Lockitron (YC S09) Lets You Unlock Your Door With Your Phone
techcrunch.com
techcrunch.com
One feature I'd love to see is connecting it with the doorbell, then I would forget about my battery worries and go straight for it. Would come in occasional use for if someone you're happy to let in arrives while you are out, but would also be great for day-to-day use. They press the buzzer, you get a phone call to talk to them followed by the option to let them in or not. (Where I live right now, my office is two floors up, it's pretty rare that I can hear anyone at the door.)
edit: The FAQ page is a bit vague about international orders due to "latency issues", any chance of some expansion on that? To my mind, a long distance (say, UK to California) is adding less than a second of latency, and I wouldn't have any problem if the door took a couple of seconds to unlock. But maybe I'm misunderstanding the problem latency causes?
That said, we have a couple of international beta testers who seem to have a good experience, so I think that we will reevaluate this soon.
edit: One international issue that has occured to me is the cost of texting a foreign number. Do you have any idea of how many users you'd want to have from a country in order to get a number that's local to them? (And/or is your SMS provider unable to do that?)
I think that 4-5 customers using our text message feature would be sufficient for us to consider internationalizing SMS, assuming Tropo support in that country.
jeff at twilio
Why not have the phone talk to the lock through the local wifi? Or put a wifi/bluetooth radio right in the lock? That should be more dependable and faster. Is that what you are talking about here?
"if you would like to access Lockitron only via your local network, then we welcome you to flash your base-station with a new image that gives you full access to develop as you see fit (coming soon)"
Or, you could communicate via QR code on the screen, using a camera in the door (that doubles as a remote peephole).
Or, you could encode the data as high-frequency sound and use the speaker/mic for two-way comm.
There are all sorts of possibilities that beat going over the internet.
The easy way to do this was susceptible to a number of different attacks so we disabled it. The hard way is being sorted out.
>>Is that what you are talking about here?
Sort of. If you buy the equipment, it's yours to hack...this includes expanding functionality to support eccentric authentication mechanisms. I'll post some stuff to our blog in the coming weeks to give you an idea.
Current users who encounter this usually find some way to unlock their door for their guests after a phone call, leaving keys inside. The prevalence of affordable prepaid phones is helping to alleviate this issue.
Kwikset also sells an iphone enabled lock, but an extremely cursory search didn't turn up a patent for them.
I wish them the best, but I'm having trouble coming up with a compelling argument to buy from them instead of buying what appear to be more mature, fully-featured products, backed by major lock manufacturers that are pretty well guaranteed not to go away in a year or two.
> main advantage [...] is that everything is in the cloud (your data is encrypted).
What? Someone is trying to feed me buzzword soup again.
I fail to see any advantage in having my front door "keys" stored in the "cloud".
Lockitron could chose to release their hardware with that already done, so it plugs into the router and is ready to go. In that case, there are no benefits of the cloud, and the downside that it adds an extra possible point of failure. An example that would fit your comment, but not your theory, better is "you probably don't run your own router control panel web server". How many routers want you to control them through their manufacturer's remote servers, rather than just having an HTTP server built in? And is that in some way as time-consuming as grinding your own flour or making your own furniture?
Sure, as it stands right now, you might not be able to buy a Lockitron device and run it yourself quite as easily as using their servers. But this chain of comments isn't discussing "which choice should buyers make", it's "is their use of buzz words justified when they say 'main advantage [...] is that everything is in the cloud'", and frankly I don't think that's an advantage over a system where all devices run their own servers.
They may not be benefits that you want, but they're the benefits that Lockitron are stressing.
(Personally, I'm happy with a key and, FWIW, my parents don't run their own control panel on their Vodafone local cell-network box - they call up the service people and they access the box remotely. So I can happily agree with your comparison too, if you like.)
I'd much rather have a system where the lock uses an NFC sensor and a CPU, and it works with phones that have NFC. Yes, you wouldn't be able to do remote revocation (you'd have to be standing in front of the lock to send an updated CRL), but it would be a lot more secure, and it avoids dependence on a central server.
I would be a lot happier with a single RFID tag per user (globally; it could be your phone with NFC, or a $0.05 tag) which could be remotely added or removed from the ACL on doors (use zigbee or even a 3g chipset built into the door; it only updates infrequently).
That way you don't need to pull your phone out in a dark alley and hit a button to unlock the door, and if your Internet connection is down (or power is out), the door can still unlock.
You could hack this up with the Schlage locksets and new firmware.
I guess it's a question of feature prioritization: no keys at all but a clunkier UX with less features, or a single RFID tag with lots of other benefits.
Edit: Legic is Austrian, not German. Fixed.
Edit 2: I was obsessed with this topic in '06-07 as the RFID startup I worked for struggled to maintain relevance as each use case for RFID proved pathetic ROIs vs existing solutions. I left when it was clear NFC/ payments was the only viable strategy and the startup was unwilling to drop the other verticals and pursue NFC (which is only now about to become viable).
I like the hacker aesthetic of lockitron, but want the robustness of the pro stuff too. Although if they do NFC tag reads in the lockset, it wouldn't be too hard to work as a simple internet-programmable RFID lock.
EDIT: The hope with NFC is that the phone can become a passive (non-power requiring) tag that can be read without internal power. As well, the hope is that it can read tags as well, though they are often referring to ISO 15693 and ISO 14443 (These are considered RFID standards) tags as far as readability (don't even get me started on ISO 14443A vs ISO14443B....Ugh).
The big issue is, of course, hardware development cost in getting active NFC into the locksets. Some of the high end hotel & commercial locksets from Assa and Schlage are adding NFC capabilities, but I suspect the software is plagued by the same, traditional problems.
They use the iClass, which is the new HID thing.
Once I get a home/office set up with a hardware lab later this month, I'm going to try to see if I can build something user-powered vs. battery which does this kind of thing (similar to how the Mas-Hamilton or Kaba-Mas X09 works) and speaks to iClass.
Self powered by the user moving the handle.
I was hoping for something a bit more discreet on the outside of the door like the Lockitron, and uses FeliCa or MIFARE cards.
What we want is reliable software that we can own, run locally, integrate into our existing systems, and maintain in the event of failure.
This already happened with PBXes; next, it should happen with access control, and then with building management (HVAC; imagine if logging into your workstation allowed you to have programmed lighting/heating controls for your work area happen automatically; especially useful if you work at night or on weekends in a big office)
On the other hand the little RFIDs are absolutely awesome to open doors with, try to use them instead (they are cheap enough that it doesn't matter).
You can, however, argue that taking out your phone, launching the app, and clicking a button is as an aggregate action more involved than just inserting and rotating a key. I think the real benefits become apparent when you realize all the stuff this enables you to do: your spouse/friends no longer get locked out, you never have to do the "did I lock it or not?" dance, and if they provide an API, you can sync a lot of stuff when your door opens, like turn on appliances, trigger a network setting, boot your computer, text your friends, anything really.
As for not locking the door, that is definitely a problem (as is, as I have also done, unlocking the door and leaving the keys in it) but I have never really been in doubt that I locked the door, even if I hadn't.
This isn't disruptive to household locks, but to the high ticket price door entry systems.
eg: using keyfobs = a) regularly lost, b) regularly forgotten, c) small expense every time you give to people, d) never get them back.
If the makers get it to work, I'd be happy for them, but my estimation is that it's going to be dead in a couple of years.
There are numerous problems with the market, that IMHO, Lockitron is attacking (which is not the residential market)
Why wouldn't ever office to lease use this over elaborate and expensive key entry systems?
We really, really don't need mobile phone based key unlock systems. I een considered building one for our home, but diacarded the idea due to the user experience complexity of having to use my phone instead of a simple key (but still carrying a key in case of failure).
As for Airbnb users, all you need is a programmable keypad (or an RFID entry system.)
This is a solved problem.
I would love this to replace my Volvo key. It's as big as the iPhone (kidding - but, it is big)
And from their website: "starting at $295 with no monthly fees for our basic service."
Would it unlock the door if I captured packets sent by the phone, then replayed them later? (Would that be difficult to do? I've never done it.)
The short answer is no. The long answer depends on how many packets you capture. See also: http://www.mozilla.org/projects/security/pki/nss/ssl/draft02... (Section D.3)
We've gone to great lengths to ensure any additions are pareto-secure.
I thought enough people knew by this time that storing all your passwords in plaintext file on desktop is insecure. Why do you even need a phone if you have a key somewhere on the property.
Nobody's going to find your emergency spare key if it's left in a non-obvious place; there are no rings of thieves with metal detectors scouring half acre properties.
Then I actually thought about unlocking my door with my phone. This is a great idea.
I'd much have a 4096-bit public key, than a flimsy piece of metal.
Can you tell us about the architecture? What kind of wireless link do you use? Does the lock poll the base station? How do you traverse the home firewall? Do you poll continuously?
Depends on the batteries...a 4 pack of name brand alkaline's from Target should get you between 10,000 and 18,000 cycles or about 1-2 years. I haven't tested with some of the crazier 22,000mAH ones one can get through Industrial resellers
>>What kind of wireless link do you use?
For the residential units, the server talks to the door lock using the same protocols found in car fobs.
For the commercial systems, we use electrical strikes. There is no wireless communication. We manually trip a relay.
>>Does the lock poll the base station?
Receive only.
>>How do you traverse the home firewall?
Encrypted Tunnels
>>Do you poll continuously?
Push
How did you come out with 4 different locks at once? Did you partner with an existing lock manufacturer?
You know you have to release an API.