Skip to main content

Indiegogo-backed Tapplock proves breakable and hackable; fixes incoming

For a product that’s been backed to over $300,000 on Indiegogo — over 500 percent of its original goal — Tapplock is having a bad week in the security department. Specifically, some friendly hackers at Pen Test Partners were able to crack the Bluetooth-enabled smart lock in seconds using only a cell phone.

Unlocked

Digital Trends wrote about the lock and its “cutting edge encrypted fingerprint sensor” back in 2016, but the $100 smart lock turns out to be pretty vulnerable to security penetration, both in terms of its physical makeup and its security platform.

First, its physical makeup is somewhat compromised. Sure, a pair of bolt cutters can go through the lock like a hot knife through butter but that’s true of most consumer market locks. Never mind that the lock isn’t even waterproof but merely “water resistant.” It turns out the lock is made up of an industrial alloy called Zamak 3, comprised of zinc aluminum more commonly found in die-cast toys and door handles, an element that isn’t strong, is brittle, and melts at temperatures below 800 degrees Fahrenheit. By comparison, an air-only blowtorch burns at more than 3,600 degrees F while an oxygen-fed torch fires up at more than 5,000 degrees.

But that’s not all on the physical security front. Several YouTubers have already put up videos demonstrating the fragility of the lock. On June 1, a user called JerryRigEverything was able to employ a sticky GoPro mount to remove the back of the lock, dismantle it with a screwdriver, and open the shackle. Subsequently, CNET tried the same trick and couldn’t break the lock, so whether the lock is physically secure is still up in the air.

In the meantime, Tapplock has issued a statement that all future lock batches will use proprietary screws in the inside chambers as a secondary protective mechanism. The company is also offering free replacements to any customer who is able to crack the back cover without damaging the lock.

TappLock Series: Your Fingerprint, Your TappLock

Meanwhile, the company is dealing with the bigger headache of Pen Test Partners being able to break the Tapplock’s internal software in less than two seconds. The process took the penetration testers less than an hour. Not only was the software broadcasting over unencrypted HTTP lines, but the locks are using the same data every time. Any bad actor on the same network can sniff the traffic, grab the unlocking data, and use it to unlock the device into perpetuity. There is no factory reset for the lock.

“This level of security is completely unacceptable,” wrote Pen Test Partners researcher Andrew Tierny. “Consumers deserve better, and treating your customers like this is hugely disrespectful. To be honest, I am lost for words.”

When informed of the back, Tapplock’s backer Pishon Lab told Tierny, “We are well aware of these notes.”

Subsequently, the company says that it is upgrading its QA process and pushing out a security patch to address its software vulnerability. Its QA procedures now include a 2-step inspection to ensure the lock’s spring-pen mechanism is effective, while a software patch upgrades the security protocol that includes additional authentication steps. The patch involves an app update as well as a firmware update, administered via the company’s proprietary app.

Pishon Labs also offered thanks to Pen Test Partners for “the timely prompt and ethical disclosure.”

Clayton Moore
Clayton Moore’s interest in technology is deeply rooted in the work of writers like Warren Ellis, Cory Doctorow and Neal…
Nest Doorbell vs. Ring Battery Doorbell Plus: which is the better video doorbell?
The Ring Battery Doorbell Plus installed outside a front door.

Ring and Nest are responsible for some of the best video doorbells available. With easy-to-use smartphone apps, simple installation processes, and the ability to customize your motion alerts, the Ring Battery Doorbell Plus and Nest Doorbell have quickly established themselves as two of the best video doorbells money can buy.

But what exactly is the difference between these two popular gadgets? And which is better for your smart home?

Read more
The best Apple HomeKit devices for 2023
A person unlocking the Aqara U100 smart lock with their phone.

While not as widespread as Google Home or Amazon Alexa, Apple HomeKit remains one of the most popular smart home ecosystems of 2023. The software plays well with iOS devices, and several other gadgets such as smart lights, smart locks, thermostats, and cameras can be controlled using the fancy technology. If you’re looking to build your smart home around Apple’s ecosystem, here are the best HomeKit devices available today.
Locks

HomeKit doesn’t have the largest selection of smart locks, but that doesn’t really matter when you have something as well-rounded as the Aqara Smart Lock U100. Not only does it offer full HomeKit support, but you’ll even gain access to Apple home keys -- allowing you to unlock your door with your iPhone or Apple Watch. There’s also the standard keypad for entering a passcode, along with a fingerprint sensor that can store several dozen fingerprints (so your whole family can enter the home without worrying about forgetting their password or smartphone).

Read more
Secure your home with Ring Floodlight Cam Plus and save $80
Ring Floodlight Camera placed on a wall outside.

Best Buy has one of the best security camera deals at the moment with $80 off the Ring Floodlight Cam Plus Outdoor Wired Surveillance Camera. Usually priced at $200, it's down to $120 for a limited time only so if you're fast enough, you'll save a lot of cash. If you're looking to secure your home, keep reading while we tell you all about the advantages this security camera offers.

Why you should buy the Ring Floodlight Cam Plus
Considered to be one of the best floodlight cameras for someone seeking a hard-wired solution, the Ring Floodlight Cam Plus Outdoor Wired Surveillance Camera is a highly effective home security measure.

Read more