6 ms·
For the purposes of information security, the nameplate capacity is the correct number to consider for a very simple reason: we must defend as if hackers will p
by 1053r 2y ago
For the purposes of information security, the nameplate capacity is the correct number to consider for a very simple reason: we must defend as if hackers will pick the absolute worst moment to attack the grid. That is the moment when the sun is shining and it's absolutely cloudless across Netherlands, California, Germany, or wherever their target grid is.
At that moment, the attacker will not only blast the grid with the full output of the solar panels, but they will also put any attached batteries into full discharge mode as well, bypassing any safeties built into the firmware with new firmware. We must consider the worst case, which is that the attacker is trying to not only physically break the inverters, but the batteries, solar panels, blow fuses, and burn out substations. (Consider that if the inverters burn out and start fires, that's a feature for the attacker rather than a bug!)
So yes, not only is it 25 medium sized nuclear power plants, it's probably much higher than that! And worse, that number is growing exponentially with each year of the renewable transition.
This was probably the scariest security expose in a long time. It's much much worse than some zero-day for iphones.
A bad iPhone bug might kill a few people who can't call emergency services, and cause a couple billion of diffuse economic damage across the world. This set of bugs might kill tens of thousands by blowing up substations and causing outages at thousands to millions of homes, businesses, and factories during a heat wave. And the economic damage will not only be much higher, it will be concentrated.
- hn_throwaway_99 2y agoWhile I agree that the important metric to consider is peak output and not average output, I would still guess that in a country like the Netherlands that peak output is nowhere near nameplate capacity.
- deleted 2y ago[deleted]
- Retric 2y agoYou can get close to peak output just about anywhere, assuming the panels are angled rather than laying flat. You just can’t get it for very long in most locations.
- mapt 2y agoThe new method this past year that appears to be highly beneficial is to use various compass orientations of _vertically_ mounted panels. The solar cells got so cheap that every penny we spend on mounting hardware and rigid paneling now stings, and posts driven vertically into the ground which string cables tight between them are cheaper than triangles, way easier to maintain (especially in places with winter), and trade a lower peak (or even a bimodal peak) for a much wider production curve.
- idiotsecant 2y agoThis is wildly overstating the issue. Hackers are not going to break into hundreds of separate sites, compromise inverters, compromise relay protection, compromise SCADA systems, and execute a perfectly timed attack. Even if they did, these are distributed resources, they don't all go through a single substation and I doubt any one site could cause any major harm to any one substation. Instead, they're going to get a few guys with guns and shoot some step of transformers and drive away. The problem with infosec people is they tend to wildly overestimate cyber attack potential and wildly underestimate the equivalent of the 5 dollar wrench attack.
- Gud 2y agoMost(more or less all of them) grid operators can operate their network remotely from a single control room. I suspect most grids are extremely easy to hack(never tried, don't bite the hand that feed you etc). Info sec is just a hobby of mine. I install high voltage switch gear for a living.
- TwiztidK 2y ago> I suspect most grids are extremely easy to hack I’d expect the opposite. All companies controlling equipment that is part of the “Bulk Electric System” have to be NERC CIP compliant and are audited regularly with large fines for non-compliance. Doesn't guarantee perfect (or even good security) but it’s more likely to be a priority.
- ufocia 2y agoHow do fines make things better? They confiscate resources that could be used to improve.
- applied_heat 2y agoThe management at the utility doesn’t want to be recognized for being a deficient operator that doesn’t meet standards, so they hire employees to ensure they are compliant A fine is a black eye for a utility where people pride themselves on the reliability of the service they provide
- bramblerose 2y agoThe failure mode is much simpler: you don't need to physically break anything, you just need to drop 10GW of production from the grid (send a "turn off" command to all solar inverters) leading to a cascade of failures. Getting the grid back online is a laboreous manual process which will take (a lot of) time. Think https://en.wikipedia.org/wiki/Northeast_blackout_of_2003 https://en.wikipedia.org/wiki/Northeast_blackout_of_2003 or https://en.wikipedia.org/wiki/2021_Texas_power_crisis https://en.wikipedia.org/wiki/2021_Texas_power_crisis .
- tivert 2y ago> Getting the grid back online is a laboreous manual process which will take (a lot of) time. Think... It would be even more laborious and take more time to bring things back online if the attacker manages to damage or destroy equipment with an overload like the GP describes.
- msandford 2y agoThe "turning the grid up to 11" attack isn't really possible. I know it seems like it is, but the inverters will only advance frequency so much before they back off, the inverters will only increase voltage so much. Etc. Sounds scary, isn't practical. Turning everything off when the panels are at peak output? That lets frequency sag enough that plants start tripping offline to protect themselves and the grid and it'll cascade across the continent in just a few minutes. Then you have a black start which might take months. There's an excellent video on how catastrophic a black start is. https://youtu.be/uOSnQM1Zu4w?si=x0dA7X7-19CJm6Kf https://youtu.be/uOSnQM1Zu4w?si=x0dA7X7-19CJm6Kf
- kortilla 2y agoMonths isn’t correct. Unless there was damage it could be recovered within a day.
- msandford 2y agoWould love to know more about this. How would that happen? What's the process to bring it back up so fast? The video has a lot of good info and seems compelling. During the Texas freeze many power company officials said the exact same thing, if the Texas grid went down it would have taken weeks to bring everything back online.
- mschuster91 2y ago> We must consider the worst case, which is that the attacker is trying to not only physically break the inverters, but the batteries, solar panels, blow fuses, and burn out substations. Power transformers have a loooooooot of thermal wiggle room before they fail in such a way and usually have non-computerized triggers for associated breakers, and (at least if done to code, which is not a given I'll admit) so do inverters and every other part. If you try to burn them out, the fuses will fail physically before they'll be a fire hazard.
- 1053r 2y agoThis is true, especially for low frequency (high mass) inverters. The inverters that are covered here are overwhelmingly high frequency (low mass) inverters. We hope that they practiced great electrical engineering and layered multiple layers of physical safeguards on top of the software based controls built into the firmware. Of course a company that skimped to the point of total neglect on software security would never skimp anywhere else, right? Right? :crossed-fingers: <- This is what we are relying on here. And even if they did all the right things with their physical safety, the attackers can still brick the inverters with bad firmware and make them require a high skill firmware restore at a minimum and turn them into e-waste and require an re-install from a licensed electrician at a maximum.
- mschuster91 2y ago> Of course a company that skimped to the point of total neglect on software security would never skimp anywhere else, right? Right? At least in Europe, product safety organizations and regulatory agencies have taken up work to identify issues with stuff violating electrical codes (e.g. [1] [2]) and getting it recalled/pulled off the market. Sadly there is no equivalent on the software side - it's easy enough to verify if a product meets electrical codes, but almost impossible to check firmware even if you have the full source code. [1] https://www.bundesnetzagentur.de/SharedDocs/Pressemitteilungen/DE/2023/20230609_Marktueberwachung.html https://www.bundesnetzagentur.de/SharedDocs/Pressemitteilung... [2] https://www.t-online.de/heim-garten/aktuelles/id_100212010/stromerzeugung-mit-balkonkraftwerk-anker-ruft-wechselrichter-zurueck.html https://www.t-online.de/heim-garten/aktuelles/id_100212010/s...
- t0mas88 2y agoThe risk is not turning all solar installations "on maximum". That happens nearly every summer day between 1 and 2pm. Automatic shutoff when the grid voltage is rising can be disabled, but more than 9 out of 10 consumer solar installations in the Netherlands deliver their maximum output on such a day for most of the summer, not running into the maximum voltage protections. The big risk is turning them all off at the same time, while under maximum load. That will cause a brown-out that no other power generator can pick up that quickly. If the grid frequency drops far enough big parts of the grid will disconnect and cause blackouts to industry or whole areas. It will take a lot of time to recover from that situation. Especially if it's done to the neighbouring grids as well so they can't step in to pick up some of the load.
- more_corn 2y agoNot if we have grid scale batteries. Solar shuts off, oh no. Sometime in the next four hours we need to get that fixed or something else up. Also flattens out the demand curve and allows arbitrage between the peak and valley.
- ale42 2y agoProblem is, those batteries are not there (yet)...
- huijzer 2y agoDon’t underestimate exponentials. Tesla produced 6.5 GWh of battery storage in 2022, 14.7 GWh in 2023, and will probably double again in 2024. And other battery manufacturers such as BYD grow fast too.
- automatic6131 2y agoAlways underestimate exponentials: none exist in nature, they're just an early phase of an S curve (sigmoid, if you want the $10 word)
- verisimi 2y agoTldr; We can't talk about proper numbers cos hackers.
- immibis 2y agoThe "bad iPhone bug" scenario happened a few weeks ago, in the form of Crowdstrike. You underestimated the damages.