Live data from Hacker News

Picking the FB50 smart lock

icyphox.sh

21–30 of 67 posts

Re: Picking the FB50 smart lock

#21
post #18
post #4

Earlier quoted context omitted.

I dont think Apple is that hard on this. I peeked a bit the guidelines, couldn't find the section you mentioned.

https://developer.apple.com/app-store/review/guidelines/#dat... : ”(v) Account Sign-In: If your app doesn’t include significant account-based features, let people use it without a log-in.”

"Apps may not require users to enter personal information to function, except when directly relevant to the core functionality of the app or required by law."

Re: Picking the FB50 smart lock

#22
post #17

I'm a big fan of electronic locks, but I refuse to have a smart lock. I know enough about IOT and security to know that a lock with a wifi chip might as well not be there at all. I just program a few extra codes into the lock ahead of time, and if I need to let someone in in an emergency, I just give them one of my burner codes and delete it when I get home. I don't really need a log of every entry because the camera…

Why is a WiFi lock so bad? It opens you up more, but the number of people who can hack even the most insecure example is vastly smaller than the number of people who can kick down a door or break a window. Household locks are almost always just about deterring casual criminals, and internet vulnerabilities don’t move the needle much on that.

Re: Picking the FB50 smart lock

#23

I’ve been getting into home automation recently and I’ve given myself a rule: nothing cloud connected. If I can’t run it off my local server, I don’t want it. I have much more motivation to secure my home than any company ever will.

That's awesome! Are you using any video surveillance? What about alarm system?

Been looking for that for a while but no way I ever trust a cloud connected one anf everything passable connects to cloud.

Re: Picking the FB50 smart lock

#24

Locks are often fairly weak against real attackers. I enjoyed this youtube video of another smart (fingerprint?) lock being broken due to a digital reset. It has a plastic panel on the front where the fingerprint reader is. If you remove the panel with a razor blade (it's just attached with glue), it even has a reset button exposed which resets the fingerprint. https://www.youtube.com/watch?v=uVvEkcN5tW8

LockPickingLawyer also picked the same lock in OP's post. If you search for the MicaLock on Amazon, the page says it's just a FB50.

https://www.youtube.com/watch?v=WeCGTosv-_c

Re: Picking the FB50 smart lock

#25

> DO NOT. Ever. Buy. A smart lock. You’re better off with the “dumb” ones with keys. Well, physical locks are not necessary harder to pick lock than electronic locks. Buy your self a pick lock set, practice a bit and be amazed how many locks you can pick.

I think you'll be surprised. You should watch some of these videos: https://www.youtube.com/channel/UCm9K6rby98W8JigLoZOh6FQ - choose any one of his videos. It'll be picked in under a minute.

Re: Picking the FB50 smart lock

#26
post #8
post #6

Earlier quoted context omitted.

And we, on HN, can make an informed decision about that calculated risk. The general public just sees "Encrypted Android App with Smart Unlock" and thinks they are safe.

Is that any different than virtually any other cyber security issue--the general public is not well equipped to do Risk Mitigation compared to more savvy individuals?

Or any other physical security issue? There are massive differences in the security of standard physical locks. How much does the average person know about that? How many people are buying locks based on an informed decision about its pick resistance and physical strength, versus buying whatever looks nice?

Re: Picking the FB50 smart lock

#29
post #8
post #6

Earlier quoted context omitted.

And we, on HN, can make an informed decision about that calculated risk. The general public just sees "Encrypted Android App with Smart Unlock" and thinks they are safe.

Is that any different than virtually any other cyber security issue--the general public is not well equipped to do Risk Mitigation compared to more savvy individuals?

It's a problem with the way technology scales. Previously difficult things become cheap to do at massive scales, and companies make tons of money doing it.

But it also make vulnerabilities scale in the same way - exfiltrating 150,000,000 SSNs isn't much harder than 150 - and the penalties for security lapses don't scale anything like the profits that operating at these scales does.

What's the solution to that? Bigger penalties so that companies prioritize security? Require companies handling data and devices to carry insurance against huge hacks? I don't know, but we need to get somewhere better than "Ignore it because consumers generally don't understand the risks and apology letters are cheap."

The one good thing about IoT locks compared to other internet security issues is that you need physical access to do anything with it. The script kiddies spamming SSH authentication attempts at every webserver from somewhere on the other side of an ocean can't break in to your house with this. Other IoT devices like security cameras are still a concern though; a vulnerability in those could scoop up a lot of private videos.

Re: Picking the FB50 smart lock

#30

> DO NOT. Ever. Buy. A smart lock. You’re better off with the “dumb” ones with keys. Well, physical locks are not necessary harder to pick lock than electronic locks. Buy your self a pick lock set, practice a bit and be amazed how many locks you can pick.

I had my house broken into once and they just used a crowbar. My neighbor heard them do it, but assumed someone was just doing some work outside.

I get why people are hard on smart locks, but I really don't see them as any more insecure then regular locks.

Post reply on HN