Gallagher Access Control Cybersecurity + CTO Interview

Published Dec 07, 2023 14:32 PM

Security researchers praised Gallagher for their cybersecurity approach, but how does Gallagher’s cybersecurity approach differ, and what competitive differences does it bring?

IPVM Image

In this report, based on an interview with the CTO Steve Bell and Director of Federal System Jeff Fields, we detail Gallagher’s cybersecurity approach, including ethical disclosure programs, HBus communication protocol and its differences to OSDP and Wiegand, and their cybersecurity focus for federal business.

Executive *******

*********'* ************* ******** ******** ******* *******:

  • *********** ********** *******, ******* ******* **** various **** ***********, **** ** ****** (see *********), *********** *** *** ********* Authority (***) ******, *** ********** **** 30 **** ***** ****. * *** access ******* ********* ** ****
  • **** ******** **** ******** ************* ************* between ******* *** ***********, ******** ********* firmware *******
  • *** ***** ******** ******** ******** *** its ********, ********** *************** ****** ********, that *** ** *** ** ****** automatically
  • ~**% ******* ******** ** *&* ******** on *************

Gallagher’s ******* ****** *** ** **** ** ******** ***********

******* **** ***********, **** ** ****** (see*** ****** ********* **** ************* ********), **** **** **** ********* ***** an ******* *** **** **** ******** to *************** **** ***********, ******* ******* with ***********.

**'* ****** **** ******, ******** *** having ******* *** ******** *** *************** disclosure ********** ******** *****. **** *********, they're **** ******** *******, ******* *** have * **** ************* **** ****, and ******** ****** ***, ****** ****** better, *** **** *** **** **** it.

Competitive ********** ** ************* *****

************* *** ******* *************** ****** ****** control **** **** ** ******* ******, with *************** *** ********* ** ************* and *********** ******** *********** ************* ***** work ******* ***** (******, ********, ***.) or ******* ***********. ***** **** ********* take * ********* ******** ** ************* disclosures (******* ** *** ******** ********** *** Industry), ********* ******* ** ******* ************* disclosure *******, *********** ************* *************** **** CVEs, *** ************* ******** *********** ** its *******.

*******, *********'* ******** ***** *** ******** translate ** ******** *********. *********'* ***** challenge ** ******* ** *** *********** against ***** *************, **** ** *** - **** ***** *** ********, ***** products ******** *** ***** ******** ******* (see*** ****** ******* ***** **********). **** ** *********'* ************* ******* could ** **** ********* *** *********** against ******** ***************, *** **** ** integration **** ******** ******** ******* **** and *** **** ** ******* *** entire ****** ** ******** *** ******* and ********** **** ** * ****** sell *** ***** **** ******** ****** control *********.

*********'* ***** ********* ** ********** *********** and ***-***** ** *** ******* ****** control *************** *******. ***** *** *** Prox ***** **** **** ********** *** over * ****** (************ **** ***************,******* **** ****** ******* ******* ******), ~**% ** *********** *** ********* cards *** ******** ******* (******* / *** *** ****** ******* Credential ***** **********), ************ *** **** ** ****** attention ** ****** ******* ***************.

**********

********* **** **** ** ********* ***** 18% ** *** ******* ** ******** and ***********, ******** ** *** ********** development ** ***** ******* **** *** platform.

*** ******* ******* **** ***** **** to ****. ** ******** * *********** portion ** *** *******, ***** **%, to *&*. **** ********** ******** *** status ** * ******* ******* ******* on ****-**** ******** ***********.

***** *** ********** ** ******* *** R&D ***** ** ****** ** ***** than ***********, ********* *** ******* ******* business ******** ***** *&* ******** **** do *** ******** ********* ** ************* or ******* ************.

*** *** ******* ********** ** *********'* integrated ******, ***** ******** ***********, *******, and ******** ********* ***** ****, *********** SSL ********** *** ****** ****** *********** and *** ********** ********* ** ***** platform.

*** ****** ** ** *********, ************ native **-***** *********** ***** ****, **** SSL ********** *** ****** ***********. **'** developed *** *** ***********, ***********, *******, and ********. *** **** *** ****** been ** **** ********* *** ********* our ********.

Responsible ********** *******

********* **** ***** ******** ** ************* includes ******* ******* ********** ******** *** actively ******** ***************.

** *** ******* ********** ******** *** address *************** ***********, ******** *** ****** through *** *******. ***** **** ******** vulnerabilities **** *** ****** *****, ** acknowledge *** ******* ******* ****** *************.

********* *** *********** *** ********* ********* (***) *********** ****. *** ******* ***** ** *** **** ******** *** one ** *** ** *** *******.

IPVM Image

***** ******* ***** ************ ********* **** a *** ******, **** ** ****, Dahua, ******, *** *********, ********* ** one ** *** *** ****** ******* companies **** **** ******.

**** ***-********** ********* ***** *** ***** status ** **** *************** ** ****** more ******; *********, ** ** ********* to **** ** *** ****** ** CVEs ********* ** *** ***. ***** 2019,********* *** ********* **** ** ********** *** ******* *****. ** **********, HID *** ******** ~** **** ** the **** ******,********* ** **********. ** ********, **** ****** ******* vulnerabilities ** *** ******** **** *** not ********* (****** ******* *** *** ****** *** DEF *** **** ********,*** ******** ******* ***** **.** *** SE / **** ** ********** ** Cracked *** *** *** ********* ******).

Working **** ******** ***********

****** **** **** ********* ***** **** pen-testing ************* ** **** ****** ********** under ******* ********** **** ********* **** attacks.

** ****** **** ********** ************* ** test *** ******* ***** ********* **********, like ********* **** *******. *** ********* approach ** *********** *** ********** *************** is * ********* ** *** ********** to ********* *** ****** *******.

********* **** *** * **** ** security ********** *************** ***** *******.

IPVM Image

HBus **** ******** ********

****** *********’* *********** **** ******** ********, similar ** ****, **** ****** *** bidirectional ************* ******* ******* *** ***********. HBus ** ** ********* **-*** ******** with ************* **** ******** *** ******** upon *** ******* ***************,********* ** *** ********* *******. *********’* ********** ***** ******* *******, OSDP, *** *** ***** ************** *** each ********.

IPVM Image

**** **** **** **** *** ********* for ******** *********** *** ***********. **** implements ***********-***** ******** *** ******** ************** for *** **** *******, ********* *************, per *** ***.

** ********* **** *** *********** *** scalability, ******** *** ******** ** *** edge ******* ** ***********. **** ******** loading ************ **** **** ******, ******** a ****** ****** *** ******* *** reader *** **********, *** ********* ******** these **** *** ******** ********.

*********'* ************** ************ ** ***** ****** ******* HBus, ********* ******, ****** **** *********, and ********* *** ********.

*** ************ ** **** ***** **** to **** **** ******* ****** ******* 7 *** ********. ***** ****, ** have ************ ********* ** ***** **** features *** ****** *** ****** *******. For *******, ** ************* ******** ******* for ****** ******* ** **** *** 2017. ** ****, ** ***** ***** security ******** *** ****** ***** ** detect ****** *****. **** ********, ** introduced *** ********, ***** ****** *** Multi-Tech ******* ** **** ********* ****.

*********'* ************** ******* **** ******** **** **** are ***-*** ********* *** ** *** factory *** ******* *********** ******* (*.*., ESPKey) **** ***** ********* ** *** HBus *******.

****** *************, ********* ******** ************ *** Elliptic ***** **** **** **** ***** HBUS ****** ** ****** ***** ** no ****** **** *** ***** *** connect * *********** ****** ** *** HBUS *******. ** ************, ****** **** are ******** ********* *** ****** ** the ********** *** ****** ** **** even ********* ** *** **** *********** that ***** ***** *** ******** ** be ************. ************, **** **** * new ************** ******* ** *********, ****** keys *** *********. ** * ******* is ********** *** **** **** * day ***** **** *** ***********.

**** **** ****** ********* ******** ** generate ****** ****** *** **** ******* are ***** *******,*** ****** *************.

*** **** ******* ******** * ********* to ******** ** ***** ****** *** system ****** *** ****** ** ***** off-line, *** ** ******* ******* * wide ***** ** ********* ****** *******. As **** ******* *********** *** **-*** rather **** ***/**, ***** ** ** need ** ****** * ******* ******** port ** *** ***-****** **** ** the ********.

***** **** *** ** ************ *** access ******* ******* *** ******** ************* and *************, *** ***** *** ****** HBus ***** ** ****** **** ********* products, ** **** ** ******* ** a ******* ***** ** *** *******'* products. ** ****, **** ***** ** more ****** ** *** **** *** for ***** ******* ** *********** ********* lines ** ******** *** ***** *** easily ****** ** ****.

Twice * **** ******** *******

****** ******** *** ********** ** ******** service *** ******** ************* ** *** security ********. ** ******** *********'* ***** on ******** ******* ** ******* ***** threats, ************ *** *******’* ********** ** customer ************ *** ********, ** ** told ****.

*** *** ****** ** ****** ******* is ******** *******, ******* ******* ******* partnerships ** ****** ************ *******. ** emphasize *********** ******** ************* *** ********* updating *** ******* ** ******* ***** threats *** ****** *********.

*** ********* ******* ************* ******* *** ******** ***** *** months ** "**** ******* **** ***** threats *** ****** ************."

IPVM Image

Federal ******* *** *************

****** ********* *** ******** ******* ********* for ********* ******** ** ******* ************, noting *** ******* ********* *** ********* required ** ********* ********. **** ******* underscores *** *******'* ********* ** ****-******** standards, ** ** ********* ** ****.

** ******* ************, ** ***** ** how *** ******** *** ****** ****** requirements *** **************. **** ******** ********* product *******, ***** *** ***** **** three ** ****** ******, ********* ** the ******.

*** ******* ************ *********** *** *********, ********* ********, FIPS, *** ****.

IPVM Image

*** ****** ********** *** ***** ******** ******** Guide.

** *** ******* ** ****** *** coverage ** ****** ******* *************, ********* adding ************* ** ******** ****** ************* ******** - *****.***, Brivo, ***, *******, ****, ********, ***, Verkada.

Comments (14)
Avatar
James Mifsud
Dec 07, 2023
Atlas Technologies Australia

***** *******, **’* **** ** *** a *** ******* ******* ****** ***** and **** ****** **** **** *** doing *** *** ***** ******.

*********** ** ****** ******** *** * can *** *** **** *** ***** down **** ****.

(1)
UM
Undisclosed Manufacturer #1
Dec 09, 2023

******* ***** ************ ********* **** * CNA ******, **** ** ****, *****, Hanwha, *** *********

*'** ******* **** **** ** ******** increasingly *******. ******* ***** **** ******** it ********.

Avatar
Steve Bell
Dec 10, 2023

*** ** *** *** ********** ** going ******* *** ******* ** ******** a *** ** *** ******** **** the **** **** *******. ******* *** customers ******** ***** ******* *************** (***'*) and ********* **** ** *** ******** they **** **** ***** ** ** a ************** ** ** ***** *********.

UI
Undisclosed Integrator #2
Dec 11, 2023

"******* ********* ******** ***** ******* ***************" via **** ********* ** ********* **** liability ********?

Avatar
Steve Bell
Dec 12, 2023

*** ******* ** *** ********, (*** so **** ******) ** ******** ** long **** ******** ************* ******* ********* and *** ******** *** *********. ** such ********* *** ********* ** ********* product *************** *** **** ********* **** to ******* ******** ** ******** ** less ***** *********, *** **** **** about **** ******** *** *** ****** advantage ** *** ********.

UI
Undisclosed Integrator #3
Dec 13, 2023

********* ** * *** ** * strange ***** ******* ****.

***'* *** ** ***** - ***** security ***** ** *******.

* **** **** ** ****** ********* at ***** ** ********* **** *** only ** **** ** ***/*** *** also ****** ********** (******** ******/***** ******* animal ******** ***) *** ** ***** 2021 ****** **** **** ** - they **** ************ **** ******* **** as ******* ***.

Avatar
Steve Bell
Dec 15, 2023

* ***** *** ***** ********* ********* from *** ******* * *** *** how *** ***** ******** **** ***** is * ******* ******* *********. *** having **** **** ** **** "******* beast" *** **** **** ** ***** there *** **** **** ***** ***** between *** ******* ********.

**, ** *** **** * *** minutes, * **** ***** ** ********** at *********, *** ***** ** ****, a ******* ****** *** **** ******* the **** ******* *** ****** ******* product ********.

* **** ***** ** ****** **** Gallagher ** * ******* *******, ***** by *** ********* ****** *** ** years. *** ******* ********* (********* & Executive ********) **** **** ********** ** the ******* **** *** ****** *** continued *** *************** ******** ** ******* growth.

** ****, *** *******’* ****** *** credited **** *** ********* ** *** electric ***** *** *** *********** ** animals

**** *** *******’* ** *****, ************* has **** *** ** *** ********* ‘superpowers’ **** ******** ** ****** *** company *****. *** ************* ******** ********:

  • *********** - ** **** * ******* mount ********** **** **** ******* *** all *** ********** ******** ********* *** brand-new ********** **** **** *** **** processor.
  • ******** ********* ******** - *** ****** management *******; ******** ***** **********, ***** scales, ***** ********** *** *****, *** the *** ********* *******. ** ********, our ***** ** ********* ***** **********, energisers, **** ******* *** ********** ********** all *** *** ********* ******** ************
  • *** *********** ** ********* ******** ***** for *** *** ******** ********* *****.
  • * *********** ***** *** ******* ***** but **** **** *** ******** ***** of **** *** *** ********* ******* products.

******* ****** ** ******* ** *** superpowers *** *** ********** *** ******** experience ******** ******* ***** **** ****** the ********* ******* *****. ********* * product ** ********* ************* ********** ** all *** ********* ***** ******** *** be * ********* *** ** ****** valuable ****** *********’* ****** ******** *** agricultural ******* *****. ***** ** **** opportunity *** ********* ******* ******* *** Animal ********** *** ******** *&* *****.

********** *** ****** ******* ******** **** developed *** ************ ** ***, **** a ********* ***** *******, ***** *** brand **** ** ******. ** *** 1970s *** ***** *** *********** ** the *********** ** ********** *** *** station ********** ***** *********** ************** ******* communicated ** * ****** ***** *******. Part ** *** ********** *** ***** hours **** ******** ***** *** ****** cards *** ***** ****** ************ (**** encrypted *** ************** ** *** *****). These ********** ************ ****** *** ******** technologies *** ****** ****** *******.

***** *** ******* *** ****** ********** and ******** ** ********* *** ***** different *** ***** ** * *** in ****** **** *** ********* ** supplying ***** ******* **** * ***** Pacific *******. ** **** **** ******* technology ******** ******** **** ** ***** to *** ** ********* ************ *** sales ************** ** * ****** *****, and ** ***** *** ********** ** establishing **** **** ************ ****** *** world, *** ** ****** ***** ******** by *** *******.

**, **** *** **** **** * “strange *****” ** ***** ******* ** is ******** *** *************** ********** ** our ************ ********** *** ********* *** marketing ************ ****** ****** *** ************* business ***** **** ** *****.

(1)
(1)
U
Undisclosed #4
Dec 15, 2023

** *****,

** ******** ** * ******* *** user ** ********* ** *** ***. We **** **** ******** **** ********* will ** ****** ******* *** **** technology **** ******* ****** ******* *.* upwards *** ** * ******** ****** to ******* ***** ******** **** **** no ****** *** ** ******* *** GBUS ******** **** **** ******** .

On *** ******* ****** ******* *.* ** **** *** ****** ** *** ************* ******** ** ****** ***/***/****** (*** * ***** ***) **** ** **** ******** .

** **** ** ******** *** , why ** ********* ********* ******* *** customer ** ***** *********/ ******** ** thousands ** ******* ** ******* ********* working **** ******** **** **** ******** if **** ****** ** ******* ** access *** ******** ******** **** ** version *.* ******* ?

Is *** ******* **** ********** *** ******** ** *** ***** ***** *** **** ******** *** ********* ** * ****** ******* ?

Why ******'* ********* ****** ** **** *** ********* *** ****** ** **** ********* **** ** ****** *** **** ** **** ******** **** ******** *.* ******* *** *** *** ******** ** ** ** ***** *** **** ? (** ********* *** **** **** & **** ******** ** *** ****** )

This ********* ** **** *********** **** *** ***** ********* **** ** ****** ** ****** ****** ******** ****** ,***** ******** ** ********* ** *********** ***** *** ***** *** ******* * ******** *** **** ** *** * ******** ******* **** *** ** ****** ** **** ** ******** ******* ****** ******** *.* *** ******* .

* ********** ********** ******* ***** ** this ** "***** ******** " *** , *** ** **** **** ********* (especially ***** ** ****** ******** ) should ***** **** *** ****** ** we ** *** ** *** ****** GBUS ** **** ******** **** ******* 9.1 *******.

**** ******** ******* **** **** ******* to *** ****** **** ** **** in ******* * .* ******** *************.

****** *** **** ******** ** **** important *****.

IPVM Image

IPVM Image

(2)
Avatar
Steve Bell
Dec 18, 2023

****** *** *** ********* ***** *** obsolescence *******.

** ** ********** *** **** ** have **** **** ************* **** *** users ** *** ******* *** ** make *** ******* ** ****** ** possible *** *** ***** ** **** their ******* ** ** **** **** our *******.

***** *** *** ** ******* *.* you ** ***** *** ******* ******* that ** ******* ** ****** ** a * ******* *****. * ** assume *** ******** *** "**** ************ Notice" **** ** ***** **** ****. Hopefully *** **** *** *** *** back ***** ** **** ********** **** in ***** ***** ** ******* * 40% ******** *** ***** ***** ** buy * **** ********** ******. ***** that ***** *** ** ****** ** the **** *****.

*** **** ******* ********* ** *** GBUS ****** ** ******* *** **** over ** ***** ******** ********* ** when **** **** *** ********* ***** your **** ******* *** * *******.

  • **** - **** *** ********** ** our ************* ********.
  • **** - ****, *** ******* ************* protocol, *** ********** ** ***********.
  • **** - **** ******* **** ****** into ****** ****** ** **** ********** the *** ** ***** ******* **** cycle.
  • **** - **** ******* **** ****** into *** *** ******, ********** ***** was * ****** ****** ** **** products ********* *** **** **** ************ of *** **** ***** ** ******** was ********.
  • **** - ************ **** **.* **** be *** **** ******* **** ******** GBUS.

*** ******* ******* ****** ******* ***** came ** ****** ** **** *** that *** *** *** *********** ********** of *** ****** ******* *******, ** have *** * ****** ** ********* transition ***** ******* *********** ** ******* with **. ** ** ****** **** over *** ******* **** ** *** customer's **** **** *** ********** ** needing ** ****** ** ***** ****** to ***** ***** ******** ** ** the ****** **********.

** ** *** ********* * **** bar **** *** ***** ******** *********** and ** ********** *** * *** part ** *** *********** ** **** to ****** * ******** **** **** have ***** ***** ******** ******** ***** with ******* ***********. **** ** *** new ************* ** **** ******** **** the **** ** ***** **** **** on ****.

** *** ********* * *********** ****** over *** ****** ***** ** **-********* our ****** ** **** *** ************ of *** **** ***********, ** ** some ***** ** **** ** ***** the ***** ************ ******.

* **** * **** ********* ****** but ** *** **** *** ******* questions, **** * ******* *** ***** out ** *** ********* **** *** your ****** ** *** *** ("**** the ****" ** ********.*********.*** )

U
Undisclosed #4
Dec 19, 2023

***** ***** *** *** *** ******** and *** ************ . *** ,***** we **** ***** ********** ******** ** the ********* ****** **** ** ******* partner ** *** "**** ************ ******" back ** ***** **** **** ******* of *** ***** ** *** ** % ********, **** ** ***** ** certainly ***** ********* ** **.

** ********* ** * ******** ****** going ******* *** ** **** *** how ****** **** *** ** *** future.

Avatar
Steve Bell
Dec 19, 2023

*'** **** *** * **** **** Luis ***** *** ** *** ***** Directors, ** ******** *** **** ** email *************@********.*********.************ **** *****

(1)
U
Undisclosed #4
Dec 19, 2023

***** *** *****, * **** ** so ***** ***** ******** *******.

U
Undisclosed #4
Dec 21, 2023

**** ******* *****,

* ******* *** ** **** ********* afternoon *** * ** ***** ** say **** ** ********* ******** ** our ******** *** *** ********* ** work **** ** *** *** ***** to ******* ** *********'* ******** ******** for ********* ****** **** ** ****.

** *** ** * ******** **** to *** *** *** ******* ** this **********, ** ***** ***** **** being * **** *** *** **** 12 ***** ****,

" *** ********* ****** ******* ****** has **** * ***** ******** ****** for *** ***********, ******** ** *** constant ****** *** ****** *** ******* of ******** ************** "

***** , ****** ***** .