- Best case, even with a responsible implementation, you're introducing more variables than are necessary into a supposedly secure system. If one of your dependencies fucks up, your lock is exploitable.
- Worst case, you have a typical IoT device, where the "S" stands for "security."
- In _either_ case, you're likely still going to include a physical lock mechanism for keys as a backup -- so you're basically just increasing the attack surface (significantly, I should add) by doing this.
Smart locks are currently high-risk appliances, and I'm fairly confident that most others with a security background will agree with me on that.
In the end, it's your decision, but the OP's comment stands fully: all the same attack vectors still exist, along with a bunch of new ones at the expense of convenience.
Only if you distribute the “do not duplicate” key, but the whole point is to not do that.
https://www.homedepot.com/b/Hardware-Door-Hardware-Door-Lock...
AFAIK, most code-based locks include a physical lock cylinder as a backup.
While this isn't an indicator of the quality of newer brands specifically, I believe it's reflective of the state of the industry as a whole -- in that digital physical security as a whole is still immature and shouldn't be trusted to keep bad guys (determined adversaries) at bad.
A lock that can be bumped isn't very secure. A lock that can be bumped or it's code discovered via some kind of power-monitoring attack isn't any less secure. But one without a keyway that can be attacked via power-monitoring is more secure in my opinion.
Everything is tradeoffs, and physical security is no different. Don't let perfect be the enemy of good here. If you are in the security industry, you should know that "bad" security that people will use is better than "good" security that people won't.
If a "smart lock" means I forget to lock my door less, I can monitor and record those who go into my house, and I can get alerts if the door is opened via any method, I'd call that a win even if there were pretty significant vulnerabilities that allowed an attacker physically present to get in.
Look at the Brinks CompuSafe hack in 2015. Anything which increases the attack surface of a device reduces the security. In that case, a USB port.
And that wasn't even made by the lowest bidding startup.
I know people that don't lock their doors because they don't want to deal with keys, or they forget to lock their doors all the time, or leave a key under a rock in front of their house.
For them, even a fairly insecure "smartlock" will be an improvement if it means they will actually use it.
Time and time again it's been shown that if you design systems that are hard to correctly secure or make significant compromises in the name of "security", they end up being insecure because people just won't use them or will actively seek ways around them.
You can't just handwave away issues like usability and pretend that you've designed the "perfect" system or something.
If you design a good/secure keypad lock but it doesn't give people an easy way to let their family member in the house when they are away, they are just going to give out the code, leading to less security overall. If you design a secure keypad lock without a tumbler, the first time the batteries die and the user is locked out of their house they are going to replace it with something that won't lock them out.
Usability needs to be a core aspect of secure engineering. And oftentimes a "technically less secure" option is better, because it's actually usable by normal people in most cases.
A 5-point harness is safer than your average seatbelt, but we don't use them because forcing every car to have a 5-point harness would just end up with fewer people using them.
These are all problems we have solved for years before without the technology so there are established ways of handling the situations. Adding complexity and a different way of doing things actually makes it harder and riskier.
Coordinating how to use a smart lock between two people is harder than it looks.
On many occasions I was able to get a call from a family member to let them in, and there were many hundreds of times that I was able to lock or ensure the door was locked after I left the home.
I really feel layering is the ideal way to achieve this, as it means that any "smart" capability is easily disabled if found to be a problem, and we know that the underlying system is sound.
In my case I use a deadbolt that has a keypad, and they separately sell a zwave plugin for it that gives me local control, then I layer on an open source "gateway" that gives me control and notifications when away from the house.
If the gateway fails or is untrustworthy, I turn it off and the rest still works. If the zwave is found to be faulty, I pull it out and still have a functioning lock.
And until major vulnerabilities are found in any part of the "smart" add-ons, or until my lock starts unlocking on its own, it has greatly increased the security of our house, as well as increased my quality of life. No more getting out of bed at night to check that the door was locked, no more turning around to lock the door because I forgot when I left, and it was great when I was showing my last house as I could enable/disable the codes when I wanted, and get notifications when people came and left.
I'm not saying all new tech is good, just that this fear that "smart" (read "connected") is a bad thing inherently, and that the "traditional" ways of doing things, while perfectly fine for many, are not a panacea which can't be improved upon. The steam engine was great, the ICE was better, today's hybrid extremely-efficient engines are still better. Sure it's gotten more complex, but also significantly safer, easier, more resilient, and more powerful. In other words, complexity should be managed, not forbidden.
There are some gotchas (make sure you get a zwave-plus lock that incudes the AES security stuff), and you need a dedicated "hub" to communicate with it, but they are rock solid in my experience
The Nest thermostat would still be an attractive, interactive thermostat with a color screen and tons of features. Without an internet connection, the $250 thermostat doesn't turn into a brick, it turns into a $150 non-connected thermostat.
The Nest Protect smoke detector still alerts you to fires or carbon monoxide, with voice warnings, and a lighted path at night. Without an internet connection, the $120 detector doesn't turn into a brick, it turns into a $40 non-connected talking smoke/CO alarm.
The Nest smart deadbolt still lets you lock and unlock your door with either a key or a PIN code. Without an internet connection, the $280 smart deadbolt doesn't turn into a brick, it turns into a $100 keypad deadbolt.
People lose their internet connections for all kinds of reasons, and the majority of smart home devices you can buy continue to be premium devices in that state, better than the basic thermostat/detector/lock/light/etc they likely replaced.
Home assistant is open source, written in Python, has a web based UI, and integrates with everything under the sun and is VERY welcoming to new components from outside people.
I've contributed 2 so far, and I hope to have another that adds in daily electricity monitoring from my local power company ready soon.
Hass is quite possibly the best run open source project I've ever been involved in.
That being said, I think regular passcode locks without internet connectivity do add a convenience since you don't have to carry a key.
I prefer to create users, authorize, delete them than rekeying the lock every once in a while.