If you are choosing a front door lock for a Kuching house, a shop, or choosing for a client’s unit, you have probably heard both extremes: “smart locks get hacked in seconds” and “smart locks are safer than keys.” Neither is accurate. You need the whole full story.
This article sits next to our earlier article on whether a smart lock can be hacked. Here we answer are smart door locks safe, what smart door lock security actually rests on, and how a smart lock vs traditional lock choice looks like when you actually care about your doors as the person who stays behind the door, and not a sales pitch from a salesman’s perspective.
Are smart door locks safe?
Short answer: Yes, safe enough for ordinary homes and light commercial use—only if you choose a reputable brand (those that provide continuous updates for both software and firmware), install it on a solid door and frame, and manage PINs, cards, and guest access like you would manage spare keys. But…a smart lock is not magic armour. It is a lock added with electronics. One research used an “unsophisticated cyber attacker–burglar” to attack 18 domestic smart security devices (using 433 MHz radio, Bluetooth, and RFID). Out of 18 smart security device tested, the attack had worked on 16 of them! (89% successfully attacked!)
Above case is a real published case: University of Hertfordshire researchers (Allen, Mylonas, Vidalis, and Gritzalis) built an “unsophisticated cyber attacker–burglar” model and tested domestic smart security devices over 433 MHz radio, Bluetooth, and RFID. At least one high-criticality attack worked against 16 of 18 devices. Their work produced 14 published CVEs. That is not a Kuching crime wave—it is a lab sample that shows many consumer products fail basic wireless checks. Source: Smart homes under siege…, Computers & Security (2024).
Europe now treats residential smart door locks as higher-stakes consumer IoT. ETSI TS 103 815 V1.1.1 (January 2024) builds on ETSI EN 303 645 and asks for encrypted, authenticated communications, updatable software, a way to lock or unlock if power dies, and attention to mechanical security—not only the app. A later BLE study of 18 commercial locks found 14 still vulnerable to the attacks examined, with the authors stating the flaws could affect over 20 million users (IEEE TCE, Silent Intruders…). Those numbers describe tested products, not every lock sold in Sarawak. There is no honest public “hack rate” for Malaysian homes.
Practical takeaway: Buy brands that still update firmware after the purchase, set a unique admin password (and 2FA where offered), keep the door and strike strong, and revoke guest access when people leave.
Can a smart door lock be hacked?
Short answer: Yes, in principle. That does not mean every terrace house on your street will be opened from a café Wi-Fi this week. Most published demos need proximity(near distance), special tools, or a weak product—not some random stranger on the street with only a phone number. But still, we want to be honest and tell you that hacking a smart lock is possible.
In 2025, researchers at UC San Diego (paper at USENIX WOOT) reverse-engineered a very big and prominent Door Lock Brand – Master Lock Bluetooth Deadbolt D1000. They showed a nearby attacker could record a full BLE unlock session and replay it to open the lock again. They also showed a former guest could keep unlocking after access should have been revoked—Master Lock told them the D1000’s access profiles could remain valid for up to nine months because of an earlier clock-related firmware decision, with mitigations planned. Source: Diao et al., No Key, No Problem; summary: https://bit.ly/3VdVrre.
Such ‘session reuse’ weakness is not unique to one brand. NIST’s entry for CVE-2022-46480 describes incorrect session management on another big brand, Ultraloq UL3 BT (2nd Gen, firmware 02.27.0012): an attacker in Bluetooth range could sniff unlock data and reuse it while the session stayed open. Companion technical report: arXiv:2312.00021. NCC Group’s work on Nuki products found issues that could let someone open or disrupt a lock; Nuki released patches (SecurityWeek coverage).
Practical takeaway: How to realisticly lower the risk for you: patchable firmware, no shared admin PIN, guest codes that expire, and turning off always-on auto-unlock if you do not need it. Read more: Can a smart door lock be hacked?.
Smart door lock security: what actually matters
A smart door lock’s strength is dependent on 3 factor: the software—credentials, radio/app path, and the steel in the door. A good and strong advanced fingerprint reader – yes it is strong, but if the door lock latch is weak, the overall lock is still low security. A boring PINCODE lock, but the locking is a reinforced-multipoint-bolted lock on a solid door, this is be the safer choice.
Also, the access card. The same Hertfordshire team’s technical report on a big lock brand, Yale’s Conexis L1 (CVE-2023-26941) shows how MIFARE Classic-class RFID tags can be cloned when an attacker gets brief physical proximity to the original card. Their write-up describes recovering keys and duplicating tags in about 20 seconds of access to the original tag (arXiv:2312.00021). Classic’s Crypto-1 cipher has been publicly broken since 2008; correctly configured DESFire EV2/EV3-class AES credentials are far harder to clone (overview).
Some opinions believe the door lock can only be attacked by someone near the door lock. But distance is not really a deterrent. Attacker can attack a smart door lock even from overseas, even from 1,960KM away. In an ACM WiSec ’22 paper, Staat and colleagues used an analog bluetooth relay and unlocked a Nuki Smart Lock 2.0 while bridging about 65 m between the lock and an authorised phone (DOI 10.1145/3507657.3528536; arXiv:2202.06554). On the access-control side, researchers relayed HID Seos over the public Internet and unlocked a lab door with a card about 1,960 km away (ePrint 2023/450). Fox-IT’s advisory is blunt: treat passive proximity unlock with caution; prefer a deliberate tap/button, stronger ranging (e.g. UWB where available), or disable auto-unlock (Fox-IT).
Fact with source: ETSI’s smart-lock vertical explicitly lists credential copy, replay, and relay among credential-related threats, and ties cyber rules to mechanical building-hardware practice (TS 103 815, threat notes and Annex C).
Takeaways: For day-to-day smart door lock security in Kuching, we still care more about bolt throw, strike fit, humidity-tolerant hardware, and whether parts will still be available in five years—see why some locks are so cheap and five ways to tell a smart lock is good. ETSI also expects you can lock or unlock if power is lost (TS 103 815, SDL 5.9-1)—battery contacts and/or a mechanical key override. A weak cylinder becomes the weak link no matter how good the fingerprint module looks (fingerprint reader differences).
Smart lock vs traditional lock
Neither wins by default. A quality traditional cylinder on a reinforced door often beats a no-name “smart” lock with weak cards and no updates. A durable smart lock with deletable credentials, honest logs, and a proper install often beats a worn knobset and a key under the mat.
Look again at the Master Lock D1000 findings: convenience features (temporary guest access, audit logs over BLE/phone) became attack surfaces when session handling and revocation were weak (WOOT paper). Traditional keys do not have that exact failure mode—but they also cannot revoke a copied key without a rekey. Different tools, different messes.
ETSI frames residential smart locking as needing both cyber and mechanical controls (TS 103 815). Traditional mechanical locks have almost no internet attack surface; they still fail through picking, drilling, worn pins, or broken keys depending on the cylinder and bolt. Smart locks add PIN/card/phone revocation and optional entry logs—and add BLE, Wi-Fi, apps, and cloud paths that quality and patching decide. If you want mechanical-only options, start here: high-security mechanical door locks.
What to check before you buy (Kuching homeowners & contractors)
Short answer: Match the lock to the door, the people who need access, and who will service it in five years from now.
- Door type — Timber, metal, multipoint security door? Wrong body equals a weak install (smart locks on security/metal doors).
- Who comes and goes — Family only, staff codes, or short-term rental? Plan code rotation for Airbnb-style use (Airbnb lock notes).
- Brand support — Will firmware and spare parts still exist? (Korea-made durability; repair after years).
- Connectivity — Fully offline digital vs Bluetooth vs Wi-Fi. More connectivity means more account responsibility.
- Credentials — Deletable PINs and cards; ask what RFID tech the cards use; treat passive auto-unlock as optional.
- Backup — Mechanical key and/or external battery contacts; spare batteries on the shelf.
- Install — DIY only if the door already matches; mortise and security doors are easy to get wrong (DIY caveats).
More selection context: How to choose the right smart door lock.
Soft next step
If you want a second pair of eyes on a model—or an install that respects latch, strike, and multipoint hardware—talk to Fine Lock Shop. We work with Kuching homeowners, shops, and project partners (contractors and interior designers). Browse https://bit.ly/4AFyVrE and smart digital door locks, or visit the showroom and ask us to explain trade-offs in plain language. We will not invent a “hack-proof” promise. We will help match risk, door, and budget honestly.

Leave a Reply