Hackable 125kHz Access Control Migration Guide

Author: Brian Rhodes, Published on May 19, 2017

Despite being one of the most popular credentials, 125 kHz credentials are easily copied and insecure as we showed in our test results, video embedded below:

However, changing to more secure credentials is not always a clear path, and doing it can cost thousands of dollars for even smaller systems.

In this guide, we cover the most common migration paths and examine the pros and cons of each, so you can help choose the best path forward.

This guide covers:

  • The 3 Most Common Migration Paths
  • Pros & Cons of Each Method
  • Biometrics Option
  • HID Global Formats More Costly
  • 13.56 MHz Read Ranges Shorter
  • Changeover Cost Is The Biggest Factor

******* ***** *** ** *** **** ******* ***********, *** *** credentials *** ****** ****** *********** ** ** ****** ** *** **** *******, ***** ******** *****:

*******, ******** ** **** ****** *********** ** *** ****** * clear ****, *** ***** ** *** **** ********* ** ******* for **** ******* *******.

** **** *****, ** ***** *** **** ****** ********* ***** and ******* *** **** *** **** ** ****, ** *** can **** ****** *** **** **** *******.

**** ***** ******:

  • *** * **** ****** ********* *****
  • **** & **** ** **** ******
  • ********** ******
  • *** ****** ******* **** ******
  • **.** *** **** ****** *******
  • ********** **** ** *** ******* ******

[***************]

The ***** ****

*** **** ***** ** *** *******: *** **** ****** *** kHz **** ******* **** ** ****** *** ********** ***********, ** copying **** ** **** * ****** ** * *** ******* and ***** * *** *******. ***** *** **** ****** ** these ******** *********** ** ******** ***, *** **** **** ******* are **** ** ***** **** ******** ********** ** * **** issue *********.

Three ********* *****

*** ******** ** ***************: **** ***** *** *** ***********. ***** that *****, ****** ********* ******** ******* ********** *** ********* ******* of **** ******* ***** ********* ** ***** ********* ******* ***** them * ******* ***********.

*******, ***** *** * ****** ** ******* *** ********* *******, each **** ******* ***** *** ********* *** ********:

  • ****** ***** & ******* ***********
  • ******* *****-******** *******, ********* ******* *****
  • ******* ******** *******, ********* ******* *****

*****, ** ******* **** ****** ** ***** *** ***** *** pros **. **** ** **** *********** ***** **** ** **** for ******** *******.

HID ****** ******* **** ******

*** *** ************* **** ********* **** **** ****** ******* ** deciding ***** **.***** ****** ****** ** ******* ** *** *****? The *** **** ****** ******* ***** **** **** *** ********* vendors:

** *******, *** ****** ****** ** **** ********* ** * per-reader *** ***-********** ***** ******** ** ******/*******. *** ****** ** the **** ********** ** ******* *** ** *********, ** *** HID ******* ** ********, ** *** ************ ********, ** *** or ***** ****** **** *****. ** ********, *** ***-*** ******* are '**** ***' *** *********** **** *** *** ************ ** build ******* ******* **** **** ** ********* ****.

*** ****** ******* ********** ******* ****** ****** ******* ****** ***** on ********** **** *******, *** *** **** ********** ********* ****** 10% - **% **** *** *** *** ********. *******, ********** in ***** *******, *******, *******/******* *******, *** ******* ************ *** be ****** *** *** *** ******* *********** ****** ***** ** that ******. ********* ** *** *****, ***-***** ******* *** ** more *******, *** *******/******* *** ** **** *********.

*** ******** ******** ******* *** *** *******, *** ***:*** ** *** ***************.

13.56 *** **** ****** *******

**** ** *** *** **** ********** ******* ***********. ******* **** range ****** **** ** ************* *********, **** *** ***** ********* 125kHz ****** ******** ****** *********. ***** *** ******* ***** ** not * ******* ****** *** **** ***** ** ******* ***** applications ***** ***** **** **** **** * ****** **** **** the ******, ***** **** ********* **.***** ******* ****** **** ** ranges ****** *** ******* ****** ** ******* **** ************.

*** *******, ******* *** **** ***** ************ ** ** **" **** ******** *** ******* ***********, *** their**.** *** **************** ***** **" *** **** ********* *** ** **** ********** *** **************** *** ****** ****** ******* *** **** ***********.

Pros & **** ** ****

******** **** *** ***** *******, *** **** ****** *** ******* but ******* **** *** ****** ****** ****** ** ********* *********** of **** *** *** ******* *** **** *****, ***** *** least ********* *** *********** **** *** **** ********** ****** ** simply ******** * **.** *** ****** ***** ******** ***** *** begin ******** *** ***** ** ***** ** ******.

*** **** *** ** *** ****, ********** ******** ***********, *** low ****** ****** ** ** *** * *********** ****** **** can **** ******** **** *********** *** *******, ***** ****** '*****-********' readers. **** ***** ***** *** *****-****:

** *** ******** *****, ** ******** **** **** ** *****.

One: ******* *** ***** & ******* ***********

**** ********* **** ** *** **** ******, *** ** ****** the ******** *** *** ******* ** ********* *********** ** *** system ******* *** ***** ** ****. *********** ********** *** ** 125 *** *********** ***** **** *** ******* **** **********, *** such * ******* **** ******** **** ********* ****** *** ******* coordination ** ********* ******** *** *** ****** *********** **** *** replacement **.** *** *****.

** *******, * ****** **.** *** ****** *** **** $*** - $*** *** * ****** **** ***** ***** $* - $7 ****** ********** ************, *************, *** **** ******** *****, ** even * ******* ****** **** **** **** * ***** *** 50 ***** *** *** **** *** ********* ** *******, *** large **********/ *****-**** ******* *** **** ******** **** ** *********.

** ******** ** *** ****, ********* ******** *** *** ******* means ******** *********** *** *** *****, ** ******* *** ******** a ******* ***** ***** ********* *** ******* *** *********** **********. And ****-***** ************ *** **** ** ** **-********** ********.

** * ******, *** '******* ********** ** ****' ********* ** typically **** **** ** ******* ******* ***** *** **** *** logistic ****** *** *****.

Two: ******* *****-******** *******, ********* ******* *****

**** ********* **** ** ***** *** *** ****, *** ***** and ******** *** ***** ** *********. **** *** ***** ******, option *** ******** ********* *********** ** *** ******* ** * new ****** **** ********** **** *********** ** ****. ***** ****** 'multiclass' ** '***************' *******, ***** ***** *** **** ****** ********** frequency *** ******** *******.

***** **** **** ** ****** ***** **** ****** *********** *** be ******** ** * ******* ***** ****** **** *** ** once, ***** ******** * *** ****** *** *** ********* ******* of *********** *********** ** * ********** ********.

***** *** **** ** ***** ******* ** ***** ****** ** a ***-**** ***** ******** ** * ****** ********** **.** ***-**** unit, *** ******* ** ****** ** **% - **%. *** price ********** ** ********* ******* *** ***** **** *********, *** spreading *** *** ******* ** ********* ********** ***********, **** ** the **** ** ********** ******** *** *** ******* *** ****** or ***** ****, ** ********** *** **** ******** ********.

Three: ******* **** *******, ********* ******* *****

*** ***** ****** ** ***** *** ***** *********, *** ******** disciplined *********, ******* ****** ********, *** ***** ******* ******** ***** used: ******* * *** ****** **** ** *** *** ***.

**** ** ******-**** ******* ** ***** **** **** *****-********/********** *****, and **** *** ** ********* ******* ********** ********** ** *** existing ******* *** ***********.

*******, ********** *********** ******* **** **** *****, **** **** **** use ********* ***********, *** ****** **** ***** *********** ** **** unit. ********* ** ***** ** *** ****** **** ***** *** or ********* ********* **** **** ***** ** ***** * ***** trial ********.

** *********** ** *** ** *****, ********** *** **** **** prove ** **. ******** ********** ******* **** ** **** ***** creates ** ********* ***** *** ***** ***, ******** *** *** and *** **.** *** ******:

********, **** ********** ******** *** *** ******* **** **** *** reader *****, *** ********, ***********, *** ******* **** ********** ********* of *** ****** *** ** ********.

*******, *** ******* ** **** ****** *** ***** ******** ** no ***** ******* ********** **** ****** ************, *** ********* ** new *********** *** ** **** **** ** ***** *******, **** whatever **** ** ****** ********** ** ********** ** *** *** kHz **********.

Considering ********** *******

*** **** *******, *** *********** ** ******* *** ******** ***** credential ***** ********, **** **********. ***** *** **** ** ******, palm, *** **** ******** **** ********* **** *** **** ******, the **** ** ***** ****** ***** *** ********* **** **** 13.56 *** ************, *** **** ***** ******* *********** ******* *** user ********** *** **** ******** ** *** ** ******** *** the *** *******.

***** **** ***** *********** '**** *****', ***** *** ***** *********** or *********** ****** **** ********** ***** *********** **** ** ******* or ****** ************, ******* ********* ******** ******* ** *** ******* (and **** ******** ******** **** ******), *** ** **** ************* additional *********** **.** *** *********** *** ******* *** *********** ** certain ***** **********.

******* ** *** **** **** *** ********* *********** ******, ********* from *** *** ** ********** ** ********, ******** ********* ******** of ***** *********** ****** * **** ******** ****** ******* ****** copying ** ********** ******.

Changes **** *****

** *** *** *** ******** ****** *******, ******** **** ********* limits *** **** ********* *******. *** ***** *** ******** ******** often *** ****** ** ***** *** **** ** *** *** products ******* *** **** ** ********* **** **.

*** **** *****, *** **** *** ********* ** *** ***** to ******* ******** *****, *******, *** ********* ** ***** **** copiers *** ******* *** ********* *** *****. ******** ******** ****** now ******** *** ********** ** ******* ************ ********** *** '**** tech' *** *** ***** ** **** ** ******* '*** ****' duplicate ********** **** *** ** *** ******** ** *** *** retail *****.

Next **: ***** **.** *** *** ******?

** ******** *******, ** **** **** ********* **.** *** ******* to *** ***** **** *** ********** ** ******* ** ******** attacks ***** ********** ******* ** *********** ******** ***** *****. **** for *** ******* ** ***** ****** ****** ** '****' *** if **** ***** *** *****.

Comments (8)

** **** *** **** *** **** ******* ** *** ** our ********* *** **** **** **. ********** ****** **** ***** boys, ******.

*** ****** ***********/**** **** ******** ***** ******* **** *** ******** to ***** *** ********* ******? **** ******** ** ******* ** "digital *************" ** *** **** *** ****** ***** ** ***% unless ******* ** **** ** * **** *** *** ** using **** ******** ******* *** *** ****** *** ******* ** be ***********.

**** *** *** ***** ** ******** *** **** ***** ***** the ******* ** ******* *** ** *** ************* *** ********? When *** **** **** *********** *** **** *** ****** ****** replacing *** ************* ** *** ** **** ****.

** **** ********* ******* ******** *******/******* *** **** ** ***** a **** **** ****. **** *** **** ****** ****.

**** **** ** ******** *** ****** ********** ** *** **** cards **** ****-****** *** *****, **** *********** * ******* ** begin ********* ******* *** *** **** ******* **** ****** ***** at +** ***** ********* **** *** *********, **** **** ****** points *** ******** *****. **** ****** * ********* ** *** security ****** **** *** *** *** *********** ******* *** ** be ******. ******* ** ******* ****** ****; **** *********** **** 6mths *** ******* ** ** ******* *** ********** **** (******, security *********, ***'* ***). ** ****** *** ***** ********** **** both ****** *******, ** *********** ** *** *** *****. ****-****: if *** ******* * *** *********** **** ****** *****, *****'* matter ** ****** **** * ***** (** **** ** ****** don't **** *** *** **** *** ****).

** *** ******* * *** ***********

#*, ****** *** *******. *** ***** **** *** ******* ******** or ********** ***** ********* * ***? ** ***** **** ** increase ***** / *** ************ ** ********. ** *** ***** hand, ********* ** *** ****** **** ******** ***** ** **, it *** ** ***** **.

***** *** *** *** **** ********** ******? * **** *** to ***** ****** **** ** ** **** *** **** ** is. * ***** ******** **** * *** ** ******* *** cards **** **** *** **.

****** **** ****** ********, *** **** *** *********** **********, ******* the **** *** ***** ** * ******** (***'* **** ********** for ******** *****).

*** ************ *** ****** **** ** ***** ** **** ** our ******** ********, ************ ** ******** ***** ******* ** **** business *****. **** *** *** ******** *** ****** ** ****** points ***** ****'* ********* ****** (**** **** *** ****/***********) *** only ***** **% ** ***** *** ******** ** *** ***********.

******* ********* *** ***** ******** **** *** ******** **** *** years, *** ****** ****** ***** ***'*. ***** *** *** ** roll-out ***** ** ******** ****** ** **** * *** *** and **** ** **** ** *** ********** ******* (**** **** signing ** *** * ****** ****).

**** **** ******** ** ** ********* *********** ** ******* *** PIN's *** ********.

**% ** ****** **** ******** ** ****** ****, **% **** tow *** **** ** ****** ****, **'* *** ****** **% you **** ** *** *** *** **** *** *** **** way ** ** **** ** **** * **** ********* *** comm ********.

******, **********. * ***** ** ** ** * *** **** helpful **** ************* **** *** **** ******** ** *** ********* on * ******* *****, *** **** **** ********* ** ********. If *** ******* ******** ********** *********** *** ***** ** ***** these ********* *** ***** ****, *** *********** ***** **** *** their ************* *** ********** ** *** *******, ****'** * *** more ****** ** *** *** ****. ****'* *** *** ******* a *** *********, *** ********* *******, *** **** ****** **** like ****'** **** ** *** ********, *** **** * ****** of **.

Login to read this IPVM report.
Why do I need to log in?
IPVM conducts unique testing and research funded by member's payments enabling us to offer the most independent, accurate and in-depth information.

Related Reports

Axis Criticizes OEMs: "When You Buy An Axis Camera, An Axis Camera Is What You Get!" on May 19, 2017
When you buy a Honeywell camera, you likely get a Hikvision, Dahua or some other company's product. The same goes for easily 100 different...
Cisco: Hikvision Hired Us on May 16, 2017
The day after Hikvision's backdoor was confirmed by the US Department of Homeland Security, Hikvision issued a press release about a...
Technician Personal Protective Equipment (PPE) Guide on May 12, 2017
Technicians encounter multiple hazards when running wires and installing security devices. Wearing personal protective equipment, or PPE, helps...
Hikvision Blaming Backdoor On Others, Cannot Hide From DHS on May 11, 2017
Numerous Hikvision employees are blaming their backdoor on others but Hikvision cannot hide from the US Department of Homeland Security. Blaming...
Burglar Alarm Partitions Guide on May 10, 2017
Many burglar alarm systems have a single designated level of access for users. A user can arm or disarm the entire alarm by entering a single code....
Alarm Circuits Guide on May 09, 2017
Alarm circuits are a fundamental element of wired burglar systems. Designing the alarm circuit greatly affects its performance. In particular,...
Hikvision Backdoor Confirmed on May 08, 2017
The US Department of Homeland Security's Industrial Control Systems Cyber Emergency Response Team (ICS-CERT) has issued an advisory for...
Smartphone Controlled Kevo Lock Tested on May 04, 2017
Smartlocks are a growing market, with millions sold. Kwikset's Kevo is one of the most common choices, using the Unikey smart phone access control...
Hack Your Access Control With This $30 HID 125kHz Card Copier on May 01, 2017
You might have heard the stories or seen the YouTube videos of random people hacking electronic access control systems. The tools that claim to do...

Most Recent Industry Reports

Pelco Shutting Down Clovis Line, Laying Off 200 on May 22, 2017
Pelco's Clovis facility once turned out some of the industry's most popular products. Now, the facility is mostly building "obsolete" equipment,...
IP Camera - 15 Year Shootout on May 22, 2017
How far have IP cameras come? We bought and tested 4 cameras across the past 15 years to understand how much and where performance has...
Remote Video Monitoring Providers Directory on May 21, 2017
Remote video monitoring can help integrators generate RMR plus end users lower their security costs and/or improve response to critical...
Axis Criticizes OEMs: "When You Buy An Axis Camera, An Axis Camera Is What You Get!" on May 19, 2017
When you buy a Honeywell camera, you likely get a Hikvision, Dahua or some other company's product. The same goes for easily 100 different...
Hackable 125kHz Access Control Migration Guide on May 19, 2017
Despite being one of the most popular credentials, 125 kHz credentials are easily copied and insecure as we showed in our test results, video...
Forget The Backdoor, "ALL HIKVISION PRODUCTS" On Sale on May 18, 2017
Less than 2 weeks after the Hikvision Backdoor was confirmed, Hikvision has launched a sale "ON ALL HIKVISION PRODUCTS". In this note, we examine...
Amazon Techs Installing IP Cameras Tested on May 18, 2017
In 2015, Amazon started offering video surveillance installation. Now, Amazon has made it a lot easier, with automatic add-on options and...
Hanwha Recorder Vulnerability Analyzed on May 18, 2017
ICS-CERT has released a vulnerability notice for Hanwha SRN-4000 recorders.  Hanwha provided additional information to IPVM about this issue,...
DMP Video Doorbell / Access Reader Examined on May 17, 2017
Consumers increasingly demand video doorbells, with "doorbells selling like hotcakes, everyone wants a doorbell", according to ADT's CEO. At ISC...
ShotSpotter To IPO, Facing Low Revenue and Losses on May 17, 2017
A rare event for North American security manufacturers is upcoming. ShotSpotter is planning to IPO on the NASDAQ, aiming to raise $34.5...

The world's leading video surveillance information source, IPVM provides the best reporting, testing and training for 10,000+ members globally. Dedicated to independent and objective information, we uniquely refuse any and all advertisements, sponsorship and consulting from manufacturers.

About | FAQ | Contact