Every time you unlock your door, your key makes a sound. Hackers seem to have found a way to hear it.
Researchers at the National University of Singapore published a paper in a journal earlier this year describing how, using just a smartphone microphone and a program they designed, a hacker could clone your key. What’s more, if a thief could install malware on your smartphone, smartwatch , or smart doorbell to record audio remotely, they wouldn’t even need to be near your home to carry out the attack.
The key (ahem) for the attack, called SpiKey, is the sound produced by the lock pins as they move over the tops of a typical key.

“When a victim inserts a key into the door lock, an intruder records the sound with a smartphone microphone”, the article describes in the newspaper.
With this recording, the hacker can use the time between audible clicks to determine the distance between ridges along the key. Using this information, a hacker could then calculate and then generate a series of possible keys.
“[On average], SpiKey is able to provide 5,10 candidate keys guaranteeing that it includes the correct key, from a total of 330.424 keys, with the 3 candidate keys being the most common case”.
In other words, instead of messing around with lock picking tools, a thief could simply try out a few pre-made keys and then head straight to the door .
Of course, there are some limitations in the real world. The attacker would need to know what kind of lock the victim has. This information can be discovered simply by looking at the outside of the lock.
Second, the speed at which the key is inserted into the lock is assumed to be constant. But researchers have considered that too.
“This hypothesis may not always hold in the real world, therefore, we intend to explore the possibility of combining information across multiple inputs”, they explain.
Make sure that no one is around you, recording you, when you put your key in a lock.
“We can exploit other approaches to collect click sounds, such as installing malware on a victim ’s smartphone or smartwatch , or door sensors containing microphones to capture a recording with a higher signal-to -noise ratio ,” the study authors explain. “We can also exploit long-range microphones to avoid suspicion. Additionally, we may increase the scalability of SpiKey by installing a microphone in an office hallway and collecting recordings for multiple doors.”
In other words, they’re already thinking about ways to make it easier to attack. While so-called smart locks present their own security problems. Amazon ’s security cameras , remember, are constantly being hacked. And as the researchers argue, a hacker could, in theory, use the microphone built into such a camera to record the sounds your key makes and then use the SpiKey technique to generate physical keys for your house.
However, there are easier ways for your key to be cloned by the hacker. Even so, you may need to make a little noise when you unlock your door. Your neighbors might think you are a bit strange, but at least they won't be able to use SpiKey to get into your house.
