Brivo Mobile Pass Opens Any Door by Smartphone

Author: Brian Rhodes, Published on Sep 25, 2015

One of the major trends in access control are 'mobile' credentials.  

NFC and BLE have been fighting for the title but neither has really has taken off.

Now, Brivo has announced a new way of doing this that sidesteps the hassle, and claims to work with any door, any reader, and the majority of all smartphones in seconds.  

In this note, we examine Brivo Mobile Pass, explaining how it works, what it costs and what potential security risks it has.

*** ** *** ***** ****** ** ****** ******* *** '******' ***********.  

*** *** ******* **** ******** *** *** ***** *** ******* *** ****** has ***** ***.

***, ***** *** ********* * *** *** ** ***** **** that ********* *** ******, *** ****** ** **** **** *** door, *** ******, *** *** ******** ** *** *********** ** seconds.  

** **** ****, ** ******* ***** ****** ****, ********** *** ** *****, **** ** ***** *** **** potential ******** ***** ** ***.

[***************]

No ****** ******

****** ***** ****** *********** **** ******* ******* ******* *** ******** smartphones, ***** **** ***** * ***** **** ******** ***** ********** app.

***** ****** ***** **** ***** ****** ** ******** *** ***, connecting ** *** **** ********** ******* *****'* ***** *******, *** essentially ******* *** '****** ******' ******* ** *** **** ******* the *** *********. **** **** ** ** **** ********* ** operator ******* *** *** *********** ** ******* / ***** ** any ********** ****.

** **** ***, *** **** ******** *** ****** *** ***** entirely *** **** ********** ******* *** ********** ******** *******. 

App ***** ********

*** ***** ***** ***** ***** *** ***** ********:

************

*** ******** **** ***** **** *****'****** ******* **.* ******* *** *** *** ***** *******.

***** ****** ******

************** *** ****** * ****** **** ** ** ********** **********. Passes are ******* **** ****** ** ***** ** *** ******, *** users *** ***** ***** ***** ** ******** ** ****** **** if **********. * ****** **** ** **** *** *** ****** of *****, *** *** ** ********* ** **** **** ** certain ***** ** ** ************* *****. *******, **** **** * mobile **** ** ****** (** *** ** ***** ****** **** Brivo's ********** ********), ** ******** * ****.

*********** ****

***** **** ****** ****** **** ** ********* ** *** *** ******* operating ******* *** *** ***** ****** ******* **** *******, ****, etc.

Mobile **** **** **********

***** ***** ****** ***** **** * '****' ****** ******. ********** passes *** ********* ** $** *** ***. ***** **** **** ** effectively ~** ***** *** ****, **** ** ****** *********** ********** compared ** ******* ****** ***** ***** *** *** ** **** **** the ****** ****.

******** *****

****** ****'* ******* **** ** *** **** **** *** **** to ** **** * **** ** ****** **, ****** *** and ***. *** *******, **** *****'* ****** ****, * **** could **** *** **** ** *** **** **** ******** **** they *** ********** ***, ********** ** *** *** **** **** are. ******* **** ******* ************* ** ** *******, *** ******* that ************ *********** *** **** ********** ****** ** * ********** risk. 

*** ****** *** ** ***** **** ** *** ****** *** to ******* ***** ** ****** ***** ** *** ****, *** is ******** ** *** ** *****-******* ******* **** ********.  ***** says **** *** ******* ** ****:

"** *** **** *******, ***** ****** **** **** *********** ********** ******** ***** *** ******* *** ****** user ** ** ****** * ********* ******** ** *** **** (***** GPS) ** ** *** ***** **** *******. "

*******, ***** **** ** *****, ***** ****** ** ********.

*** ***** **** ** *** ***** *** ** *** **** a ******** *** ***** *****. ** **** *****, ****** ******* ** ******** those ***** ***** **** *** ***** ****** *** *** ****** *** door **** ***** *** **** **********.

****

Comments (31)

** ******** **** ** ******* **** * ********** *** ** (Card ******) ********** ***********, * ***** **** *** *** ** the ********** ** ******* ***** **** *** *****. *********** *** alongside * ********* ****** ***** ** *** **** ** ** opinion. ***********, *** ***** ******* ** *** ** *** ***** that ***** ** ************* ****** *** ********** *******. *** *** would **** *** **** ****** *** ******* ** ** * CA **********. **** ** ***** ** *** *** *******, *** phone ***** **** *** *******; **** ********* * ****** ** inches ** *** ****** ** ***** *** ******** ****** ******** were ** ** ******** **** **** ** -**** ** ***** transmit *** ** ********** ********* *** ***.

********** ****** *** ********* ** $** *** ***. ***** **** this ** *********** ~** ***** *** ****, **** ** ****** inexpensive ********** ******** ** ******* ****** ***** ***** *** *** or **** **** *** ****** ****.

** ***** *** *** **** ** **** ** "***********", ** "rather ****** *** ******** ** ***** ****".

***** *** *****.

****** **, **** **** ******* **** **** ******** *** ****? :)

****** **, **** **** ******* **** **** ******** *** ****? :)

***.

*** *** ****** ******** ** ****.

*** ******* ****** ******** ** ****.

*** ****** *** ** ****.

*** ****** ******* ******* ** ****.

*** *****-***** ****** *** ******** ***** ** ****.

"** ****"

*** ** ******* ****. "** ******** ** *** ***** ** the ******** *******."

** *** ***********, ******** ***** ******* *** ******** **** ******** physical ******* (** **** * ****) ** **********.

***** ** **** ****** ****** *********** ***** **** **** *** *** *** , *** **** sell * ****** *** ****, ****** *** **** ********* ***...** just ******* **** **** *** ** ***** **** ** ***.

****** *** **** ** ******

***, ***** *** ********* * *** *** ** ***** **** that ********* *** ******, *** ****** ** **** **** *** door,any ******, and the majority of all smartphones in seconds.

*** ******, ** **** *** **** **** *** ******* ********** into *****?

"*** ******** **** ***** **** *****'****** ******* **.******** *** *** *** ***** *******."

* ****'* **** ***** **** * ******.

****** **** *****'* *** * ****** ** ****.

*** ****** ****** ** ********** ****. ****'* *** *****.

****** ****.

** **** ***, *** **** ******** *** ****** *** ***** entirely *** **** ********** ******* *** ********** ******** *******.

* ** ****** ********* ** *** ******* ** *** ****, over **** **** **** ****** ********** ** * *** **** is ***********. * ***** ** ******* ** **** *** **** people **** ** ** * *** **** **. **** ****.

*********** *** **** ** * ******* *** **** **** *** and ** **** ******* ***** **** ******* ** *** **** it...

*****, **** ********!

*****'* **** ** ***** ** *** ** *** ***** ** be ************* **********. ** *** **** **** *** ** ***** split *** ******* **** ***** **** *********** **** **** *** 50 - ** *****.

****** *****. ******* ** ** **** ** *****, *** **** the ******** ********, *** **** ** ** ****** ** * local **** ******* **** *** *********** *** **** **, *****?

*** ***** ******** **** *** **** ****/ **** * ******** network ***** *** ********** ****** **** ** '*** *****', *** on * ***** ******.

*****,

** *** ** ****** *** ** ***. * ********** **** only ***** ********* ** *** ****** *** ***** ***** **** have *** ** *** ****** *** *****.

**** *********** ****** ********** ****:

****** ********** ***** **** ******** *******-* ****** *.* (** ******) software ** ******* * ********** ***** ********** **** *** ** used ** *** ** *** **** ** * ****** ** person *****. ****** ** ********* *** ********** ** ** *** corporate ******* ******** *** ****, **** ********* ********* ** *** building, ** *** *** ******** ********** ******** *** ** ****** Credential **** ******** * **** ********** *** ** **** **** the **********. ** *** ************, **** ****** *** ** ******** to ** ** ********* ** *** ******** (****** **** *****) while ****** *** *** ***** ****** ********** **** ******** ** the *************’* **********.

***********. ****** *** ******** ** **!

*** *******, **** *****'* ****** ****, * **** ***** **** any **** ** *** **** **** ******** **** **** *** authorized ***.

* ***** *** **** ***** **** **** ****** *** ******** as ****, ** *** ****** **, ******* ** ***** ** meet ****. ******* **** ** ********* ** ******* ******.

********* **** *** *******/*********** ****** *** **** *** ******** *** the ***** ****. ***** ****** ******* * ******** *** *** length ** **** ******* *** *****/******** ********** ** **** * imagine ** * ********* *** **********.

** ****** **** **** **** ***** **** ***** ******* *******, but *** **** *** ****** ******* ******** ******** ********** **** 4G ** *** ***.

********* **** *** *******/*********** ****** *** **** *** ******** *** the ***** ****. ***** ****** ******* * ******** *** *** length ** **** ******* *** *****/******** ********** ** **** * imagine ** * ********* *** **********.

** ****** **** **** **** ***** **** ***** ******* *******, but *** **** *** ****** ******* ******** ******** ********** **** 4G ** *** ***.

**** ** *** **** **** **** **** ***** **** ******* systems? **** *****?

* ******* ***** *** ** ***** **** **** ** ************* in ***** ******* ***** ***** ******** *** ** ******** ** cloud ******* **************.

*** * *** *** **** ** ** ****** ****** ** the **** ** **** * **** *******'* ****** ******* *********** are ****** *******.

** *** *** *******, **** *********** ***** ** ** ******** new ***** *** ****.

********' ****** ********** *** ******** ** **** **** *** **** that ***** *** * ****** *** ** *** * ********** for ****** ******* **** **** *********** *** *** ****/****** ***********, we ***** **'* ***** **** ***** *** ****** **.

*** ******* ****** *** *** ** * '****** ******', *** it's **** **** ** *** **** ** ********* *** **** the *** ****. ***, ****'* *** **** ** **, **'** been **** ******* ** **** **** **** *** ********** ** secure **** **** ** ********** *********** *** **** **** ** the ***** ** ** ****** ** *******. **** ****** ********** the ***** *****'* **** *** ** ** * ****** ******, it **** ***** *** ** ******* * ********** ** *** system *** *** *** ****** ** *** *** ******** ******. I ***** ******* ***** *** **** ********* ******* ** ****.

*** ************* ****** ** ********, ** ** ******** ************, *** can ****** ** **** **** ***** *** ******** ** *** limit **** ** **** ********* ** *** ******** (**** ******), and ****** * ****** **, ******** **** ** ***** ****** from ********. ** *** ***** ******** **'** ********** ** ****, this **** ** ****** **** **** *** ****** ** ******.

**** *****'* **** *** **** **** **** ********, *** ** need ** *** ****** ** *********** ****, ** **** *** can ********* *** ***** ** ***** ************* ******* *** ******** mobile ********** *** - **** ****, ***** **, ******, ***. via *** ***** ******, **** ** ***** ** ***** *** certified **** ** ********.

"**** ****** ********** *** ***** *****'* **** *** ** ** a ****** ******, ** **** ***** *** ** ******* * credential ** *** ****** *** *** *** ****** ** *** the ******** ******."

*****, *** **** ******** ****** **** *** ****** **? ** other *****, ** * ** ** ******** ** * ******* who **** ******** *** *** ****** ********** ******* ** ** phone. * ***'* ** ** ******?

****,

**'* * *** ***** ********* *** ** *********. '********* ******' typically ***** * ****** ******, ******* **** *** ********** ********. But **** **** ***** *** **** ******* *** **** ** effectively *********. ** (*** *'* ***** ******** ****) **** **** someone ******** *** ********* ****** *** **** ** *** ** knowing *** ******** **** ******* *** ****. ** ********* ****** in **** ******* ** *** ****** **** ******. ***** *** been ***** ****** ** *** ** *** *********** (*** *****) on ******* ******* * ********** **** **** ********* ******* ***** door ** * ******, ** *** ****** ** ****** ***** a ******** ****** ********* ***** ** *************.

**** *** ***** **** ** * **********, **** * ********** is *********, *** ****** ** ******* ***** ** *** *******. i.e. '**** **** **** ****** ** **** **** ** **** time?'. **** *******/***** ** ****** ** *** **** *** **** through *** ****, ** ** ***** *** ********* ***** **********. There ** ******* ** *** ***** ** ***** ****** *** credential. ********* ** ******** *******'* *********** ** ********* *** ****'* on ***** ********** ******* ******** *** ** ** *********** ******* any **** ** **** ** **** ******** ** *** **********.

** **** **** ****** ******* ** *** **** **** ** one *** ***: **** ***** ** ****** ********** **** ** rights ** *** **** *** ******** *** ********* ** ****** to ******* *** ******* ** *** ****** ***** **** *** their **********. **** ** ***'* ***** *** **********-**** ******** **** it.

*****, * ***** ***'* ********** **** *** *** ******** ** do. *** ** *** ****** **** *** ****** *** '********* unlocks' * **** ***** * ****** ********** ** ** *** door ** **** ***** ****?

*** ** *** ****** **** *** ****** *** '********* *******' a **** ***** * ****** ********** ** ** *** **** at **** ***** ****?

****, **'* ****** **** ****** ********** *****'* ** * "********* unlock".

*******, *** ****** **** * ************ ****, **** ** ***** with * **** ****, *** **** ********** ***** **** *** credenditial **** **** *** ***** ** *** ** *** ****** instead ** *** ******.

* "********* ******" **** *** ********** ********, ** *** ***** hand, **** **** *** ******** *** ******** ********* *** ******, not *** ** *** ****** ***. ** **** **** *** require **** *** ****** *** ********** ******* ****** ****** ** granted ** *** *********.It's * **** ******** "****-**".

******* ****** ****** "******* **** *** ****** *** '********* *******' is ** *** **** ** **** ***** ****.", ***** **** using *** ****** ******* *** ***** ** ******** ****** *** world, ***

**** *******/***** ** ****** ** *** **** *** **** ******* the ****,or ** ***** *** ********* ***** **********.

**;**

'********* ******' **** **** *** ******** ********** *** ****** *** does *** ******* *** ****** ********* ******* ****** ****** ** granted ** *** ****** *********. ** "** *** ** ******* who" ** **** ****.

****** ********** **** *** ****** ********** *** ****** *** ******* they **** ********* * ***** **********. **** *** **** ** least *** ********* *** ******** *******, ****** *** ***'* ** sure **** *** ******** ** *** **** ** ****** **** the **** ** *** ******.

********** - ** *** * ***** ******. ** ***** ***** Mobile **** ** ****** *********. * ***** *** ******** ** very ********** *** ******* ** *** * *******. *** ***** performance *** ****** ************* - ****** ** ***. ****, *** entry ** *** ******** *** ******** **** *** ** ******.

**** ** ***** ** ** ******** - ***. ********* ******* for *****-****** ********** - **** ** ***** - ***** *** having ** *** *** **** * ******** ****** ***** ** beneficial. ** ******* ** ***** *******. ***** *** ***** ********* with "******" ******** ********, ***** **** *** ***-******* ******* ** available.

*** ******* * **** ** *** ****** ** ***** *** and ********* ** ** ***** *** *** **** - **** one **** ******* ******.

* ***** ***** * ***** ************ ** **** ***** ** the ****** ***** ** ****'* **** *** **** ******* ** all *** *****!

**** ** ***** ** ** ******** - ***. ********* ******* for *****-****** ********** - **** ** ***** - ***** *** having ** *** *** **** * ******** ****** ***** ** beneficial. ** ******* ** ***** ******.

******* ******* ** ***** **** *** ***-***** ******* *:**** *** 1:30PM ** ***********.

**** ******** **** **** ******** **** *****/******** *********. *** ** someone ***** ** *** *'* *** ****** ** ******** * can **** ** *** ****** ***, ****** ** ***** **** are ******** ** *** **** *** *** **** ** ** not. (* ***** **** **** **** ** ***** ****** ** limit *********** *** ***- *******)

- **** **** *** *** ********* *** **** *****/******/***** ** they **** ***** *** *** ****.

- ********** ****** ** ** ****** *** * ***********. ** I ** ** ***** ** ** * ****** ** **** to **** * **** ** *****. *** **** **** *** opened *** ****, ** ***** ** ***** ** ***** ***** if ****** *** **** ******** ******* ***** *** **** *** world.

Login to read this IPVM report.
Why do I need to log in?
IPVM conducts unique testing and research funded by member's payments enabling us to offer the most independent, accurate and in-depth information.

Most Recent Industry Reports

Uniview Low-Cost Bullet PTZ Tested on Jun 21, 2017
Uniview is offering a HD zoom bullet camera, the IPC742SR9-PZ30-32G, with an integrated pan / tilt positioner, for the price of a low-cost...
QSR Video Surveillance Best Practices on Jun 21, 2017
Fast food restaurants or QSRs (quick service restaurants), are frequent victims of crime and fraud. Because they are open late, deal with cash, and...
45 Drives 'Lowest Cost' Enterprise Storage Company Profile on Jun 21, 2017
45 Drives claims the "lowest cost per Hard Drive Slot in the industry." But who or what is '45 Drives'? What started as a product design to...
No Hack, Still Liable, Court Finds ADT on Jun 20, 2017
Recently, ADT has been in the news for a $16 million settlement for a cyber security vulnerability class action suit. One of the most important...
Resolver / PPM 2000 Incident Management Platform Profile on Jun 20, 2017
You might have seen the company whose employees wear hockey jerseys at trade shows and wondered "what do they do?" PPM 2000 has been active in...
Axis P3225 Mk II Tested Vs. Original on Jun 20, 2017
Axis has released a number of 'Mk II' versions of their cameras, which are the same fundamental camera but with specific improvements. We tested...
Directory of 40 IP Camera Manufacturer Discovery Tools on Jun 19, 2017
Locating the IP address of a DHCP client or factory defaulted device on a network is often a difficult task.  In another report, we discussed...
Dahua Demotes USA CEO on Jun 19, 2017
Dahua has demoted their USA CEO Tim Wang. Inside this note, we examine the move, Dahua's challenges and what lies ahead for the...
Avigilon Increases Prices In Canada, Europe and UK on Jun 19, 2017
While many video surveillance companies are racing to see who can cut prices the fastest, Avigilon is taking a contrary approach, actually raising...
VMS UI - Light vs Dark Preferences on Jun 16, 2017
Several VMS manufacturers have the ability to choose a user interface with either a light or dark color theme. 150+ integrators told us which they...

The world's leading video surveillance information source, IPVM provides the best reporting, testing and training for 10,000+ members globally. Dedicated to independent and objective information, we uniquely refuse any and all advertisements, sponsorship and consulting from manufacturers.

About | FAQ | Contact