"MOST Readers Still Had PROX Turned ON!!!" Says HID Mobile Credential Director

Mert Karakaya
Nov 17, 2023
IPVMU Certified

Related: Prox / 125 kHz Access Control Credential Usage Statistics, HID Standard Profile Makes 13.56 MHz SE / Seos As Vulnerable As Cracked 125 kHz For Downgrade Attack, Integrators Are Responsible For HID 13.56 Mhz Downgrade Attack Using Multiclass Readers

*** ****** ********* ********, **** ************* ** ******** ****** ** ****** readers ************, ******** ** **** *** *******, and "**** ******* *** **** ****** on."

IPVM Image

****** **** ********* ******* (******** *******) on *** ******* **** *********** ********** to * ********* ****** (****** ******** ******* ***** **.** *** SE / **** ** ********** ** Cracked *** *** *** ********* ******).

******* **** ** *** ******** ***** (embedded *****), "*** **** **** ** unbelievable ****** ** **** ******* ** these ********* *****-******* ****** *********."

*** ** *********** *** ***** "*******" prox ********** *** ****** *******? ********?

John Honovich
Nov 17, 2023

****** **** ********* ******* (******** *******) on *** ******* **** *********** ********** to * ********* ******

** ****** ********** **** *** ********* take ***** ***** ** **** **** the ****** *** *** *********.

* ******* **** ******* ** *****, but **'* ** ******* ****-*** *** HID ** * *****.

Undisclosed #1
Nov 19, 2023

** ****** **** ******* ****** * problem ** *** ***/****** ******* ******** doesn't **** *** **** ******** ******* and *******? * **** *** ******* you **** ** ******* *** ****** and **** **** ** ***** *** a ********** ** ****. ***'* **** pretty ******** ****** ***** ********?

Mert Karakaya
Nov 19, 2023
IPVMU Certified

*#*, *** *** ******* **** *** requires **** ****** *** **** **** to ****** ***********; ******* ********* **** not ******* *** **** **** (**. Seos, ******, ** ****).

** ********** **** ****** ******* ******* ******, ** ****** **** **** *** be ********** ** ****** ****.** *** **** *****, ** **** ******* (******* '******* ** *******' ******) ** ****** *** **** ********** in ****** ****** *** **** **** to ********* ** ****** *** **** access. ** **** **** **** **** a **-*** **** **** ** ****** format ** ****** ** *** ****** differentiates ******* ** & ** ********** types.

** *****, ******* **** *** *** card ****** *** **** ****, *** various ***** ** *********** *** **** in *** **** *******. *** ******* validate *** **** ** ***********, *** if *** ***** *** ******* (****, iClass, ****, ***.) *** *** **** data *** *** ****** (******, ******, etc.) ***** *** ** *** ******** credentials ** *** ******, *** **** will ** ******* ******.

Undisclosed #1
Nov 21, 2023

******* ********* **** *** ******* *** card **** (**. ****, ******, ** Prox).

** ***** ****'* * ******** ****** flaw? *'* **** *** ********** ***'* tell *** ******** **** ****** ** is, *** ***** *** ****** ** controller ***? ** ***** *** ** additional ***** ** ********.

Mert Karakaya
Nov 21, 2023
IPVMU Certified

** *** ****** *** *** ********** are ************* **** *******, **** **** data ** **** **** *** ******. If **** *********** **** ****, ********** data **** ** **** ****, *** be ******** ****.

**** ****** ****** ******* ******** **** *********.

Undisclosed Integrator #2
Nov 22, 2023

*** ************* *******, *** ****** **** not ****** *** ********** **** ** standard ******* ** **** **********.

*** **** ** **** *** *** upgrade **** **** *********** ** ********* like **** **********. *** ******** ** that *** *** ********* **** **** credentials ** **** **********.

**'* ** ** *** ********** ** configure *** ****** ** *** ******* prox, ** ** ***** * ***-**** SKU.

New discussion

Ask questions and get answers to your physical security questions from IPVM team members and fellow subscribers.

Newest discussions