A cybersecurity company warns that smart meters are easily hackable: this is what they have discovered



At a time like the one we live in, in which the price of electricity rises almost every day to prices that are unaffordable for a large part of the population, almost any measure is welcome to try to curb spending. A process in which connected meters are a fundamental part. Some devices that apparently are not as safe as it seems.

This is what a Galician company, Tarlogic, has discovered, which has developed a tool called PLCTool which, as they call it, is something like “the swiss army knife of smart meters”. And it is that thanks to this development it has been possible to verify that connected meters are vulnerable and not as safe as we thought.

The electricity meter at your feet

Slowly connected meters conquer electrical rooms and related spaces of our homes. These types of smart meters are responsible for collecting electricity consumption hour by hour and day by day and send it to the electricity distributor so that it can then be sent to the customer’s marketer so that they can bill the electricity consumption.

How to save on your electricity bill using the CNMC web price comparator to hire a cheaper rate



Now, this company has discovered that its strength, connected meters, is not such. It is something that they have achieved thanks to PLCTool, a tool that allows any user to make changes that go from altering consumption or changing the contracted electrical power to leaving neighbors without electricity.

tarlogic has discovered different vulnerabilities that can be used with PLCTool, a software and hardware tool that allows full control of the meter. In fact, on the Tarlogic website they state that they have communicated these vulnerabilities to the distributors and have not received a satisfactory response.

The purpose of the released tool is to analyze PRIME traffic, capture credentials and send and receive PRIME and DLMS messages, documented in the standard, such as the ICP disconnection message. Tarlogic does not directly or indirectly support the commission of fraud in the electrical networks. We can understand the discomfort that this investigation has caused in the sector, but we believe that after notifying those affected more than two years ago and our vocation to share our work and help companies, it has been enough time to start taking steps towards protection of these infrastructures. It has been this that has finally led us to disclose the investigation in an exercise of responsible disclosure, helping other researchers and security analysts to continue our work.

To demonstrate that this is not the case, Tarlogic has made available to all interested parties on Github the necessary tools to carry out the whole process and in case of finding faults, that these be communicated as a Feedback.

The company has discovered security breaches in the counters. Flaws that affect the nonexistent encryption of communications or that secure authentication is not allowed, something that can allow an attacker with malicious intentions to take control of the counter or counters and execute almost any type of order that modifies different parameters and can even cut off the power supply.

Light

In different sections they detail how the PLCTool project works, made up of two repositories: the PLCTool application itself and Candleblow, the firmware developed for the evaluation kit. They also offer an installation and use guide to be able to carry out all the steps.

With this guide, any user can access their meter information from home and, what is more important, change all kinds of parameters, which exposes the lack of security offered by this type of device.

Via | tarlogic



Related News

Le Google Pixel 6a peut être chargé sans fil avec ces accessoires

Pour beaucoup, c'est une erreur que Google ait lancé le Pixel 6a sans prise en charge de la recharge sans fil, mais cette fois, nous comprenons l'entreprise. Ils ont

Todos los detalles sobre Windows 11 23H2: Sun Valley 3

La primera actualización importante de Windows 11 para 2022 se implementará para todos en unos meses. La versión 22H2, cuyo nombre en código es Sun Valley 2, alcanzó el estado RTM hace algunas semanas

Todos los detalles sobre Windows 11 23H2: Sun Valley 3

La primera actualización importante de Windows 11 para 2022 se implementará para todos en unos meses. La versión 22H2, cuyo nombre en código es Sun Valley 2, alcanzó el estado RTM hace algunas semanas

Conoce la Gran Renuncia, el Gran Reseteo

Bienvenido a Startup Weekly, una nueva presentación humana sobre las noticias y tendencias de esta semana. Para recibirlo en su bandeja de entrada, suscríbase aquí.

¡Tienes mucho! (2023) – reseña de la película [Canal+]. Una comedia típica sobre la mentalidad polaca.

The movie "You're in luck!" tells the story of the Bednarski family, who learn that their deceased grandfather Józef (Mikołaj Grabowski) was buried with a