I was 75% done with negotiations and planning with an installer to Enphase micro-inverters and their battery system installed along with a 18KW solar grid and luckily I did my homework and found that Enphase was just on the cusp of releasing new firmware for most of their devices that requires cloud based control systems. Meaning I would have to ask permission from servers that I don't control to be able to control equipment at my home behind my firewall. They are also implementing this and have started threatening void of warranties if you block this firmware from loading despite protections from the Magnuson Moss warranty act that prevents them from doing so.
There is a huge reason why industrial control systems in use are considered a joke security wise if they require an internet connected cloud system to be able to control those systems. I work in the IT security field and cannot in good conscience install any system that requires the usage of off site servers to be able to control and get reporting for my system. It truly is a security joke, but a very bad one. Before I started with Enphase I had a quote for a Generac system that also required the same thing.
People with a security clue have to start standing and pushing back against this crap. Yes, it should be something available to users who don't to control this themselves, but in any other case it should not be forced on users. It really is the equivalent of buying a home and your real estate agent insisting that you not get a key to your own home and that you must ask them for permission to come and go. Also the security of the system is much greater when there is a zero trust model in place. This is the same model that any good industry or commercial site uses for control systems. A home owner should not be forced to trust the maker of any system they choose. There should be no connection to the system possible unless the owner of the system is aware of it and there is a documented need for even the manufacturer to connect to the equipment. Then the homeowner would allow them access for support or a firmware upgrade.
The cloud security model is a joke and people need to wake up.
There is a huge reason why industrial control systems in use are considered a joke security wise if they require an internet connected cloud system to be able to control those systems. I work in the IT security field and cannot in good conscience install any system that requires the usage of off site servers to be able to control and get reporting for my system. It truly is a security joke, but a very bad one. Before I started with Enphase I had a quote for a Generac system that also required the same thing.
People with a security clue have to start standing and pushing back against this crap. Yes, it should be something available to users who don't to control this themselves, but in any other case it should not be forced on users. It really is the equivalent of buying a home and your real estate agent insisting that you not get a key to your own home and that you must ask them for permission to come and go. Also the security of the system is much greater when there is a zero trust model in place. This is the same model that any good industry or commercial site uses for control systems. A home owner should not be forced to trust the maker of any system they choose. There should be no connection to the system possible unless the owner of the system is aware of it and there is a documented need for even the manufacturer to connect to the equipment. Then the homeowner would allow them access for support or a firmware upgrade.
The cloud security model is a joke and people need to wake up.
Comment