New smart electricity meters target for hackers

  • Associated Press
  • Friday, March 26, 2010 8:36pm
  • Business

SAN FRANCISCO — Computer-security researchers say new smart meters that are designed to help deliver electricity more efficiently also have flaws that could let hackers tamper with the power grid in previously impossible ways.

At the very least, the vulnerabilities open the door for attackers to jack up strangers’ power bills. These flaws also could get hackers a key step closer to exploiting one of the most dangerous capabilities of the new technology, which is the ability to remotely turn someone else’s power on and off.

The attacks could be pulled off by stealing meters — which can be situated outside of a home — and reprogramming them. Or an attacker could sit near a home or business and wirelessly hack the meter from a laptop, according to Joshua Wright, a senior security analyst with InGuardians Inc. The firm was hired by three utilities to study their smart meters’ resistance to attack.

These utilities, which he would not name, have already done small deployments of smart meters and plan to roll the technology out to hundreds of thousands of power customers, Wright told The Associated Press.

There is no evidence the security flaws have been exploited, although Wright said a utility could have been hacked without knowing it. InGuardians said it is working with the utilities to fix the problems.

Power companies are aggressively rolling out the new meters. In the U.S. alone, more than 8 million smart meters have been deployed by electric utilities and nearly 60 million should be in place by 2020, according to a list of publicly announced projects kept by The Edison Foundation, an organization focused on the electric industry.

Unlike traditional electric meters that merely record power use — and then must be read in person once a month by a meter reader — smart meters measure consumption in real time. By being networked to computers in electric utilities, the new meters can signal people or their appliances to take certain actions, such as reducing power usage when electricity prices spike.

But the very interactivity that makes smart meters so attractive also makes them vulnerable to hackers, because each meter essentially is a computer connected to a vast network.

There are few public studies on the meters’ resistance to attack, in part because the technology is new. However, last summer, Mike Davis, a researcher from IOActive Inc., showed how a computer worm could hop between meters in a power grid with smart meters, giving criminals control over those meters.

Alan Paller, director of research for the SANS Institute, a security research and training organization that was not involved in Wright’s work with InGuardians, said it proved that hacking smart meters is a serious concern.

“We weren’t sure it was possible,” Paller said. “He actually verified it’s possible. … If the Department of Energy is going to make sure the meters are safe, then Josh’s work is really important.”

SANS has invited Wright to present his research Tuesday at a conference it is sponsoring on the security of utilities and other “critical infrastructure.”

Industry representatives say utilities are doing rigorous security testing that will make new power grids more secure than the patchwork system we have now, which is already under hacking attacks from adversaries believed to be working overseas.

“We know that automation will bring new vulnerabilities, and our task — which we tackle on a daily basis — is making sure the system is secure,” said Ed Legge, spokesman for Edison Electric Institute, a trade organization for shareholder-owned electric companies.

But many security researchers say the technology is being deployed without enough security probing.

Wright said his firm found “egregious” errors, such as flaws in the meters and the technologies that utilities use to manage data from meters. “Even though these protocols were designed recently, they exhibit security failures we’ve known about for the past 10 years,” Wright said.

Talk to us

> Give us your news tips.

> Send us a letter to the editor.

> More Herald contact information.

More in Business

FILE — Jet fuselages at Boeing’s fabrication site in Everett, Wash., Sept. 28, 2022. Some recently manufactured Boeing and Airbus jets have components made from titanium that was sold using fake documentation verifying the material’s authenticity, according to a supplier for the plane makers. (Jovelle Tamayo/The New York Times)
Boeing adding new space in Everett despite worker reduction

Boeing is expanding the amount of space it occupies in… Continue reading

Paul Roberts makes a speech after winning the Chair’s Legacy Award on Tuesday, April 22, 2025 in Tulalip, Washington. (Olivia Vanni / The Herald)
Paul Roberts: An advocate for environmental causes

Roberts is the winner of the newly established Chair’s Legacy Award from Economic Alliance Snohomish County.

Laaysa Chintamani speaks after winning on Tuesday, April 22, 2025 in Tulalip, Washington. (Olivia Vanni / The Herald)
Laasya Chintamani: ‘I always loved science and wanted to help people’

Chintamani is the recipient of the Washington STEM Rising Star Award.

Dave Somers makes a speech after winning the Henry M. Jackson Award on Tuesday, April 22, 2025 in Tulalip, Washington. (Olivia Vanni / The Herald)
County Executive Dave Somers: ‘It’s working together’

Somers is the recipient of the Henry M. Jackson Award from Economic Alliance Snohomish County.

Mel Sheldon makes a speech after winning the Elson S. Floyd Award on Tuesday, April 22, 2025 in Tulalip, Washington. (Olivia Vanni / The Herald)
Mel Sheldon: Coming up big for the Tulalip Tribes

Mel Sheldon is the winner of the Elson S. Floyd Award from Economic Alliance Snohomish County

Craig Skotdal makes a speech after winning on Tuesday, April 22, 2025 in Tulalip, Washington. (Olivia Vanni / The Herald)
Craig Skotdal: Helping to breathe life into downtown Everett

Skotdal is the recipient of the John M. Fluke Sr. award from Economic Alliance Snohomish County

Dick’s Drive-In announces opening date for new Everett location

The new drive-in will be the first-ever for Everett and the second in Snohomish County.

A standard jet fuel, left, burns with extensive smoke output while a 50 percent SAF drop-in jet fuel, right, puts off less smoke during a demonstration of the difference in fuel emissions on Tuesday, March 28, 2023 in Everett, Washington. (Olivia Vanni / The Herald)
Sustainable aviation fuel center gets funding boost

A planned research and development center focused on sustainable aviation… Continue reading

Helion's 6th fusion prototype, Trenta, on display on Tuesday, July 9, 2024 in Everett, Washington. (Olivia Vanni / The Herald)
Helion celebrates smoother path to fusion energy site approval

Helion CEO applauds legislation signed by Gov. Bob Ferguson expected to streamline site selection process.

The Coastal Community Bank branch in Woodinville. (Contributed photo)
Top banks serving Snohomish County with excellence

A closer look at three financial institutions known for trust, service, and stability.

Image from Erickson Furniture website
From couch to coffee table — Local favorites await

Style your space with the county’s top picks for furniture and flair.

Support local journalism

If you value local news, make a gift now to support the trusted journalism you get in The Daily Herald. Donations processed in this system are not tax deductible.