Uploaded by CCCen on Dec 30, 2011
Smart Hacking For Privacy
Advanced metering devices (aka smart meters) are nowadays being installed throughout electric networks in Germany, in other parts of Europe and in the United States. Due to a recent amendment especially in Germany they become more and more popular and are obligatory for new and refurbished buildings.
Unfortunately, smart meters are able to become surveillance devices that monitor the behavior of the customers leading to unprecedented invasions of consumer privacy. High-resolution energy consumption data is transmitted to the utility company in principle allowing intrusive identification and monitoring of equipment within consumers' homes (e. g., TV set, refrigerator, toaster, and oven) as was already shown in different reports.
This talk is about the Discovergy / EasyMeter smart meter used for electricity metering in private homes in Germany. During our analysis we found several security bugs that range from problems with the certificate management of the website to missing security features for the metering data in transit. For example (un)fortunately the metering data is unsigned and unencrypted, although otherwise stated explicitly on the manufacturer's homepage. It has to be pointed out that all tests were performed on a sealed, fully functionally device.
In our presentation we will mainly focus on two aspects which we revealed during our analysis: first the privacy issues resulting in even allowing to identify the TV program out of the metering data and second the "problem" that one can easily alter data transmitted even for a third party and thereby potentially fake the amount of consumed power being billed.
In the first part of the talk we show that the analysis of the household's electricity usage profile can reveal what channel the TV set in the household is displaying. We will also give some test-based assessments whether it is possible to scan for copyright-protected material in the data collected by the smart meter.
In the second part we focus on the data being transmitted by the smart meter via the Internet. We show to what extent the consumption data can be altered and transmitted to the server and visualize this by transmitting some kind of picture data to Discovergy's consumption data server in a way that the picture content will become visible in the electricity profile. Moreover, we show what happens if the faked power consumption data reflects unrealistic extreme high or negative power consumptions and how that might influence the database and service robustness.
Speaker: Dario Carluccio, Stephan Brinkhaus
EventID: 4754
Event: 28th Chaos Communication Congress (28C3) by the Chaos Computer Club [CCC]
Location: Berlin Congress Center [bcc]; Alexanderstr. 11; 10178 Berlin; Germany
Language: english
Start: 30.12.2011 16:00:00 +01:00
License: CC-by-nc-sa
-
5 likes, 0 dislikes
-
As Seen On:
Tesla Motors Club - E...
2:21
28C3 BlinkenArea - Behind Enemy Linesby BlinkenArea1,227 views
4:16
Electric Meter Hack! How To Cut Your Electricity Bill.wmvby ayushcutebaby220,843 views
2:15
Como hackear msn com Smart hack 100% funcionandoby cheartocheaX504 views
4:04
Foiling a "smart" meter on the street, San Francisco CAby thisirradiatedlife80,845 views
3:13
1-858-504-0573 METER BARREL LOCK TOOL KEY ELECTRIC METER CHANGE METER PANEL toolguysrusby MrChinaelectron146,912 views
51:19
Apple vs. Google Client Platforms [28C3]by CCCen827 views
2:39
NOT SO SMART METERby doug287745,718 views
8:34
Hacking Websites - You think you are secure?by videosbyjoshjones3,701 views
4:55
Tutorial - Weak Website Security (View Admin & More)by onlinetechs2,877 views
2:51
75% saving on your electricity with new deviceby marcbarker167,732 views
26:41
A Brief History of Plutocracy [28C3]by CCCen1,015 views
1:09:40
Introduction to Hackingby elithecomputerguy75,893 views
26:03
28c3: Reverse Engineering USB Devicesby 28c37,800 views
1:46
Smart Grid Benefitsby GreenMountainPower152 views
2:12
Concerns Over Smart Meters Cyber Securityby kocotv7,063 views
0:48
Electric Meter Hack, Free Electricity ¡¡ Luz Gratis CFEby Elkarlooz794 views
32:52
The Dark Side of 'Smart' Metersby eon3162,710 views
1:33
Cut Your Electricity Bill. Stop an electricity meter.by morozilka347,104 views
57:09
Food-Hacking: Eating in the Anthropocene [28C3]by CCCen757 views
9:17
InduSoft Web Studio v7.0 OPC Xi Demoby InduSoftVideo4,724 views
- Loading more suggestions...
@MrReoNetro Not every one is comfortable with it, I know I'm not. I respect this guy for trying and together they present a clear picture of a very interesting subject.
SolarWebsite 1 month ago
uhh why is he nervous? you should have more presentations during primary school its easy to learn if you start early enough
MrReoNetro 1 month ago