Keypads For Access Control Tutorial

Published Jul 28, 2020 13:47 PM

Keypad readers present huge risks to even the best access systems. If deployed improperly, keypads let people through locked doors almost as if they were unlocked.

IPVM Image

However, despite the drawbacks, keypads are still one of the most common choices in access today.

With this note, we examine the weaknesses of keypads including:

  • Revealing Buttons
  • Snooping Eyes
  • PIN Sharing is Easy

Inside we offer advice on how to deploy them securely and examine a type of keypad that overcomes glaring weaknesses.

Operation Described

The function of keypads in access control is simple. A door or gate remains locked until the user enters a valid combination string into a nearby number pad, usually a sequence of numbers.

Most access control applications assign each user their own number, called Personal Identification Number (PIN). Unless the user enters a valid combination, the opening remains locked.

Why Use Keypads?

If these input readers are so terrible, why do people use them? The single biggest 'pro' in using keypads is that no external credential is required. There are no cards or fobs to buy, fingerprints to enroll, and template records to manage. A user is given an access code that is presumably memorized or included in other documents, and nothing else is required.

The lack of external credentials results in a lower operating cost relative to 'credential-based' systems.

The Problems

Despite being one of the oldest and most used access readers, keypads have huge vulnerabilities. Worse still, it takes no special tools or skills to exploit these problems. While individual units may be better, or even worse, than others at these shortcomings, the biggest problems are:

  • Revealing Buttons
  • Snooping Eyes
  • PIN Sharing is Easy

In the sections below, we examine these issues and address how they undermine even the best access control platform and most secure locks.

Revealing *******

****** ******* **** *** ******* **** over ****. **** ** * **** problem ******* **** *** ******* ****** to **** ****** *** *** **** typically ******* ***** ** ***.

***** *******

*** ****** ***** *** ******* **** pick ** **** *** ***** **** the ****'* *******. ** ***** ******, only **** ******* **** **** ****, but **** *** **** ************* ******** would ****** ********* *** ******** ******** of *** ****** **** * ****** characteristic ** *** ****, *** ** Post *******.

****** ******** *** **** **** * minutes ** ********** **** **** **** 'secured' ****. ****** *******, **** **** representing * '******' ******, ****** *** potential ************ **** **** ** ********* to * *** *******, *** ****** combinations (*******/*****/********* *******) *** **** ******* to ****** ****.

IPVM Image

**** *******

********, **** ** ******* ** *** example *****.

******* ** *****, ****** *** ****** buttons *** *********** ** ******* **** is **** *** **** ****. ** this ****, ******** *** **** ****** combinations ** ************* ***** ** ****** the ******* **** ********** ****:

IPVM Image

**** ** ******/********

* ***** ****** ******** ** ******, stickers, ** ******** **** **** * valid *** ***** ** ***** ****:

IPVM Image

** *******, ***** ****** *** ****** as * ****** ** ***********, *** users ******* ******** *** ******** ***** of *** *** ** ***, *** the ***** ** ****** ******* ** the ******* *** ** ****** ** pointless *** **** ************.

Snooping ****

**** **** ******** ** ***** ************ is *** *******, ***** *** ** watched ******** ***** *****.

****** * **** ** ********** ** shielding ***** ******* *** *** ****** while ******** * ***, **** * casual ******** *** **** *** ******** the ****. * **** ********** ******** may **** *** ****-***** ****** ** even '******' ******* ******* ** ***** out ***** ************:

IPVM Image

PIN ******* ** ****

**** ** '*******' ***** ** ******* a **** *** *********, * **** vulnerability ****** ********** ** ******** *** users ******* ***** ********. ** *** seem **** ** **** ******** *** an ************ ************, *** ******* * unique *** **** **** *** ***** person ***** **** '****** *******' ** lost.

**** ***** *** ******** ***** ***** and ******* ***** *** ******* ** labels ** ********, ******* ** *** unit ** ***** *****, *** ******* undermine ****** ********** ****** ***** ** all:

Configuring ******* *** ** ***********

********** *** ****** ** * ********** may **** ***** ***********. *** ************* protocol ****** ** **** ******* *** many *****, *******, *** ********* ********* without ***** ********* ** *** ** incorporate ****** *******.

** * ******, ************* ****** ****** can ** **********, **** **** *********** requiring *-***, *-***, ** **-*** ******. Generally, *********** ******* *** *********** *** these ********, *** *** ***** ****** needed **** **** ********* ** ***** Keypad ****** ** ****.

OSDP *******

*** ** *** '************'******* ** ****** **** ****** ******* *** *********** values ** ************ (*** *********) ***** formats.

*** ******* ** *** **.*.* **** standard ******** **** (*.**) ** ***** below:

IPVM Image

Steps ** ******** ****** **********

**** ******* ********* *** ****** **********, the ******** **** **** ******* *** be *********. *** ***** *******:

***** *** ******** *****

**** **** ****, *****, *** **** 'temporary' ******* **** ****. ********** ******* inside ** ****** ********** *** ****, but ********** ********** *** *******, ******* them ***** **** * **** ******* (rubbing ******* ** *******), *** ********** the ******* *** ****** *** **** will ** * **** *** ** preserving ********.

*******, *** *** ********** ****** ******* in *********** **** *** ********* ****** by ***** ********** ***** **** *********** cards ** **********.

********* ****** ****

*** ** *** ******* ******** ** keypad ** **** *** *********** ***** change. **** ****, *** ****'* ***** of ************** ** **** *** ****** of ****** *****.

*** **** *** **** ************* ****** of ********* ***** ******* ** **** is ****** ** ****** **** ** a ******* *****. *** ********* ** changes ******* ** *** ********** ** users, *** ******* **** **** **** 100 ****, ******** *****-****** ***** ******* the ***** ** ****'* *****.

*********** **************

******* *** ****** ** ******* ** keypad ******** ** ** ******* **** with **** **** *** **********. *** example, ********* ***** ** ***** **** credential ***** *** *** ************ *** the ***** ****** ** ******** **** neither ****/****** ***** *** ****** ***** can ** ************ ****. ** ******* using ******** *********** ******** ** ********-****** ************** ******.

IPVM Image

*******, *** ******* *** ****** ********** factors ********* ****** ** ********** **** to ********** ******* ******** *** *******/*********** secondary ***********.

Use ******** *******

**** ******* *** **** ****** **** others. * ******* ****** '******** ****' or '****** ****' ** *** ******* numerical ****** ** * *********** "*-*,*" orientation, *** *******, ********* *** ****** every **** **** *** ****. *** randomness ********* *** '****** ****' ************* and ****** *********** **** ***** *** buttons. *** ****** ***** *** ***** below:

IPVM Image

*** ********** ** ***** ***** *** the ********** *********** ** ****** **** time * **** ******* ** * code, ****** ** ****** ****** ******** in ***** ** *** ****. *******, they *** **** ********* (~$*** - $1200, ******** ** types) *** *** ****** ********* ** the ****** ******.

[****: **** ***** *** ********** ******* in ****, *** ************* ******* ** 2020.]

Comments (12)
UM
Undisclosed Manufacturer #1
Jul 28, 2020

** *** ******** *************** ***** **** the **** ***** *********** *** **** strike ** *** *******, ********* **** of *** **** ****** ****** **** tethered ****** ** *** ******* ****** wall? ** *** ******* ***** ******* inside *** **** *** ****** ** tethered *******.

SD
Shannon Davis
Jul 28, 2020
IPVMU Certified

*** *** ***** ******* ****** ****** is ******** *** ** ***'* **** new ******** **** **** **** ** with ** *****. * *** ******** searching **** *** *** *** * good ******* ****** **** ****'* * stand ***** ******.

IPVM Image

(2)
(2)
U
Undisclosed #2
Jul 28, 2020
IPVMU Certified

** ***** * ****** *** ***’* rearrange *** ******* ***** **** ** even *** *** ****?

IPVM Image

** **** ***** * **** *** could **-*****?

UM
Undisclosed Manufacturer #3
Jul 29, 2020

** **** ***** ** ****** ***** ? ***** ** ** *** *****

UM
Undisclosed Manufacturer #3
Jul 29, 2020

****** **** ************ **** **** *** System, ******** ** **** **** ******* something **** ****** ****** *** ****** the **** *** **** **** ******** way ** **** *** **** ** the ****** *****

UE
Undisclosed End User #4
Sep 23, 2020

*** *** *** ******* **** *** years.

U
Undisclosed #5
Oct 18, 2020

****** - ****** ********* *** *** security

JC
John Cebrowski
Sep 24, 2021
IPVMU Certified

*'* *** * *** ** ****** locks ** **** *** ********** **** an ****** ******* ******. ***** ** well *** * *****. ** ***** is * ********** ****** ******* ** was ** ************ *** ** ********* costly ** ********** ** *** * wire **, * *** ********** *** need *** ***, *** ** ***** be * **** ******* ****** ************ at *** **** ******* ** ** a ********.

DR
David Rasmussen
Mar 16, 2022
IPVMU Certified

*'* **** ***** ** *** **** multifactor ************** *** ********* ** ****. In * ******** ****, * ******* physical ******** ** * **** ******** site. ** *** ***** ****, ** moved **** **** ******-****** ************** ******* to ***********. ** ****** *****, ** is **** *** **** *** ****** to ***** * *** ****, ********** if *** **** * ***** ****** of *********. **** **** *********** **************, we **** ** * **** ******* to ******** *** "**** ** ******" or *********** ****** ***** *********** ************** now ******** * **** ***** *** pin. ** ******* *** *******, **** as **** ** ****, ***. ****** it *** * **** ** ********* manage, **** *** ********* **** ******* on *****, ** **** ****** **** more ******. ********* ** **** ******** is ********* ****** ****** ***** ****** your *** **** * ** **** incorrect ***** *** ******* **** ** back. ******* **** ***** ** *** high ******** ***** **** ******** ******** managing *** ******** *** ***.

(1)
Avatar
Scott Lindley
Mar 16, 2022
Farpointe Data, Inc.

**** ******* *****. ***** *** *** sharing.

Avatar
Isaiah Calvo
Jan 30, 2023
IPVMU Certified

** ********** ********, ******* *** ******** more ************* *** ****-********. **** ** evidenced ** *** ********** *** ** touchscreen ******* *** ********* ************** *******, which ******* * **** ********** *** secure *** ** ****** ********* *** other ****** *****. ************, *** *********** of ******* **** ***** ******** *******, such ** ******** *** *********** *******, is * ***** **** ** ****** to ******** ** *** ****** *** smart ********* *****. ***********, *** ******** of ****** **** **** ********* **** the ****** ****** ***** ***** ***** to ******** **** *** ****** *****, view ****** ****, *** ******* ************* for ****** **** ** **** ******** and ********. **** ***** ******* ** additional ***** ** *********** *** ******** for *****, ** **** ***** ** able ** ****** ****** **** ***** smartphones.

UE
Undisclosed End User #6
Jan 30, 2023

@*********** *** ****!