HyreGarage

Research study

Fixed-code garage door openers: how rolling code replaced them

Your remote’s code could once be copied. Here is how makers fixed that in the 1990s, without any federal rule.

Updated September 2026 · Data as of US Patent 6,154,544, 47 CFR 15.231 and CISA ICSA-23-094-01, retrieved 2026-09-06

Written by HyreGarage Research Desk Primary-source research and data analysis

Audited by HyreGarage Research Desk Citation, computation and retrieval-date audit

4,096 maximum possible codes on a 12-switch fixed-code remote HyreGarage computation, 2^12.
~8 seconds to transmit every possible fixed code, per a published 2015 proof-of-concept Samy Kamkar’s OpenSesame, published June 4, 2015.
Never a federal requirement: rolling code was a manufacturer response, not a mandated rule 16 CFR Part 1211 and FCC Part 15.231.

The finding

Before the mid-1990s, most garage door remotes sent the same fixed code every time, set by 8 to 12 DIP switches: just 256 to 4,096 possible codes.

Samy Kamkar’s 2015 OpenSesame device tried them all in about 8 seconds. Rolling code, which changes on every press, arrived in 1996 as Chamberlain’s Security+ (patent priority May 17, 1995). No federal rule ever required it.

What did we find?

Two unrelated things changed about garage door openers in the 1990s, and most accounts mix them up. Our photo-eye sensor study covers entrapment protection: a federally required sensor that stops a closing door on an obstruction.

This page covers a separate change. The radio code your remote sends stopped repeating.

Before the mid-1990s, most home remotes used a fixed code set by 8 to 12 physical DIP switches. That gives 256 to 4,096 possible combinations. A fixed code can always be recorded and replayed.

DASMA’s own retrospective dates the industry’s answer to fall 1994. Chamberlain’s rolling-code patent has a priority date of May 17, 1995. It reached the market as Security+ in 1996.

The weakness was real. Samy Kamkar’s OpenSesame, published June 4, 2015, sends every possible fixed code in about 8 seconds. We do not reproduce the technique.

No federal rule ever required rolling code. Neither 16 CFR Part 1211 nor FCC Part 15.231 covers how a remote encodes its signal. Rolling code was a manufacturer response to a demonstrated weakness, never a safety regulator’s mandate.

What does this page claim, and what not?

Remote security and entrapment safety are two stories that share a decade. Keeping them apart is the point of this page.

This is not the entrapment-protection story.

That story is 16 CFR Part 1211 and the photo-eye or edge-sensor rule. Our pre-1993 opener study and photo-eye study cover it. This page is about remote-control radio security, a separate problem with a separate history.

We publish no attack method.

We say that a public proof-of-concept exists, who published it, when, and roughly how fast it worked, with a link to the researcher’s own writeup. We do not reproduce frequencies, timing sequences, code values or step-by-step instructions.

No federal safety rule ever required rolling code.

We looked. CPSC’s garage door opener standard does not cover it. FCC’s transmitter rules limit how long a remote transmits, not how its code works. Rolling code is a market and patent-lawsuit story. Calling it regulated would be a claim we cannot support.

An old fixed-code opener is not automatically dangerous.

The practical risk from a legacy fixed-code remote is someone getting in, not the entrapment hazard covered elsewhere on this site. Makers stopped shipping fixed-code home openers decades ago. The exposure is in remotes and receivers that have never been replaced.

We did not verify a “combinations” figure for modern rolling code.

Manufacturer marketing states very large numbers for rolling-code systems. We found none from a technical, non-marketing source we could confirm, so we do not repeat one.

Today’s documented weakness is not about fixed code at all.

CISA’s 2023 Nexx advisory concerns hardcoded cloud credentials, an app and cloud failure, not radio replay. We include it so the picture of garage opener security today is not stuck in 1994. See our smart opener security study.

When did garage remotes change from fixed code to rolling code?

Between 1994 and 1996. Each event below has its own source: a patent record, a trade association page, a court opinion, a researcher’s own account, or a federal advisory.

Through the 1980s and into the early 1990s

Fixed code is the market standard

A bank of physical DIP switches in both the remote and the receiver sets a code. There are typically 8 to 12 switches, giving 256 to 4,096 possible combinations. The remote sends that same value every time. It let installers match a replacement remote to the receiver, for convenience, not security.

Fall 1994

Anti-code-grabbing technology is announced

DASMA’s retrospective says that in fall 1994, Street Smart Auto Security introduced a garage transmitter/receiver that “randomly changes the digital code with every use”. The aim was “to thwart high-tech thieves who could record the transmitter’s radio signal and play it back later.” It is the earliest dated anti-replay product we could verify.

May 17, 1995 (priority date)

Chamberlain files the patent behind Security+

US Patent 6,154,544, “Rolling code security system,” has a priority date of May 17, 1995 and a filing date of June 11, 1997. It was granted November 28, 2000 to inventors Bradford L. Farris and James J. Fitzgibbon, assigned to Chamberlain Group. We checked the patent record directly.

1996

Security+ reaches the market

Chamberlain calls its rolling-code system Security+. Through the late 1990s, other makers introduce similar systems, often sold as “rolling code,” “hopping code” or “Intellicode”. This was a manufacturer response to a known weakness. No regulator required it.

August 31, 2004

Chamberlain Group v. Skylink Technologies, 381 F.3d 1178 (Fed. Cir.)

The Federal Circuit rules against Chamberlain in a Digital Millennium Copyright Act (DMCA) case. Skylink’s Model 39 universal remote could open Chamberlain’s Security+ openers without using rolling code itself. The court held that an opener’s owner is authorized to access its software, so Skylink did not unlawfully get around an access control.

June 4, 2015

OpenSesame is published: a working proof against fixed code

Security researcher Samy Kamkar publishes a device built from a discontinued children’s toy. It opens a fixed-code garage door by sending every possible 8-to-12-bit code as one overlapping de Bruijn sequence. That takes about 8 seconds, down from roughly 29 minutes by brute force. Kamkar says it fails against rolling code and recommends upgrading.

August 2015

RollJam targets the newer technology instead

At DEF CON 23, Kamkar shows a second device, RollJam, that beats rolling-code systems in car remotes and garage openers alike. It jams and records a transmission, then later replays the intercepted, unused code. It is a different attack from OpenSesame’s brute force. Rolling code closed the fixed-code replay hole, but not every hole.

April 2023

A new kind of weakness: hardcoded cloud credentials

CISA advisory ICSA-23-094-01 lists five CVEs (CVE-2023-1748 through -1752, CVSS scores 6.5 to 9.3) in Nexx smart garage controllers. Hardcoded credentials, authorization bypass and weak authentication in the maker’s cloud service let an attacker control any customer’s door. This is a cloud and app failure, not a radio code issue.

What is a fixed code, and why does it fail?

A fixed code is a signal that never changes, so anyone who records it can reuse it. A garage door remote is a small radio transmitter. Pressing the button sends a short burst on an unlicensed frequency, commonly 300–400 MHz for US home openers.

The receiver in the motor unit (the powerhead) acts on the signal if the value matches what it expects.

On a fixed-code system, that value is set once by a bank of DIP switches inside both the remote and the receiver. There are typically 8 to 12, each a simple on/off toggle. Eight switches give 2⁸ = 256 possible settings; twelve give 2¹² = 4,096.

Whatever the switches say, the remote sends that value every time the button is pressed, for as long as the remote exists.

HyreGarage analysis: this is not careless engineering. It is simply what a fixed code is. Any system where the same signal always opens the same door can be beaten by a device that records the signal once and plays it back. That is called a replay attack.

The DIP switch design was never sold as tamper-proof. It was sold as configurable, so an installer could match a replacement remote to a receiver in the field without special tools. The same design that made a remote easy to match also made it easy to copy.

The number of possible codes matters too. 256 or 4,096 sounds like a lot until a machine, not a person, is trying them. A patient person with a universal remote could already step through a small fixed-code space.

What changed by 2015 was a purpose-built device that could step through every code of a 12-switch system in seconds, not hours. That turned a theoretical weakness into a demonstrated, practical one.

How many codes can a fixed-code remote have?

Between 256 and 4,096 on common remotes. The count is two raised to the number of switches. The chart uses a log scale because the range spans two orders of magnitude.

Possible fixed codes on a DIP-switch garage remote, by switch countTotal possible fixed codes on a DIP-switch garage remote, by switch count, shown on a logarithmic scale. 6 switches: 64 possible codes; 8 switches: 256 possible codes; 9 switches: 512 possible codes; 10 switches: 1,024 possible codes; 12 switches: 4,096 possible codes. The two most common configurations sold in the 1980s, 8 switches and 12 switches, are highlighted: 256 and 4,096 possible codes respectively — small enough that Samy Kamkar’s 2015 OpenSesame device could transmit every combination in about 8 seconds. Rolling code, introduced from 1994 onward, replaced this fixed keyspace with a value that changes on every transmission rather than a larger fixed one.Possible codes (log scale)642561,0244,096646 switches2568 switches5129 switches1,02410 switches4,09612 switchesCommon commercial configurationsPossible fixed codes on a DIP-switch garage remote, by switch countTotal possible fixed codes on a DIP-switch garage remote, by switch count, shown on a logarithmic scale. 6 switches: 64 possible codes; 8 switches: 256 possible codes; 9 switches: 512 possible codes; 10 switches: 1,024 possible codes; 12 switches: 4,096 possible codes. The two most common configurations sold in the 1980s, 8 switches and 12 switches, are highlighted: 256 and 4,096 possible codes respectively — small enough that Samy Kamkar’s 2015 OpenSesame device could transmit every combination in about 8 seconds. Rolling code, introduced from 1994 onward, replaced this fixed keyspace with a value that changes on every transmission rather than a larger fixed one.Possible codes (log scale)645124,0966 switches648 switches2569 switches51210 switches1,02412 switches4,096Common commercial configurations
Possible codes on a fixed-code DIP-switch remote, by switch count. The shaded bars, 8 and 12 switches, were common configurations sold through the 1980s and into the early 1990s. HyreGarage computation (2 raised to the switch count), retrieved 2026-09-06.
DIP switchesPossible codes (2^n)Commercially common?
6 switches64Less common, but the same principle applies
8 switches256Yes, a widely sold configuration
9 switches512Less common, but the same principle applies
10 switches1,024Less common, but the same principle applies
12 switches4,096Yes, a widely sold configuration

HyreGarage computation. A fixed code’s security depends entirely on how long it takes someone to try every value in this column. Rolling code avoids the whole calculation by changing the value sent on every use, instead of relying on a large fixed code space.

How does rolling code work?

In outline, at the level Chamberlain’s own public patent describes it. Enough to explain the idea, not enough to act as a specification.

A code that changes every time

The abstract of US Patent 6,154,544 describes a signal with a fixed part and a part that changes on each press. So the exact signal sent is different every time, even with the same remote and receiver.

A window, not one expected value

A remote can be pressed out of range of the receiver: a pocket press, or a press while traveling. So the receiver cannot demand only the next value in sequence.

The patent describes a window of acceptable next values ahead, and a rejection window behind. It accepts a remote that legitimately skipped ahead, and rejects an old, already-used value.

Why a recorded signal does not work twice

Once a value is accepted, the receiver moves its expected position forward. A device that recorded that signal and replays it later is sending a value the receiver has already used. That is the exact failure a fixed code cannot avoid.

What do the terms mean?

Fixed code
A remote system where the signal never changes. On older home openers it was set by a bank of DIP switches, giving as few as 256 to 4,096 combinations.
Rolling code (also "hopping code")
A remote system where the signal changes on every use, following a shared formula known to both remote and receiver. A recorded signal cannot be replayed later.
Replay attack
Recording a real transmission and sending it again later to get the same result. It is the weakness a fixed code cannot avoid by design, and the one rolling code was built to close.
DIP switch
A small bank of physical on/off toggles that sets a fixed binary value. "DIP" stands for dual in-line package, which describes the switch’s physical shape, not anything about security.
De Bruijn sequence
A math technique that packs every possible short binary string into one long overlapping sequence. Testing every code then takes far less transmission time than sending each one separately. Kamkar’s OpenSesame used it to finish its search in about 8 seconds.
FCC Part 15.231
The federal radio-interference rule for occasional transmitters like garage remotes. It includes a 5-second maximum transmit time after release and limits on periodic transmissions. It governs spectrum use, not code security, and does not require or mention rolling code.

Is rolling code required by federal law?

No. Rolling code did not arrive the way entrapment protection did, through a statute, a CPSC rule and a compliance deadline. Our UL 325 timeline documents that kind of regulatory history for a different feature of the same product.

CPSC’s rules for garage door openers, at 16 CFR Part 1211, cover entrapment protection: whether a closing door detects an obstruction and reverses. We reviewed the current section list of Part 1211. Nothing covers remote transmission, encoding or radio security in any form.

The Federal Communications Commission does regulate the radio in a garage remote, but for interference, not security. 47 CFR § 15.231 says “[a] manually operated transmitter shall employ a switch that will automatically deactivate the transmitter within not more than 5 seconds of being released.”

It also limits periodic and polling transmissions to short total times per hour. People sometimes mistake this for a security rule. It is not one. Nothing in the text we retrieved requires, specifies or even mentions a changing code.

HyreGarage analysis: that makes rolling code a market-driven and, later, lawsuit-driven change. DASMA members, and Chamberlain in particular, spotted a demonstrated weakness (fall 1994, per DASMA’s own account). Chamberlain built a patented answer (priority date May 1995), and it became a competitive advantage worth defending in court.

Chamberlain v. Skylink was a fight over whether a universal remote maker could sell a device that opened Chamberlain’s rolling-code openers without using rolling code itself. The Federal Circuit sided with the universal remote maker on DMCA copyright-circumvention grounds. It made no safety or security ruling.

No regulator forced this change. The industry made it because it worked, and because customers who bought a security feature expected it to be secure.

Has anyone actually opened a garage this way?

In public demonstrations, yes. Saying a fixed code “can be replayed” describes a design property. It does not prove anyone has done it outside a lab.

The clearest dated public demonstration we could verify is Samy Kamkar’s OpenSesame, published June 4, 2015. It is a Radica Girltech IM-ME children’s texting toy, modified with a cheap radio chip. It sends every possible code for an 8-to-12-bit fixed-code remote as one overlapping sequence, finishing in about 8 seconds.

Kamkar’s own account says plainly that it targets fixed code only and does not work against rolling code. He recommends upgrading to rolling code, hopping code, Security+ or Intellicode. We link to his writeup rather than a summary, and we do not reproduce his method.

Two months later, in August 2015 at DEF CON, Kamkar published a second, unrelated device, RollJam. It targets rolling code itself, in car remotes and garage openers alike.

RollJam does not guess a code. It blocks a real transmission from reaching the receiver while secretly recording it. The next time the owner presses the button, it replays the intercepted, never-used code and keeps one valid code in reserve.

That is a real weakness in rolling code, but it is a different attack (jamming plus interception, not brute force) against a different target. Rolling code still solved the problem it was built for, the fixed-code replay hole. It left a different hole open, a common pattern in security engineering.

For a homeowner today, the two demonstrations point in different directions. If your remote is truly fixed-code (DIP switches, no rolling-code branding), OpenSesame-style replay is the documented risk. The fix, available since the 1990s, is a rolling-code remote and receiver pair. Our opener selector helps you choose an opener.

If your opener already uses rolling code, RollJam-style interception is the more relevant risk, and much harder to pull off casually. There is no simple consumer fix beyond the usual advice: do not leave a remote clipped to a visible visor in an unattended car.

What could we not verify?

The exact date fixed-code home openers stopped shipping. Rolling code arrived in 1994–1996 and became dominant through the late 1990s. Retail sources describe Chamberlain-family "Orange/Red Learn button" units from roughly 1997–2005 as the first rolling-code generation.

We found no single date after which no US maker shipped a fixed-code home unit, and we did not guess one.

A verified modern rolling-code combinations figure. Manufacturer marketing states very large numbers. We found no technical specification, separate from marketing copy, that we could verify, so we do not repeat one.

How many American garages still use a fixed-code remote. No federal dataset counts garage door openers at all, as our pre-1993 opener study shows for a different question. Manufacturers do not publish installed-base figures by code type.

Whether OpenSesame led to real burglaries. We found no CPSC recall, CISA advisory or court record tying OpenSesame-style attacks to an actual crime wave. It matters as the first public proof of a weakness that had been described but not shown. It is not evidence of widespread abuse.

One thing we chose not to publish: a walkthrough for opening up a remote to check for a fixed code, or any check beyond looking for rolling-code branding. Even a homeowner’s checklist can double as a guide to picking targets.

Questions

What is a fixed-code garage door opener?
It is an opener whose remote sends the exact same signal every time. A bank of 8 to 12 DIP switches sets it, giving 256 to 4,096 possible values. Because the value never changes, a recording of one real transmission can be replayed later: a replay attack. Most home openers moved away from this design from the mid-to-late 1990s.
When did garage door openers switch to rolling code?
Between 1994 and the late 1990s. DASMA dates the first commercial anti-replay product to fall 1994. Chamberlain’s Security+ traces to a patent with a priority date of May 17, 1995 (filed June 11, 1997, granted 2000) and went on sale in 1996. It became the dominant home technology through the late 1990s and early 2000s.
Is rolling code required by federal law?
No. CPSC’s opener safety standard (16 CFR Part 1211) covers entrapment protection, not remote encoding. FCC Part 15.231 limits how long and how often a remote transmits, for interference reasons, and does not require a changing code. Rolling code was a manufacturer response to a demonstrated weakness, never a regulatory mandate.
Can someone open a fixed-code garage door with a recorded signal?
Yes, in principle. The weakness is built into fixed code: a recorded signal can be replayed. A 2015 public proof-of-concept, OpenSesame, tried every code of an 8-to-12-bit fixed-code remote in about 8 seconds. The exposure today is openers never upgraded. Rolling-code systems, the home standard for about three decades, are not open to this attack.
What is OpenSesame?
A device security researcher Samy Kamkar published on June 4, 2015. Built from a discontinued children’s texting toy, it sends every possible code for a fixed-code garage remote as one efficient overlapping sequence, in about 8 seconds. Kamkar says it does not work against rolling code and recommends upgrading. We link to his writeup and do not reproduce it.
Is RollJam the same as OpenSesame?
No. RollJam is a different device by the same researcher, shown at DEF CON 23 in August 2015, and it targets rolling code. It jams a real transmission while recording it, then replays the unused code later. It shows a real weakness in rolling code, but it does not undo the fix for fixed-code replay.
What was Chamberlain v. Skylink about?
A 2004 Federal Circuit case, 381 F.3d 1178. Skylink’s Model 39 universal remote opened Chamberlain’s Security+ rolling-code openers without using rolling code itself. The court ruled for Skylink: an opener’s owner is authorized to access its software, so there was no unlawful circumvention under the DMCA. It was a copyright and competition dispute, not a safety rule.
How do I know if my opener uses fixed code or rolling code?
Look for rolling-code branding. Rolling-code openers are usually sold under a named technology (Security+, Security+ 2.0, Intellicode and similar) and pair remotes with a "Learn" or "Smart" button. Physical DIP switches in the remote or receiver mean fixed code. If unsure, ask a professional to check the make and model; do not open the powerhead yourself.
Are hacked garage door openers a common crime?
We found no evidence that they are. No federal recall, CISA advisory or court record ties fixed-code replay to a wave of real burglaries. The newer documented risk is cloud and app security: CISA’s 2023 Nexx advisory involved hardcoded credentials in the maker’s cloud service, unrelated to radio code design.
Is this the same topic as garage door entrapment protection?
No. Entrapment protection is 16 CFR Part 1211: whether a closing door detects an obstruction and reverses. Our pre-1993 opener, photo-eye and UL 325 timeline pages cover it. This page covers remote radio security, a separate problem that changed in the same decade for unrelated reasons.

Written and audited by

HyreGarage Research Desk

Primary-source research, data analysis and fact checking

We are not a garage door company. We read the agency file, the code record, the standards document or the public register ourselves, compute the figure from it, and publish it with the source and the date we retrieved it.

Where a number cannot be traced to a primary source, we publish the shorter page and say what we could not verify. Our own company records cover ten states; nothing national is ever derived from them.

10
states our own company records cover — and the limit of any claim made from them
3,901
garage door companies in the store
457
license records verified against a state board
0
national claims made from a ten-state store

How this desk works

  • Primary sources only. Injury counts come from CPSC. Housing counts come from the Census file, not from a summary of it. Code history comes from the building commission that adopted the code. We do not cite an article that cites a source; we retrieve the source and do the arithmetic ourselves.
  • Every figure carries its retrieval date. Registers change, datasets are revised and codes are amended. A number without the date it was read cannot be checked, so every study states one.
  • Fact, calculation and analysis are labeled apart. A quote is a quote, a HyreGarage computation says so, and an interpretation says “HyreGarage analysis”. Presenting our reading of a dataset as something the agency stated would be the easiest way to lose the only thing this desk is for.
  • Limitations go above the fold. If a figure is an upper bound, a bracket, or an association rather than a cause, that is said before the figure is quoted rather than in a footnote underneath it.
  • No DIY instructions for spring, cable or track work. Those components hold enough stored energy to cause serious injury, and CPSC records the consequences. We describe what has failed and what a competent repair involves; we do not tell you how to do it.

Data as of US Patent 6,154,544, 47 CFR 15.231 and CISA ICSA-23-094-01, retrieved 2026-09-06. Authorship on this site is organizational: the analysis belongs to the desk rather than to a named individual, and we do not publish credentials we do not hold.

Our editorial policy sets out how we source, date and correct what we publish.

Sources & retrieval dates

US Patent 6,154,544 — "Rolling code security system" (Chamberlain Group), Priority date May 17, 1995; filed June 11, 1997; granted November 28, 2000. Inventors Bradford L. Farris and James J. Fitzgibbon. Verified at the patent record. The abstract describes an interleaved trinary-bit fixed portion, a rolling portion that changes each transmission, and forward/backward windows for a remote used out of range. Retrieved 2026-09-06.
Samy Kamkar — "OpenSesame: hacking garages in seconds," published June 4, 2015, The researcher’s account of a device built from a discontinued Radica Girltech IM-ME toy. It sends every fixed code for an 8-to-12-bit DIP-switch remote in about 8 seconds using a de Bruijn sequence, versus roughly 29 minutes by naive brute force. Targets fixed code only. Checked against trade-press coverage; technique not reproduced. Retrieved 2026-09-06.
Chamberlain Group, Inc. v. Skylink Technologies, Inc., 381 F.3d 1178 (Fed. Cir. 2004), Federal Circuit opinion. Skylink’s Model 39 universal remote could operate Chamberlain’s Security+ rolling-code openers without using rolling code. The court held this did not violate the DMCA’s anti-circumvention provisions, because an opener’s owner is authorized to access its embedded software. Retrieved via case-law reporting of the opinion. Retrieved 2026-09-06.
DASMA — "10 Years Ago: Anti-Codegrabbing Technology Announced" and current garage door opener safety tips, DASMA’s retrospective says that in fall 1994, Street Smart Auto Security introduced a transmitter/receiver that "randomly changes the digital code with every use". DASMA’s current safety-tips page says: "Some thieves are able to 'record' your transmitter’s signal. Later, after you’re gone, they replay that signal and open your door," and recommends rolling code. From dasma.com. Retrieved 2026-09-06.
47 CFR § 15.231 — Periodic operation in the band 40.66-40.70 MHz and above 70 MHz, The FCC rule for intermittent radio transmitters, including garage remotes. Quoted: "A manually operated transmitter shall employ a switch that will automatically deactivate the transmitter within not more than 5 seconds of being released." It covers interference, not code design or security. Retrieved from an eCFR mirror because ecfr.gov served an access challenge. Retrieved 2026-09-06.
CISA ICS Advisory ICSA-23-094-01 — Nexx Smart Home Device, Published April 4, 2023. Five CVEs in Nexx smart garage controllers: CVE-2023-1748 (hardcoded credentials, CVSS 9.3), CVE-2023-1749 and -1750 (authorization bypass via user-controlled key), CVE-2023-1751 (improper input validation), CVE-2023-1752 (improper authentication). Allowed remote control of any customer’s door via the cloud/MQTT service. Unrelated to fixed-versus-rolling code. From cisa.gov. Retrieved 2026-09-06.

Not sure whether your remote is fixed code or rolling code?

A professional can tell which technology your opener uses in minutes. If it is an old fixed-code system, the usual fix is a new remote and receiver. Matching is still being built, so nothing goes to a company unless you agree.

Find a Garage Door Professional Open the opener selector

HyreGarage is not a garage door company, security firm or manufacturer, and does not perform, supervise or warrant garage door work. This page is a historical and regulatory account. It links to researchers’ own published work. It does not describe, demonstrate or endorse any way to access an opener without authorization.