HID Touts "Signo = Security” Despite Critical Vulnerabilities

Published Jan 04, 2024 13:35 PM

While HID markets "Signo = Security" and that "security comes first," HID obscures and features critical unfixed vulnerabilities both for low frequency / 125 kHz as well as its own proprietary cracked iClass legacy credentials.

Deceptive marketing, especially for security products, is a serious issue, one that the FTC regulates. The fact that HID not only obscures these issues but then also makes such strong marketing statements about security capabilities harms the public.

IPVM Image

HID's response to IPVM contradicted its own marketing.

Executive *******

*** ****** **** "***** = ********." But *** *** **** ***** **** its **** ******** **** "******** *******" Signo ******* *** ********, *** **** supporting ******** *********** **** *** **** but **** ******** ********* ****** ******** credentials **** **** ** ** *********** by ******* *** ******* **** *** iClass. ******* ** ******** ***** ******, HID ******** ****. *** ******* ****** says ******* ** **** *** ********* that **** *** "******" ************.

*** *** ***** **** ****** ********* or ********** ****** ***** *** ******** capabilities ** ******** *********** ** ****** or ********* ******** ***** § * of *** *** ***. *********, ********* security *************, **** *** ********* ** exaggerate ******* ************ *** **** **** a ********** ***** *** *** ***** made ** ***********. ** ********* *** to ******** *** ******** *** ** make **** ********, **** ******** ************. If ***, *** ******* ***** **** FTC ************ *** *****.

HID ****** "***** = ********"

******* *****'* ***************,*** *********** ************** "***** = ********," *** **** "no ****** *** ******* **** ****** control *****, ******** ***** *****":

IPVM Image

** ******** ****** ******* ****, *** ****** **** * "********* promise ** *****" ** "*****[***]... ********," and **** *** ******* **** "********* security" *** "************ ***********":

IPVM Image

*** ***** ******* ****** ** ******* of *** *******' ******* *****, ************** ****** ****** ***,***** ****** ****** ***,***** ****** **, ******** ****** **, ******** **** *** ******* **** a "***** ******* ******** ** ****** electronic ****** *******":

IPVM Image

*********,******* ******** "******** ***** ********* **** *** Signo":

IPVM Image

FTC **** ******** ****** **** *** *******

*** *** ***** **** ******** *************** paired **** ********** *********** *** ********** an ****** *** ********* ******** ***** § * ** *** *** ***. A ****** ******* ** ******'* **** **** ******* *-****(* ********* ******* ****** ** *******, routers, *** ***** *********) *** ****** and ********* *********.

****** **** ** *** **** ******* D-Link**** *** ******* ******** ********* ** making * **** ** ********** ********** about ******* ********. *-**** ******** § 5 ** *** *** *** ** making ***** *************** **** *-****’* ******* and ** ******* **** “****** **** unauthorized ******" *** **** *-**** *** taken “********** ***** ** ****** ***** products **** ************ ******."

*** **** ***** ***** ** ***. The ******* *** ******* ********* ** making ****** ****** ****** ***** *** Signo *******' ******** ************.

****** **** **** ** *** ************* *-**** “****** ** **** ********** steps ** ****** *** ******** *** their ******* *** ** *******.” ** failing ** ** **, *-**** “******, or ... ****** *****[*], *********** ****** to ********* ** *** ****** ****** that ** *** ********** ** ************** benefits ** ********* ** *********** *** is *** ********** ********* ** *********.” According ** *** ***, **** *********** an ****** ******** ***** § *.

***'* ******* *** ** ******, ***. By "****[***] ** **** ********** ***** to ******" ****'* *** ****'* ***************, HID ***** "****[***] *********** ****** ** consumers." ********* ** ******* **** ******* ****, *** ********, *** **** ** easier ** ********* ****** ****** ******* systems **** *** *** *** ****. If * ******** **** * ***-******* device ** ***** **** * ***-********** facility, *** *** ***** **** ********* about *** *** ****** ** *** known ******** ***************.

FTC ******** ** ************ *** ************** **** **********

***’* ********** ****** ***** ******** ************ could **** *** ******* *** ******** on *********** ************ *** **************.

*** *** ** ***** **** ********* must *** *********/********** ******* ************. *********** *. ****** *********, *** *** ***** **** ****** of ******* *** ********** *** ********** of ********** *** ******* *** ******* to *** * $**+ ******* **********. In** ** *** ****** *******, ***., *** *** ********** **** ****** maker ****** *** *********** ******* ****** benefits. *** ** *********** *** ******** capabilities *** ***** **** *** *********.

********* ******** ** **** * ********** ******** *** ***** **** ** ***********. Companies **** **** *********** ******* ****** almost ********* ***’* **** ******** ************** - ** * ********* ** *** accurate, **** *****'* **** ****** *** proper ******** ** ******* **. *** likely **** *** **** ****** ************** for *** ****** ****** **** "***** = ********."

*** ** *** ****** **** *** of ***** **** **** ******* *** company ***** ******** ********. *** *** says **** *****-**-*********** **** ***** ******* to "********* ** ******** ********":

IPVM Image

** *** **** *** ******* *** Signo *******' *************** *** ****** ********** advertising, *** ******* ***** **** *** questions.

HID *******

*** ********* ** * ******* *** comment **** ****, ******:

*** ******** ** *** ********* ** HID’s *** ********. *** ***** ******* have * ***** ** ********** ******** that **** ********** *********find *** ***** ******* ******* *********** *** ********. For example, each Signo reader is currently offered with 8 different pricing options, 6 of which do not support Prox. Multi-technology readers offer customers the opportunity ** ******* *** **** ** ********* **** **** ****** ********** ************, a migration they may not be able to make otherwise. We also offer tools like HID Reader Manager to update reader configurations in the field and work *********** ** ******* *** ********* ** *** ********** ** ********* ****** ********** ********** unless needed. [emphasis added]

***'* ********* ***** ******* * ******* between *********** *** ******** *********** *** own *********, ***** **** **** "******** comes *****" *** **** "***** = Security."

*** ****** ** ********, *****, *** forthright ** *** ****** ********* ** that *** ****** ******** ** ***** devices, ** **** ** ****** *** may *** ***** ******** ** ***, know *** ***** ********.

Comments (6)
ZH
Zachary Hamm
Jan 05, 2024

*** **** **** *********** ******** ** push *** **** ****** **** **** Wiegand ******* **'* ***** *** **** doesn't ****. **** *** ***** ***'* understand *** *** ******* ** ******** MITM ******* ** *******, *** ***'* pay ** *** **** ********** ****** you *** ******* *** ***** ****.

** *** ** * ****, **** over ****** ** ***** ******, *** should ** *** *** *** ************ using *** ** **********.

*******, ** **** ** ********* ********** is ***** ***** **** *** **** technologies, ***** **** ****** ** * back ****. ****'* ***** ****** **** PKOC **** **** ****, *** ** always **** *** ******** ********, ** will **** ***** (** *** *******) to *********.

JH
John Honovich
Jan 05, 2024
IPVM

**** *** ***** ***'* ********** *** the ******* ** ******** **** ******* or *******

** ***** ** ***** **** *** manufacturer ** ******** ********* ********* **** Signo ** ******** *** **** "******** comes *****" **** *** ******* ** that **** *** ************ *********** *** profits **** ********.

(1)
UI
Undisclosed Integrator #1
Jan 06, 2024

*** **** ****'*. **** ********* ****** more *** *** ********. **** **** integrators *** ** ** ****.

**** *** ************* ******** ***** ******* on **** ** *** ** *** integrators ** ** *** ***** *****, and ********* *********** *** *** ****** and ******** ***********.

**** **** ** *** **** **** to **? ******* ********* ************* ********? They **, ** *** **** ******* readers. ********* ********* ************* ** ** option ********?

*'* ******* - **** ** ** that *** **** *** ** **?

(1)
JH
John Honovich
Jan 06, 2024
IPVM

**** ** ** **** *** **** HID ** **?

*'* **** **** *** *** *** to ********** *** *** ********** ***** about *********.

***'** **** ***** ****** ** ********* arguments ******. ** ***** ** **** this **** *** ***** ********* ** ignore *** *********** ** *** **** market. *** *** *** ******* **, companies *** **** **** ****-*********** ************* and **** ********** **** *** *** defend **** *****.

****** **-**** *** **** *** *** regulatory ******** *** ******* ****. *'* then ***** ** ******* ** ****.

UI
Undisclosed Integrator #1
Jan 06, 2024

* **** *** ******* ** **** one ** ****** ***** **** **** studying ***** ********.**** ****’* *******, ** ** * real **** **** *** ***** ******/********** systems.**’* ***** *******, **** **** ********* against ********* *** ************.

***** *** ******* ******* **** ***** has **** **** *********** ******* ********.*** ** ***** ********* ********: * Signo ****** ** **** ******* ***’* be ***** *** ** **** ******* without ****** ******* **** *** *** pushing ** ** *** *******.**** ***’* ******* ****** *****, ** adding ****** *********** ***** *** *** manipulation ** **** (***** ******* ***** be ********** ** ******* **** ****** to *****, ** ******).***** *** ***** *** ******* **** anti-relay ******** (********* **** ****** *** MultiClass ******’* **.*** ******** ** **** ********, *** device ****** ** *****/***/***.

**, ***, ***** ** ***** ***** secure ******* ** ****, ** ********* secure ******* ********.

********** *** ********* ****** ************* ** the **** *** **** ***** ********* can ** ********** ** *** ******* code *******.** *** ****** ***** ********, **’* possible ** *** ** *******.*************, ************* **** ***** *********** **** mean **** ** ***** **** *** extracted (*** *******, ** ******* ****** attacks), *** *************, **** *** *** that’s ******** ****** ** *** ****** is **** ***** *********.

***** ** ********* *** *** *******’* use **** ****** * ******** ******** them.

** *** ****** ******** ** *** SEOS ******* *** ***** *** ***** party ********** *******, ** ***** **** IPVM ***** ** *********** ***** **** exploiting ******** ******** *** ******* ******** to *** **** ****.*******, *** *** ********* ****’* ********** (and **** ******, ***** *** **** are *****), ********* ** *** ****** (iClass **, ***.), ** ********* **** secure (***/***/****).

***** **** ***** **** ** *** best ******** ** *** ******, **** you *** ****.** **** *** ***** ******** ** the **** ** *** ****, ******* it’s * ************ ****** **** ********* compatibility.* ** **** **** **’* *********, but ** ****** *** ** **** than ******** ** *** ********.* ********** **** **** ** **** is * **** ** * *** better **** *** ******** ***** “**** it”, *** **** ******* **** **** because *****’* ** ********** ****.

UE
Undisclosed End User #2
Jan 06, 2024

*****…*** **** ********* ******* ** ******, user-owned, ******** *******, **** *************** ***** AES-128 ** ******. *** ******* *** is ***** **’* **.

(1)