Lockink hardware, and locking yourself out on purpose
Some devices bought to test an integration — including the part that isn't in my favour — and the setup people keep asking me about: how to hand yourself a way out you genuinely cannot reach.
The hardware
I've bought several Lockink devices to see whether I can integrate them properly. Before anyone gets excited, here is what I already know, including the part that doesn't help me.
Lockink publishes no developer API. The devices are driven over Bluetooth, locally, with no server in the loop and no server-side token exchange. That has one consequence bigger than all the others:
A Lockink cage can always be opened by the official Lockink app.
Not “unless you configure it right” — always. There is no server-side lock to take away.
So if I integrate Lockink, what you would realistically get is control, status and stats from inside Chastikey — not a device I can promise you can't open. I'd rather say that now than let anyone buy a cage on a promise I can't keep. The devices where the app genuinely holds the way out are the ones where a code, not a motor, stands between you and freedom.
I'll report back honestly once they arrive — including if the answer is “this doesn't work well enough to ship”.
Locking yourself out of your own keyholder account
This is the setup I keep being asked about. It uses pieces that already exist.
- On the web, make a second account — your “keyholder”.
- Let the browser generate a long random password for it. Don't read it, don't memorise it.
- Start your lock, and paste that password into the app's lockbox code field.
- Sign out of the keyholder account.
The only copy of the way out is now sealed inside your own lock. The field exists for the code printed on a physical lockbox, but it holds any string — and the app won't show it back to you until the lock ends.
Sudden death started as a lock against its own creator
Before the mechanics, you should know where this mode comes from, because it wasn't designed for you first — it was designed for me.
I'm the solo dev. On an ordinary lock the lockbox code is encrypted with a key held on my side, and there is a support path if something goes badly wrong. That cuts both ways: nothing technically stops me from recovering my own key early. I built the app. I can reach the keys. On the low nights — if you're in this community, you know exactly the nights I mean — I am my own weakest link, and no setting in my own app protects a developer from himself.
So I built the mode that takes the keys away from me. On a sudden-death timer lock, the lockbox code is encrypted to a drand time-lock round computed from the lock's natural end. Not “hidden until then” — mathematically unavailable until then. No recovery key, no support path, nothing left for me to grab at 3am. Cheating stopped being a question of willpower; it became impossible, and I wanted that for myself before offering it to anyone.
Two precisions, because it's the most dangerous setting in the app
The seal only applies to a timer lock. Sudden death on a cards, combination or keyholder lock still keeps the ordinary recoverable envelope — the mode blocks cancelling and early release, but the code is not sealed against me. If you want the version where nobody can help you, it has to be a timer.
The emergency safety stop does not release the code early. It ends the lock, but the seal still opens only at the original end time, and there is no operator fallback.
Combine that with the keyholder-account setup and you have a real, unrecoverable lockout of your own account for the full duration. Some of you want exactly that. Please understand it isn't a figure of speech.
Before you trust any of this
Rehearse it. One minute.
Create a lock for one minute with a lockbox code in it. Let it end. Check that you actually get the code back, on your device, in your hands. It costs you nothing and it tells you whether the whole chain works for you before it matters. If you can't find the finished lock: on the home screen, scroll down and tap the three dots.
Keep a copy of that password somewhere outside the app. Paper in a drawer, a password manager, a sealed envelope you give to someone. This isn't caution for legal reasons — with sudden death there is genuinely no other way back, and “I'll just email the dev” does not work.
The server is solid and I look after it. But it is one person's infrastructure. If the database were ever seriously damaged I would do everything I can to restore it, and I still cannot guarantee that a sealed code survives. I'm not liable for what a device does to your body, and I can't be the only copy of your way out.
Your safety is yours
Keep bolt cutters or a spare key within reach. Get out immediately on numbness or pain. In an emergency: phone, hospital. No app, no timer and no other person is your emergency release.