Research study
Fixed-code garage door openers: how rolling code replaced them
Your remote’s code could once be copied. Here is how makers fixed that in the 1990s, without any federal rule.
Written by HyreGarage Research Desk Primary-source research and data analysis
Audited by HyreGarage Research Desk Citation, computation and retrieval-date audit
The finding
Before the mid-1990s, most garage door remotes sent the same fixed code every time, set by 8 to 12 DIP switches: just 256 to 4,096 possible codes.
Samy Kamkar’s 2015 OpenSesame device tried them all in about 8 seconds. Rolling code, which changes on every press, arrived in 1996 as Chamberlain’s Security+ (patent priority May 17, 1995). No federal rule ever required it.
What did we find?
Two unrelated things changed about garage door openers in the 1990s, and most accounts mix them up. Our photo-eye sensor study covers entrapment protection: a federally required sensor that stops a closing door on an obstruction.
This page covers a separate change. The radio code your remote sends stopped repeating.
Before the mid-1990s, most home remotes used a fixed code set by 8 to 12 physical DIP switches. That gives 256 to 4,096 possible combinations. A fixed code can always be recorded and replayed.
DASMA’s own retrospective dates the industry’s answer to fall 1994. Chamberlain’s rolling-code patent has a priority date of May 17, 1995. It reached the market as Security+ in 1996.
The weakness was real. Samy Kamkar’s OpenSesame, published June 4, 2015, sends every possible fixed code in about 8 seconds. We do not reproduce the technique.
No federal rule ever required rolling code. Neither 16 CFR Part 1211 nor FCC Part 15.231 covers how a remote encodes its signal. Rolling code was a manufacturer response to a demonstrated weakness, never a safety regulator’s mandate.
What does this page claim, and what not?
Remote security and entrapment safety are two stories that share a decade. Keeping them apart is the point of this page.
That story is 16 CFR Part 1211 and the photo-eye or edge-sensor rule. Our pre-1993 opener study and photo-eye study cover it. This page is about remote-control radio security, a separate problem with a separate history.
We say that a public proof-of-concept exists, who published it, when, and roughly how fast it worked, with a link to the researcher’s own writeup. We do not reproduce frequencies, timing sequences, code values or step-by-step instructions.
We looked. CPSC’s garage door opener standard does not cover it. FCC’s transmitter rules limit how long a remote transmits, not how its code works. Rolling code is a market and patent-lawsuit story. Calling it regulated would be a claim we cannot support.
The practical risk from a legacy fixed-code remote is someone getting in, not the entrapment hazard covered elsewhere on this site. Makers stopped shipping fixed-code home openers decades ago. The exposure is in remotes and receivers that have never been replaced.
Manufacturer marketing states very large numbers for rolling-code systems. We found none from a technical, non-marketing source we could confirm, so we do not repeat one.
CISA’s 2023 Nexx advisory concerns hardcoded cloud credentials, an app and cloud failure, not radio replay. We include it so the picture of garage opener security today is not stuck in 1994. See our smart opener security study.
When did garage remotes change from fixed code to rolling code?
Between 1994 and 1996. Each event below has its own source: a patent record, a trade association page, a court opinion, a researcher’s own account, or a federal advisory.
Through the 1980s and into the early 1990s
Fixed code is the market standardA bank of physical DIP switches in both the remote and the receiver sets a code. There are typically 8 to 12 switches, giving 256 to 4,096 possible combinations. The remote sends that same value every time. It let installers match a replacement remote to the receiver, for convenience, not security.
Fall 1994
Anti-code-grabbing technology is announcedDASMA’s retrospective says that in fall 1994, Street Smart Auto Security introduced a garage transmitter/receiver that “randomly changes the digital code with every use”. The aim was “to thwart high-tech thieves who could record the transmitter’s radio signal and play it back later.” It is the earliest dated anti-replay product we could verify.
May 17, 1995 (priority date)
Chamberlain files the patent behind Security+US Patent 6,154,544, “Rolling code security system,” has a priority date of May 17, 1995 and a filing date of June 11, 1997. It was granted November 28, 2000 to inventors Bradford L. Farris and James J. Fitzgibbon, assigned to Chamberlain Group. We checked the patent record directly.
1996
Security+ reaches the marketChamberlain calls its rolling-code system Security+. Through the late 1990s, other makers introduce similar systems, often sold as “rolling code,” “hopping code” or “Intellicode”. This was a manufacturer response to a known weakness. No regulator required it.
August 31, 2004
Chamberlain Group v. Skylink Technologies, 381 F.3d 1178 (Fed. Cir.)The Federal Circuit rules against Chamberlain in a Digital Millennium Copyright Act (DMCA) case. Skylink’s Model 39 universal remote could open Chamberlain’s Security+ openers without using rolling code itself. The court held that an opener’s owner is authorized to access its software, so Skylink did not unlawfully get around an access control.
June 4, 2015
OpenSesame is published: a working proof against fixed codeSecurity researcher Samy Kamkar publishes a device built from a discontinued children’s toy. It opens a fixed-code garage door by sending every possible 8-to-12-bit code as one overlapping de Bruijn sequence. That takes about 8 seconds, down from roughly 29 minutes by brute force. Kamkar says it fails against rolling code and recommends upgrading.
August 2015
RollJam targets the newer technology insteadAt DEF CON 23, Kamkar shows a second device, RollJam, that beats rolling-code systems in car remotes and garage openers alike. It jams and records a transmission, then later replays the intercepted, unused code. It is a different attack from OpenSesame’s brute force. Rolling code closed the fixed-code replay hole, but not every hole.
April 2023
A new kind of weakness: hardcoded cloud credentialsCISA advisory ICSA-23-094-01 lists five CVEs (CVE-2023-1748 through -1752, CVSS scores 6.5 to 9.3) in Nexx smart garage controllers. Hardcoded credentials, authorization bypass and weak authentication in the maker’s cloud service let an attacker control any customer’s door. This is a cloud and app failure, not a radio code issue.
What is a fixed code, and why does it fail?
A fixed code is a signal that never changes, so anyone who records it can reuse it. A garage door remote is a small radio transmitter. Pressing the button sends a short burst on an unlicensed frequency, commonly 300–400 MHz for US home openers.
The receiver in the motor unit (the powerhead) acts on the signal if the value matches what it expects.
On a fixed-code system, that value is set once by a bank of DIP switches inside both the remote and the receiver. There are typically 8 to 12, each a simple on/off toggle. Eight switches give 2⁸ = 256 possible settings; twelve give 2¹² = 4,096.
Whatever the switches say, the remote sends that value every time the button is pressed, for as long as the remote exists.
HyreGarage analysis: this is not careless engineering. It is simply what a fixed code is. Any system where the same signal always opens the same door can be beaten by a device that records the signal once and plays it back. That is called a replay attack.
The DIP switch design was never sold as tamper-proof. It was sold as configurable, so an installer could match a replacement remote to a receiver in the field without special tools. The same design that made a remote easy to match also made it easy to copy.
The number of possible codes matters too. 256 or 4,096 sounds like a lot until a machine, not a person, is trying them. A patient person with a universal remote could already step through a small fixed-code space.
What changed by 2015 was a purpose-built device that could step through every code of a 12-switch system in seconds, not hours. That turned a theoretical weakness into a demonstrated, practical one.
How many codes can a fixed-code remote have?
Between 256 and 4,096 on common remotes. The count is two raised to the number of switches. The chart uses a log scale because the range spans two orders of magnitude.
| DIP switches | Possible codes (2^n) | Commercially common? |
|---|---|---|
| 6 switches | 64 | Less common, but the same principle applies |
| 8 switches | 256 | Yes, a widely sold configuration |
| 9 switches | 512 | Less common, but the same principle applies |
| 10 switches | 1,024 | Less common, but the same principle applies |
| 12 switches | 4,096 | Yes, a widely sold configuration |
HyreGarage computation. A fixed code’s security depends entirely on how long it takes someone to try every value in this column. Rolling code avoids the whole calculation by changing the value sent on every use, instead of relying on a large fixed code space.
How does rolling code work?
In outline, at the level Chamberlain’s own public patent describes it. Enough to explain the idea, not enough to act as a specification.
A code that changes every time
The abstract of US Patent 6,154,544 describes a signal with a fixed part and a part that changes on each press. So the exact signal sent is different every time, even with the same remote and receiver.
A window, not one expected value
A remote can be pressed out of range of the receiver: a pocket press, or a press while traveling. So the receiver cannot demand only the next value in sequence.
The patent describes a window of acceptable next values ahead, and a rejection window behind. It accepts a remote that legitimately skipped ahead, and rejects an old, already-used value.
Why a recorded signal does not work twice
Once a value is accepted, the receiver moves its expected position forward. A device that recorded that signal and replays it later is sending a value the receiver has already used. That is the exact failure a fixed code cannot avoid.
What do the terms mean?
- Fixed code
- A remote system where the signal never changes. On older home openers it was set by a bank of DIP switches, giving as few as 256 to 4,096 combinations.
- Rolling code (also "hopping code")
- A remote system where the signal changes on every use, following a shared formula known to both remote and receiver. A recorded signal cannot be replayed later.
- Replay attack
- Recording a real transmission and sending it again later to get the same result. It is the weakness a fixed code cannot avoid by design, and the one rolling code was built to close.
- DIP switch
- A small bank of physical on/off toggles that sets a fixed binary value. "DIP" stands for dual in-line package, which describes the switch’s physical shape, not anything about security.
- De Bruijn sequence
- A math technique that packs every possible short binary string into one long overlapping sequence. Testing every code then takes far less transmission time than sending each one separately. Kamkar’s OpenSesame used it to finish its search in about 8 seconds.
- FCC Part 15.231
- The federal radio-interference rule for occasional transmitters like garage remotes. It includes a 5-second maximum transmit time after release and limits on periodic transmissions. It governs spectrum use, not code security, and does not require or mention rolling code.
Is rolling code required by federal law?
No. Rolling code did not arrive the way entrapment protection did, through a statute, a CPSC rule and a compliance deadline. Our UL 325 timeline documents that kind of regulatory history for a different feature of the same product.
CPSC’s rules for garage door openers, at 16 CFR Part 1211, cover entrapment protection: whether a closing door detects an obstruction and reverses. We reviewed the current section list of Part 1211. Nothing covers remote transmission, encoding or radio security in any form.
The Federal Communications Commission does regulate the radio in a garage remote, but for interference, not security. 47 CFR § 15.231 says “[a] manually operated transmitter shall employ a switch that will automatically deactivate the transmitter within not more than 5 seconds of being released.”
It also limits periodic and polling transmissions to short total times per hour. People sometimes mistake this for a security rule. It is not one. Nothing in the text we retrieved requires, specifies or even mentions a changing code.
HyreGarage analysis: that makes rolling code a market-driven and, later, lawsuit-driven change. DASMA members, and Chamberlain in particular, spotted a demonstrated weakness (fall 1994, per DASMA’s own account). Chamberlain built a patented answer (priority date May 1995), and it became a competitive advantage worth defending in court.
Chamberlain v. Skylink was a fight over whether a universal remote maker could sell a device that opened Chamberlain’s rolling-code openers without using rolling code itself. The Federal Circuit sided with the universal remote maker on DMCA copyright-circumvention grounds. It made no safety or security ruling.
No regulator forced this change. The industry made it because it worked, and because customers who bought a security feature expected it to be secure.
Has anyone actually opened a garage this way?
In public demonstrations, yes. Saying a fixed code “can be replayed” describes a design property. It does not prove anyone has done it outside a lab.
The clearest dated public demonstration we could verify is Samy Kamkar’s OpenSesame, published June 4, 2015. It is a Radica Girltech IM-ME children’s texting toy, modified with a cheap radio chip. It sends every possible code for an 8-to-12-bit fixed-code remote as one overlapping sequence, finishing in about 8 seconds.
Kamkar’s own account says plainly that it targets fixed code only and does not work against rolling code. He recommends upgrading to rolling code, hopping code, Security+ or Intellicode. We link to his writeup rather than a summary, and we do not reproduce his method.
Two months later, in August 2015 at DEF CON, Kamkar published a second, unrelated device, RollJam. It targets rolling code itself, in car remotes and garage openers alike.
RollJam does not guess a code. It blocks a real transmission from reaching the receiver while secretly recording it. The next time the owner presses the button, it replays the intercepted, never-used code and keeps one valid code in reserve.
That is a real weakness in rolling code, but it is a different attack (jamming plus interception, not brute force) against a different target. Rolling code still solved the problem it was built for, the fixed-code replay hole. It left a different hole open, a common pattern in security engineering.
For a homeowner today, the two demonstrations point in different directions. If your remote is truly fixed-code (DIP switches, no rolling-code branding), OpenSesame-style replay is the documented risk. The fix, available since the 1990s, is a rolling-code remote and receiver pair. Our opener selector helps you choose an opener.
If your opener already uses rolling code, RollJam-style interception is the more relevant risk, and much harder to pull off casually. There is no simple consumer fix beyond the usual advice: do not leave a remote clipped to a visible visor in an unattended car.
What could we not verify?
The exact date fixed-code home openers stopped shipping. Rolling code arrived in 1994–1996 and became dominant through the late 1990s. Retail sources describe Chamberlain-family "Orange/Red Learn button" units from roughly 1997–2005 as the first rolling-code generation.
We found no single date after which no US maker shipped a fixed-code home unit, and we did not guess one.
A verified modern rolling-code combinations figure. Manufacturer marketing states very large numbers. We found no technical specification, separate from marketing copy, that we could verify, so we do not repeat one.
How many American garages still use a fixed-code remote. No federal dataset counts garage door openers at all, as our pre-1993 opener study shows for a different question. Manufacturers do not publish installed-base figures by code type.
Whether OpenSesame led to real burglaries. We found no CPSC recall, CISA advisory or court record tying OpenSesame-style attacks to an actual crime wave. It matters as the first public proof of a weakness that had been described but not shown. It is not evidence of widespread abuse.
One thing we chose not to publish: a walkthrough for opening up a remote to check for a fixed code, or any check beyond looking for rolling-code branding. Even a homeowner’s checklist can double as a guide to picking targets.
Questions
What is a fixed-code garage door opener?
When did garage door openers switch to rolling code?
Is rolling code required by federal law?
Can someone open a fixed-code garage door with a recorded signal?
What is OpenSesame?
Is RollJam the same as OpenSesame?
What was Chamberlain v. Skylink about?
How do I know if my opener uses fixed code or rolling code?
Are hacked garage door openers a common crime?
Is this the same topic as garage door entrapment protection?
Written and audited by
HyreGarage Research Desk
Primary-source research, data analysis and fact checking
We are not a garage door company. We read the agency file, the code record, the standards document or the public register ourselves, compute the figure from it, and publish it with the source and the date we retrieved it.
Where a number cannot be traced to a primary source, we publish the shorter page and say what we could not verify. Our own company records cover ten states; nothing national is ever derived from them.
- 10
- states our own company records cover — and the limit of any claim made from them
- 3,901
- garage door companies in the store
- 457
- license records verified against a state board
- 0
- national claims made from a ten-state store
How this desk works
- Primary sources only. Injury counts come from CPSC. Housing counts come from the Census file, not from a summary of it. Code history comes from the building commission that adopted the code. We do not cite an article that cites a source; we retrieve the source and do the arithmetic ourselves.
- Every figure carries its retrieval date. Registers change, datasets are revised and codes are amended. A number without the date it was read cannot be checked, so every study states one.
- Fact, calculation and analysis are labeled apart. A quote is a quote, a HyreGarage computation says so, and an interpretation says “HyreGarage analysis”. Presenting our reading of a dataset as something the agency stated would be the easiest way to lose the only thing this desk is for.
- Limitations go above the fold. If a figure is an upper bound, a bracket, or an association rather than a cause, that is said before the figure is quoted rather than in a footnote underneath it.
- No DIY instructions for spring, cable or track work. Those components hold enough stored energy to cause serious injury, and CPSC records the consequences. We describe what has failed and what a competent repair involves; we do not tell you how to do it.
Data as of US Patent 6,154,544, 47 CFR 15.231 and CISA ICSA-23-094-01, retrieved 2026-09-06. Authorship on this site is organizational: the analysis belongs to the desk rather than to a named individual, and we do not publish credentials we do not hold.
Our editorial policy sets out how we source, date and correct what we publish.
Sources & retrieval dates
Not sure whether your remote is fixed code or rolling code?
A professional can tell which technology your opener uses in minutes. If it is an old fixed-code system, the usual fix is a new remote and receiver. Matching is still being built, so nothing goes to a company unless you agree.
HyreGarage is not a garage door company, security firm or manufacturer, and does not perform, supervise or warrant garage door work. This page is a historical and regulatory account. It links to researchers’ own published work. It does not describe, demonstrate or endorse any way to access an opener without authorization.