A Google staffer hacked the Software House smart locks of Google's Sunnyvale offices last July and says fixing this make of lock means replacing onsite hardware
I cover crime, privacy and security in digital and physical forms. — Last July, in Google's Sunnyvale offices …
Context & Ripple Effects
This story sits at the physical edge of Google's otherwise strong security record. On the digital side, Google has publicized hardening wins — requiring physical Security Keys that it says have kept its 85,000+ employees phish-free since early 2017 — and it has repeatedly disclosed and patched software flaws, from a Workspace sign-in bypass to state-sponsored espionage campaigns tracked by its Threat Analysis Group.
The Sunnyvale incident shows the same company's building-access layer failing in the opposite direction: an insider demonstrated he could hack the Software House smart locks on Google's own offices, and the vendor's remedy isn't a patch but replacing onsite hardware. That gap between over-the-air software fixes and rip-and-replace physical infrastructure is what makes this more than an anecdote.
First-order effects
- Google faces a hardware replacement bill and downtime at its Sunnyvale offices, since remediating this make of Software House lock means swapping onsite units rather than pushing a firmware update.
- Software House carries the reputational hit of a vulnerability demonstrated inside one of the world's most security-conscious tenants, with no software-only fix to offer.
Second-order effects
- Other Software House customers — corporate campuses running the same lock line — now face the same replace-don't-patch calculus, pressuring the vendor toward retrofit-friendly designs or discounted swap programs.
- Competing access-control vendors gain a sales argument built on updatability, mirroring how Google's own Security Key mandate reset expectations for credential hardware after phishing resistance became measurable.
Third-order effects
- If insider-demonstrated lock exploits keep surfacing, commercial building security converges on the model Google proved digitally: verifiable, revocable credentials and remotely patchable devices, with fixed-function smart locks treated as liability hardware rather than assets.
- Physical and digital security procurement merge into one budget line, because a breach in either layer now carries the same disclosure and remediation burden for large tenants like Google.
The trend: Building access control is being pulled toward the same patchable, hardware-verified security model that transformed enterprise authentication, leaving vendors of fixed-function smart locks facing forced hardware cycles.