30 votes

US Federal Communications Commission bans foreign-produced solar inverters

7 comments

  1. nukeman
    Link
    While I doubt the sincerity of this (and the Chinese humanoid robot ban) action, it does reveal the deeper issue of everything being internet-connected all the time: Devices can be remotely...

    While I doubt the sincerity of this (and the Chinese humanoid robot ban) action, it does reveal the deeper issue of everything being internet-connected all the time: Devices can be remotely compromised and shut down at any moment with nearly zero warning. It used to be that you could check an item during procurement, and then occasionally during a (manually installed) update. Now everything is operating on the public internet and hypervigilance is required in the cyber domain.

    10 votes
  2. [5]
    TonesTones
    Link
    Thank you for posting. Is this blanket ban just an attack on renewable energy? I need someone with more technical expertise to weigh in, but my intuition says there should have been less...

    Thank you for posting.

    Is this blanket ban just an attack on renewable energy? I need someone with more technical expertise to weigh in, but my intuition says there should have been less disruptive ways to achieve the same result.

    The concern, as written, is about widespread malicious firmware updates. Would there be large obstacles (e.g., IP boundaries) to having foreign hardware run U.S. firmware maintained by U.S. software companies? Could you block network access to the inverters and still rely on them to work properly?

    I’m used to assuming the worst combination of malice, corruption, and incompetence from this administration. I would still like to make sure my total lack of experience with this kind of hardware isn’t leading me to make bad assumptions.

    4 votes
    1. [3]
      carsonc
      Link Parent
      So, these parts are correct and have been known for a while. This same website published an article about these vulnerabilities in April. And there is a precedent, as the Chinese company Deye...

      “The lack of a secure U.S. supply chain for inverters and the continuous inflow of foreign-produced or controlled inverters and inverter components poses threats to U.S. economic and national security . . . Inverters’ remote connectivity introduces additional vulnerabilities which compound as inverter-based resources proliferate on the U.S. grid. These vulnerabilities could enable foreign firms to turn off the inverters or use them to collect and exfiltrate data, facilitate remote access and surveillance by foreign government actors, or be otherwise exploited
      through a cyberattack.”

      So, these parts are correct and have been known for a while. This same website published an article about these vulnerabilities in April. And there is a precedent, as the Chinese company Deye remotely shut down inverters in the US, UK, and Pakistan in 2024. Now, these were apparently improperly sold in the US, but the point still stands: they could have also done it maliciously, had they wanted.

      The fact that there was no intentional malware discovered could easily be neither here not there. If the devices can have new firmware remotely pushed, then the "malware" can simply be introduced at a later time. This, of course, is also true for US-made devices, but US-companies are unlikely to trigger such an attack for the same reasons as a foreign country.

      I won't speculate on motivations, but after a few minutes of thinking about it, I can imagine some less chaotic ways to achieve equivalent outcomes. First, the mandate could have compelled all devices to be placed under the control and supervision of wholly US-owned companies. So that other countries can still make and sell them, but only US companies can access and operate them. They could do this right now and all the companies would have to start handing over the keys to US firms.

      Second, the mandate could require foreign-devices sold to have all telecommunication capability disabled prior to interconnect. They could have relaxed what US-made means.

      It makes me glad that we already have our solar system set up, but I guess my dreams of low cost battery storage will remain just that.

      12 votes
      1. [2]
        nukeman
        Link Parent
        There are companies making these components in the U.S. Victron is one example. And apparently existing companies that manufacture in China have some sort of workaround.

        It makes me glad that we already have our solar system set up, but I guess my dreams of low cost battery storage will remain just that.

        There are companies making these components in the U.S. Victron is one example. And apparently existing companies that manufacture in China have some sort of workaround.

        1 vote
        1. vord
          Link Parent
          Probably greasing the palms of the president or his cronies.

          And apparently existing companies that manufacture in China have some sort of workaround.

          Probably greasing the palms of the president or his cronies.

          2 votes
    2. Grayscail
      Link Parent
      It not entirely coming out of nowhere, cybersecurity on the grid in general is a big concern for defense agencies, as currently there isnt really much effort put into securing infrastructure. More...

      It not entirely coming out of nowhere, cybersecurity on the grid in general is a big concern for defense agencies, as currently there isnt really much effort put into securing infrastructure.

      More relevantly, there was some chatter last year about some chinese inverters being flagged as having remote shutdown capacity built in. I found an old article from last year about it.

      There have been a number of small incidents throughout the years that have laid the foundations for conspiracy theories about grid attacks, but I dont think there has ever been any conclusive evidence that anyone is planning to try anything like that.

      6 votes
  3. skybrian
    Link
    From the article:

    From the article:

    The Federal Communications Commission Public Safety and Homeland Security Bureau added foreign-produced power inverters to its Covered List, triggering an immediate and absolute ban on new equipment sales in the United States.

    This means any solar or battery storage project relying on an inverter made outside the United States that has not already received an official FCC ID cannot legally turn on or interconnect. Because there is no phase-in period, grandfather clause, or grace window, the regulatory pipeline is frozen today, forcing developers to halt active procurements and find new hardware vendors.

    The action effectively overrides the Department of Energy analysis from January 2026, which inspected 30 Chinese inverters and found zero evidence of malicious hardware. The White House interagency council determined that physical bugs do not matter because the risk is purely digital. The administration ruled that the wireless connectivity inherent in modern smart inverters allows foreign adversaries to push firmware updates that could shut down solar arrays remotely, making all foreign-assembled units an unacceptable threat to the critical power grid.

    The immediate practical result is a massive equipment shortage that will delay upcoming commercial and utility projects. Department of Energy data shows that domestic manufacturers supply only seven percent of the U.S. solar inverter market, leaving a 93% deficit that cannot be filled by local factories anytime soon.

    The hardware blockade hits right as developers plan to connect more than 58,000 MW of new solar and storage over the next year. Without certified inverters, fully built solar farms will sit dark and unable to feed electricity to the grid.

    3 votes