Subscriber Discussion

iCLASS Credential ID Sharing Risk?

UE
Undisclosed End User #1
Nov 17, 2021

Is there a risk to sharing the credential number of a HID iClass Dl card ? A client has been asked to share this information with a vendor (Food Machine vendor) The vendor has access to a current iClass so would then also have access to the facility site code as well.

Is it possible to take all of this information and clone a card with out having access to the physical card ? We are not sure if providing this information is a security risk.

Avatar
Brian Rhodes
Nov 17, 2021
IPVMU Certified

** ***** * **** ** ******* the ********** ****** ** * *** iClass ** **** ? * ****** has **** ***** ** ***** **** information **** * ****** (**** ******* vendor) *** ****** *** ****** ** a ******* ****** ** ***** **** also **** ****** ** *** ******** site **** ** ****.

** *******, ***** ** ** ****** this **** ***** ** ****** ** shared. ***** *** ****** ******** ***** assigning * ********* ********** ** * visitor *** **** ************ ** ***** access ** ******. ************,****** **** *** *** ******** *****.

*** **** ** ********* * **** that ******* * ***** **** ** low, *** *** ****, *** * wouldn't ********* **. ********** ** **** voice ** *** ** ********, ******* credentials ** *** ******.

** ** ***********, * ***** ***** a *** ** ******* ** **** to *** *******. ***** *** ***** potential ******** **** **** ****, *** I ****** ***** *** ***** ****** info.

(3)
UE
Undisclosed End User #1
Nov 17, 2021

***** * *** *** ******* ** detail **** ** *** * ******** vending *******, *** *** **** ** wanting ** ****** *** ****** **** the ********** ******* ** **** ********* at **** **** *** *** ****** badges ****** **** ****** ** ***** cash ******. **** *** ***** *** card *** ******* **** ** ******** from ***** ******. *** ****** **** be ** ****** ** ********** *** software *** ******** *** ********* *** data **** **** ***** ***** *** credential **** ** ** ********.

Avatar
Brian Rhodes
Nov 17, 2021
IPVMU Certified

**** ******, ***** *** ******* ********* containers/groups ** **** ** *** ****, per ****** ****. *******, *** ***** serialize ******** ******** ***** **** *** this **** ** *********** *** *** would *** **** ******** ******** ****** data ** ** ******* ********.

** *** **** ** *** *** using ****** **** *****?

UE
Undisclosed End User #1
Nov 18, 2021

******* ** *** ***** **** **** list *** ****** **, ** ************* is **** **** *** **.** *** based. **** *** **** **** *** a *** ***** *** **** ** the ******* ******* ***** **** **** to *** **** ** ***** *** be ********** **** ** **** ***** not **** ***** ** *** ***** card ******.

RB
Ramsey Burns
Nov 18, 2021

**** ******* *** *** **** *** there ** ** ****** ** **** as **** *** ** ********* ********. The ****** ******* ****** ** ****** cards ** ***** *** *** ******** code *** **** ******* *** ****** and, **** **** **********, ** ** open-read *** *** ** ****** **** by *** ****** ****** ** ******** type. ** *** **** ******* ****** could ****** **-****** ***** **** ***** reader/controller, ****** **** * **** ** names/card ******* **** ** ****** **** the ****** ** ***** ****. ******* are **** *** ********* **** **** get ******** ******** *** ** *** in *** ******* ******.

**** ******** ******** ******* **** *** a ****** ****** ** ** * smart **** (********* ******** ****** ** well ** ****, ******, *******, ***) that ***** *** ** ******** ******* having *** ***, *** *** ***** system **** **** ****, ********** **** they ***'* **** ** **** ***** of ****** *******, ****** *** **** times *** **** **** *** *********.

***** *** **** ** **** ****** from ***** **** ** **** *** actual **** ******, *** ***** *** not **** **** *****. **'* **** true **** ** *** *** *** using * * ******/**** ******** ****** or * ********* ******** **** (*.*. Corp1000), **** ******* *** ** ***** the **** **** ****** & ******** code *** *** ** ***** ** card *******. **** ** *** ** use *****-****** ************** *** ****** ************.

(1)
(1)
Avatar
David Clarke
Nov 24, 2021

* **** ** *** **-**** **** programmer - **** ** * *** clone **** *** **** **** ** not ***** ******* ****. ** **** use **** **** *** ***** *** not ** ****** ****** *** **** the *** ****.

*** ***** ******** ***** *** **** technology *** ***** *** ******* *** food ******* **** * ********* ********** - ** *** **** / **** cards *** **** *** *** **** info ** ******.

(1)
RB
Ramsey Burns
Nov 24, 2021

**** **** ***** *** *********. ** your **** ********** ** ** *** size, ****** ** *** * ****** that *** *** ** *********** **** on ******/******. *** ******* *********** **** will ** *** ****** ** *** ongoing **** ****. ****** ****...

(1)
Avatar
David Clarke
Nov 24, 2021

**** *****. * **** ****** ****** to *** ** *** *** *********** area ** * **** *** ***** never *** *** ** ******* **** or *** ** ** **!

RB
Ramsey Burns
Nov 24, 2021

**'* **** ***** ***** * ***** with ** *** *** **** ***** is * ******** *** **** ****** be ******* ***. * ***** **** of *** ******* *** **** ***** you *** *** ***.

Avatar
David Clarke
Nov 24, 2021

******! * ** ***** ** **-**** this ** *** *** ****. ** have **** ******** *** ******** ** Aero *** *** **** *** ******.

(1)
RB
Ramsey Burns
Nov 24, 2021

*** ** **** *** ****** *** the **** *** **** *** **** why *** ****** *********** *****, ***** is *** ** *** ***** ******* points ** **** ********? ******* ******/******* is ***** *********. *'* **** *** technical ******* ***** **** *** **** this **** *** ** *** ****** an *** *******.

(1)
Avatar
David Clarke
Nov 24, 2021

* **** **** **** ** *****. I ***** *********** *** ****** ************ are ********* ******* ******. **** **** Vertx *** **** ******* *** ********* groups. *'* ***** ** *** ****** this ****.

RB
Ramsey Burns
Nov 24, 2021

**** ** ** *** *** ***** this ***** *** **** ********* *** I ***** ** ***** ***** ***** more ********** ******* (**** **** **** platform ********) :)

UI
Undisclosed Integrator #2
Nov 24, 2021

**** ****** ******* ********.

*** **** ********* ** *** ****** areas ** *** *****?

*** **** ********* **** ****/********** **** is ** *** *****?

,

(1)
RB
Ramsey Burns
Nov 25, 2021

*** * ***** *** **** *** exception ** ******** **** **** ****** 'out ** *** ***' (*** ******, STid ********, ***) *** **** ******** of ******* ***'* *** ****** *****.

*'** **** **** ******* **** ******** have *** ********** ** ***** ****** sector **** **** *** ***...**** **** they **** ******* *****!

UI
Undisclosed Integrator #2
Nov 25, 2021

*****!

New discussion

Ask questions and get answers to your physical security questions from IPVM team members and fellow subscribers.

Newest discussions