Schlage locks going offline/online

We’re screwed. Here is the response from ST:

Greetings from Smartthings!

Hi, John! This is Donna. We have received an update from Escalation Team regarding your concern, apologies for the late reply. Please check their reply below;

"The SmartThings devs(developers) have investigated the recent issue with Schlage locks falling offline after the recent hub update and have provided the following information

This issue is related to a recent security patch from SciLabs (chipset manufacturer) that was deployed to resolve a security advisory. When looking at the hub logs we are seeing these locks are attempting to re-use a specific value used in secure communication. We believe that Schlage was relying on this loophole when writing their firmware for these older locks.
We are reaching out to Schlage to make them aware of this issue. However, the team has decided they will not roll back the SciLabs security patch as it creates a vulnerability for the SmartThings hubs.

Let the users know that we have investigated and determined the issue is related to how these Schlage locks implemented the secure transmission protocol on these devices.

We will not be able to provide a fix for this issue. For additional support, they will need to reach out to Schlage. In the meantime, the user will need to replace the lock with a different model or continue using the lock manually until Schlage addresses the issue."

Thanks.

5 Likes