KeyWe Smart Lock Has a Major Design Flaw
Summary
As The Register reports, cyber-security company F-Secure has discovered that the KeyWe Smart Lock, which currently sells for $155 on Amazon, can be circumvented due to "improperly designed communications protocols." Worst than that, though, is the fact this design flaw cant be solved due to the smart lock having no way of allowing a security patch to be applied. The common key is created "based on the device Bluetooth MAC address available globally," while the key calculation process "can be retrieved from the mobile application." F-Secure believes a malicious attacker could intercept and gain access to the lock from a range of up to 15 meters away. There is no way of mitigating this design flaw right now, and it seems unlikely there will be if the KeyWe Smart Lock cant be patched.