Bsides Cymru 2024

Home Renewables Security Or: How I forgot to RTFM and got Pwned by my 12 year old
04-27, 09:30–10:00 (Europe/London), Main Room (Ballroom) - Track 1

An exploration of the threats against home renewable technologies such as solar panels, EV chargers and smart heating systems with inspiration from real world vulnerabilities.


Adoption of home technologies to help reduce CO2 emissions and energy costs are on the rise as more and more people engage with the green revolution. Whether it’s solar panels and battery technology, Electric Vehicles (EV) and their chargers or smart home heating for both conventional fossil fuel heating and electric heating such as heat pumps.

All of these technologies are built on electronics, software, are networked and often include cloud management capabilities, as well as often being physically located outside of the home.

This talk will explore the threat model for home renewable technology with real world examples of vulnerabilities. It will also explore what manufacturers should be doing to support their customers to maintain the security of home renewable technologies.

The presentation will conclude with the story of how my 12 year old took advantage of poor default security settings on a solar inverter.

Jon is Deputy Director of Commercial Research at NCC Group, a cyber security consultancy and services company headquartered in Manchester, UK. His role involves managing cyber security research for NCC Group's customers globally, across technologies and sectors, and delivered by technical experts from across the company.

Jon's technical background is in the design and integration of secure networked systems with experience across telecommunications, enterprise and military communications networks, vehicle platforms and key management systems.