Can smart door locks be hacked easily?

By huanggs
Approximately 23% of smart door locks worldwide have unpatched firmware flaws, according to the 2023 report published by CISA (Cybersecurity and Infrastructure Security Agency of the United States). Some low-end types can be broken in 30 seconds by means of Bluetooth protocol flaws, namely BLE-MITM man-in-the-middle attacks. For instance, at the DEF CON 2022 Hacker Conference, academics showed on-site the employment of a Raspberry PI tool costing just $50 to conduct a signal replay attack on a particular kind of smart door lock with a success unlock probability as high as 89%. With the price of a single device increasing by 15%–20%, this kind of attack usually depends on the default key of the device not being updated or weak encryption algorithms (such AES-128 not enabling dynamic keys), resulting in an attack cost of under $200; the defense cost has to rise to the integration of hardware-level security chips (such as SE security components). The security risks in the supply chain are also rather important. Due to an unencrypted API interface of a third-party cloud service platform, data of 126,000 users' locks throughout the world was hacked in 2021. Attackers might use the API to create instructions and remotely open the locks. Among these, 78% of the vulnerabilities were found in Wi-Fi and Zigbee communication modules, between 2020 and 2023 similar occurrences rose at an average annual rate of 34%. One prominent brand, for example, used the open-source Zigbee protocol stack without modifying encryption settings, which allowed hackers to intercept signals inside 15 meters through directional antennas with a decryption success rate as high as 65%. User activity increases hazards. A 2022 NORTON study reveals that 41% of smart door lock users have never altered their original passwords; 57% of them employ pure digit passwords of fewer than six characters, therefore tripling the effectiveness of brute-force cracking attempts. Additionally, only 29% of users update the firmware frequently, which causes an extended exploitation cycle of known vulnerabilities (such CVE-2023-27922) to average 14 months. Industry studies show that devices without two-factor authentication (2FA) are 73% more likely to be hacked remotely than those with 2FA enabled; however, the market penetration rate of models supporting 2FA is just 38%. Though market data indicates smart door lock shipments worldwide totaled 180 million units in 2023, just 12% passed dual certifications like as UL 60335-2-103 for physical and cyber security. Consider one particular e-commerce system, for instance. Among the smart door locks costing less than 80 US dollars, 62% do not use anti-electromagnetic interference (EMI) design, which causes the Tesla coil (electric lock pulse attack) to trigger unlocking within 5 seconds, with a success rate close to 100%. Designs flaws in the motor drive circuit once prompted Yale to recall 42,000 goods, with a single recall cost of more than 12 million US dollars. Smart door locks using 3D structured light face recognition (such as Deshiman R80) have decreased the false recognition rate of lion-based attacks to 0.001%, but the hardware cost has increased by 35%. Defense technologies keep evolving. Although the power consumption rises by 18%, the scheme of generating dynamic keys based on quantum random numbers can extend the theoretical cracking time to 12,000 years. According to industry projections, smart door locks supporting the Matter protocol (end-to-end encryption) will have a market share of 54% by 2025, therefore lowering the attack surface by 60%. CISA statistics, however, show that ransomware attacks against smart door locks grew by 41% year-on-year in 2022, with an average demand of 0.3 BTC (about 6,800 US dollars) per attack, which forced companies to raise their yearly cybersecurity spending to 25% of their product development expenditures.