Lora Smart Water Meter Security Analysis

Conference:  Defcon 26



The presentation discusses the security risks of Lora-based smart water meters and how to analyze their firmware and hardware for vulnerabilities.
  • Wireless communication modules are being used in water meters to collect usage data.
  • Lora wireless protocol is used in the example water meter analyzed.
  • Security risks are analyzed from physical, data link, and sensor perspectives.
  • Reverse engineering and analyzing firmware and hardware is explained.
  • The presentation provides useful methods for testing other Lora-based systems.
  • The presentation includes anecdotes about using a strong magnet to interfere with the sensor data and using a logic analyzer to capture traffic and configure the Lora module.
The presenter demonstrated how a strong magnet can be used to interfere with the sensor data of a water meter, making it appear as though no water is being used. This could be caught if a technician physically inspects the meter. The presenter also discussed using a logic analyzer to capture traffic and configure the Lora module, which allowed for the reverse engineering of the system's parameters.


