IT security on inverter

32 comments started 2024-03-01 last 2024-03-24
GivEnergy ProductsBattery
#1 Midlands_Solar

Working in cyber security I was a little surprised to learn that

1) The wireless SSID is configured as open
2) I was able to connect to the inverter wireless SSID and browse the internet
3) I was able to connect to the admin configuration page and guessed the username and password as

admin
admin

Is this genuinely how the GivEnergy inverters are left as configured? Or is my situation a “one off” I’m a little concerned to say at the least

V
#2 Vestas

Midlands_Solar That's your installer not giving a damn. The installers guide tells them to set the password to the inverter serial number.

#3 Midlands_Solar

Thanks that’s interesting, I’ve made some configuration changes to plug this security issue

1) Hidden the SSID
2) Enabled a WPA passphrase
3) Set an admin password

V
#4 Vestas

Midlands_Solar Don't hide SSIDs, it does nothing apart from increase co-channel and adjacent channel interference which is the last thing the 2.4GHz band needs

Also anyone with a clue who is in range will probably feel obliged to give it a prod to find out what it is 😉

Edit - if there's an option then best thing you could do is turn the dongle's transmit power to low.

#5 PianSom

Midlands_Solar
Also, if you have an AIO then both the AIO and Gateway are likely to have open SSIDs

#6 hoggy

If you search "Dongle Security" on here there's various threads on it.
Pointless trivia, but I only noticed yesterday that the "on Dongle" server/setup pages bear a striking resemblance to Solarman ones although given I believe the chipsets inside for both are HiFlying branded so this may be more due to that, than any shared long forgotten partnership.

S
#7 SJB

Midlands_Solar The installer is supposed to change this during the installation process, but it often doesn't happen. I did the same as you about 5 minutes after the installer left.

D
#8 DD

Hmm... it occurred to me that I ought to check that I can get connect to the dongle's AP, in case I need to for some reason. The AP name is set to the dongle's serial number (starting WH). The inverter's serial is the same except for the starting two letters. Neither seems to work as the password (and would seem rather too close to the name...)

At least it's not open, but...

A
#9 alfwro

That's GE approach, insecure by design.
Can you imagine telecom companies doing the same thing - sending home routers with admin/admin and open wifi and blaming it on installers that it is their job to secure them?
You are not the only one - every single person I know with GE kit had their kit setup with default password and open wifi.

#10 Midlands_Solar

Definitely does not have security at the core of the product that’s for sure 🤔

T
#11 TX200

There are new dongles to come which will be secure by default. Not sure when, but it is on Paul's list.

#12 Midlands_Solar

TX200 that’s great to hear, not storing the wi-fi password on the inverter in clear txt would be a good security upgrade as well

A
#13 alfwro

TX200 will they be sending them to all existing customers? My guess is no.
I just hope that their backed IT is more secure then the kit they are selling.

V
#14 Vestas

TX200 which will be secure by default

Yeah & I believe in Santa 🙂

D
#16 Digger

As my inverter is hard wired to my router I take it that this isn't an issue for me.

#17 Midlands_Solar

Digger

It will still be broadcasting its potentially unsecured SSID, I’d get an IT person to check it for you

L
#19 lifco

Vestas Don't hide SSIDs, it does nothing apart from increase co-channel and adjacent channel interference which is the last thing the 2.4GHz band needs

You should hide the SSID name as a extra layer of security, its not like you need to connect to the network

So your not going to run in to any problems

Plus most peeps are using 5GHz or even 6GHz bands

It was said right at the being, ages ago do the 3 steps to make it secure

  1. Change the Device Management admin / admin to something a hell of a lot better
  2. Change the AP Interface Setting to WPA2 and pick AES and then a good pass phrase (password)
  3. Change the AP Interface Setting click the hidden button
K
#20 kram

Problem with hiding the SSID is anyone with the most basic scanning tools can see it’s there.

If it’s there are hidden, then people get more curious and determined to find out.

L
#21 lifco

kram

Totally agree ,but if they are that close to your network and can get past WPA2 / AES, then they can jump on your main router anyways

V
#22 Vestas

lifco

lifco You should hide the SSID name as a extra layer of security, its not like you need to connect to the network

So your not going to run in to any problems

Plus most peeps are using 5GHz or even 6GHz bands

This is rubbish. Do you even know how SSIDs work? Clearly not.

D
#23 Digger

Hi I contacted GE and they sent me the Wi Fi setup. With the following instructions.

'Is there a password on this network? We do know of the inverter broadcasting while in LAN mode but it should be secured by a password on site the day its installed, if not I have provided a guide to walk through, ignore step 3,4,5 and 6 as this is irrelevant you just need to get onto the 10.10.100.254 page and set a password in the AP interface setting page.
You can stop the broadcast in this page also by hitting the HIDE SSID box,'

I have done this leaving the password as my inverter serial number but I do have a further question, in security mode ‘DISABLE’ is selected. Should this be WPA2 PSK? Or doesn’t it matter as I am hard wired LAN.
The inverter now doesn't appear in list of available networks. Which is what I was aiming for.
Thanks I hope these questions and answers will help others.

T
#24 TX200

Yes, set it to WPA2 PSK. Or WPA3 if it offers that, probably doesn't.

T
#25 T-M

Midlands_Solar I took the time to make sure both the AIO and Gateway dongles were secured. Yesterday I finished hard wiring them with LAN cables, and changed the AIO & Gateway DIP switch settings as set out in the installation manual.
Tonight I've just spotted that both the dongles have reverted to their default INSECURE settings. Coincidence? Or am I going to have to watch them like a hawk for the foreseeable future?

I was going to hide both the AP SSIDs, but if I do that it will just make it harder for me to keep an eagle eye on them so I think maybe not.

T
#26 T-M

Digger The "Hide SSID" checkbox does NOT stop the dongle broadcasting. Think of it as a flag that just says "Please ignore me". Criminals will have kit that ignores the "Please ignore me" flag. Security by obscurity is not security.

The AP password should preferably be something long, convoluted, but relatively easy to remember. My installer set mine to be the same password as I use for my 2.4GHz network. If someone can crack that, they can gain direct access to my network let alone my dongles, so it seemed a reasonable thing to do in my case.

Set both the AP and STA settings to WPA2PSK with AES encryption for best security

S
#27 SunnyWithAChanceOfPV

I've had to secure the Inverter & battery WiFi points about 5 times each since we had the AIO installed mid-December. They will revert to default, IE WIDE OPEN for no reason I can see.
I'm using the wired ethernet option to link them to my IoT VLAN and would very much like to permanently switch the WIFI option OFF.
It's surely a matter of time before someone with an insecure-by design GivEnergy battery gets seriously digitally done-over and out come the lawyers.

K
#28 kram

SunnyWithAChanceOfPV

Someone around here has a GE system… maybe I’ll keep an eye out. 😂😂

Set up home assistant to dump their power to the grid when I want to import and be green 😂

T
#29 T-M

SunnyWithAChanceOfPV I wonder if putting one of those foil keyfob bags around them will block access to them, or cause them to go bang! Have to be on a wired LAN first though, obv

D
#30 Digger

I have now changed in the AP page to WPA2-PSK and AES plus changed all pass words etc. Not done the STA page yet as I like to only change one step at a time. But out of curiosity what does AP and STA stand for?

T
#31 TX200

Digger access point (AP) and wireless client/station (STA)

D
#32 Digger

All pass words changed and security upgraded in AP and STA to AES & WPA2-PSK so now should be as secure as it can be.
Thank you all for the assistance. I hope this may be of help to others.