The sound of the bolt sliding back on your front door when you tap your phone is strangely comforting. You won’t have to search for the keys or worry about leaving it unlocked. You only need to tap once to gain access. This concept was effectively marketed by smart locks, and millions of people both literally and figuratively adopted it. However, the more time goes by and security researchers dissect these systems, the more difficult it is to ignore a silent, unsettling reality that is right at the front door.
Digital access systems and smart locks are fundamentally little computers that are linked to the internet. They can also be compromised, just like any other internet-connected computer. That isn’t speculative. Security experts have repeatedly shown that all it takes for an attacker to gain remote access to a front door is a compromised smartphone app or a weak home Wi-Fi network. There was only one threat model for the physical key: someone stealing it. There are dozens in the digital key.
The factory is where the issue, somewhat embarrassingly, begins. A common joke in cybersecurity circles is that many smart devices, including locks, still come with default credentials that are so predictable. Passwords like “Admin.” and “1234.” are so obvious that automated tools systematically search the internet for them on a scale that is impossible for a human attacker to handle on their own.
If a homeowner purchases a smart lock, installs it over the weekend, and never modifies the default credentials, they have unintentionally left something that resembles a copy of their house key on the front porch. Cybercriminals don’t need to be cunning when the defaults do the work for them, according to Thomas Hyslip, an assistant professor at the University of South Florida who studies cybercrime.

Then there is the issue with the app. Smart locks are not standalone devices. They communicate with cloud-based systems, which communicate with mobile applications, which communicate with your wireless network. Each link in that chain has the potential to break. Since phones are frequently lost, stolen, and hacked, if someone manages to breach your smartphone, they will inherit the access you had. Your front door is part of that. One security consultant gave a straightforward explanation of the situation: your lock will follow instructions if someone gains access to your phone or Wi-Fi. It is unable to distinguish between you and the person with your credentials.
The devices are made to feel seamless, so it’s possible that most people haven’t really considered this sequence of events—not because they’re irresponsible. The product is that seamlessness. Friction has been eliminated through engineering. The picture becomes a little more difficult to look at comfortably as soon as you consider what’s really going on behind that frictionless tap: the data traveling between your phone, a cloud server somewhere, and a motor in your door.
The extent of exposure is what really distinguishes digital keys from the threats that were already present. Conventional locks are a local issue. Anyone with the appropriate credentials can remotely access a compromised smart lock from any location.
The 2016 Mirai botnet attack demonstrated the extent to which this type of activity can spread: hundreds of thousands of compromised home devices were taken over to take part in attacks on international infrastructure rather than to spy on specific families. In a very real sense, the security of your smart lock is no longer solely your concern.
All of this does not imply that smart locks are useless or that people should return to using keys. Some of these systems are truly reliable; they come from reliable manufacturers and have robust encryption and regular software updates. The majority of consumers are unable to distinguish those products from the packaging, and there is a huge gap between them and the less expensive options that are gaining shelf space online. One of the more beneficial things a homeowner can do is to find out if a manufacturer truly releases firmware updates on a regular basis before making a purchase. Putting smart devices on a network apart from laptops and phones is also a good idea. Turning on two-factor authentication, which is accessible on the majority of platforms but is surprisingly uncommon, is also a good idea.
Spending time with this content gives one the impression that the industry has outpaced the consumer. The marketing was polished, the devices were delivered quickly, but the security discourse was years behind. Governments in Australia, the UK, and other countries are starting to require baseline security standards for connected devices, which is gradually closing that gap. However, the devices that are currently installed in tens of millions of homes are not waiting for policy to catch up, and regulation is moving slowly.
Life was supposed to be easier with the smart home. Generally speaking, it has. However, easy and safe are not synonymous. And that difference still matters a lot, somewhere between the click of a bolt and the tap of a phone.
