Google Search

Showing posts with label electric. Show all posts
Showing posts with label electric. Show all posts

Thursday, September 19, 2013

How to hack an electric car-charging station

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Caution tape, image courtesy of ShutterstockIs there anything more annoying than infrastructure that turns on you?

For years we've been warned about the specter of hacker-induced nuclear power plant meltdowns, breached electric-grid control systems or Samsung TVs that let hackers watch you. We've even heard we could lose our data to juicejacking, when all we want is an emergency phone charge.

And the lack of security in SCADA systems? It's more like SCAD-DON'T.

The latest entrant into the scary-infrastructure category comes from a technology that feels like it should be a lot warmer and fuzzier: namely, electric car-charging stations.

In a video recorded at Hack In The Box 2013 Amsterdam and posted courtesy of Help Net Security, Ofer Shezaf, founder of OWASP Israel, talks about the lack of security in these charging stations, which often amount to little more than a computer sitting behind a key-lock panel on the street.

A computer that takes customers financial and personal information, that is.

For three years, Shezaf, an application security expert, worked for a company that makes infrastructure for the car-charging stations.

The equipment in a charging station typically includes these components, he says:

Main board; Communication equipment to connect with a central server and, often, with the internet;An RFID card reader that lets users identity themselves and begin charging their cars; andElectric components, such as a circuit breaker to protect from electrocution and a meter to measure the amount of electricity consumed.

Why do you need such a computer sitting on the street? Somebody has to pay for the electricity, Shezaf says, and controls are needed. You can't have everybody getting electricity at the same time, or the system will fry.

But once you put a computer on the street, information security comes into play, as does the potential for hacking.

Here are the ways Shezaf says attackers might hack into an electric car-charging station:

Via physical access on the street equipment. The computers, typically Linux-based, are often protected with a panel opened with a simple key. Once an attacker opens the panel, he has access to the components, allowing analysis and reverse-engineering of hardware, CPU, and firmware. Also, attackers can connect via processor ports to enable real-time analysis while customers are charging their cars.

Electric car, image courtesy of Shutterstock Via communications. In many cases, Shezaf says, there's a large number of charging stations in a single parking lot, linked via serial connection, which he calls "very slow and very, very ancient, with very little security." This can enable hackers to tap in to intercept information about the identities of the customers who are charging their cars, plus their payment information. Another potential is for attackers to conduct a man-in-the-middle attack.Via RFID card. There's high pressure on manufacturers to buy the cheapest ones available. Such cheap RFID cards are known to include either no encryption or insufficient encryption protocols. Back doors that allow technicians to connect to charging stations and get immediate access. Maintainability is a key element of these large physical networks. It has to be cheap and easy for technicians to fix issues, Shezaf says. He found one example in an equipment manual online that describes how access to the charging station is gained through a physical key. Beyond that, there's no security whatsoever - not even a password requirement.

What can hackers do once they're in? Shezaf gave this list:

Charging station, image courtesy of Shutterstock Identity theft. Attackers can intercept information while people charge.Financial theft. Charging for free or charging on someone else's account. DoS. A hacker can, for example, take out an entire parking lot, making cars inoperable. Hackers could also potentially shut down an entire network, shutting down electric car traffic in an entire city or region.

How likely are these types of physical attacks? Not very, Shezaf says, given a few things.

First, they sound simple, but they're not:

"You need a subject matter expert. That limits the number of people who can do it."

For one thing, encryption is a key challenge of securing charging infrastructure. But encryption is "a tough subject," he says. There just aren't that many people who know how to break it.

We don't see charging stations getting hacked or, for that matter, planes falling out of the sky, but we do see virtual hacking galore.

The reason, Shezaf proposes, is that physical damage frightens us, from an evolutionary standpoint.

If you're out to make some easy money, hacking a bank online is physically safe. The same can't be said for physical attacks against, for example, smart cars or car-charging stations:

"While naturally criminals and nation states will use those techniques, a lot less people who are doing it for money will try to hack charging stations."

Hopefully, that all adds up to this particular hacking scenario being relevant, for the most part, to Hollywood scriptwriters.

Follow @LisaVaas
Follow @NakedSecurity

Images of electric car, charging station and caution tape courtesy of Shutterstock.


View the original article here

Sunday, November 4, 2012

Chinese hackers linked to breach of control systems used in electric grids

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

electricity_170Attackers breached Telvent's network, the company has informed its customers in a letter. Telvent is the maker of an industrial control system that remotely controls smart grid networks used in portions of the electric grid.

Telvent told its customers that on Sept. 10, it learned that hackers had breached its internal firewall and security systems, implanted malicious software, and stolen project files.

According to
Chinese Hackers Blamed for Intrusion at Energy Industry Giant Telvent" href="http://krebsonsecurity.com/2012/09/chinese-hackers-blamed-for-intrusion-at-energy-industry-giant-telvent/" rel="nofollow">KrebsOnSecurity, which first reported the breach, the project files concerned Telvent's
Standardized, centralized SCADA solutions from Telvent" href="http://www.telvent.com/en/business_areas/smart_grid/solutions_overview/smart_grid/smart_operations/oasys-scada.cfm" rel="nofollow">OASyS SCADA product, which offers energy firms a bridge between older technology and advanced smart grid technologies.

Telvent, which is owned by Schneider Electric, told customers that the attack spans operations in the US, Canada and Spain.

Experts detected digital fingerprints implicating a Chinese hacking group that has been tied to cyber-espionage campaigns against Western interests.

Telvent_logo

KrebsOnSecurity cited Joe Stewart, director of malware research at Dell SecureWorks, who said that website and malware names mentioned in a more recent letter from Telvent can be traced to a Chinese hacking team known as the "Comment Group."

That group, often referred to as the Comment group, has been under investigation by US intelligence for years.

Researchers told Bloomberg that during two months of monitoring last year, targeted companies spanned a vast scale as data "bled from one victim to the next":

...from oilfield services leader Halliburton Co. (HAL) to Washington law firm Wiley Rein LLP; from a Canadian magistrate involved in a sensitive China extradition case to Kolkata-based tobacco and technology conglomerate ITC Ltd. (ITC)

A loose-knit group of some 30 North American private security researchers tracking the group have called the Comment Group one of the biggest and busiest hacking groups in China.

Bloomberg quoted Shawn Henry, former executive assistant director of the FBI in charge of the agency’s cyber division, who said that typical cybersecurity headlines about data breaches scarcely hint at the scope of the group's activities:

What the general public hears about — stolen credit card numbers, somebody hacked LinkedIn (LNKD) — that’s the tip of the iceberg, the unclassified stuff. … I’ve been circling the iceberg in a submarine. This is the biggest vacuuming up of U.S. proprietary data that we’ve ever seen. It’s a machine.

Evidence indicates that at least 20 organizations have been harvested for data, many of whose secrets could give China a leg up on its path to becoming the world’s largest economy.

Bloomberg cited unnamed security experts who said that the breaches have sprung data leaks in major oil companies, who've lost seismic maps charting oil reserves, while patent law firms have been squeezed for clients' trade secrets and investment banks have been targeted for market analysis regarding global ventures of state-owned companies.

Telvent said that investigations are still under way, but it's taken the precaution of severing data links between clients and the affected portions of its internal networks.

The company also said that it hasn't yet found evidence that the attackers had been able to compromise customers' systems:

Although we do not have any reason to believe that the intruder(s) acquired any information that would enable them to gain access to a customer system or that any of the compromised computers have been connected to a customer system, as a further precautionary measure, we indefinitely terminated any customer system access by Telvent.

Telvent gave me this statement:

Telvent is aware of a security breach of its corporate network that has affected some customer files. Customers have been informed and are taking recommended actions, with the support of Telvent teams. Telvent is actively working with law enforcement, security specialists and its affected customers to ensure the breach has been contained.

Meanwhile, the Obama adminstration and Congress have grown increasingly vocal about Chinese and Russian cyber espionage and attacks, with the White House close to completing the first draft of a cybersecurity executive order designed to bring about stronger cyber security around the nation's water, electrical and transportation systems.

It's a reasonable thing to call for stronger protection around vital infrastructure.

But as Reuters pointed out in a recent report on what one top US cybersecurity official called "reckless" cyber behavior from nation states, the US's right to complain about other nations' cyber warfare might be questionable, given what is by now a widespread belief that the US and Israel were behind Stuxnet.

Follow @LisaVaas
Follow @nakedsecurity

electricity images courtesy of Shutterstock


View the original article here