How This Guide Was WrittenThis is editorial research — not hands-on lab testing. We cross-reference manufacturer specifications, CSA/Matter certification databases, and recurring themes in Amazon verified reviews and owner forums. Product recommendations are current as of 2026 and include Amazon search links so you can verify pricing before buying. Focus areas for this guide: lock credentials, camera storage models, and security sensor placement.
UWB Lock Security: What’s Actually at Risk
UWB smart locks (Aqara U400, Level Lock Pro) use cryptographic challenge-response over IEEE 802.15.4z — not replayable Bluetooth proximity spoofing from 2018-era attacks.
Documented attack classes:
| Attack | Practical risk | Mitigation |
|---|---|---|
| Relay attack (stretch proximity) | Low for consumer homes | UWB time-of-flight makes relay harder than BLE |
| Lost phone | Medium | Stolen phone + weak PIN = risk; use Face ID + stolen device protection |
| Vendor cloud breach | Low for unlock path | Unlock is local; cloud is config sync |
| Physical bypass | Same as any deadbolt | Grade 1 deadbolt + proper install |
What “Hacked” Usually Means in Headlines
- Research demos on development firmware, not retail locks
- Bluetooth-only locks from 2016–2019, not ALIRO UWB 2024+
- Misconfigured guest PINs, not broken cryptography
Recommended Hardware for This Setup
These are specific products that match what this guide describes — not generic placeholders. Verify current pricing on Amazon before buying.
1. Aqara U400
ALIRO UWB + NFC HomeKey — the reference for evaluating UWB lock security claims.
Check Current Price on Amazon (paid link)
2. Yale Assure Lock 2 Touch
Fingerprint fallback for households that want non-UWB credentials.
Check Current Price on Amazon (paid link)
HTR Takeaway
- Start here: UWB + HomeKey locks from established vendors with active firmware updates.
- Avoid: No-name Bluetooth 'auto-unlock' locks with no ALIRO/HomeKey certification.
- Bottom line: Modern UWB locks are materially more secure than first-gen Bluetooth proximity locks — treat headlines with context.