SA households with batteries connected to Deye inverters could get paid R1,000 to R2,000 per year for sharing their storage

And they did that in Australia (did you not watch the video I sent). In the 90s they privatised their grid now there is 3 main players and then there is companies that buy from those 3 and sell to the population. Since 2010 people's electricity price has gone up 8% each year in a country with very low inflation rate.

I like the VPP system a lot but we shouldnt kid ourselves that this is being done to benefit people in any way.

VPP to me is like Uber. The driver buys the car, fixes the car, insures the car. Uber then says for a small fee I will give you customers. Thats what Deye is doing here. They found a way to make even more money off the once off solar items they sell. They get to make a recurring profit.

You bought their inverter, battery etc. And now they will say for a small fee every day or month or whatever let us have access to your equipment with the promise that they will make even more savings and money for you.

Muni's and Eskom will sit there and say, wait, Deye and its customers want us to expand and upgrade the grid in order to handle all these systems feeding back into the grid. If they want us to do this, then we cant just keep the fixed charges the same, we need to increase the charges (like Europe, Australia). This gets passed onto the consumer again.

The only winner is Deye. The just found a way to create a subscription off solar users in SA. And they dont have to spend a dime. Once their system is running its just maintenance of their servers etc.
And while Deye is discharging your system, Citipower decides to blow a substation in the middle of the night with your batteries sitting at 20% or whatever.

Some things just dont work well in Africa.
 
And while Deye is discharging your system, Citipower decides to blow a substation in the middle of the night with your batteries sitting at 20% or whatever.

Some things just dont work well in Africa.
That's where the problem is. They will have to have complete control of your system and decide when and how you use the power. Nah, I'm not ready for that leap just yet.
 
Curious to know how they verify that you are actually charging or discharging as instructed, Sounds like you could make a device that looks like a Deye inverter, and reports reasonable charge/discharge/SoC figures, but doesn't actually do anything at all.

Not that I'm advocating that anyone does this, but I am curious how they would detect/prevent it.

I'd guess some sort of link to the municipality's smart meter would be the most foolproof way, but I'm dubious that they would get meaningful access to the meter's data.
 
Curious to know how they verify that you are actually charging or discharging as instructed, Sounds like you could make a device that looks like a Deye inverter, and reports reasonable charge/discharge/SoC figures, but doesn't actually do anything at all.

Not that I'm advocating that anyone does this, but I am curious how they would detect/prevent it.

I'd guess some sort of link to the municipality's smart meter would be the most foolproof way, but I'm dubious that they would get meaningful access to the meter's data.
You set the parameters and then it does it automatically using IOT.
1785847408191.png
 
You set the parameters and then it does it automatically using IOT.
View attachment 1927200
Mmmm, I have heard of this IoT. In reality, it's just a bunch of computers talking to each other, and if one computer says something, the other computer needs to verify that what it says is correct.

As an information security practitioner, I know all about making computers do things their manufacturers never expected them to do. For example, the wifi dongle on my Sunsynk inverter is running my own code, talking modbus to my inverter. Switching that around, I could easilly make a device that appears to be a Deye/Sunsynk inverter, and answers the WiFi dongle's modbus queries with whatever values I provide. Of course I have 100kWh of battery storage attached, and can discharge at 20kW quite happily. Solar panels? Oh sure, 50kWp, at your disposal.

Hence my question. How do they validate what is said vs what is actually done? The smart meter would be the final arbiter, but I am not convinced they will get the access required to verify the figures independently. In which case, they might be relying on the subscriber forwarding copies of their municipal bill, but even that needs to be verified ...
 
Mmmm, I have heard of this IoT. In reality, it's just a bunch of computers talking to each other, and if one computer says something, the other computer needs to verify that what it says is correct.

As an information security practitioner, I know all about making computers do things their manufacturers never expected them to do. For example, the wifi dongle on my Sunsynk inverter is running my own code, talking modbus to my inverter. Switching that around, I could easilly make a device that appears to be a Deye/Sunsynk inverter, and answers the WiFi dongle's modbus queries with whatever values I provide. Of course I have 100kWh of battery storage attached, and can discharge at 20kW quite happily. Solar panels? Oh sure, 50kWp, at your disposal.

Hence my question. How do they validate what is said vs what is actually done? The smart meter would be the final arbiter, but I am not convinced they will get the access required to verify the figures independently. In which case, they might be relying on the subscriber forwarding copies of their municipal bill, but even that needs to be verified ...
tldr
 
Mmmm, I have heard of this IoT. In reality, it's just a bunch of computers talking to each other, and if one computer says something, the other computer needs to verify that what it says is correct.

As an information security practitioner, I know all about making computers do things their manufacturers never expected them to do. For example, the wifi dongle on my Sunsynk inverter is running my own code, talking modbus to my inverter. Switching that around, I could easilly make a device that appears to be a Deye/Sunsynk inverter, and answers the WiFi dongle's modbus queries with whatever values I provide. Of course I have 100kWh of battery storage attached, and can discharge at 20kW quite happily. Solar panels? Oh sure, 50kWp, at your disposal.

Hence my question. How do they validate what is said vs what is actually done? The smart meter would be the final arbiter, but I am not convinced they will get the access required to verify the figures independently. In which case, they might be relying on the subscriber forwarding copies of their municipal bill, but even that needs to be verified ...
Typically those things talk to an endpoint that expects the device to have at least a TLS certificate, along with other validation checks. That's how I implemented it at the corporate slog I work at. If you succeed in making it connect to a fake server, it won't send anything unless there's mutual authentication.

IoT is notoriously lacking in this regard. Ask me privately about the fun I had with one of C-Track's trackers I found in my car
 
Mmmm, I have heard of this IoT. In reality, it's just a bunch of computers talking to each other, and if one computer says something, the other computer needs to verify that what it says is correct.

As an information security practitioner, I know all about making computers do things their manufacturers never expected them to do. For example, the wifi dongle on my Sunsynk inverter is running my own code, talking modbus to my inverter. Switching that around, I could easilly make a device that appears to be a Deye/Sunsynk inverter, and answers the WiFi dongle's modbus queries with whatever values I provide. Of course I have 100kWh of battery storage attached, and can discharge at 20kW quite happily. Solar panels? Oh sure, 50kWp, at your disposal.

Hence my question. How do they validate what is said vs what is actually done? The smart meter would be the final arbiter, but I am not convinced they will get the access required to verify the figures independently. In which case, they might be relying on the subscriber forwarding copies of their municipal bill, but even that needs to be verified ...
Cyber security is a big thing in the UAE with Iran busy trying to sabotage the grid. Hopefully Deye is doing something on that front. Imagine hackers jumping into everyone's inverter and destroying the firmware etc inside the inverters bricking them. Would be fun.
 
Typically those things talk to an endpoint that expects the device to have at least a TLS certificate, along with other validation checks. That's how I implemented it at the corporate slog I work at. If you succeed in making it connect to a fake server, it won't send anything unless there's mutual authentication.

IoT is notoriously lacking in this regard. Ask me privately about the fun I had with one of C-Track's trackers I found in my car
TLS over TCP/IP to the WiFi dongle is one thing. But the inverter doesn’t talk that natively. The dongle talks modbus over rs232 to the inverter. Which has no security to speak of, unless they have implemented something non-standard over and above what the dongles are currently doing.
 
TLS over TCP/IP to the WiFi dongle is one thing. But the inverter doesn’t talk that natively. The dongle talks modbus over rs232 to the inverter. Which has no security to speak of, unless they have implemented something non-standard over and above what the dongles are currently doing.
yes, I was one step beyond that. Those protocols are as insecure as you get. They are by design insecure, because the data they exchange is so trivial at times the processing overhead, and processing power does not justify the means. Also these protocols are legacy, from an era when security wasn't the clusterfukk it is today.

As you discovered, when you did the pentest at my day job at the time, some years ago, it is quite difficult to secure legacy serial interfaces.
 
yes, I was one step beyond that. Those protocols are as insecure as you get. They are by design insecure, because the data they exchange is so trivial at times the processing overhead, and processing power does not justify the means. Also these protocols are legacy, from an era when security wasn't the clusterfukk it is today.

As you discovered, when you did the pentest at my day job at the time, some years ago, it is quite difficult to secure legacy serial interfaces.
There is no need to secure the protocols themselves. Rather the medium by which the inverter is communicating to the Internet.
 
Yeah no thanks. They can keep their peanuts, and I will keep my off grid, unregistered system.
 
Top
Sign up to the MyBroadband newsletter
X