{"id":2813,"date":"2011-11-06T16:58:08","date_gmt":"2011-11-07T00:58:08","guid":{"rendered":"http:\/\/daviddilworth.com\/pol\/?p=2813"},"modified":"2026-03-04T12:10:09","modified_gmt":"2026-03-04T20:10:09","slug":"smartmeters-facilitate-cyber-war-against-us","status":"publish","type":"post","link":"https:\/\/daviddilworth.com\/pol\/smartmeters-facilitate-cyber-war-against-us\/","title":{"rendered":"SmartMeters Facilitate Cyber War Against US"},"content":{"rendered":"<h3 style=\"text-align: center;\"><strong>SmartMeters Facilitate Cyber War Against US<\/strong><br \/>\n<strong> (c) Copyright 2011 David j Dilworth<\/strong><\/h3>\n<p><strong>This didn&#8217;t happen &#8212; yet.<\/strong><\/p>\n<div style=\"width: 348px\" class=\"wp-caption alignright\"><a href=\"http:\/\/en.wikipedia.org\/wiki\/Northeast_blackout_of_2003\"><img loading=\"lazy\" decoding=\"async\" class=\" \" title=\"New York Power Blackout 2003\" src=\"http:\/\/web.archive.org\/web\/20160202102842\/http:\/\/www.ctweather.com\/images\/power-outage-northeast.jpg\" alt=\"New York Power Blackout 2003\" width=\"338\" height=\"226\" \/><\/a><p class=\"wp-caption-text\"><strong>New York Power Blackout<\/strong> 2003 (simulation)<\/p><\/div>\n<blockquote><p><strong>&#8220;Within a quarter of an hour, 157 major metropolitan areas have been thrown into knots by a nationwide power blackout hitting during rush hour. . .<\/strong><\/p>\n<p><strong>&#8220;Subways have crashed in New York, Oakland, Washington, and Los Angeles. . . . Aircraft are literally falling out of the sky as a result of midair collisions across the country. . . . Several thousand Americans have already died.&#8221;<\/strong><\/p><\/blockquote>\n<div id=\"attachment_9565\" style=\"width: 400px\" class=\"wp-caption alignright\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-9565\" class=\"size-full wp-image-9565\" src=\"https:\/\/daviddilworth.com\/pol\/wp-content\/uploads\/2011\/11\/0408_richard-clarke_390x220.jpg\" alt=\"Richard Clarke, President's Advisor\" width=\"390\" height=\"220\" srcset=\"https:\/\/daviddilworth.com\/pol\/wp-content\/uploads\/2011\/11\/0408_richard-clarke_390x220.jpg 390w, https:\/\/daviddilworth.com\/pol\/wp-content\/uploads\/2011\/11\/0408_richard-clarke_390x220-300x169.jpg 300w, https:\/\/daviddilworth.com\/pol\/wp-content\/uploads\/2011\/11\/0408_richard-clarke_390x220-150x85.jpg 150w\" sizes=\"auto, (max-width: 390px) 100vw, 390px\" \/><p id=\"caption-attachment-9565\" class=\"wp-caption-text\"><strong>Richard Clarke, <\/strong>Obama &amp; Bush Advisor<\/p><\/div>\n<p><strong>This is an excerpt from <a href=\"http:\/\/www.amazon.com\/Cyber-War-Threat-National-Security\/dp\/0061962236\">&#8220;Cyber War&#8221; by Richard Clarke, former National Security Advisor to Presidents Obama and Bush.<\/a> Its an <a href=\"http:\/\/www.newyorker.com\/reporting\/2010\/11\/01\/101101fa_fact_hersh?currentPage=all\">&#8220;edgy account of America\u2019s vulnerability to hackers, both state-sponsored and individual, especially from China.&#8221; &#8211; Seymour Hersch, Online Threat, New Yorker, Nov 2010<\/a><\/strong><\/p>\n<p><strong><!--more-->How does this relate to us as individuals? Well, a local scientist, Monterey Councilman Jeff Haferman, raised a concern at a Monterey Council meeting about Smartmeters. He asked &#8220;<em>If PG$E (local electric power provider) can turn off your power remotely with a smartmeter, what keeps a hacker from doing that ?<\/em>&#8221; Or worse, he asked &#8220;<em><span style=\"text-decoration: underline;\">what keeps a hacker from turning off whole neighborhoods &#8211; or an entire community ?<\/span><\/em>&#8220;<\/strong><\/p>\n<p><strong>The PG&amp;E representative was silent until prompted to respond. &#8220;I don&#8217;t have any information on that. I&#8217;ll get back to you.&#8221; That was in February 2011, its now October and PG&amp;E has made no response or answer yet.<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignright\" title=\"Hackable WiFi Meter - called a 'Smart'meter\" src=\"http:\/\/web.archive.org\/web\/20130202000237\/http:\/\/c276521.r21.cf1.rackcdn.com\/wp-content\/uploads\/2010\/11\/smart-meter.jpg\" alt=\"Hackable WiFi Meter - called a 'Smart'meter\" width=\"450\" height=\"338\" \/><\/p>\n<p><strong>What we have learned since then is that <a href=\"http:\/\/1hope.org\/hopeblog\/?p=1061#comment-127\">your data going out and PG&amp;E&#8217;s &#8220;Power Shutoff&#8221; radio commands are <span style=\"text-decoration: underline;\">not encrypted<\/span> at the neighborhood level.<\/a> This means &#8220;Smart&#8221;meter communication data is in &#8220;plain English&#8221; &#8212; <span style=\"text-decoration: underline;\">it is readable by anyone with a laptop and WiFi<\/span>. This means your so-called &#8220;Smart&#8221;meter is easily controlled by anyone with a laptop and a WiFi. Is this a wild speculative fantasy? No.<\/strong><\/p>\n<p><strong><span style=\"text-decoration: underline;\">This &#8220;Fraternal&#8221; WiFi Break-In Did Happen:<\/span><\/strong><\/p>\n<p><strong>Here&#8217;s a recent CBS article giving an actual example of a virtually identical break in of medical equipment &#8211; <a href=\"http:\/\/www.cbsnews.com\/8301-501465_162-20088598-501465.html\">&#8220;Black hat hacker can remotely attack insulin pumps and kill people.&#8221;<\/a> The article mentions already successful WiFi attacks on heart pacemakers and defibrillators. (&#8220;<a href=\"http:\/\/www.theregister.co.uk\/2012\/10\/17\/pacemakers_open_to_wireless_attack\/\">Pacemakers and implanted defibrillators are vulnerable to wireless attacks that could kill tens of thousands<\/a>&#8220;)<\/strong><\/p>\n<p><strong>A CNN report warned &#8220;<a href=\"http:\/\/www.cnn.com\/2009\/TECH\/03\/20\/smartgrid.vulnerability\/index.html\">&#8216;Smart Grid&#8217; may be vulnerable to hackers<\/a>.&#8221;\u00a0Only a month later an <a href=\"http:\/\/blogs.discovermagazine.com\/80beats\/2009\/04\/08\/electrical-espionage-spies-hack-into-the-us-power-grid\/\">actual hacker Smart Grid Infection<\/a> was detected and reported. That infection <\/strong><\/p>\n<blockquote><p><strong>&#8220;could allow outside agents to seize control of the grid and disrupt the flow of electricity across the nation.&#8221;<\/strong><\/p><\/blockquote>\n<p><strong>Even if utilities like PG&amp;E ever intended to add encryption as a policy &#8211; some &#8220;smart&#8221;meters don&#8217;t really encrypt their data &#8212;<\/strong><\/p>\n<blockquote><p><strong>&#8220;Verizon has also discovered problems with some smart meters being sold on the market. In one case, <a href=\"http:\/\/web.archive.org\/web\/20120618030349\/http:\/\/energy.aol.com:80\/2011\/08\/05\/smart-grid-privacy-and-security-risks-loom-for-agencies\">a smart meter developer claimed their device was encrypted but Verizon&#8217;s tests showed it was protected only by a basic authentication mechanism<\/a>.&#8221;<\/strong><\/p><\/blockquote>\n<p><strong>Similar to <a href=\"http:\/\/www.sfgate.com\/cgi-bin\/article.cgi?f=\/c\/a\/2011\/11\/06\/BUPB1LQLLV.DTL\">Washington DC and Silicon Valley, the Monterey Peninsula community probably has more than its share of foreign spies<\/a>.<\/strong><\/p>\n<div id=\"attachment_9566\" style=\"width: 303px\" class=\"wp-caption alignright\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-9566\" class=\"size-full wp-image-9566\" src=\"https:\/\/daviddilworth.com\/pol\/wp-content\/uploads\/2011\/11\/Samsung-Spy-Software.jpg\" alt=\"Spy - Causing Chaos\" width=\"293\" height=\"288\" srcset=\"https:\/\/daviddilworth.com\/pol\/wp-content\/uploads\/2011\/11\/Samsung-Spy-Software.jpg 293w, https:\/\/daviddilworth.com\/pol\/wp-content\/uploads\/2011\/11\/Samsung-Spy-Software-150x147.jpg 150w\" sizes=\"auto, (max-width: 293px) 100vw, 293px\" \/><p id=\"caption-attachment-9566\" class=\"wp-caption-text\">Spy &#8211; Causing Chaos<\/p><\/div>\n<p><strong>So here&#8217;s (most of) the recipe an ordinary and not-even-clever foreign spy could follow (in his spare time) to shut down our whole community&#8217;s electric power. He does not need to have any hacking skills. (<a href=\"http:\/\/www.networkworld.com\/community\/blog\/hacking-privacy-2-days-amateur-hacker-hack-smart-meter-fake-readings\">It took an amateur computer user only two days to get more control than is described here.<\/a>)<\/strong><\/p>\n<p><strong>1. Rent a cheap house.<\/strong><\/p>\n<p><strong>2. Turn on laptop to start recording the <a href=\"http:\/\/1hope.org\/hopeblog\/pges-smartmeters-apparently-send-your-data-un-encrypted\/\"><em>unencrypted<\/em> Smartmeter signals<\/a>. The <a href=\"http:\/\/1hope.org\/hopeblog\/pges-smartmeters-apparently-send-your-data-un-encrypted\/\">unencrypted signals<\/a> are easily found and if the premise also has a &#8220;smart&#8221; gas meter, the frequency from the electric meter to the gas meter is the same as your WiFi.<\/strong><\/p>\n<p><strong>3. Then stop paying the bill &#8211; until PG&amp;E sends the radio frequency shutoff command to your Smartmeter through the air.<\/strong><\/p>\n<p><strong>4. After PG&amp;E has turned off your power, then pay the Bill so PG&amp;E turns power back by sending the radio frequency &#8220;ON command&#8221; to your Smartmeter through the air.<\/strong><\/p>\n<p><strong>5. Analyze the recorded data to uncover the (unencrypted) &#8220;Shutoff command&#8221; and the &#8220;ON command.&#8221;<\/strong><\/p>\n<p><strong>6. Repeat at another house until you find the general format for the &#8220;Shutoff command.&#8221;<\/strong><\/p>\n<p><strong>Compare the signals sent to the first house and the second house to see how the &#8220;Shutoff command&#8221; changes from one house to another. (It probably just uses a 10 to 14 digit incrementing system for a specific neighborhood. Ten digits would allow more than a billion devices.)<\/strong><\/p>\n<p><strong>Now the foreign spy will have all the information needed to shut down your house electricity and <span style=\"text-decoration: underline;\">millions of others<\/span>&#8211; and probably all electricity and gas for your community&#8217;s businesses and government as well. (I will not publish any information on how to broadcast the data to actually shut the meters off.) It is likely that the format of the &#8220;Shutoff command&#8221; and the &#8220;ON command&#8221; is the same or has very little variation across the US.<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignright\" title=\"WiFi Hacker Turning Off Power for All of California\" src=\"http:\/\/weeble.net\/wp-content\/uploads\/2011\/04\/Samsung-Spy-Software.jpg\" alt=\"WiFi Hacker Turning Power Off forAll of California\" width=\"293\" height=\"288\" \/><\/p>\n<p><strong>I&#8217;m not the only one concerned about this potential harm. One firm <a href=\"http:\/\/web.archive.org\/web\/20120618030349\/http:\/\/energy.aol.com:80\/2011\/08\/05\/smart-grid-privacy-and-security-risks-loom-for-agencies\">&#8220;successfully reverse engineered a smart meter&#8211;known as Advanced Metering Infrastructure (AMI)&#8211;and demonstrated the ability to inject a worm into the grid that would grant a hacker full control over the grid devices.&#8221;<\/a><\/strong><\/p>\n<p><strong>Presidential Security Advisor Richard Clarke is right. Just because there is not yet any documented widespread power outage caused by hackers &#8211; does not mean it cannot happen. Clarke may have some technical details a bit off, but his description of the threat to our nation&#8217;s electrical power system is alarmingly accurate.<\/strong><\/p>\n<p><strong>Commentary: The so-called &#8220;Smart&#8221;meter blitz is a greed driven rush to ignore serious harm by PG&amp;E that the California Public Utilities Commission rubber-stamped and refused to require an <a href=\"http:\/\/1hope.org\/ceqa.htm\">Environmental Impact Report<\/a>.<\/strong><\/p>\n<p><strong><a href=\"http:\/\/1hope.org\/hopeblog\/whay-smartmeters-need-an-environmental-impact-report\/\">An Environmental Impact Report needs to be prepared for the many harms posed by &#8220;Smart&#8221;meters.<\/a><\/strong><\/p>\n<p><strong>Then we need to require SmartER meters (<a href=\"http:\/\/1hope.org\/hopeblog\/smarter-meters-solve-all-the-problems-with-smart-meters\/\">SmartER-meters Solve All the &#8220;Smart-meter&#8221; Problems<\/a>) that eliminates WiFi (commands and data privacy loss) and the <a href=\"http:\/\/1hope.org\/hopeblog\/unknown-safety-of-smartmeters-new-disconnect-switch\/\">dangerous high-amp fire hazard switch<\/a>.<\/strong><\/p>\n<p><strong>Additional reading :<\/strong><\/p>\n<p><strong><a href=\"http:\/\/web.archive.org\/web\/20120618030349\/http:\/\/energy.aol.com:80\/2011\/08\/05\/smart-grid-privacy-and-security-risks-loom-for-agencies\">&#8220;Smart Grid Privacy And Security Risks Loom For Agencies&#8221; by Dan Verton<\/a><\/strong><\/p>\n<p><strong><a href=\"http:\/\/1hope.org\/hopeblog\/smartmeter-articles-on-hopes-blog\/\">27 Exclusive Smartmeter Articles on HOPE\u2019s Website<\/a><\/strong><\/p>\n<p><strong><a href=\"http:\/\/venturebeat.com\/2011\/08\/06\/hacking-water-meters-is-easier-than-it-should-be\/\">Hacking water meters is easier than it should be<\/a><\/strong><\/p>\n<p><strong><a href=\"http:\/\/www.sfgate.com\/cgi-bin\/article.cgi?f=\/c\/a\/2011\/11\/06\/BUPB1LQLLV.DTL\">Cyber-spying poses economic threat to U.S., firms<\/a><\/strong><\/p>\n<p><strong><a href=\"http:\/\/www.theregister.co.uk\/2012\/10\/17\/pacemakers_open_to_wireless_attack\/\">Pacemakers, defibrillators open to attack<br \/>\nCrims could send 830 volts str<\/a><\/strong><\/p>\n<div id=\"attachment_9565\" style=\"width: 400px\" class=\"wp-caption alignright\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-9565\" class=\"size-full wp-image-9565\" src=\"https:\/\/daviddilworth.com\/pol\/wp-content\/uploads\/2011\/11\/0408_richard-clarke_390x220.jpg\" alt=\"Richard Clarke, President's Advisor\" width=\"390\" height=\"220\" srcset=\"https:\/\/daviddilworth.com\/pol\/wp-content\/uploads\/2011\/11\/0408_richard-clarke_390x220.jpg 390w, https:\/\/daviddilworth.com\/pol\/wp-content\/uploads\/2011\/11\/0408_richard-clarke_390x220-300x169.jpg 300w, https:\/\/daviddilworth.com\/pol\/wp-content\/uploads\/2011\/11\/0408_richard-clarke_390x220-150x85.jpg 150w\" sizes=\"auto, (max-width: 390px) 100vw, 390px\" \/><p id=\"caption-attachment-9565\" class=\"wp-caption-text\">Richard Clarke, President&#8217;s Advisor<\/p><\/div>\n<p><strong><a href=\"http:\/\/www.theregister.co.uk\/2012\/10\/17\/pacemakers_open_to_wireless_attack\/\">aight to your heart<\/a><\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>SmartMeters Facilitate Cyber War Against US (c) Copyright 2011 David j Dilworth This didn&#8217;t happen &#8212; yet. &#8220;Within a quarter of an hour, 157 major metropolitan areas have been thrown into knots by a nationwide power blackout hitting during rush &hellip; <a href=\"https:\/\/daviddilworth.com\/pol\/smartmeters-facilitate-cyber-war-against-us\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"iawp_total_views":11,"footnotes":"","_links_to":"","_links_to_target":""},"categories":[],"tags":[],"class_list":["post-2813","post","type-post","status-publish","format-standard","hentry"],"_links":{"self":[{"href":"https:\/\/daviddilworth.com\/pol\/wp-json\/wp\/v2\/posts\/2813","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/daviddilworth.com\/pol\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/daviddilworth.com\/pol\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/daviddilworth.com\/pol\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/daviddilworth.com\/pol\/wp-json\/wp\/v2\/comments?post=2813"}],"version-history":[{"count":50,"href":"https:\/\/daviddilworth.com\/pol\/wp-json\/wp\/v2\/posts\/2813\/revisions"}],"predecessor-version":[{"id":9567,"href":"https:\/\/daviddilworth.com\/pol\/wp-json\/wp\/v2\/posts\/2813\/revisions\/9567"}],"wp:attachment":[{"href":"https:\/\/daviddilworth.com\/pol\/wp-json\/wp\/v2\/media?parent=2813"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/daviddilworth.com\/pol\/wp-json\/wp\/v2\/categories?post=2813"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/daviddilworth.com\/pol\/wp-json\/wp\/v2\/tags?post=2813"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}