Tuesday, December 5, 2023
Kiratas
  • Home
  • World
  • Lifestyle

    Trending Tags

    • Pandemic
  • Business
  • Entertainment
  • Sports
No Result
View All Result
  • Home
  • World
  • Lifestyle

    Trending Tags

    • Pandemic
  • Business
  • Entertainment
  • Sports
No Result
View All Result
Kiratas
No Result
View All Result
Home World

Balcony power plants: Threatening security gaps at Hoymiles

Eliza Houghton by Eliza Houghton
September 30, 2023
in World
0
Balcony power plants: Threatening security gaps at Hoymiles
0
SHARES
1
VIEWS
Share on FacebookShare on Twitter

Hoymiles has now reacted and filled the gaps.

Advertisement

Serious security gaps in the cloud service of the Chinese photovoltaic manufacturer Hoymiles threaten several hundred thousand microinverters. The service, called “S-Miles Cloud”, offers the manufacturer’s customers yield monitoring and shows what the small photovoltaic systems are doing. This requires a “Data Transfer Unit”, DTU for short, called a radio bridge that is connected to the Internet, or a newer Hoymiles inverter with integrated WLAN.

An anonymous whistleblower who claims to be a security researcher contacted c’t via the investigative mailbox on Sunday last week and uploaded a 25-page document with detailed descriptions of the gaps. We were able to verify the editorial advice through tests on our own hardware.

The attack apparently unlocks access to all DTUs and inverters registered in the S-Miles cloud. This cannot be verified, but since Hoymiles provides the same two apps for all devices, it is likely that only one service is used. A query also showed that around 230,000 systems, each with at least one inverter, are currently connected to the service.

Users who do not read the inverter at all or use alternative bridges such as Ahoy and OpenDTU are not affected.

Many c’t investigative research is only possible thanks to anonymous information from whistleblowers.

If you are aware of an issue that the public should know about, you can provide us with information and material. Please use our anonymous and secure mailbox.

https://heise.de/investigativ

Danger of short circuit

During the course of his analysis of the cloud, the security researcher discovered several loopholes through which he could manipulate inverters in such a way that infrastructure was damaged and the inverter was destroyed. In the worst case, there is a risk to life and limb.

Among other things, it would be possible to deactivate NA protection and island protection. The NA protection ensures that the grid and inverter are disconnected if voltage and frequency limit values ​​are exceeded or fallen below. Island protection switches off the inverter if the grid connection is interrupted. This also prevents systems connected via a protective contact plug (Schuko) from posing a safety risk when unplugged; If you deactivate the function, there is a risk to life from open contacts.

If you use the gaps in a suitable combination, you can even manipulate the alternating voltage generation of the devices. It is also possible to permanently switch on all transistors. If this happens in mains operation, the resulting short circuit on the AC voltage side will destroy at least the inverter’s fuse – if not also its transistors. The whistleblower verified that this actually works with a low voltage.

Manufacturers have so far remained silent

In an email sent on Tuesday, we asked the Chinese manufacturer for comment. Although we contacted several company departments and wrote to a company technician and the Senior Sales Manager for Europe directly, we received neither an acknowledgment of receipt nor any contact made. c’t has already had difficulty establishing contact with Hoymiles in the past and there has been no smooth communication so far.

Users of Hoymiles DTUs should now disconnect the devices from the Internet as quickly as possible so that no more commands can reach the inverters via the cloud service. If you don’t want to miss out on yield monitoring, you should take a look at the alternatives Ahoy and OpenDTU. Ready-made devices can be purchased online. Since these are cloudless and manufacturer-independent firmwares, they are not affected by the vulnerability.

(amo)

To the home page
#Balcony #power #plants #Threatening #security #gaps #Hoymiles

Tags: balconybalcony power plantgapsHoymilesMicroinverterPhotovoltaicsplantspowerSecuritySecurity gapsSolar energyThreatening
Previous Post

Mette Marit from Norway, a princess on sick leave willing to make visible the misunderstanding of chronic diseases

Next Post

The gigantic sphere of Las Vegas is born, Made in Zaragoza

Eliza Houghton

Eliza Houghton

Related Posts

Kyiv mayor accuses Zelenskiy of authoritarianism, ending Ukraine’s political truce
World

Kyiv mayor accuses Zelenskiy of authoritarianism, ending Ukraine’s political truce

by Eliza Houghton
December 5, 2023
EHDS: Ministry of Health promises the right to object to electronic patient files
World

EHDS: Ministry of Health promises the right to object to electronic patient files

by Eliza Houghton
December 5, 2023
Borja Prado will leave the presidency of Mediaset after a year and a half in office
World

Borja Prado will leave the presidency of Mediaset after a year and a half in office

by Eliza Houghton
December 5, 2023
Sevilla presents its new Sánchez-Pizjuán stadium
World

Sevilla presents its new Sánchez-Pizjuán stadium

by Eliza Houghton
December 5, 2023
The product workers: Product owners from the developers’ perspective
World

The product workers: Product owners from the developers’ perspective

by Eliza Houghton
December 5, 2023
Next Post
The gigantic sphere of Las Vegas is born, Made in Zaragoza

The gigantic sphere of Las Vegas is born, Made in Zaragoza

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

Premium Content

The jury finds the accused guilty of killing a rival of the street markets in Malaga

The jury finds the accused guilty of killing a rival of the street markets in Malaga

October 20, 2023
MMA continues to boom in Spain with the return of WOW 10 to Madrid on September 30

MMA continues to boom in Spain with the return of WOW 10 to Madrid on September 30

September 18, 2023
Apple TV: WebEx app and changes to the TV application

Apple TV: WebEx app and changes to the TV application

October 25, 2023

Browse by Category

  • Science
  • Sports
  • World

Browse by Tags

Amazon America amnesty Apple Artificial Intelligence attack attacks China Court data due Economy Gaza Gaza Strip Germany Google government Hamas health investiture iOS iPhone Israel law live Madrid Microsoft million news people police Politics PSOE Russia Security Spain Sánchez Ukraine United States Updates Vulnerabilities war workshop world years
Kiratas

Latest News from World, Health, Politics, Sports, Business, Education, Technology, Arts and Latin America, the Middle East, South Asia.

Categories

  • Science
  • Sports
  • World

Browse by Tag

Amazon America amnesty Apple Artificial Intelligence attack attacks China Court data due Economy Gaza Gaza Strip Germany Google government Hamas health investiture iOS iPhone Israel law live Madrid Microsoft million news people police Politics PSOE Russia Security Spain Sánchez Ukraine United States Updates Vulnerabilities war workshop world years

Recent Posts

  • Kyiv mayor accuses Zelenskiy of authoritarianism, ending Ukraine’s political truce
  • EHDS: Ministry of Health promises the right to object to electronic patient files
  • Borja Prado will leave the presidency of Mediaset after a year and a half in office
  • About Us
  • Home
  • Privacy Policy
  • Terms and Conditions

© Aroged 2023. All Rights Reserved.

No Result
View All Result
  • Home
  • Landing Page
  • Buy JNews
  • Support Forum
  • Contact Us

© Aroged 2023. All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.