5 ms·
Coming from an infosec background and having touched on physical security, just don't use a smart lock: - Best case, even with a responsible implementation, yo
by verandaguy_alt 8y ago
Coming from an infosec background and having touched on physical security, just don't use a smart lock:
- Best case, even with a responsible implementation, you're introducing more variables than are necessary into a supposedly secure system. If one of your dependencies fucks up, your lock is exploitable.
- Worst case, you have a typical IoT device, where the "S" stands for "security."
- In _either_ case, you're likely still going to include a physical lock mechanism for keys as a backup -- so you're basically just increasing the attack surface (significantly, I should add) by doing this.
Smart locks are currently high-risk appliances, and I'm fairly confident that most others with a security background will agree with me on that.
- Uberphallus 8y agoWhat would you do if you rent an apartment to several people per week? Because even "don't copy" keys can be copied.
- mynameisvlad 8y agoMost smart locks only replace the "back" part of the lock anyway, or augment the physical key slot to leave it as a backup, so, the point still stands that it only introduces new attack vectors. You'd still have the problem of someone being able to copy your "do not duplicate" key not to mention bumping/picking the lock, along with hacking the smart portion of the lock. In the end, it's your decision, but the OP's comment stands fully: all the same attack vectors still exist, along with a bunch of new ones at the expense of convenience.
- steve_musk 8y agoI the the idea was you wouldn’t have to give out the key to renters and could just give them passcode/phone access, so it actually would be removing an attack vector.
- dragonwriter 8y ago> You'd still have the problem of someone being able to copy your "do not duplicate" key Only if you distribute the “do not duplicate” key, but the whole point is to not do that.
- sitkack 8y agoUse a keypad controlled, reprogrammable door lock. No internet required, codes easily rotated. https://www.homedepot.com/b/Hardware-Door-Hardware-Door-Locks-Electronic-Door-Locks/N-5yc1vZc2bd https://www.homedepot.com/b/Hardware-Door-Hardware-Door-Lock...
- verandaguy_alt 8y agoIf you're comfortable using a totally (physical) keyless solution, try a hotel-style mag strip-based access card, or an NFC alternative like a ProxCard. AFAIK, most code-based locks include a physical lock cylinder as a backup.
- Klathmon 8y agoHaven't those been found time and time again to be trivially exploitable?
- verandaguy_alt 8y agoThat varies from brand to brand, but generally, yes. Given that it's happened to devices whose manufacturers have a long history of being part of large enterprise security mechanisms, flaws are still being found and actively exploited. While this isn't an indicator of the quality of newer brands specifically, I believe it's reflective of the state of the industry as a whole -- in that digital physical security as a whole is still immature and shouldn't be trusted to keep bad guys (determined adversaries) at bad.
- Klathmon 8y agoI feel that "digital physical security" might be limited, but it's still better or the same in most cases as regular old "physical security". A lock that can be bumped isn't very secure. A lock that can be bumped or it's code discovered via some kind of power-monitoring attack isn't any less secure. But one without a keyway that can be attacked via power-monitoring is more secure in my opinion. Everything is tradeoffs, and physical security is no different. Don't let perfect be the enemy of good here. If you are in the security industry, you should know that "bad" security that people will use is better than "good" security that people won't. If a "smart lock" means I forget to lock my door less, I can monitor and record those who go into my house, and I can get alerts if the door is opened via any method, I'd call that a win even if there were pretty significant vulnerabilities that allowed an attacker physically present to get in.
- reaperducer 8y agoIf you're going to run an amateur hotel, then try to do what the hotels do.
- drakenot 8y agoPhysical locks are trivially exploitable. I don't really see this as increasing the attack surface greatly when physical locks are so weak.
- setquk 8y agoAgree entirely. Look at the Brinks CompuSafe hack in 2015. Anything which increases the attack surface of a device reduces the security. In that case, a USB port. And that wasn't even made by the lowest bidding startup.
- Klathmon 8y agoBut bad security that people will actually use is always going to be better than good security that they won't. I know people that don't lock their doors because they don't want to deal with keys, or they forget to lock their doors all the time, or leave a key under a rock in front of their house. For them, even a fairly insecure "smartlock" will be an improvement if it means they will actually use it.
- setquk 8y agoYou can’t fix idiots. We already know that.
- Klathmon 8y agoIt's that kind of thinking that makes bad security. Time and time again it's been shown that if you design systems that are hard to correctly secure or make significant compromises in the name of "security", they end up being insecure because people just won't use them or will actively seek ways around them. You can't just handwave away issues like usability and pretend that you've designed the "perfect" system or something. If you design a good/secure keypad lock but it doesn't give people an easy way to let their family member in the house when they are away, they are just going to give out the code, leading to less security overall. If you design a secure keypad lock without a tumbler, the first time the batteries die and the user is locked out of their house they are going to replace it with something that won't lock them out. Usability needs to be a core aspect of secure engineering. And oftentimes a "technically less secure" option is better, because it's actually usable by normal people in most cases. A 5-point harness is safer than your average seatbelt, but we don't use them because forcing every car to have a 5-point harness would just end up with fewer people using them.
- deleted 8y ago[deleted]