← The Signal Report Work with me

Report 167 · Luxury Home Security

What hands-free unlock is really measuring

The new Aliro standard is bringing hands-free, phone-in-your-pocket unlocking to smart locks from the biggest names in the business, and the explainers say its ultra-wideband radio "effectively prevents" relay attacks. It does beat the relay attack that broke Bluetooth locks. But a hands-free door isn't checking who you are. It's checking how far away your phone is, and peer-reviewed research has already shown that the UWB distance measurement itself can be shortened. Here is what that means for an exterior door.

Aliro 1.0 was released in February, and lock makers including Allegion, Kwikset and Nuki are among those the standard's own announcement expects to certify first. The pitch is the same everywhere: walk up with your phone in your pocket and the door opens. Before you enable that on the front door of a house worth protecting, it helps to know what the lock is actually deciding when it opens.

What Aliro is

The Connectivity Standards Alliance, the group behind Matter, released the Aliro 1.0 specification on 26 February 2026. It is a common protocol and credential format so one digital key in an Apple, Google or Samsung wallet can open locks from many vendors. The Alliance says it uses asymmetric cryptography between phone and reader, and that it supports three radios, each for a different job:

Near Field Communication (NFC) for tap-to-access, Bluetooth Low Energy (Bluetooth LE) for user-initiated long-range communication, and Bluetooth LE plus Ultra-Wideband (UWB) for a seamless, secured hands-free authentication method.

Read that carefully, because the design choice in it is the whole story. Bluetooth alone is for "user-initiated" unlocking, where you do something. Hands-free is reserved for Bluetooth plus UWB. There is a good reason for that split.

The attack that broke Bluetooth hands-free

A hands-free lock has two questions to answer. Is this an authorized phone? Is it right here at the door? Cryptography answers the first. It can't answer the second, and that is where relay attacks live.

In May 2022, NCC Group published a technical advisory by Sultan Qasim Khan showing a relay attack on the Kwikset/Weiser Kevo smart lock, which offered Bluetooth "Touch-to-Open." The method is simple to describe. One attacker's device sits near the lock. Another sits near the owner's phone, maybe across a restaurant. The devices forward the radio traffic between them, and the lock and phone "believe they are adjacent when they may actually be great distances apart." The cryptographic handshake completes, because the real phone really is answering. It is just not at the door.

NCC's tool worked at Bluetooth's link layer, adding so little delay that it fell "within the range of normal GATT response timing variation," so timing checks didn't catch it. The advisory's recommendation is the sentence the whole lock industry built Aliro around:

As currently defined, the Bluetooth Low Energy standard lacks a suitable mechanism for secure ranging. Angle of arrival and RSSI measurement do not protect against attacks where a relay transmits from the same location and with the same power as a legitimate device. Secure ranging is normally implemented using technologies that support time-of-flight measurement, such as Ultra-Wide Band (UWB).

Why UWB is a real improvement

UWB measures distance by timing. The lock sends a pulse, the phone answers, and the round trip tells the lock how far the signal traveled, at the speed of light. The crucial property, as the Ghost Peak researchers below put it, is that "a relay can only increase the ToF," the time of flight, "and, thus, the measured distance." A relay has to receive and retransmit, which takes time, which makes the phone look farther away, not closer. The classic relay attack stops working.

That is a genuine fix, and it is why I'd take a UWB hands-free lock over a Bluetooth-only one without hesitation. It is also why one widely read explainer, matter-smarthome.de's guide to Aliro, says UWB ranging "effectively prevents so-called relay attacks." Against the relay NCC demonstrated, that's fair. The mistake is hearing "relays are beaten" as "the distance can be trusted."

Shortening the distance instead of relaying it

If you can't make the phone look close by relaying it, you can try to make the lock mismeasure the distance. That is a distance reduction attack, and in 2022 a team from ETH Zurich and TU Darmstadt demonstrated one against UWB in practice. Their paper, "Ghost Peak: Practical Distance Reduction Attacks Against HRP UWB Ranging," was published at the 31st USENIX Security Symposium. From its abstract:

Our attack operates without any knowledge of cryptographic material, results in distance reductions from 12 m (actual distance) to 0 m (spoofed distance) with attack success probabilities of up to 4 %, and requires only an inexpensive (USD 65) off-the-shelf device.

They attacked pairs of Apple U1 chips, the UWB chip in iPhones and AirTags at the time, and U1 chips working with NXP and Qorvo UWB chips. The standard these chips implement, IEEE 802.15.4z, protects each timing exchange with a cryptographically generated sequence an attacker can't predict, called the STS. The researchers' point is that this doesn't settle it. In their words, the receiver "never verifies the correctness of the STS explicitly." It decides when the signal arrived by looking for peaks, and an attacker who injects the right kind of noise can plant an early "ghost" peak often enough to matter.

How often is enough? The authors compare their success rate with what security systems are normally designed to tolerate:

Typically, false acceptance rates are 1/220 for gate access control and 1/248 for mobile payments, such that it would take days to years until a fake measurement gets accepted.

One in 220 is about one in a million. The attack's best rate was about one in 25. And they conclude that "mere compliance with IEEE 802.15.4z does not protect systems against distance reduction attacks," because the real security lives in proprietary receiver algorithms nobody outside the vendor can inspect.

The limits of that result, stated fairly

  • It needs your phone fairly close. The attack shortens a real distance; it doesn't reach across town. For Apple's U1, the paper puts the maximum reduction at 5 m, 10 m or 15 m depending on which packets are attacked. So the realistic case is a phone inside the house, within a dozen meters or so of the door. For many homes, that is the kitchen counter, the entry table or the bedroom above the foyer.
  • It is 2022 hardware. The researchers disclosed to Apple and NXP and were disclosing to Qorvo. Chips and firmware have moved on since then. I found no public test of current UWB chips against this attack, which means I can't tell you whether they are fixed. Neither, for the same reason, can the marketing.
  • It isn't a script-kiddie tool. The authors deliberately did not publish attack code, noting that doing so "would violate German laws and might allow malicious actors to enter a system secured by UWB distance ranging." That raises the bar. It doesn't make the physics go away.
  • Defenses exist, with costs. The paper describes stronger receiver checks and outlier detection, and says plainly that they pull against battery life and against the fast response people expect from a door.

Why this beat cares

I help design the AI security systems for a veteran-owned (SDVOSB) home-security company run by fellow veterans. I do not own that company and earn nothing from this link. Full policy here.

The electronic warfare lesson I'd bring to any front door is that a system which decides based on a measurement can be attacked through the measurement. Time of arrival is the oldest trick in the EW book, for finding emitters and for fooling them. A hands-free lock has turned "is the owner here?" into "how long did a radio pulse take?" That's a much better question than Bluetooth signal strength. It is still a radio measurement, made in a split second, by a chip whose checks you can't see.

What to do with this

  • Decide per door, not per house. Hands-free on an interior door or a garage entry you already watch is a different risk from hands-free on the front door of an estate. On exterior doors, prefer tap (NFC) or a deliberate action in the app or wallet.
  • If you use hands-free, insist on UWB. Ask the vendor directly whether hands-free unlock can ever happen over Bluetooth alone. Aliro's own design says it shouldn't; older proprietary locks may not follow that rule.
  • Ask what happens when the phone is sitting still. NCC noted that Kevo's app disabled touch-to-unlock after the phone was stationary for over 30 seconds. A phone parked on the kitchen counter is exactly the case that matters for a distance reduction attack from outside.
  • Assume the lock can be wrong, and layer. A door contact on the alarm, an entry delay, a camera at the door and an alert on unexpected unlocks turn a fooled lock into a detected entry. No lock should be the only thing between a stranger and the house.
  • Keep firmware current and ask the question. Whether a given lock's UWB chip resists Ghost Peak-style attacks is a fair question to put to a manufacturer. A vague answer is information too.

What I could not confirm

I have not read the Aliro 1.0 specification. Everything I say about Aliro comes from the Alliance's public release. I don't know what the specification requires of a UWB receiver, whether it limits how many ranging attempts a lock accepts, or what its certification tests check.

I don't know the status of current chips. The Ghost Peak paper tested specific 2021-2022 chips in their openly accessible configurations, and its authors say themselves that other configurations might behave differently. I have not found a public follow-up test of today's phones or locks.

The "one in 25" is my arithmetic. It is the reciprocal of the paper's best success rate of up to 4%, and it assumes each attempt is independent. The paper does not state how many attempts a real lock would allow, and neither do I.

Nothing here evaluates or recommends any lock, phone, chip or manufacturer. Kwikset/Weiser appears because it is the product NCC Group tested in 2022, not as a comment on its current locks.

The signal

Hands-free unlocking asks a radio to prove that your phone is at the door. Bluetooth couldn't prove it, and relay attacks exploited that. UWB's time-of-flight ranging fixes the relay problem for real, which is why Aliro reserves hands-free for Bluetooth plus UWB. But published research shows the UWB measurement itself can be shortened, with cheap hardware, at rates far above what access control is supposed to tolerate. That doesn't make UWB locks bad. It makes "effectively prevents relay attacks" an incomplete sentence. On the doors that matter most, treat hands-free as a convenience setting, and make sure something else is watching the door.

Sources

  1. Patrick Leu, Giovanni Camurati, Alexander Heinrich, Marc Roeschlin, Claudio Anliker, Matthias Hollick, Srdjan Capkun and Jiska Classen, "Ghost Peak: Practical Distance Reduction Attacks Against HRP UWB Ranging," Proceedings of the 31st USENIX Security Symposium, Boston, 10-12 August 2022, pp. 1343-1359. Full paper PDF (open access); artifact appendix. (PRIMARY. The published proceedings version, all 18 pages, and the artifact appendix were read directly. Source of, verbatim: the abstract passage on 12 m to 0 m, up to 4 % and USD 65; "a relay can only increase the ToF and, thus, the measured distance"; the 1/2^20 and 1/2^48 false-acceptance comparison; "never verifies the correctness of the STS explicitly"; "mere compliance with IEEE 802.15.4z does not protect systems against distance reduction attacks"; and, from the artifact appendix, the reason attack code was withheld. Also source of the chips tested, the 5/10/15 m maximum reductions for Apple U1, the disclosure to Apple, NXP and Qorvo, and the countermeasure discussion.)
  2. Sultan Qasim Khan, NCC Group, "Technical Advisory – Kwikset/Weiser BLE Proximity Authentication in Kevo Smart Locks Vulnerable to Relay Attacks," 15 May 2022. (PRIMARY. Read in full. Source of the relay attack description and "believe they are adjacent when they may actually be great distances apart"; the link-layer timing passage; the recommendation paragraph on BLE lacking secure ranging, quoted verbatim; and the 30-second stationary-phone mitigation.)
  3. Connectivity Standards Alliance, "Introducing Aliro 1.0: A Unified Standard to Transform the Access Control Ecosystem," press release, 26 February 2026. (PRIMARY for the standard's public description. Source of the release date, the wallet partners, the asymmetric-cryptography statement, and the NFC / Bluetooth LE / Bluetooth LE plus UWB passage quoted verbatim. The specification itself was not read.)
  4. Frank-Oliver Grün, "What Is the Aliro Standard?" matter-smarthome.de, 6 January 2026, updated 17 June 2026. (Coverage, opened and read. Quoted for "effectively prevents so-called relay attacks.")
  5. Onur Oncer, "What actually opens your door," The Signal Report 066, and "When revoking smart lock access doesn't," The Signal Report 035. (Earlier reports in this beat.)

Scope note: this report explains published security research on proximity-based unlocking and what it implies for choosing lock settings. It contains no attack instructions, evaluates no specific current product, and is not a substitute for a qualified security designer assessing a specific property. Disclosure: the author helps design AI security systems for a veteran-owned home-security company, as stated in the body of this report, and does not own that company.

Onur Oncer
Onur Oncer

U.S. Army combat veteran (Counter-IED / Electronic Warfare), peer-reviewed researcher in microwave spectroscopy, and founder & CEO of Shroombiosis. Consults on laboratory operations, AI, and supplement formulation.

← All reports