6 ms·
Lockitron (YC S09) Lets You Unlock Your Door With Your Phone
- aberman 15y agoI live with the founders so I've had Lockitron for about a year. in my unbiased opinion: it's absolutely amazing especially if you have a lot of house guests (hacker sleepovers).
- busted 15y agoI'd be interested to hear what kind of backups the founders have. My biggest worry would be what do I do if something happens to my phone while I'm out: broken, mugged, or even just the battery died. It would suck if on top of that I couldn't get into my own house. Do you guys still take your keys with you, or keep a spare around?
- kapilkale 15y agoI bought one for my father, who tends to be OCD about locked doors, and he absolutely loves it.
- Devilboy 15y agoWill this also SMS me whenever someone opens my door? I think I want one.
- ccamrobertson 15y agoWe have logging, but alerts are a high priority! If you buy one I will build it for you :)
- kordless 15y agoDid someone say logs?
- Steko 15y agoI can see micromanaging parents more interested in this then the keyless entry aspect.
- asmithmd1 15y agoHow long do the batteries in the lock last? Can you tell us about the architecture? What kind of wireless link do you use? Does the lock poll the base station? How do you traverse the home firewall? Do you poll continuously?
- paulgerhardt 15y ago>>How long do the batteries in the lock last? Depends on the batteries...a 4 pack of name brand alkaline's from Target should get you between 10,000 and 18,000 cycles or about 1-2 years. I haven't tested with some of the crazier 22,000mAH ones one can get through Industrial resellers >>What kind of wireless link do you use? For the residential units, the server talks to the door lock using the same protocols found in car fobs. For the commercial systems, we use electrical strikes. There is no wireless communication. We manually trip a relay. >>Does the lock poll the base station? Receive only. >>How do you traverse the home firewall? Encrypted Tunnels >>Do you poll continuously? Push
- asmithmd1 15y agoThanks for the info - but I want more info, where is your blog? How did you come out with 4 different locks at once? Did you partner with an existing lock manufacturer? You know you have to release an API.
- paulgerhardt 15y agoWe've only just come out of stealth mode after nearly two years of quiet work. We'll be posting some more stuff in the coming days...
- tomjen3 15y agoHmm this seems to me even more annoying than keys - why phone is bigger and more difficult to get out of my pocket. On the other hand the little RFIDs are absolutely awesome to open doors with, try to use them instead (they are cheap enough that it doesn't matter).
- yan 15y agoI'm not looking at it that way. Keys are just another thing to keep in your pocket, but your phone is always with you. The way I carry stuff in my pockets, my phone is always more readily available than my keys so taking it out is a natural motion. You can, however, argue that taking out your phone, launching the app, and clicking a button is as an aggregate action more involved than just inserting and rotating a key. I think the real benefits become apparent when you realize all the stuff this enables you to do: your spouse/friends no longer get locked out, you never have to do the "did I lock it or not?" dance, and if they provide an API, you can sync a lot of stuff when your door opens, like turn on appliances, trigger a network setting, boot your computer, text your friends, anything really.
- tomjen3 15y agoYeah but all of that could be done from a phone if the house was locked with an RFID tag (and they are cheap enough that you can hand them out more or less like candy, since they are about that price). As for not locking the door, that is definitely a problem (as is, as I have also done, unlocking the door and leaving the keys in it) but I have never really been in doubt that I locked the door, even if I hadn't.
- picasso81 15y agoThis app is brilliant! Congrats guys.
- corin_ 15y agoI love the idea, but I don't think I could trust myself with it. Generally my phone will still have a healthy chunk of battery left at the end of the day, but fairly often, if I'm out of town for a day for meetings or whatever, by the time I'm back home I will have spent so much time on calls that it will have completely drained my battery. One feature I'd love to see is connecting it with the doorbell, then I would forget about my battery worries and go straight for it. Would come in occasional use for if someone you're happy to let in arrives while you are out, but would also be great for day-to-day use. They press the buzzer, you get a phone call to talk to them followed by the option to let them in or not. (Where I live right now, my office is two floors up, it's pretty rare that I can hear anyone at the door.) edit: The FAQ page is a bit vague about international orders due to "latency issues", any chance of some expansion on that? To my mind, a long distance (say, UK to California) is adding less than a second of latency, and I wouldn't have any problem if the door took a couple of seconds to unlock. But maybe I'm misunderstanding the problem latency causes?
- ccamrobertson 15y agoYou hit it on the head with the latency - although it only adds second or two at max, we want to make sure that we can keep it as short as possible. That said, we have a couple of international beta testers who seem to have a good experience, so I think that we will reevaluate this soon.
- corin_ 15y agoPersonally I don't think I'd care if it was a 10 second delay. (It often takes me that long to find the right key to open the door.) edit: One international issue that has occured to me is the cost of texting a foreign number. Do you have any idea of how many users you'd want to have from a country in order to get a number that's local to them? (And/or is your SMS provider unable to do that?)
- ccamrobertson 15y agoWe currently use Twilio, but they removed their beta international SMS support a while ago. That said, Tropo has international numbers in some countries. I think that 4-5 customers using our text message feature would be sufficient for us to consider internationalizing SMS, assuming Tropo support in that country.
- tealtan 15y agoReally cool idea, but I think any system like this needs to have a fail-safe option, for when your phone runs out of batteries.
- armored 15y agoUhh, it uses a standard key as a failsafe.
- mdolon 15y agoWhat's the point of unlocking with my phone if I have to carry my key around in case my battery dies?
- dangrossman 15y agoHide the key on the property or in your car. You don't have to carry it around with you.
- xentronium 15y ago> Hide the key on the property or in your car. I thought enough people knew by this time that storing all your passwords in plaintext file on desktop is insecure. Why do you even need a phone if you have a key somewhere on the property.
- dangrossman 15y agoYou need a phone to make and receive phone calls, among other things. That's why you already have it. You don't need the key for anything but opening your front door. The point of this device is to obviate the need to carry that key all day for that single moment it's needed. Nobody's going to find your emergency spare key if it's left in a non-obvious place; there are no rings of thieves with metal detectors scouring half acre properties.
- anateus 15y agoReally killer for things like providing access to Airbnb guests without having to be there.
- proee 15y agoThey should add a keypad as well for people without a phone. Keypad code gets set automatically for each Airbnb guest and expires automatically. This of course requies the Airbnb space to have an internet connection.
- dandelany 15y agoHow many Airbnb users do you expect to not own a mobile phone?
- quadhome 15y agoI often don't have a mobile or mobile number when I enter a foreign country.
- ccamrobertson 15y agoWe don't have the perfect solution to this yet, but we've been mulling the idea of key code locks for a while. Current users who encounter this usually find some way to unlock their door for their guests after a phone call, leaving keys inside. The prevalence of affordable prepaid phones is helping to alleviate this issue.
- justincormack 15y agoI expect batteries to run out. You could have a usb port perhaps...
- bhickey 15y agoI used AirBnb in Paris and my mobile didn't work. The host was gracious enough to send someone around to find the confused looking foreigners when she couldn't reach me.
- rdl 15y agoThis is great (and would be nice if it did cars and worked with HID office keys, too). I would be a lot happier with a single RFID tag per user (globally; it could be your phone with NFC, or a $0.05 tag) which could be remotely added or removed from the ACL on doors (use zigbee or even a 3g chipset built into the door; it only updates infrequently). That way you don't need to pull your phone out in a dark alley and hit a button to unlock the door, and if your Internet connection is down (or power is out), the door can still unlock. You could hack this up with the Schlage locksets and new firmware. I guess it's a question of feature prioritization: no keys at all but a clunkier UX with less features, or a single RFID tag with lots of other benefits.
- 18pfsmt 15y agoAustrian RFID (ISO 14443) company Legic has had a deal with Schlage for a while. And Swedish lock company Assa Abloy ($B conglomerate) also owns HID (and its numerous subsidiaries), which pretty much dominates RFID-based access control, and has had a solution in place for at least 3 years that I know of. Edit: Legic is Austrian, not German. Fixed. Edit 2: I was obsessed with this topic in '06-07 as the RFID startup I worked for struggled to maintain relevance as each use case for RFID proved pathetic ROIs vs existing solutions. I left when it was clear NFC/ payments was the only viable strategy and the startup was unwilling to drop the other verticals and pursue NFC (which is only now about to become viable).
- rdl 15y agoYeah, the value is in having a decent API, easy self-install lockset for homes and small businesses; HID type stuff is almost always professionally installed, requires wiring to the door, etc. The legic/schlage system has really bad software, and the service is lame, too -- bad enough that I bought one and didn't install it on an exterior door. I like the hacker aesthetic of lockitron, but want the robustness of the pro stuff too. Although if they do NFC tag reads in the lockset, it wouldn't be too hard to work as a simple internet-programmable RFID lock.
- 18pfsmt 15y ago
- deleted 15y ago[deleted]
- darraghbuckley 15y agoWe use one at the office - couldn't be happier with it. Great product!
- suhail 15y ago<3 Lockitron
- zitterbewegung 15y agoAnyone think this is a bad idea? What if your phone becomes comprised or stolen? Then they have access to your house? Its easier to forge a bunch of bits than a key.
- proee 15y agoThen add a security code to get access to the app.
- e1ven 15y agoNot really.. Lock picking, particularly home-locks, isn't very hard at all. Many people attend Lock Picking competitions, and it is a somewhat popular geek-sport. I'd much have a 4096-bit public key, than a flimsy piece of metal. See Also: http://www.capricorn.org/~akira/home/lockpick/ http://www.capricorn.org/~akira/home/lockpick/
- code_duck 15y agoWhat if their servers are down when you come home at 1 am? Outages happen and this would be a pretty sensitive service to that.
- proee 15y agoThis is great feature for the fact that you could potentially lock ALL doors in your house at once. For people with 10k square foot house, this could save a lot of footwork before heading out to town.
- jessriedel 15y agoI like the idea, but I'm not paying a subscription fee for the doors to my house.
- palish 15y agoSo... What about security? Would it unlock the door if I captured packets sent by the phone, then replayed them later? (Would that be difficult to do? I've never done it.)
- naz 15y agoPresumably they use SSL, so no it isn't vulnerable to replay attacks.
- paulgerhardt 15y ago>>Would it unlock the door if I captured packets sent by the phone, then replayed them later? (Would that be difficult to do? I've never done it.) The short answer is no. The long answer depends on how many packets you capture. See also: http://www.mozilla.org/projects/security/pki/nss/ssl/draft02.html#D.3 http://www.mozilla.org/projects/security/pki/nss/ssl/draft02... (Section D.3) We've gone to great lengths to ensure any additions are pareto-secure.
- bsgamble 15y agoCan't wait to buy one of these!
- LogicX 15y agoAnyone know if there's a similar internet (wireless?) connected deadbolt with a keypad -- such that you can create multiple valid keycodes on a schedule, and receive logs back regarding accesses?
- apperoid 15y agoAFAIK Schlage offers this kind of service.
- whereareyou 15y agoWonderful gadget. Once the hardware evolves into something prettier I am all in! I am excited for a future when my phone, or just simply my presence, unlocks all my doors...especially my car door.
- snowmaker 15y agoThis the kind of idea that sounds so obvious in retrospect. Now that everyone carries around a phone at all times, bringing a key as well is just redundant. Can't wait to see this get adoption.
- ImperatorLunae 15y agoMy gut reaction was "this is useless." Then I actually thought about unlocking my door with my phone. This is a great idea.
- christonog 15y agoThis works if you need to give friends or family access, but what about taking it one step further by using a finger print scan + security PIN? Trying to fiddle with your phone from your pocket and opening an app or sending a text message can be just as cumbersome as looking for your keys.
- extension 15y agoNeat idea, but it seems to me that you absolutely must hide the backup key on your property for this to be safe. There are way too many points of failure between the phone and lock. Why not have the phone talk to the lock through the local wifi? Or put a wifi/bluetooth radio right in the lock? That should be more dependable and faster. Is that what you are talking about here? "if you would like to access Lockitron only via your local network, then we welcome you to flash your base-station with a new image that gives you full access to develop as you see fit (coming soon)" Or, you could communicate via QR code on the screen, using a camera in the door (that doubles as a remote peephole). Or, you could encode the data as high-frequency sound and use the speaker/mic for two-way comm. There are all sorts of possibilities that beat going over the internet.
- paulgerhardt 15y ago>>Why not have the phone talk to the lock through the local wifi? The easy way to do this was susceptible to a number of different attacks so we disabled it. The hard way is being sorted out. >>Is that what you are talking about here? Sort of. If you buy the equipment, it's yours to hack...this includes expanding functionality to support eccentric authentication mechanisms. I'll post some stuff to our blog in the coming weeks to give you an idea.
- foxfifi 15y agoThank u for your sharing,maybe you will like http://www.airmaxenfrance.com/chaussures-air-max-light-c-68.htm.Have http://www.airmaxenfrance.com/chaussures-air-max-light-c-68.... a nice day!
- xentronium 15y ago> While the Lockitron locks do accept traditional keys, the main advantage of using the same technology as found in car key fobs to open your front door is that everything is in the cloud (your data is encrypted). > main advantage [...] is that everything is in the cloud (your data is encrypted). What? Someone is trying to feed me buzzword soup again.
- codeup 15y agoBuzzword soup yes, but it's oversalted (once again). I fail to see any advantage in having my front door "keys" stored in the "cloud".
- nagrom 15y agoThe advantage is that (theoretically) you can't lose them, you can grant and revoke access permissions at will based on time limitations and you can share them very easily. See other comments on the thread about airbnb for example.
- corin_ 15y agoReally you could have that benefit without using remote servers at all, just run a local server at home. After all, if your home connection dies, your door can't be unlocked by 'the cloud' either.
- nagrom 15y agoThat's true - but you probably don't grind your own flour, service your own car, run your own bank or make your own furniture. Why run your own server?
- corin_ 15y agoAwful examples. Running your own server for this wouldn't have to mean learning to code your own firmware for their hardware, it wouldn't even have to mean being tech-savvy enough to install something like apache. Lockitron could chose to release their hardware with that already done, so it plugs into the router and is ready to go. In that case, there are no benefits of the cloud, and the downside that it adds an extra possible point of failure. An example that would fit your comment, but not your theory, better is "you probably don't run your own router control panel web server". How many routers want you to control them through their manufacturer's remote servers, rather than just having an HTTP server built in? And is that in some way as time-consuming as grinding your own flour or making your own furniture? Sure, as it stands right now, you might not be able to buy a Lockitron device and run it yourself quite as easily as using their servers. But this chain of comments isn't discussing "which choice should buyers make", it's "is their use of buzz words justified when they say 'main advantage [...] is that everything is in the cloud'", and frankly I don't think that's an advantage over a system where all devices run their own servers.
- maxklein 15y agoAnother idea that will fail based off the user interface. Keys are too slow. Opening the door with your phone is even slower. I prefer to carry a second faster key than have this in my pocket and then click slide, start the app, wait for it to connect, then open the door.
- pclark 15y agoYou are missing that this is not necessarily aimed at regular home owners. Imagine offices, rented accommodation or as a secondary lock for homes. Being able to offer and revoke keys over the air is huge. This isn't disruptive to household locks, but to the high ticket price door entry systems.
- maxklein 15y agoBut then why mobile? Why is it not just a web based app if it's meant to manage a large number of locks? Mobile is not a convenient interface, apart from things that need to be mobile.
- pclark 15y agoWhat other devices would be an appropriate replacement for a key other than a mobile phone? (or do you mean a mobile web app?) eg: using keyfobs = a) regularly lost, b) regularly forgotten, c) small expense every time you give to people, d) never get them back.
- maxklein 15y agoIt's still pointless. The current key-system is a low tech, simple system with few associated costs and no major pain points. It's also a system that is strongly in place already. The Lockitron is a complicated system with many moving parts that will break every now and then, and that has no clear target market, and it's more expensive than current systems. If the makers get it to work, I'd be happy for them, but my estimation is that it's going to be dead in a couple of years.
- tytso 15y agoI'm not that happy that the lock has to communicate with a central server. For one, that adds all sorts of dependencies (the internet, central service, etc. have to be up for the unlock command to work). For another, what if there is a security compromise of the central server? I'd much rather have a system where the lock uses an NFC sensor and a CPU, and it works with phones that have NFC. Yes, you wouldn't be able to do remote revocation (you'd have to be standing in front of the lock to send an updated CRL), but it would be a lot more secure, and it avoids dependence on a central server.
- kleiba 15y agoCool! Where could I inspect the source code for this?
- karlzt 15y agoanother good thing is that you don't have to make copies of physical keys.