DIY Smart Doorbell with a Raspberry Pi
technicallywizardry.com
technicallywizardry.com
This is the line I am not willing to cross.
Do I believe that the security of Home Assistant and the plugins that surface this to web/mobile interfaces is such that I'd risk the physical security of my home and possessions to it?
I love the Pi doorbell project, and could eventually be onboard with a home security company producing a smart lock I would consider... but enabling a lock via Home Assistant to grant access to the house, disable alarms, etc (assuming HA scripts like "when the door is unlocked disable alarm to prevent false positive", etc)... I suspect my insurance company would consider this an act of me leaving the door open and granting access to people who later stole stuff and that they wouldn't pay out.
If you take your average thief, they will walk past your house and if it looks like it's worth breaking in they will do this, or go to the next house that looks easier or more promising. They won't even notice your custom smart lock solution and think it might be hackable (unless it's a common brand with a generic explain available, think of scriptkiddy hacking skill requirement). They will go for the easiest thing, like a open window, or break a small window to open the door from the inside.
Now if you have a dedicated thief that wants to rob you specifically, they might want to invest into hacking your lock. But only if the rest of your house is already a fortress, or covertness is really key. But if they really want something they might just take an axe to your door and threaten you to open your vault.
If you take your average thief, they will walk past your house and if looks like an wide open door, then he knows there is not much to get and will walk past next to a bit better protected door.
In parts of South Africa there has been a continual levelling up of security systems in neighbourhoods where crime can involve fatal assaults in your own home as well as casual burglary. As soon as one resident installs something that seems to add security, the neighbours may rush to install it themselves so that they aren't seen as the softest target. This is in places where many houses have signs saying that they are protected by armed rapid response teams.
Source: expat friends of mine who lived for ten years in communities that went from 'normal' houses (locks), protected properties (e.g. sharps on walls), gated communities, high-protection gated communities.
[Edit - clarity]
Some folks, like one of my wealthier uncles, even hires Gurkhas with khukris and guns to guard their house. But his house is right on the highway, so some caution might be adequate.
If, OTOH, the thief subverts the home automation system, not only can they open the door and disable the cameras, they can instruct the system to pipe the anti-intruder knockout gas into the biolab/hackerspace where you are burning the midlight oil, working on your revolutionary chimpanzee/cheetah hybrid pizza delivery servant. The thief is then able sneak in undetected and steal your zygotes and tissue samples. Worst-case scenario, they'll take a kidney as well. Yours, I mean.
This is why it's so important to have physical safeguards in place, like the mechanical stops that keep the home defense cannon in the foyer from being aimed away from the front door.
And obviously bulletproof metal shutters.
It's whether insurance pay out.
I once locked myself out of the house and called a locksmith to let me back in. He didn't even touch the lock, he just reached through the letterbox with a lever and operated the handle from the inside. I felt a bit stupid paying him to do it really, because I could totally have done that myself if only I'd thought of the idea, but of course that's easy to say once you've seen how it's done.
And once it also happened (I know...) with a secure door and lock, and although the locksmith had to break the lock he managed in under 10 minutes.
My conclusion is that residential doors and locks, even secure, expensive ones, are no match for professionals. They protect against opportunity theft and idiots.
All this said, FBI statistics on theft show that lockpicking (I believe all lock bypass methods are included in this count) is fairly rare at only a percent or so of burglaries. Up to maybe 3% if you generously assume that cases where 'doors and windows were locked, entry method unknown' were all a lock bypass. They don't break out doors vs. windows, and my suspicion is that windows are actually a large portion here because many older residential windows (and even newer ones) have pretty defective locking schemes. It is more common for the burglar to simply have a key (they don't drill in on why the burglar has a key, perhaps a hidden spare or someone known to the victim).
So in a way all security concerns around smart locks are probably somewhat moot, even with them having a somewhat poor track record for secure design. It's more useful to think about this in defense-in-depth terms, and that's where my concern about too much HA involvement comes in. An HA system, from one perspective, would ideally form a unified control point for all security devices in the home. The problem is that, for one attack vector, this reduces the "layers" of defensive measures to only one: access to the HA platform.
A situation where a burglar could potentially gain access to your HA and simply unlock the door and disarm the alarm is much more concerning than having a lock and an alarm which are independently controlled. Beyond this, for home insurers to consider an alarm as contributing to security it needs a UL certificate, and while I have not thoroughly researched this, I get the impression that the UL certification scheme is generally hostile to having alarms that are "too extensible," because it introduces a large number of new potential bypasses as well as reliability issues (this may also be an issue with your police department's false alarm program).
All of this said, if you do have a burglar alarm, having a private security company respond is not a bad idea. There are often security companies that will do this "for free," only charging you if/when they actually respond to an alarm. They will generally arrive before police and because they are being paid for their time they are often more attentive, and will do things like guarding the home until you return if a door or window has been forced and is now insecure. Their written report can also be very helpful when you go to the police and insurance.
"I'll Let Myself In: Tactics of Physical Pen Testers"
Some of these smart locks however turn out to have MASSIVE exploits (sending out unencrypted bluetooth addresses for instance). Sure, you could research and pick a lock from a wellknown brand with proven security. The downside to software security is that there is a possibility that a hack can be developed in the future. With an old-fashioned key, the risks are pretty well known.
I'm a big fan of home automation (Home Assistant user here). I'm rather proud of my setup where I can measure, control and secure my entire house. But I'm not using smart locks. Their use cases are, in my case, very limited (I've never encountered a situation where I thought 'darnit, I wish I could open that door without a key') and therefore not worth the extra risk.
Obligatory LockPickingLawyer: https://youtu.be/XXW27KKHtc8
For hackers anywhere who don't mind traveling, perhaps a few would think "hey we already got the door unlocked, maybe we can burgle the place, too."
Far fetched, but who knows.
That said, you are probably right about insurance if you installed anything yourself without mechanisms to ensure the door is closed in all failure cases.
edit: That other insurance might be less happy with that in case of fire emergencies of course.
If someone has broken into my home, I have much bigger problems than if they've managed to break into my wifi or VPN gateway from the internet.
Though I just realized that I'm privileged enough to live in an area with a low violent crime rate, so physical violence isn't part of my threat model... if someone has broken into your home and you are home at the same time, you're right, the security of your local network is probably the least of your concerns.
If you throw up HTTP basic auth on your HTTPS front end, you've now moved your risk away from bugs in HA's code, to bugs in nginx's (or whatever HTTP server you use) implementation of HTTP basic auth AND bugs in HA's code (odds of this being a real event just got smaller)
If you throw a VPN in front of all that as well, you've now moved your risk away from bugs in nginx's code, to bugs in your VPN implementation AND bugs in nginx's code AND bugs in HA's code (odds are now really small).
This is also known as defence in depth.
> HA won't be accessible to you if you are somewhere where WireGuard is not possible
At that point, you also really want OTP (along with nginx HTTP basic auth), as if you're connecting from a device you don't control, it's not a bad plan to assume a keylogger may be operational.
Can you help me understand a situation where you have to get into your HA instance, and none of your own personal devices are able to get online?
EDIT:
> Does HA have an exceptionally bad security record?
Is a lack of regular security fixes needed evidence of good code, or due to lack of inspection / identification of vulnerabilities? HTTP basic auth is like a seat belt. It's a minor inconvenience that adds a layer of security. I haven't had a car crash, nor has my infra been exploited to the best of my knowledge. I still use both HTTP basic auth and seat belts every day.
The secure solution is to not allow remote access and use a VPN to connect to your local network (such as WireGuard) as the commenter you replied to suggested.
Would I install it on the Raspberry PI I have Home Assistant on? And they how would I remote into it over the internet?
The main points are:
Wireguard uses fairly strong and trusted encryption; this is basically shown by the fact it managed to be mainlined. It's basically foolproof, you don't have a myriad of options to choose from that can lead to insecure configuration.
It's faster than OpenVPN and less complicated then IPSec. It's easy to tunnel all traffic or just a subset through the VPN. It should deal with roaming IP addresses fairly well (so works on a train as well as your net will).
Basically, if the only open port from the internet to your LAN is wireguard, you're probably not going to be breached by someone coming in the front door.
Obviously, if you open a cat.jpeg.exe when on you're network, your inbound firewall security is no longer going to be helping you, however there are also ways around this. I.E. you could segregate your desktop and phones from the main network, etc. But then a rouge IOT device that does need to connect to your homeassistant could cause problems, and you probably want some access too, so you probably want to setup some kind of auth...
Yeah, I guess it can get convoluted if you're not happy with some risk / work...
Once I had seen how you add a client (correct word?) to the VPN via the ssh QR code thing, my mind was a little blown and I very much felt I was in the future.
Then you use the app on phone or laptop to connect to your home lan.
It all runs in Docker, and a mini warning - the internal networking of the WG install was a little finicky for this first timer.
A slightly smarter thief might carry a hammer specifically designed to break double glazing [2]. Mind you carrying that in the UK could count as 'going equipped' if you don't have a plausible excuse.
Otherwise just use a heavy pointed rock in the corner of the window.
But of course most burglars don't break windows, they take advantage of open windows, doors than can be forced, sliding doors that can simply be lifted out of the track, and other flaws in building security.
[1] Like this: https://www.smartasaker.no/no/artiklar/resqme-belteskjarer-a... [2] For instance: https://www.amazon.co.uk/dp/B00EFZC62Q
It seems massively easier to break into a home this side of the channel.
B) Does your home have easier ingress methods that don’t require finding the server, hacking into it, and hitting the correct button? For example, a first floor window?
I need a video doorbell with my own remote storage. but the camera sensor part and the button needs to be the only thing on the untrusted side of the door.
1. Securing the device - which in practice meant all my hardware had to be mounted inside the property of the back of the front door
2. power supply - i battled with voltage sag due to the crap thin wires i used and the long run from the plug socket
3. The video resolution was terrible, to the point of not being useful at all
It's interesting to me that in almost 10 years, only #3 is really "solved". 2 is arguably solved given the cheap high capacity lithium batteries available.My attempt back in 2011:
Linksys WRT54G, I broke out the GPIO pins to service a microswitch on the letterbox and the doorbell button. A cheap USB "spy cam" from ebay with a resolution of around 20px x 20px. It looked horrendous despite my best efforts to mount it neatly.
OpenCV existed at the time but wasn't available on this platform. Instead i read from /dev/video, converted the image to greyscale, then comparing pixel by pixel the luminosity vs. the previous saved file. If the cumulative value crosses a certain +ve or -ve threshold it treats it as motion detected - which turned out a terrible approach in practice :-)
Use 12V wall wart and a small 12V to 5V converter by the Pi.
I've found great use of these little ones:
The little stripboard daughter board in the pics is hosting an LM7805 to power the usb webcam thing because the wrt54g usb port itself was a bit of a hack https://wiki.dd-wrt.com/wiki/index.php/USB_mod_WRT54
The LM7805 works fine for low currents, but being a linear regulator wastes a lot of power which gets turned into heat once the current goes above 100mA or so.
Besides lighting and heating and cooling appliances, the use cases for a smart fridge, oven, or microwave make no sense to me.
It would be great to be able to throw a prepared casserole in the oven, go to the park with my kids, and then turn the oven on when we're about ready to head home so dinner's basically waiting for us when we get back.
Currently if I want to take the kids to the park before dinner I end up choosing between leaving earlier so there's time to make dinner, getting take out on the way home, or doing something super fast and low effort when we get back. Sometimes I use a slow cooker which provides some sort of solution but limits the type of dishes I can make.
Ahem nest.