Thanks Siri… “Smart Lock” Lets the Neighbor In

Someone decided to automate his house with Philips Hue LED lights bulbs you can turn on with your phone, Ecobee Wi-Fi thermostats and remote temperature sensors for the house. He also bought himself an August Smart Lock: a Bluetooth-enabled lock that recognizes your mobile phone when you approach and unlocks the door.

from Reddit

I made the mistake of adding an August Home Smart Lock to my front door. It’s an Apple HomeKit device so it requires a hub for Siri; either an AppleTV or iPad. I use an iPad Pro in the living room for this purpose. I was showing off my home automation setup to a neighbor a few days ago, he’s cool techy guy like myself. Fast forward to this morning, I’m pulling out of my driveway and he runs up and asks to borrow some flour to fry wings for an office wing party/contest; dope. So I put the car in park and to go back inside and he’s like “I’ll let myself in.” I’m stunned, like what the f*ck. Dude walks up to my front door and shouts, “HEY SIRI, UNLOCK THE FRONT DOOR.” She unlocked the front door.

Apparently though, his iPad was also connected to the Apple HomeKit. The neighbor yelling was able to activate Siri and she complied.

iOS 10.0.2 put’s the Apple HomeKit on everyone’s iPhones.

Breakdown interview from Sophos.

This entry was posted in Security Blog and tagged , , , , , , , , , , , , , . Bookmark the permalink.