Your Door Keeps a Diary
11% of US households (over 11 million homes) now use smart door locks. [1] Every lock, unlock, and failed attempt is logged. That data can be shared with police, accessed by landlords, or stolen by hackers.
In March 2024, CISA warned of a 9.1/10 severity vulnerability in Chirp Systems smart locks, affecting an estimated 50,000 homes. [2] That same year, ADT was breached twice, exposing customer data. [3]
Your smart lock promises convenience. It delivers surveillance.
The Perfect Record of Your Life
Traditional locks don't keep records. Smart locks do.
Every smart lock maintains detailed logs of: [4]
- Every entry and exit: timestamped to the second
- Who unlocked the door: which user, which code, which phone
- Failed attempts: wrong codes, denied access
- Remote unlocks: when you let someone in from your phone
- Battery levels and tampering alerts
This creates what the Electronic Frontier Foundation calls "a perfect record of exactly when an individual was and was not home." [5]
Who Gets Access to This Data?
- Law enforcement: Companies can share entry logs with police, often without a warrant [5]
- Landlords: Can track tenant habits and discover minor lease violations [5]
- Insurance companies: Could use entry patterns for risk assessment
- Hackers: If the company is breached, your schedule becomes public
- The manufacturer: Most store your data on their cloud servers
The CISA Warning: 50,000 Homes at Risk
On March 7, 2024, the US Cybersecurity & Infrastructure Security Agency (CISA) issued an urgent warning about Chirp Systems smart locks. [2]
The Vulnerability
- Severity rating: 9.1 out of 10 (critical)
- Attack complexity: Low
- Remotely exploitable: Yes
- Estimated affected homes: 50,000
The flaw: hard-coded credentials in the Chirp Android app. Attackers could use these credentials to masquerade as the developer, enumerate all locks in the system, and potentially control them. [2]
Chirp provides software for compatible locks from vendors like August. Yale and August are both owned by Sweden's Assa Abloy. [2]
The Response
August claimed their investigation "found no evidence that would substantiate the vulnerability claims." [2] CISA later downgraded the severity, noting the credentials could primarily be exploited within Bluetooth range (~30 meters) to change configuration settings.
But the pattern is clear: these devices have fundamental security issues that put homes at risk.
ADT: Breached Twice in Two Months
ADT, one of the largest home security companies in America, was breached twice in 2024. [3]
August 2024 Breach
Hackers obtained: [3]
- Customer email addresses
- Telephone numbers
- Postal addresses
ADT reported the breach to the SEC.
October 2024 Breach
A second breach occurred just two months later. A hacker accessed ADT's network using compromised credentials from a third-party business partner. ADT claims only "encrypted data associated with employee user accounts" was accessed. [3]
Two breaches in two months from a company trusted to secure millions of homes.
Smart Lock Vulnerabilities Are Common
Security researchers have examined locks from Level, August, Yale, Ultraloq, Kwikset, Honeywell, Schlage, and others. Common findings include: [6]
- Static key material: Encryption keys that don't change when access is revoked
- Plain text passwords: Credentials stored without encryption
- Replay attacks: Capturing and reusing unlock commands
- Device spoofing: Pretending to be an authorized device
- Decompilable apps: Extracting credentials from the mobile app
Master Lock Vulnerabilities (March 2025)
Researchers reported vulnerabilities to Master Lock in March 2025. Fortune Brands Connected Products (which owns Master Lock, Yale, and August) acknowledged the findings and discussed mitigation progress. [6]
The research found issues with "maintenance and synchronization of access policies, including static key material that is not rotated on revocation." In plain English: when you revoke someone's access, the old keys might still work.
The Landlord Surveillance Problem
Smart locks have become popular with landlords, and that's a problem for tenants. [5]
What Landlords Can See
- When you come and go
- How often you have guests
- Whether you're following lease terms (unauthorized occupants, pets, etc.)
- Your daily schedule and patterns
- Whether you're home during work hours
Legal Pushback
In 2019, tenants in New York City forced a settlement after a landlord attempted to require smart locks. The settlement required an option for physical keys. [5]
The EFF advocates for laws requiring: [5]
- Consent to collect this data
- A warrant for police access
- Strong data minimization requirements
Most states don't have these protections.
Police Access: No Warrant Required?
Smart lock companies can share entry data with law enforcement. The Brennan Center for Justice has documented how police access smart device data. [7]
The Third-Party Doctrine Problem
Under the "third-party doctrine," data you share with a company may not be protected by the Fourth Amendment. If your smart lock company stores your entry logs on their servers, police may be able to access them without a warrant, just a subpoena or even a request.
Company Policies Vary
SimpliSafe
"We won't share personal information or camera footage with law enforcement unless required by law (specifically, to comply with a warrant or court order)." [8]
Monitoring agents can only view camera footage if users opt in to video verification. Indoor cameras have privacy shutters with LED indicators.
ADT
All device data is collected. Information is shared with "service providers, business partners, emergency services, legal authorities and affiliates, as well as with a new controlling company in case of a merger, sale or reorganization." [3]
ADT does not restrict video footage access like SimpliSafe.
What Smart Security Systems Collect
Smart Locks
- Entry/exit timestamps
- User identification
- Failed access attempts
- Remote unlock history
- Battery and device status
Security Cameras
- Video footage (often stored in cloud)
- Motion detection events
- Audio recordings
- Facial recognition data
- Activity patterns
Full Security Systems
- Arm/disarm times
- Sensor triggers (motion, door, window)
- Who armed/disarmed and when
- Emergency dispatch records
- Integration with other smart devices
The Market Is Booming
- 11% of US households (11+ million homes) use smart locks [1]
- 60% of Americans projected to adopt smart home tech by 2025 [1]
- Smart home security market growing rapidly with ADT, Vivint, and SimpliSafe leading [9]
More homes with smart locks means more data being collected, more potential breaches, and more surveillance infrastructure.
How to Protect Yourself
Before You Buy
- Read the privacy policy: What data is collected? Who is it shared with?
- Check for local storage options: Does data have to go to the cloud?
- Research security track record: Has the company been breached?
- Look for warrant requirements: Will they require police to get a warrant?
- Consider "dumb" alternatives: Do you really need remote access?
If You Have a Smart Lock
Security Steps
- Update firmware regularly: security patches fix known vulnerabilities
- Use strong, unique passwords for the associated app/account
- Enable two-factor authentication if available
- Disable features you don't use (remote access, voice assistant integration)
- Review access logs periodically for unauthorized entries
Privacy Steps
- Minimize cloud storage: use local storage if available
- Review and delete old logs regularly
- Limit third-party integrations: each connection is a data risk
- Opt out of data sharing where possible
- Use a separate network for IoT devices
For Renters
- Know your rights: Some jurisdictions require landlords to offer key alternatives
- Request physical key option: Cite the NYC settlement as precedent
- Document everything: If landlord monitors your entries, keep records
- Check local tenant laws: Surveillance may violate privacy protections
Safer Alternatives
- Offline smart locks: Bluetooth-only models that don't connect to the internet
- Local-only systems: Security systems that store data on local servers
- Mechanical keypad locks: PIN codes without internet connectivity
- Traditional locks: No data collection, no hacking, no surveillance
Questions to Ask Security Companies
Before signing up for a smart home security system:
- Where is my data stored? (Local vs. cloud)
- Who has access to my camera footage?
- Do you share data with law enforcement without a warrant?
- How long is my data retained?
- Can I delete my data? How?
- What happens to my data if the company is sold?
- Have you experienced any security breaches?
The Bottom Line
Smart locks create a permanent record of when you come and go. That data can be accessed by police, landlords, hackers, and the companies themselves.
CISA warned of a critical vulnerability affecting 50,000 homes. ADT was breached twice in two months. Security researchers find fundamental flaws in locks from major manufacturers.
Meanwhile, the EFF is calling for basic protections (consent, warrants, data minimization) that most states don't require.
To protect yourself:
- Research before buying: Check privacy policies and security track records
- Minimize data collection: Use local storage, disable unnecessary features
- Keep devices updated: Security patches fix known vulnerabilities
- Know your rights: Especially if you're a renter
- Consider alternatives: Sometimes "dumb" is smarter
A lock should secure your home, not surveil it. Until smart lock companies prioritize privacy as much as convenience, that's exactly what they're doing.
References
- Market.us - Smart Lock Statistics and Facts (2025)
- Krebs on Security - Crickets from Chirp Systems in Smart Lock Key Leak (April 2024)
- US News - ADT Home Security System Review 2025
- Lockly - Door Lock Security: How Smart Locks Handle Your Data
- Electronic Frontier Foundation - Smart Locks Endanger Tenants' Privacy and Should Be Regulated
- USENIX - No Key, No Problem: Vulnerabilities in Master Lock Smart Locks (2025)
- Brennan Center for Justice - Law Enforcement Access to Smart Devices
- SimpliSafe - Privacy Policy
- OpenPR - Smart Home Security Market 2024 Growth Report