Live data from Hacker News

Picking the FB50 smart lock

icyphox.sh

41–50 of 67 posts

Re: Picking the FB50 smart lock

#41
post #33
post #31

Earlier quoted context omitted.

> Why is a WiFi lock so bad? Scalability. Once you know how to pick one, you can pick them all quickly and remotely. Kicking down a door or picking a physical lock takes time and effort and exposes you to scrutiny while doing it.

Picking a lock remotely seems rather pointless.

> Picking a lock remotely seems rather pointless.

From another country, maybe.

Via WIFI? You are not more than a few hundred meters away. Doing that from across the street is much more convenient. Once they are done, they can just walk right in.

Re: Picking the FB50 smart lock

#42

I’ve been getting into home automation recently and I’ve given myself a rule: nothing cloud connected. If I can’t run it off my local server, I don’t want it. I have much more motivation to secure my home than any company ever will.

I can think of obvious reasons you'd want at least some devices cloud connected - for one, if some sort of disaster (fire, tornado, etc) hits your home, you probably want your surveillance getting off-site in realtime.

Re: Picking the FB50 smart lock

#44
post #30

> DO NOT. Ever. Buy. A smart lock. You’re better off with the “dumb” ones with keys. Well, physical locks are not necessary harder to pick lock than electronic locks. Buy your self a pick lock set, practice a bit and be amazed how many locks you can pick.

I had my house broken into once and they just used a crowbar. My neighbor heard them do it, but assumed someone was just doing some work outside. I get why people are hard on smart locks, but I really don't see them as any more insecure then regular locks.

There are limits to how secure your house can (should) be without violating fire regulations (if applicable) - or safety.

If there's a fire or medical emergency (heart attack, allergic reaction/anaphylactic shock etc) - you generally don't want it to be too hard to break in...

Re: Picking the FB50 smart lock

#45
post #30

> DO NOT. Ever. Buy. A smart lock. You’re better off with the “dumb” ones with keys. Well, physical locks are not necessary harder to pick lock than electronic locks. Buy your self a pick lock set, practice a bit and be amazed how many locks you can pick.

I had my house broken into once and they just used a crowbar. My neighbor heard them do it, but assumed someone was just doing some work outside. I get why people are hard on smart locks, but I really don't see them as any more insecure then regular locks.

The lock is only as good as the door it's attached to.. and the doors in a lot of new construction (especially in suburban McMansions) is really bad. You could probably kick most of 'em in.

Re: Picking the FB50 smart lock

#46

Earlier quoted context omitted.

I think you'll be surprised. You should watch some of these videos: https://www.youtube.com/channel/UCm9K6rby98W8JigLoZOh6FQ - choose any one of his videos. It'll be picked in under a minute.

LPL is an amazing lock picker, anyone with this level of skill is much better off working as a locksmith or a security consultant. Most B&E’s aren’t exactly executed by master thieves they aren’t single pin picking your locks. When selecting a door lock or a pad lock you should care only that it can be raked or bypassed, for bike locks you should also care that it can’t be easily cut. For the most part your door is l…

Many people even install glass windows.

Re: Picking the FB50 smart lock

#47
post #42

I’ve been getting into home automation recently and I’ve given myself a rule: nothing cloud connected. If I can’t run it off my local server, I don’t want it. I have much more motivation to secure my home than any company ever will.

I can think of obvious reasons you'd want at least some devices cloud connected - for one, if some sort of disaster (fire, tornado, etc) hits your home, you probably want your surveillance getting off-site in realtime.

Fair point. I suppose I should have said "nothing someone-else's-cloud connected". I'm actually considering setting up remote access on my system, but if I do it will be through a server I control.

Re: Picking the FB50 smart lock

#48

Doesn't this suggest that the unlock code comes from the "cloud" and not your phone/app? So if you loose internet access you are not able to unlock? Or maybe it locally caches the key?

First, this is obviously hilariously bad from a system perspective (un-authenticated/unauthorized rebind of lock) [1]

OTOH it appears the problem is entirely server side, and could be patched/mitigated by the provider?

It still seems possible that the lock is secure-ish. It might conceivably have some form of anchored trust (pinned cert?) to communicate with the server - and a secure/better rekey flow could maybe be implemented?

Still sounds crazy to delegate authorization entirely to the cloud (I'm guessing you can open the lock wo internet, but not re-key).

I'm not even crazy about "find my phone"-services - and that's considering the vendor typically owns the hw, the kernel and can push updates (ie: all bets are off anyway).

[1] I'm also curious about the "lock code" field in the data - does the service advertise the pin if you give the correct serial/hw ID of the lock? Or something else?

Re: Picking the FB50 smart lock

#49
post #30

> DO NOT. Ever. Buy. A smart lock. You’re better off with the “dumb” ones with keys. Well, physical locks are not necessary harder to pick lock than electronic locks. Buy your self a pick lock set, practice a bit and be amazed how many locks you can pick.

I had my house broken into once and they just used a crowbar. My neighbor heard them do it, but assumed someone was just doing some work outside. I get why people are hard on smart locks, but I really don't see them as any more insecure then regular locks.

One of the problems with many "smart" locks is that they tend to be made by people that don't have a lot of experience making locks. Many smart locks are vulnerable to many types of physical attack, including very old exploits that most locks (even many cheap locks) defend against.

For example, here[1] is a "keyless bluetooth padlock" that can be opened trivially by rapping the locking pall with any hammar-like tool ("rock"). (it also has far too much around the shackle, so can also be opened with a a simple shim (e.g. a small cutout from a cola can). Another common problem are locks that don't seal their electronics securely, so they can be attacked by simply unscrewing a panel, ripping out the electronics. and touching the battery wires to the locking pal's actuator.

However, that type of problem are simply poor designs. In theory, in the future better designs could be made that include protections against well-known attack methods similar to what is already included in many "regular" locks.

A fundamental concern with locks that depend on radio (or worse, the internet) is what the lock does when when the radio/internet communication fails (for any reason). Does the lock fail-open, or fail-closed[2]? Did the lock even address this important question? Does the lock open if someone unplugs the router? Or does it trap people behind the lock if a fire destroys the cable/DSL modem? Physical locks also have failure-mode concerns, but they tend to be limited to something happening locally, With "smart" devices, you are adding remote resources (like the internet router in another room, or remote servers, etc) as a critical component of the lock's security. That is a terrible idea if you that remote resource is intrinsically outside your control.

[1] https://www.youtube.com/watch?v=vIbXC5LR8aQ

[2] https://en.wikipedia.org/wiki/Fail-safe#Fail_safe_and_fail_s...

Re: Picking the FB50 smart lock

#50
post #33

Earlier quoted context omitted.

Picking a lock remotely seems rather pointless.

> Picking a lock remotely seems rather pointless. From another country, maybe. Via WIFI? You are not more than a few hundred meters away. Doing that from across the street is much more convenient. Once they are done, they can just walk right in.

Doesn’t seem very scalable. Maybe you can knock over 10x as many houses in a night as a normal criminal. Normal criminals are 1000x (at least) more numerous, so it’s not a big increase in the threat.
Post reply on HN