Sunday, February 12, 2012

Is your Smart Meter Spying on You?

Most of us by now have one these devices on our house - the new-fangled meter that allows the power company to take a reading of our power consumption remotely without having to send a service representative around the neighborhood the write it all down. Innocent as can be right?

Potentially not.

The meter can tell when you use power, what applicances are drawing loads, and by extention, when you are home, what rooms you use the most, what temperature you keep your house at, how many people live there, and on and on. Your TIVO already tracks every show you watch, every commercial you skip or watch - and even every slice of tv you rewind (thank you Janet Jackson). Doesn't feel so innocent any more does it?

Who else would want your data than just ther power company?



  • Neighborhood “busy bodies” will want to know what their neighbors are doing for the sheer pleasure of knowing, or the greater pleasure of gossiping.

  • Vengeful ex-spouses, jealous paramours, determined stalkers, and civil litigants may want to know an individual’s whereabouts and activities.

  • Burglars could use intercepted data to determine when a location is unoccupied, what an occupant is doing,and whether valuable electronics are inside.

  • A thief gaining access to bi-directional communications or controls could activate or deactivate intrusion alarms to divert police from, or to facilitate unlawful access to, a target.

  • Vandals could manipulate environmental controls, fire suppression systems, etc., to damage property as an end in itself.

  • Lastly, market manipulators, extortionists, terrorists, and others with political agendas could use unauthorized access to AMI command and control systems to disrupt the delivery of services to targeted facilities, create widespread blackouts, disrupt load balancing commands, or create fear and panic among the general population.

  • Insurance companies could petition for the data to reject a claim based on activities within the house. Most policies require you to have someone attend the home at least once in 24 hours. If you are on vacation and Aunt Edna forgets to come by, and the house burns down - the insurance company could deny your claim.


  • Follow the money

    Corporations, utilities, vendors, and third party data brokers will want to position themselves to sell meter data or analytics, just as credit reporting agencies have done. If utilities want to capture this revenue, and/or to prevent others from capturing it, they will need carefully crafted contractual provisions that clearly define who owns the AMI data and what rights the consumer, utility, service provider, or other third parties have to use or transfer it.

    Surely the constitution protects me?

    Law enforcement will also want on-demand access to your data. In the U.S., law enforcement presently has limited access to meter data to establish ownership of a place involved in criminal activities or to obtain search warrants for facilities suspected of drug production.Otherwise, the prohibition of unreasonable searches and seizures in the Fourth Amendment of the U.S. Constitution limits access to this data without first obtaining a warrant from a judge.

    However, because these protections generally do not apply to information revealed to third parties, a California Court of Appeals held that data collected from a specially installed surveillance electricity meter could be obtained by law enforcement without a warrant. Because the metering equipment was outside and did not reveal information about activities within the home, the Court found no constitutional protection.

    Sophisticated analysis of metering data might reveal enough about in-home behavior to reverse this outcome. On the other hand, as the use of such technologies becomes more common, consumer expectations may change, thereby placing law enforcement use of meter data outside of Fourth Amendment protections. As a result, data revealed to a utility, billing agency, or other vendor may now be available to law enforcement without a warrant. Utilities and others handling meter data will need to understand what they may, or must, do when law enforcement agencies demand access.

    So what am I going to do about it?

    Each utility has to be responsible for the data. Each one will provide you with a privacy policy (which you probably round file). Read it - and speak up. If you don't like their privacy rules, they generally have a public overview board that you can squawk to. Lastly - ensure that when you are talking to them ask them to confirm that they are using a breach solution from a professional breach reporting / solution company. You want to be notified when they invetibably and/or accidently expose your data to the world.

    And close the fridge and stop watching Mexican wrestling on TeleMundo. Big Brother is watching you....

    4 comments:

    1. Wow! Never thought you could determine all that just from a meter reading.

      ReplyDelete
    2. Interesting eh? I guess that all the "web enabled" gadgets are capable of "spying" on you, but it depends on what you give permission for, and what purposes someone wants to use, or misuse the data!

      ReplyDelete
    3. This is interesting! For us, the problem has always been the water meters---I think they're ripping us off each month. The city has even admitted to "Guesstimating" or usage for fees. I think I should "guesstimate" how much I owe them for their service!! You've got a great blog here, by the way!

      ReplyDelete
    4. These things are more evil than you know....

      ReplyDelete