Testing HID Edge Solo

Author: Brian Rhodes, Published on Oct 03, 2013

HID is the biggest name in IP door controllers, especially for single or dual door controllers, with their Edge line. Now, as surveillance companies, like Axis and Milestone, target the access control market, competition may heat up.

HID offers a very interesting turnkey solution, "Solo", for single doors. While nearly identical in appearance and construction to HID Edge controllers, "Solo" is limited to managing a single door. It comes loaded with firmware that enables basic access control functions such as managing door locks and readers, as well as storing cardholder information, credential details, and access schedules onboard the controller. 

In this report, we share our test results of using the HID Solo with our demo door, looking at how it works and its specific weakness including operational and functional deficiencies.

*** ** *** ******* **** ** ** **** ***********, ********** for ****** ** **** **** ***********, **** ********* ****. ***, ** ************ *********, ******** *** *********, ****** *** ****** ******* ******, *********** *** **** **.

*** ****** * **** *********** ******* ********, "****", *** ****** *****. ***** ****** ********* ** ********** *** construction ** *** **** ***********,"****" ** ******* ** ******** * ****** ****. ** ***** ****** **** firmware **** ******* ***** ****** ******* ********* **** ** ******** door ***** *** *******, ** **** ** ******* ********** ***********, credential *******, *** ****** ********* ******* *** **********. 

** **** ******, ** ***** *** **** ******* ** ***** the *** **** **** ******* ****, ******* ** *** ** ***** *** *** ******** ******** including *********** *** ********** ************.

[***************]

Key ********

*** ************ ** ********** *******:

  • *****:**** ** * ****** *******, ******** ******** *** **** *** take ******* *******. ***** '******* **' **** * ******** ******** ****** ** *************, ******* ****/****** *********** ******** ****** **** *** *** ********* ***** ******* * - ** ******* **** **** *** ********** ** ** *** own******.
  • ****** *******:***** *** ********** ****** ** ** ***** *******, ************, *********, and ******* **** **** **** **** ***** ** * *** party ******** (**** *****). ******* ****** ** ****** ******, *** first **** ** ********** ** .******** ** ***** ************.
  • ** ************: *** **** **** ** * '******' ******, *** *********** the ********** ** ***** ************ ** ********* ***** ********* ** not ******** ***** *** ** ***. 
  • ******* **** *******/****** *****:**** **** **** ******* **** ***-******** **** ******* *** ***** basic ***** ** *******: *********** *****, **********, *** *******. ***** formats *** ** ********* **** (**: *** ****** *** **********), *** stored ** ********* **** ****** ** *******, **** *** *** formats.
  • ** *******/******* **: **** ********** *** ****** ***** ** ***** ** ******, and **** ****** ********* ******* * '**** *******' *** ******* of **** ****** *** *** ** **********. **** **** **** not ******* *** ********* *** **** *******, *** ** *** option ** ******/*** ******* *** ********* ******** ** *** ******.

***** *** ******** ** *** **** "****" **** **** ********* (an *** *** ***** '*** ***' *******) *** ***** ***** including * *********** ****** ** ***** *******. *** **** ***** reviews *** *** ***, *** ******/ ********** ******* ********* ************** *** ****** *** ~$***.

IP *****

*** **** **** ** * ******* ***** ****** ******. **** given * ****** ** *******, *** ****** ** ********** **** any ******* ********* ** *** **** ***. ** ******************* **** ****, ******, *** ****** *** **** **** ** *** the ********* ** *** ***** ********. *******, ** *** *** most ******** ***********, ** *** **** ********* ***** **** ****** loading **** *** ***** ******** *** ***** **** ******* ******* to ***** **. ****** ************* ******* *** *** ** ******** via *** ** ******** ****** *************, *** **** ****** ** preconfigured ** ********* ****** *** ******* ******.

Live ****** ****

*** '**** ****** ****' ** * **** ** *** ********** recent ******** *** **** ****** ******** ******** **** ******* ******* ********** of ***** ***** **** ** ********* *** **** ** *** interface. ***** **** ********** ****** **** ***** *** **** ******, options ** ******** ****/****** *** **** *** ***** ****** *** given ***** ********* *******. *** ***** ***** ***** * **** overview ** **** ******:

Adding *****/*****

*** ******* ** ****** ****** * **** ** * **** is ******** **** ******* *******. *** **** ****** * ******* of **** ***** ** *****. *** *******, ** * ****** user *** **** ******** *****, **** **** ** *** *** thousand ******* *** ****. *******, *********** **** **** *** **** falls ** *** ***** ** *** **********, **** ** *** likely * *********** **********. *** ****** ****** ** ********* * new ****** *** *********** * ********** **** ** **** ** shown ** *** ******** ***** *****:

Configuring **** **********

* ******* ****** ** *** ********** ** ******** ******* ******** to ***** *** ******** ******* ** ********. *** **** ********* offers * ********** ****** ** ********** ********** ********; ********** **** Door ****** *****, ** *** ******** *************, *** ***** ****** types *** ****. ***** ******* ** ******* (**** ***-****** *** card ******* *** ****** ******* *** *********), *** ********** ****** be **** ** ******* **** ******** ***** ******* *****. *******, more *********** ******* ********* ******** ***** (**:********) ** ***** *** ********** ******* ****** ** ********** ********** ******. The ***** ***** ******* ** ***** *******:

Reports *** ******

**** **** ****** *********** ********* ******** **** ******** ********** ************ to **** **** *** **. *** **** ****** ** *** controller ** ******* **** ****** ********** (**: **** *******, **** Events, **** *********) **** *** ********** ** * *********** **** a .************ ****. **** *****, ******** ******* (**: "**** *** **** Holder * **** **** *** **** **** ****?") **** ** filtered ** ****** ** ******* ******* *******. *** **** ***** demonstrates ****'* "******" *******:

** ********, **** ******** * ***** ****** ** '******' **** are ************ ** ******* * ****** ** ******* ******* **** 'local **** *****' - ****** *** ****** **** *** ***** - ** ******* ***** ************ ** * *** ** ***** address. ***** *** ***** ** ****** ** ***** *** ****** be ********, *** *** ******** ******* *** *****, **** ****** door ****** ************ **** ** ************ ******* ** *** ***** available. *** ***** ***** ********* **** ** ******:

Wiring *** ************

*******, ** ***** ****************, **** *** ** ************* ******* ** ******** *"**" ********** boxes ** ****** **** ** ***** ***** **********. *** ********** itself *** *** ****** *** *** *****, *** **** ******* leading ** **** ********** *** ** *** ******* ** ****** for *********. *** **********'* **** *** ******** ******** ************* ** show ** *** ***** *****:

Ideal ************

*** ******* ********** ** **** ** **** ** **** ******** one ****. ** *******, **** ********* ** *** ******** ** **** ***** ************ **** ******* individual ***** **** ******* ***** ** ******** *****, ********** *******, or ******-**** ******* *****. 

 

Comments (19)

**** ****** *** ***** ****** ********.

** ******** ** ******** ** *** ** * ****** **** style ********** ***. * ****** **** *** **** ** ******** to ***** ** ** * * ****** ***.

***** ** *****! * **** *** ******-- **** ** ****** helpful.

****’* *** ********** **** ******* *** ******* ***** ****** *** reader? **** , ******.

*** **** ****** ** *******, *** **** ***** ** ****.

***** *****,

********* *** ****** *** *** ********** ** * ****** **** puts *** **** ********** ** *** ********* **** ** *** door.

******* ***** *********** ***** *** ******/********** *** *** **** *** gain ****** ** **** ******. ******* *** ********** ******* *** door ****** ** **** ********** **** ******** *** ****** ****** and **** **** ********* ********* ** *********.

***** *** * ****** ** ****** ******** **** ******* **** way, *** **** ****** **** ****** ** **** ** ********, non-high ******** ********. *** *** **** *** **** ******:***** ****** ****

**** ** *** *****, * ** *** ** ****** ** the **** **** *** * **** *** ***** ** *** by ******. ***** *** ******** ******* ******** **** ****** *** Edge **** *******.

**** ** **** *** *******:****://***.*********.***/********/*********-********* ****** ****** *****-********** *** ****-**-*** **-***** ****** ******* ********* which, **** ******* **** *** ******** ********* ********, ***** ************ to *** **** *** ****** * **** ******* ** ******** deployments ********* ****** ********** *** ****** ********** *** ******** *** browsers, **-***** ********** *********, ****** ********* *** ****.

* ** ********* ******* ** ********://***.***-**.***/(********* ********** ************ (***)

***** ***** ****** ********. *** *** **** ******** ***** ******** to ** **** *** ******* ** **** *** ******** **** it ** ***** *** ******. *** **** *** ***** ***********.
*** ***** ******** ***. * **** *** ******* *** *** of *** ***** ********* *** ***** ** * *** **** options **** **** ****** **** **** ***** ***** **** ******.

*****, *****.

****** *** *** ********. ******, *** *** ****** **** * number ** ********* ** ******* '*********', ** ********** ********** ******** *** *** **** ******.

******* ***** ***, * ********** **** * ******** (***** * believe *** ********* ** ***) ***** ****** **** ***** ****. In *******: ** *** *** **** **** ****, *** ******* was *****. (*** ***** ****, *** ***)

***** *** ***** **** ********** *** ************* *** **** ****** '**** ****' *************, ** ****** **** prudent ** **** **** **** **** *** *** ****** ********* platforms.

**** **** **** *** *** *******. **** *** *******, * believe **** *** **** **** *** ***** ***********. *******, ***** the ********** ** "****" ************* ** **** ** * ****** system ** ***** ** ** *** **** ***** ****** *** most. ** ****, ** *** ******* *******'* ******** ****** ******** module.

*******,

  • ** ************: *** **** **** ** * '******' ******, *** *********** the ********** ** ***** ************ ** ********* ***** ********* ** not ******** ***** *** ** ***.

** *****, **** ** ***** *****. *** **** **** ***** seamlessly ** ******* ******** ******, *** *** **** ** ********** with *****, *********, *** ********* *********. ** *** *** * systems ** *** ******* ******, *** *** ** *** *********** are **** ****.

**, *** *** **** *****.

**** **** ** *** *** **** ** **** ****. *** must ***********/********** ******** ** **** * ********** **** **** ** * Host ***** ******.* ** ********* ***** * **** ************* ****.

***********, **** ******* ** **** ** *** **** **** *******. No ******** ********** ** ** **** ** **** *************.

** **** ** *** *** ********, *** **** ** ** possible. ** ****** **** **** *** ** *** *** ** is *** ********.

*****, **** ** *****'* ****, *** ****. ** *** **** how ** **** * ******? ****, *** ** **** ***:

******, *** ****** ** ********, ********** *******. ****** **** ******** down ** ****** *******, ***'* ** ****** *** ***** ***** or ***********.

*** ** '**'? * ***** **** ******, *** ****. ****** point *** ***** ********** ********.

* ** ********* *** *** ******* ** *** ******. ****** see ** ***** **** *** * ******* *********** ** **** inaccuracies.

"** *****, **** ** ***** *****."

***** *** ******* ********* ** *** ***** ** **** ********* claim. ****, * *** *** ***** **** ****, ** *** are ****** *****. **** ***!

** *********, ** *** ********* **** **** ** *** ********, I **** ******* ** *** ***.

* ***** **** ** ***** *** **** *** *** **** the ********* **** ** *** ***** *******:

****://***.*********.***/********/***********/****/*****

***** *** *** **** **** ***** ****:

"*** *** ******** **** ***** ** ****** ******** *** ** converted **** *****-***** ********* ** * ****** ****** *** * host *********** ******* *** ****** ******* *** *** *******. "

**** ******** ** *** **** **, ** ** **** ***, and *** **** **** *** ****'* ***** **** ****** *********.......

*** **** ** ********** **** '**** ****' **** *** ***** 'Edge ****'.

** ******* ****** *** ***** ** ***'* *********, ** ***** to ***********.

** **** *****, ** ** ** ****** * ****, ** is * ****. **** ** **** ** ********** **** ******* - **** ****, *** **** ****.

** *** ********** * ******* ****** ******* ******, ********* ** integration **** **** ****, *** *** *** **** **** ***** when ** ** ******** ** *** **** **** ** ***. I ** ******* ******* ** ******* **** *** ************.

******.

*** ***** **** ****, *** *** **** *** **'* "*** possible." ** ********* * ******* ***'* *** ***** **'* ********* ** ******* ALL *** *******, *** **** *** **** *** **** ** negative?

* ***** **** **** ** ***** *** **** ** *** purveyors ** * ******* ****** *** ** **** ** ** your ************** ** ******** **** ******** *********** **** *** ******* matter. ** *** ****** *** ****** ******* ** *** ****, nobody ******* ** ** *** ******** *********** ** *** ** any ********** ***. ***, ** *** ***** ****, *** ******** to *** ** * ************ ******, *** ** *** **** the ******* ********* ** * ******* ***** *** ****** ****** childish ******* *** **** **** "**** *** ** **** ***" in * ********* ******. * ***'* ******** * **** * was ******** *** **** ** ****** ****** ** * ***** and **** "**** ***** ***'** **** * *** ***** ****." You ****** **** ******* ** ** **** ***** ********* **** your **** *********. **** ****** ****.

"****** ******* ** ** *** ******** *********** ** *** ** any ********** ***"

******,

* **** ******* *** **** *** ******** *** **************, ***** fighting. *** * ********** ** ****** ******* ** *** ** act ************* *** *** ********* ******* ********** ** ***** *** the **** (********** **** **** *** ********* *****).

* **** ********* **** *******'* *******. **** ***.

****

**** *** ****. ****** **** **** *** ** ******** *** insulting. **** ****** ** **** **** *** *****.

***** ****** *****, ****** **** ****

Login to read this IPVM report.
Why do I need to log in?
IPVM conducts unique testing and research funded by member's payments enabling us to offer the most independent, accurate and in-depth information.

Most Recent Industry Reports

Milestone Entry Level Mobile Password Vulnerability Disclosed on May 24, 2017
While many manufacturers have only addressed cybersecurity vulnerabilities after public disclosures were made (or threatened), Milestone has...
How Integrators Use IPVM on May 24, 2017
150 integrators explained how they use IPVM and how it helps them stay informed and improve their business.  The 4 main uses integrators cited for...
Alarm Supervision Guide on May 24, 2017
Burglar alarms can constantly monitor the health of attached circuits, sensors, and devices to ensure that they remain operational. This is known...
Arlo Go Cellular Cloud Camera Tested on May 23, 2017
Totally wireless surveillance cameras are growing but almost all typically depend on a hub and local Internet access. However, many outdoor...
Avigilon New COO James Henderson Profile on May 23, 2017
It has been nearly 2 years since the infamous Bryan Schmode 'resigned' as Avigilon COO. Now, Avigilon once again has a COO, promoting James...
Hikvision Marketer Caught Spamming, Fails at Coverup, Fired on May 23, 2017
A Hikvision marketing employee was caught by IPCamTalk trying to surreptitiously disparage IPVM and IPCamTalk. This is an outgrowth of Hikvision's...
Aura's 'Invisible Ripple' Next Gen Intrusion Detection Tested on May 23, 2017
Aura Home is a startup intrusion detection system, but it claims new, high-tech sensing that monitors the 'invisible ripples' movement creates,...
Pelco Shutting Down Clovis Line, Laying Off 200 on May 22, 2017
Pelco's Clovis facility once turned out some of the industry's most popular products. Now, the facility is mostly building "obsolete" equipment,...
IP Camera - 15 Year Shootout on May 22, 2017
How far have IP cameras come? We bought and tested 4 cameras across the past 15 years to understand how much and where performance has...
Remote Video Monitoring Providers Directory on May 21, 2017
Remote video monitoring can help integrators generate RMR plus end users lower their security costs and/or improve response to critical...

The world's leading video surveillance information source, IPVM provides the best reporting, testing and training for 10,000+ members globally. Dedicated to independent and objective information, we uniquely refuse any and all advertisements, sponsorship and consulting from manufacturers.

About | FAQ | Contact