Axis Releases Access Credentials - Insecure But Convenient

Author: Brian Rhodes, Published on Nov 02, 2016

Axis continues to build out their own end-to-end 'solution'. The company recently announced a series of credential cards, but instead of a cutting-edge and high security type, they are promoting a format that is easily exploited with equipment bought off the internet.

But it may not prove to a bad move, and rather may make using more Axis access product easier, especially for novice installers.

Inside we examine the new card offering, explain why it is an insecure choice, but why that largely may not matter to most users.

**** ********* ** ***** *** ***** ******-**-*** '********'. *** ******* ******** ********* * ****** ** ********** *****, but ******* ** * *******-**** *** **** ******** ****, **** are ********* * ****** **** ** ****** ********* **** ********* bought *** *** ********.

*** ** *** *** ***** ** * *** ****, *** ****** may **** ***** **** **** ****** ******* ******, ********** *** novice **********.

****** ** ******* *** *** **** ********, ******* *** ** is ** ******** ******, *** *** **** ******* *** *** matter ** **** *****.

[***************]

**********

*** ********** ** ***********, *** *** *********** ****** *********** *****.

Axis' *** *********** ***********

**** *** ********* * **** *****-***** **.** *** *********** ********** *****, ** ** ********-******** **-** **** (*.* * *.* × *.** in). **** **** ********** *****, ************ ** ***, ****** ******* moisture, *** ***** *** **** ******** *** ******** *****. *** ***** *** ***** *** ******** *** ******** ** *********** imaging *** ******* ** ********.

***** ***, ****' ********* ** ****** ******* **** *** ********* of**** ********** *** **** *******, *** ** ***********. **** ******** ***** * *** ******' ***-**-*** ********* ********* ** ****** *******.

Card *******

****** ******* *** **** ***** *** ~$*** *** *** ** 200, *** ******** ***** ********. ********** ******* ** ~$*.** *** each.

**** ** ***** **% **** **** *******, ***-**** ******* ***** that **** ******* *************, ***** ****** ** ~$*.** ** ********, ********* ** ****** ** $*.**.

Based ** ******* ****** ** ******

******* ***** **.** ***, ***** ********** ***** *** *** *** high-security ************.

*** ***** *** ****** ******* ** ******, ***** **** **** long *******, **** *** ***** ******* ******** *** ******** ** NXP ** *** *** *****. ****** ******** ****, **** **** ********* **** ***** ******* ***, *** ** ********* *** ~$*** *** **** ** '*****' those *********** ** ***** * *******.

Axis ****** **********

*** ******* ******* ** **** ********** ***** ** **** *** specified ** ** ********** **** ****' *** *******:

  • *****-*: *** ******** **** ******* **** ****** ** * *****-*****, indoor/outdoor, **** ********** ***** **** * ****** ***** ** ~$***.
  • *****-*: *** ************ ** **** ***** *** *** ****, *** add * *** ****** ** *** ****** **** *** ******* *********** **************. ****** ****** *** ~$***.

********** ******** ** ***** *******, **** ******** ** ******* *** ********* of ********* ** '********' *********** ** ***** *******. **** ********** the ******* ** ******** **** *** ******** **** **** ***** with ***** *******, ** ************* *** ********** ** ********** *** ****** dealers ** ***-*****.

Not *** ********* *****

**** ***** *** ******** **** * **********, *** **** * *** *** **.** *** ******* **** iClass *** *** *********, ***** ***** **** ** *** ********* Axis ******* *** *** ****, **** ****** ** ***** ** properly ******* * ********** *** ***** ******.

** **** *****, ******* **.** *** *******, **** ***** ******** to **** *** ***********, *** ** **** ** **** *** most ***** '**** ****** ******' (***) ** **** **** ********* cards **** * ******.

Practical ***** ******** *****

***** '**** *********' ******* ******** ********** ******* **** **** **** cracked, **** **** ****'* ****** ******* **, *** ******* **** of ******** *********** ** ********* *** * ******* ** ******* by **** ***-***** *** *********** *** ************ ********** ******** *** **** **** ******/*********** ** **** *** *** *** formats.

******* ******* ** ****** ** *********, *** **** ** ******** MIFARE ******* *********** **** ** ************ *** **** ****** *****, who *** *** *** ****** ****** *** ****-***** ******* ******** to ***** **** * ******* ******* ******** ** **** ********* risks **** **********************, ****** **** ********.

Comments (7)

"*** ** *** *** ***** ** * *** ****, *** rather *** **** ***** **** **** ****** ******* ******, ********** for ****** **********."

*** ***** ******* ****** *********** **** ***** **** ****** ******* easier? ** *** **** ** ****** ** ***** *** ***** is *** **** ******* ****** ****.

****** *********** **** ****** ********* ******** *** *****'* ** ***** in ******* ***** ***********.

***, **'* *** * **** ***** **** ** ****' ****.

*** ** **** *** '* ***** ****'?

**** ***-***** ** *** **** *** *********** ******* ****** ** iClass ** ******* ** ******, *** **** *** **** ********* the **** ** ******* *** *****'* **** **** ** **** for.

**** *** * ***** ********* ** *********** ** ***** ****** products; ********, *********, ******, ***. *** ***** *** '***** *****'?

******** **** *** **** *** **** **** *** ********* ***** the ****. ****** ***** ***'* **** ** **** ******* *** Prox ***** ***'* **** ** ******/******* *******.

**'* ***** ** **** ******** ******* **** *** ************ ******** for **** ******* *** *** ******** ** ******* **** *******. Extenders, ****** *** *** ** ***** * **** ***** **** are ********* **** * ******** ** ***** *******. **'* *** to *** **** ** *****'* **** *****, * **** ******'* classify ** ** * "***** ****".

"******** **** *** **** *** **** **** *** ********* ***** the ****. ****** ***** ***'* **** ** **** ******* *** Prox ***** ***'* **** ** ******/******* *******."

**** ** *********** *** ******* *** '***-**-***' ****** ****. *** supply ***** ******* ** '**** ****** ****' *** ***** *** reorder ******* ****, ******** ******** ********* **** **** *****'* **** (but ***** *** ****) ** *******.

**** **** ****'** ****** *** "****** ****" ** "**** ****" and **** **** ******, ******* ******* $*.** *****.

**** **** ****'** ****** *** "****** ****" ** "**** ****" and **** **** ******, ******* ******* $*.** *****.

*********** *** ***** ****** ******, ****** ******* *** ********* **** is ******* ** *** ****** *** *** ****** **** ******* for $*** - $*,*** **** **** ***** **** ******* ******** Amazon *** ******* ** *** $** - $** *******.

* ** *** ********* ****, * ***** *** ***** *** / **** / ******* ********* ** * ******* ** **** a **** ********, * ** **** ****** ***** *** ********** organizations *** ***** **** **** *** **** ** ***** ** cents *** **** **** ** *** ** **** ****.

* ***** *** ******** **** *** ****. ****, ***** ***********/*******/*** users *** ****** **** *** ***** ********/******* **** ***** *** extra ******* *** *** ***** ********. **** ** ***** **** to ******** "***********", ***** ******** ****** *** ******** *** **** in *** **** *******. **** **** ***** ** ** *** hands ** *** ******** ******* ** *******. *** ***** **** care **** *** ***** **** *** ******** *** *** "****".

** ******** ** ********** ****** ** * **** **** *** Hotel *** ****** ** ******* ** ********* **** *** ****. When ** **** **** ** ********** ***** *** ***** ****** we **** *** ****** ***** ***** *** **** **** ****. They *** * ****** *** ***** ** $*.** *** ****.

Login to read this IPVM report.
Why do I need to log in?
IPVM conducts unique testing and research funded by member's payments enabling us to offer the most independent, accurate and in-depth information.

Related Reports

PoE Powered Access Control Tutorial on Oct 12, 2017
Powering access control with Power over Ethernet, like for IP cameras, has become increasingly common.  However, the demands for access power are...
Dahua Access Control Tested on Oct 10, 2017
Can Dahua become a major force in access control? We bought Dahua's ASC1202B to find out. We tested Dahua access and its management application...
Delayed Egress Access Control Tutorial on Oct 04, 2017
Is it ever legal to lock people into a building? The answer is: Yes... under specific situations. With so much of access control driven by life...
Propped Doors Access Control Tutorial on Sep 28, 2017
Doors should keep 'bad guys' out. One of the most basic problems with doors is people propping them open: Even worse, door propping...
Access Control Job Walk Guide on Sep 26, 2017
Significant money can be saved and problems avoided with an access control job walk if you know what to look for and what to ask. By inviting...
Genetec Launches Cloud Access Control (Synergis SaaS) on Sep 21, 2017
Genetec's cloud everything expansion continues, with their announcement of Synergis SaaS edition, joining their cloud video offering Stratocast,...
Automatic Door Operators For Access Tutorial on Sep 20, 2017
Opening and closing doors might sound simple, but it takes a high-tech piece of door hardware to pull it off. Integrating automatic door operators...
HID Buys Mercury Security on Sep 19, 2017
One of the biggest access control deals in years. Mercury Security, the most widely used access hardware OEM, and partner to 20+ manufacturers,...
Cloud Guy Prints Book, Misses Irony on Sep 15, 2017
On-premise security systems are dead. But $75 print books are alive and well. Such are the lessons from Brivo's CEO new book "The Five...
Master Keying Tutorial on Sep 14, 2017
Mechanical keys are the most fundamental, albeit unsophisticated, form of access control. Like access control, Master Keying allows large scale use...

Most Recent Industry Reports

Top Problems Searching Surveillance Video (Statistics) on Oct 13, 2017
When crimes, accidents or incidents happen, the video surveillance system is a key component in finding out and proving what actually...
Exacq M Series Low Cost NVR Tested on Oct 12, 2017
With recent cyber security issues hitting NVRs and cameras from low cost leaders Dahua and Hikvision, users are increasingly seeking alternatives...
Long Time Industry Exec Leads New Security Franchise Offering on Oct 12, 2017
John Nemerofsky previously built and sold a $150 million dollar integration business, and then was VP of Niscayah from its spinout of Securitas,...
PoE Powered Access Control Tutorial on Oct 12, 2017
Powering access control with Power over Ethernet, like for IP cameras, has become increasingly common.  However, the demands for access power are...
Knightscope Rockets To $20 Million Funding on Oct 11, 2017
Knightscope is celebrating. 15 months after running over a child and 3 months after a Knightscope robot drowned, Knightscope is having the last...
Avigilon / Canon New Lawsuits, No Settlement on Oct 11, 2017
In July, Canon sued Avigilon, a notably rare move amongst major players in the industry, including Canon's subsidiaries Axis and Milestone. At...
Surveillance Systems Remote Access Usage Statistics on Oct 11, 2017
Remote access is a major benefit and risk for video surveillance. It is a benefit because it allows users to manage security or review...
Genetec Launches Streamvault Hardware Revamp on Oct 10, 2017
Genetec is launching a new series of hardware appliances, dubbed "Streamvault", with updated capabilities and design. These units will replace...
Dahua Access Control Tested on Oct 10, 2017
Can Dahua become a major force in access control? We bought Dahua's ASC1202B to find out. We tested Dahua access and its management application...
ADI To Be Spun Out of Honeywell on Oct 10, 2017
Honeywell has announced it will spin off ADI and its Home products division into a new public company. This is a big move for the mega-security...

The world's leading video surveillance information source, IPVM provides the best reporting, testing and training for 10,000+ members globally. Dedicated to independent and objective information, we uniquely refuse any and all advertisements, sponsorship and consulting from manufacturers.

About | FAQ | Contact