compressor motor was way too hot to touch.
Now, that could be explained by e.g. the engine itself having enough thermal capacity to keep the shutoff switch active for a while, except... if you are careful and do small pauses between shreddings, you can keep going indefinitely - and those pauses don't feel enough to let the engine cool if that was the only thing that mattered.
Like, you shred something for 3 minutes straight and get 30 minutes cutoff, vs. shredding something for 1 minute, then 30 seconds break, then 1 minute, then 30 seconds break, ... and you can keep going like that for hours.
Yes, and it excels at it. From your description it does look like it
What if the electric operator’s software malfunctions and causes rapid power cycles to customers’ meters?
The end result would be the same, and it certainly wouldn’t be considered “abuse” then.
Yes because it's not built to be activated in that manner. Especially for high power/high voltage. This is not a mechanical keyboard switch.
> What if the electric operator’s software malfunctions and causes rapid power cycles to customers’ meters?
Then this is on the power company to fix it and fix the downstream failures this might cause. (Same as power outages that cause damages)
> it certainly wouldn’t be considered “abuse” then.
Abuse: Misuse; improper use; perversion.
And sure, they’ll have to fix it, but it’s still a glaring issue that should have never happened in the first place. A smart meter should very much be tolerant to this form of “abuse”.
As other commenters have said, controls for such a thing should most certainly have been put in place by the smart meter manufacturer. This isn’t something they couldn’t possibly protect against like your sledgehammer example. This is fully within their control, they just chose not to protect against it.
I explicitly used the fact that a bug could cause this to trigger at the scale of an entire electric company to show how bad this could be.
> What if the electric operator’s software malfunctions and causes rapid power cycles to customers’ meters?
> The end result would be the same, and it certainly wouldn’t be considered “abuse” then.
Those very well could be catastrophic failures, but that doesn’t in any way shape or form change this also being one.
My argument is that ’software error at the power company’ can easily cause catastrophic failures at the meter, which it stands no chance of being able to prevent. So why should it specifically be built to defend itself against the remote possibility that the master control program sends it too many on/off switch commands too quickly?
Why should it specifically be built that way? Because it's bad for devices to self-destruct with no attempt at mitigation whatsoever.
As the other commenter stated, that does not in any way imply "robust against all possible issues coming upstream" and it would be ridiculous to expect that.
Which scenarios you engineer the system to tolerate with what level of survivability and serviceability is going to be a matter of engineering to budget, right?
If a standing desk and shredder can handle that, then a smart meter should very much also be able to.
None of this was your original point, anyway. You instead chose to focus on a completely different and irrelevant failure case.
There is a world of difference between "voltage regulation issues might cause major problems" (your point) and "turning the thing on and off too quickly causes the whole thing to self-destruct" (the actual point).
Sure, this is targeted abuse, but your device should not accept unauthenticated radio input that allows destruction.
Authentification makes things more complicated, but it would still allow authorized personel to do the switching.
This is ridiculous. Manufacturers are responsible for the safety and security of their products. It's a perfectly legitimate expectation.
The meter should not accept unauthenticated commands and should have temperature protection.
In general you have a point, but making these devices accessible to remote tampering is an avoidable escalation of risk with no counterbalancing upside.