Lockitron Announces the $99 Bolt, a Deadbolt You Can Unlock with Your Phone
techcrunch.com
techcrunch.com
Their app was the most buggy piece of Android software I've ever had the privilege of using, which is pretty amazing for an app that consists of one single button. It was essentially a webview on the lockitron website, and it would often just display raw-html error messages instead of the lock/unlock button.
The sheer amateurism of this "company" blows my mind. I wouldn't touch this new product with a ten foot pole.
Their site still says "Any smartphone can control Lockitron through our mobile website." What could possibly go wrong with a website that can unlock thousands of doors?
Do they offer "lawful access" to cops? Do you get told when that happens?
Agree on "sheer amateurism". This is version 2 of their product, they've been in business for a while, and they're only taking "pre-orders".
No mechanical key and no emergency battery terminal? Better have another door.
Edit: also I love you guys. You've done a great job keeping people up to date, handling support requests (my emails get answered in hours). I think you'll get there. Just frustrated with the product.
We pinged the Android BLE folks and only ever received crickets on how to resolve these issues. We're more hopefully based on what we're seeing with 4.4 and 5 but without a full library of handsets the onus of testing which OS/device mix "works" has fallen on our users up until now.
Does anyone know the reality of how well these work?
I wonder what the behaviour would be if I hooked a car battery up to the exterior lock... not a concern with the previous, electrically disconnected from the exterior, model.
Oh, and how well it fares when rain gets in it.
Also with the car battery example, where are you hooking up what? Electricity follows the path of least resistance. If both jumpers are connected to the outside of the metal deadbolt, you're not going to affect the interior. You would need one jumper on either side of the door to do what I think you have in mind.
This subtlety is what allows one to do something neat like this: https://www.youtube.com/watch?v=fPoomwdNZeY - on their build log you can see the musician does accidentally hurt himself from time to time when bits of his chain-mail don't make for complete coverage but he never goes into cardiac arrest. The current allows goes for the shortest, least resistant path to ground.
A similar effect is also what determines survival rates in lighting strikes. If the current passes through the brain it can arrest breathing, or through the heart and it can cause arrhythmia. If it just passes through a smaller area like a finger it can do more local damage but you'll survive. This is despite your body being 70% water or the equivalent of 'the same wire.'
If you wanted to "shock" Lockitron's motor you would need to ensure the motor is in the current path - this is pretty difficult as it's isolated in a plastic container with only two wires grounded it with the pcb, itself mounted in plastic.
(I'm not recommending those activities, just pointing out that the car battery is pretty hypothetical)
We'll be offering a tapered latch which helps a little bit, however, using it with an out of alignment door is non-ideal as it will wear down the batteries faster.
From the article. Particularly useful for: AirBnB hosts, people with roommates, friends/family visiting, etc.
The key was encrypted based on a username and password and I could revoke it at will. It filled a need for the time he stayed at my place and worked great.
Or you could have visited the locksmith (or your local hardware store with a key department) and gotten 1 or more spares in minutes.
If it was my mom, sure then I would have had to do the locksmith route.
In addition to the other use cases that folks have replied: You are young now, but you will find there are older people whose hands do not work quite so well. Keys, bottles, and a host of other items that you take for granted with well-working hands become serious obstacles to daily living.
[I should add that arthritis can hit even young people.]
If you don't understand the truth of that statement for some people, then consider yourself lucky.
If you were to design a new access system today from scratch, would you set it up so that A) you give everyone the same 2 character password B) you don't give anyone a username and C) anyone can give anyone else admin credentials with no authentication?
Probably not, but this is the way regular house keys work. Lockitron represents a step in fixing that. Keys worked fine in the 20th century when matter was difficult to work with. This won't be the case for the 21st century.
False security? In what way? False as in they don't do anything? Or false in that they give you a false sense of security?
Deadbolts prevent the most casual of crime and crime of opportunity. Which I would argue is probably the most prevalent type of crime.
works just fine there.
Also, keep in mind that Lockitron is obviously shooting for the consumer market, where concerns about sharing keys are basically non-existent. Commercial users who actually have to frequently deal with key revocations have been using RFID and other per-user access management technologies for ages.
My driveway is four cars deep and two wide, so my various housemates all have to make a copy of their key available so we can move any cars blocking us in. If we could just generate a sub-key, that'd be much more convenient.
Similarly, how about the ability to easily give a temporary house key to your visiting friends/family without having to have n spare keys sitting around? (Right now we have a re-programmable keypad, but if we could generate temporary subkeys without either giving out the master code or programming in a subcode, that'd be ideal.)
For example, you can remotely grant 2 hours of access to a tradesman to enter your property and fix something.
You can grant access to realtors to enter your property that is for sale, and you can track how many times they were there and how much time they spent on each visit.
You can grant the cleaning person access between 9am and 1pm on Wednesdays.
You can get into your house with any BLE-enabled device. Even if you lose your phone, you could borrow the neighbor's phone, run the appropriate app, enter the correct PIN, and gain entry. Then give them back their phone and they have no more access to your home than they did before you used it.
Of course, you can argue - a physical key or a keycard doesn't require batteries. But, a keycard can be erased or scrambled or lost. Then you need to quickly reprogram the lock so whoever finds it can't use it. Impossible with a traditional lock, and varying degrees of difficulty with a keycard system.
Now I can experience a much bigger problem if I'm mugged again.
It's helpful for friends, dog-walkers, etc. Also, no keys to misplace! (I rarely drive.)
However, I use a simple PIN-code lock, not a phone-based lock. I'm not sure the phone system is worth the extra overhead for me.
I can't wait until I can ditch the wallet too...
Edit: I've had the Schlage keypad locks for about 3 years now without any problems. I haven't even had to replace a battery yet.
I used to work in a factory that had a reasonable quality push button mechanical lock in combination with insurance grade cylinder lock on a sturdy door. That cylinder lock was sometimes left "on the latch" when people were working there.
One night (they worked night shifts) a guy got access by brute-forcing the pin-combination lock. It took him (there was CCTV) about 7 minutes to get in.
You can use longer codes, order matters, and they throttle failed passcode attempts to prevent brute-force attacks.
What does a battery-operated keypad lock do better than a mechanical one? EDIT: Or were you being sarcastic?
That's a lot of startups up there. A lot
Sometimes you see job openings and you read their business model and you think "really?!"
What do you not understand?
Before this lock, my wife would leave the front door unlocked in the morning until the cleaners showed up hours and hours later. I'm not a fan of having my house unlocked, and I wasn't really interested in giving the cleaners a key that they could use anytime they wanted.
What is my alternative other than having my house sit unlocked until my wife gets home in the evening?
If the founders of Lockitron think that I will be fooled again by a new product, they're sorely mistaken. I'd rather support a lock that has been out in the field for longer with a company that has proven they can deliver a real product, like the August lock for sale at Apple stores.
With the original Lockitron, a renter could just install it wherever they were currently staying. With the Bolt, the renter has to get permission to install a new deadbolt and has to get a new key pattern each time.
this:https://www.kickstarter.com/help/faq/kickstarter+basics#faq_...
and this: https://www.kickstarter.com/help/faq/kickstarter+basics#faq_...
all of which seem to pretty clearly say you might not get what you think you paid for.
There's a bunch of soft language, but it ends with If they’re unable to satisfy the terms of this agreement, they may be subject to legal action by backers.
But as davefp already pointed out, Kickstarter isn't relevant here.
I'm not interested in this product at the moment because of how my house is set up, but as a security and privacy-conscious person, I'd much prefer something that requires zero internet connection, even if that means using a version that has fewer features.
A $15 dollar SDR wouldn't do it either. Most electronic locks aren't susceptible to replay attacks unless they're using KeeLoq and it's out of range. You might be able to do another kind of attack with three Ubertooth One's though. We got something like this working in our lab and I talked about it at DefCon 21 in the Wireless Village track - the basic patch is to use corroborate with other data (geo, time, etc.)
You know those people that have 20 different OSX extensions all running in the upper right ?
That's what I think of when I think of having 50 different networked computers all chattering away on Internet/bluetooth/wifi/zigbee/whatever throughout every room of my house.
Eventually I had the lock working fine and all I had to do was remember to swap out the batteries every month or so. Unfortunately, the thumb turn on my lock stripped and I have to replace the deadbolt now. I'm not sure if this was Lockitron's fault or that I didn't tighten in the thumb turn retention bolt enough after I install their door adapter.
I would consider either the classic Lockitron or the Bolt, even after this. I remember when I was at the DefCon Wifi Village and someone from Lockitron offered hackers $1000 to turn the bolt remotely; pretty ballsy!
Between getting burned on this and the SOAP router, I will never back a hardware based Kickstrarter. I figure it's better to let someone else pay for the privilege to get the alpha version and struggle with it until the bugs are worked out.
Honestly, doors and locks do not need 'disruption.' Many many other things could use this treatment and the hours put in.
Aside: We decided the pricing sweet spot was 40, as that's about double the cost of a real lock. Also, this actually passes one of the Valley tests, that the company help get you laid (Fb, Google, Uber, etc all do this and the lock here does too as it is 'James Bond-y')
A different use case: over New Year's I was on a trip to Germany, working with some friends in a hackerspace there. Since it was a private space (and open at all hours), the door was not kept unlocked, but a relatively large number of people had access to it. The hackerspace could have handed out keys, or used some more complicated keycard system, but instead they used a Lockitron-like device (not sure which one; it being a hackerspace, they were managing the lock over SSH!). This way they could give anyone (potentially temporary) access without complicated logistics.
First world solutions.
Fool me once, shame on you;
fool me twice, shame on me.Shipping delays for kickstarted products are not a new or unexepcted thing nowadays.
A year and a half later and I still don't have it. Communication has been pretty bad, with many blown dates, infrequent messages, and a dashboard that often showed "ship by" dates that were months in the past. Now they're switching my order to a completely different product that I'm not sure I want.
Pre-orders have risk too, but not of even remotely the same magnitude. This behavior might be reasonable for a crowdfunded product, but not for one where the product is supposedly done and shipping imminently.
If you're that worried about your nanny having a key, maybe you should stop trusting that person. A door lock only keeps out the honest anyway. Unless you live in a bunker.
I actually had this issue once. I solved it very easily, I put the key in an envelop and mailed it.
With all due respect, but considering all the issues with the first Lockitron (which apparently hasn't shipped to all backers yet) I'd have serious considerations trusting this product.
If you couldn't ship a product that would rotate a motor, how should we trust you now to actually have a reliable physical lock and keyway as well!?
Previously you complained Lockitron was too expensive[1], now you complain it's too cheap?
I'm not complaining about the price. I'm concerned that now there are two points of failure and that not only there is the risk of the electronics not working and randomly stopping (based on your track record of poor product development) but people are putting an inferior mechanical deadbolt on their door which can be broken into easier and possibly fail more than a regular $20 deadbolt from Home Depot.
I would think as a company with such a checkered past you would be more humble instead of attacking your potential user base.
Some locksmiths are trying to revoke the Grade 1 rating on those Kwiksets you mentioned because of the Smartkey vulnerability. (Grade 1 requires a certain threshold of "pick proof" and "drill proof" which they argue fails to hold up.) Bolt does not have that same vuln. but you can see what it looks like here: https://www.youtube.com/watch?v=H1mmjVvMsGs
It has to do with how easily one can drill into it, or pry it off with a crowbar, or pick it etc.
The spec is only a few dollars, you might want to buy it from BHMA.
The point is Grade 1 ANSI rating is important and offers security against intrusion. You're offering everyone a Grade 2 bolt and from your response seem to be even confused about the difference between the two.
Your deadbolt as you already said is Grade 2. So now you're saying is Grade 1??!
It wasn't about the retail price.
I got tired of the delays and bought a Kevo; doesn't fully satisfy all the things I wanted from Lockitron but hey, I can buy it at the local Home Depot today.
Also, what happens if your phone is dead? This is a serious issue that's not mentioned anywhere on the website. It would be nice if there was a physical key backup.
If you report to your insurance company you have a deadbolt and then your house gets broken into. (Perhaps due to a flaw in the software?) Now your insurance company finds out you have a Bluetooth dohicky on your door rather than a physically locked deadlock lock. Your insurance now won't pay up.
I'm not sure how much those Proxcards that every business in the world uses costs, but they sure are time tested and convenient. Probably expensive though. I believe they are RFID.
Don't put this on your rental property either until you consult your local laws regarding requirements for doors and locks for rentals to see if this meets the requirements.
I installed a proximity card system a few jobs ago, and each IP enabled reader from HID (http://www.hidglobal.com/products/readers/iclass/rw400) was about $550 for both the external RFID interface and then the internal in-wall control unit (that used POE Ethernet to connect to the network). The cost per card is fairly trivial.
> Don't put this on your rental property either until you consult your local laws regarding requirements for doors and locks for rentals to see if this meets the requirements.
There are no code issues with this as long as if power fails, internal occupants can still exit the building (fire code).
How do you know? Landlord tenant laws are incredibly local (you can't possibly know all of them for all locales in the world) and can be very specific and probably haven't gotten caught up to new technology. My town (just the town!) has a 30+ page document on what a landlord has to provide a tenant written in very VERY specific terms. Thats not even considering state laws. And federal.
I admit there may be some batshit insane locale that prohibits RFID access control, but its not a concern for almost everyone else.
Disclaimer: I have been a landlord previously, in several Illinois cities.
I deal with extremely detailed regulations and policy on a regular basis (I work in a very regulated field) and we MUST do things that are very specific all the time. We need to follow the letter of the law (not just the intention). Looking up "hey, can I do this?" is part of my job, so I'm ALWAYS thinking that way. Policy is usually one step back from new technology. You may have laws and regulation that details specific technologies that may be used in different applications.
I work for a company that makes many types of locks and currently is developing NFC and BLE solutions.
The fact is, any kind of lock is vulnerable to a determined and skillful attacker. There are BLE locks that "phone home" to check a password before they'll open; there are NFC locks that are actuated by RF-powered NFC chips that are almost un-crackable except by the Chinese Army or similar organizations.
Then there are conventional badges, key cards and physical keys in universal use, that are rather easily cracked or copied.
Vulnerabilities are already factored into insurance rates. The advantage of a connected BLE or NFC entry system is that it can require a remote login before the door will open. For example, enter the BLE region, the app pops up and prompts you for a PIN, then actuates the unlocking mechanism using an encrypted protocol. No technology is perfectly secure, but these technologies do present great possibilities for improving on current approaches to access control.
No. It was a hypothetical situation to CONSIDER. Everyone's situation is different. You should consider what insurance ramifications would be and make sure you are reporting accurately to your insurance company, because inaccuracies can potentially have bad consequences. Unknowingly. Unlikely, but worth looking into first. Check the wording on your policy, it may list things that are disallowed. It may have a different category for electronic locks (and you may even get a discount!) Not saying this is insecure or a physical lock is better, but its use may be excluded in your policy for whatever stupid or non stupid reason. Check it. Thats all I'm saying.
You read my post wrong.
That's why he asked if you were in the lock or insurance industry. Someone with experience in these matters would be qualified to speculate on the importance of taking this into consideration. Without that expertise, rhetoric like this feels like advice to always wear a helmet in case of flying debris. Well-meaning, but unrealistic.
It isn't "worst-first" thinking, it is "ok, I'm replacing a critical component, does this replacement meet all the the required specifications of the thing I am replacing it with? What are the potential consequences?" Which takes almost no time, its just a question that needs to be answered in my field.
Perhaps my work in such a regulated environment has taught me to think that way.
I have family in the insurance business, and they've talked about having to deny claims for various (kinda silly in a way) reasons. And getting death threats because of it...
You can't say your homeowners insurance won't cover you because your house burned down because you were cooking and you aren't a world-class chef.
My insurance covers me in the case of theft. When I applied for my policy the adjuster asked me questions about my physical security. Do I have a deadbolt? Security system? Things like that. These variables (along with others, crime rate of my neighborhood, for example) were plugged in and I was given a policy with a premium tailored to my risk. If I lie about my risk to get a lower premium, then if I make a claim, then I won't be covered.
Consider a 100% purely hypothetical situation where I told my insurance company I have a deadbolt on my door. They issue me a policy based on that information. This policy has language in it that defines what a deadbolt is. I then replace my deadbolt with something that doesn't fit the language of my policy. I make a claim, and an insurance adjuster comes to my house. They notice that I was using a tool to secure my door that didn't fit with my policy language. Now I won't be covered because I didn't follow the policy.
Of course that's entirely hypothetical. Maybe (probably?) not even likely. But since it takes all of 5 minutes to verify if the new lock you are installing is compatible with your insurance policy, it would be braindead to not check.
Just something to consider...
Using a bluetooth deadbolt can be compared to using a lock with medeco biaxial pins. The insurance company finds out that medeco biaxial pins are easier to break into with specialized tools and they deny your claim.
This is a moot point, so I would suggest an easier way to break in to your home that doesn't require advanced tech skills: use a rock to break a window ;)
Neglect is defined as "neglect of an insured to use all reasonable means to save and preserve property at and after the time of loss."
My insurance adjuster also asked me specifically about deadbolts.
Nope, they shall see none of my money. I'll also pass the word around that their stuff doesn't work.