Nortek Mobile Access Reader BluePass Examined

Published Feb 12, 2019 15:28 PM

Nortek's Linear access control division claims to make mobile credentials "more secure and easier to use than ever before" with their BluePass reader.

However, the company's approach potentially uncovers big security vulnerabilities. Inside we examine:

  • BluePass Readers & Credentials Key Claims
  • Linear System Pricing
  • Potential Wiegand/125 kHz Weakness
  • Compared to HID Origo Mobile & Openpath Readers
  • Partnership with Unikey

Product ********

******/******'* ******** ****** ******** ***-****** *******, allowing ****** ***** ** ******* ***** or ******* *********** ** ******** *********** via ********* *** ****** (***).

*** ***** ***** ** *** ************'* overview:

*** ********:

  • **** ********** ******: ******** ***** **** ***-***** *** or ******** **-***/**-*** *** *** ***********.
  • ***** *******: **** ***** *** ******* (*.*.: ********), ***** *** **** ** ********* phone ** ***** ****** *** ****** 'touch' *** ****** ** ****** *** door.
  • ***** **** **** ****** *******: *** **** ******** ** * controller *** ******* *** **** ******* data *******, ** ******** *** ** retrofit **** **** ******** ******* ** swapping *** ******.

Key ***** ******* / ************

*** ******** ****** ****** **** **** a ****** ** ******* ******** ** relative ************, *********:

  • ******* ****: * ******* ************* ** ******** credential **** ****** ******* ******** **** not *** ********* ************** **** ****.
  • **-*** ** **-*** ****: ** ******* *** ***** ****** or ***** ********** *******, ******** ****** a ****** ** ******* ****** *** doors ******* ** *** ******.
  • ****** ****** *****: ****** ****** **** *******, **** PIN *** ******** ****** ** ****** range ****-***** ***** *** *** *********.
  • ***-********** ********** ******: *** ************** ********, * *** portal **** ** **** ******** **** the ****** ****** ******, ******* ***** to ****** *** **** **** ******** times.

BluePass ****** *******

****** ****** *** ******** ******* *** ~$250, ********* **** **** ******** *** alarm ************ *** ****** *********.

Credential *******

****** *** ********** ****** ****** ***** between $*.** - $*.** **** ** a ***-**** ********, ********* ** *** volumes *********. ******** **** * - 100 *********** *** *********.

** ********* ****** ** ********** **** is **** **** **** ****** **** have * ******** ********** ******** ** it, ********** ** ** ******* ** be ****** ** *** **** ********** to *** ****** ******.

************, *********** *** *** ************ *** are ****** ** ******** *******. **** cannot ** '******' *** *********** ***** visitors ** ******** **** **** ******* are ******** ** ********, *** *** BluePass *********** **** ** *********.

********** With ******** *** *** ***********

*** ** *** **** *********** ******* is ******** *** ****** **** ***** of ******** ****** *********** ** **** enrollment *** ** **** ******* **-*********** existing ****** *******.

******** ****** ** *** ****** ******** 26 *** ** ** *** *********** and ****** ****** ****** ** ****** that ***** ***** *******. ***** ******** to **** ***** *** ********** *****, they *** *** ** *** **** common *** ******* ****** *********** ** use. ***** **** ****** ********* ** advanced ******* ****** ** ****, **-***/**-*** credentials ****** *******, **** ****** **% ** *********** ***** ******* *** **** '**** *******' and **** ******** ******* ***** ***** them.

****** ****** *** ****** ******* ******** uploading * .*** **** **** ******** card *******, *****, *** ***** ********* to ***** *** ******, *** **** those ******* *** **** ********* **** BluePass ****** **** *** ************ ** users **** ***** ******.

Single ***** ****

*******, ***** ******** *********** *********** ***** be ******, *** ******** ****** **** comes ** * ******, ******* *****, short (******** **********) **** ***** ***** *** may *** ** ******** *** ***** door ** ****** ***********. ******'* **** BLE/125 *** ****** **** **** ******-**** boxes **** ** ******** *******.

*** ****** ****** ** ** **** and **** *-***** ***** @ ***** typical ** **** ***** *** *** be ******* ** ********** ******* **** *********** ******* ******* ********** ***** ******** ** new *******.

*** ***** ******* ***********, *** **** also ***** ******* *** *** ***** or ****.

** ****, *******, *** ******** ****** *** no ****** (** *** *******), *** the **** ***** *** ******** *** kHz ** ****** ******, *** ************ with ******** ***** (*.*.: ******* *******), only *** ******-***** *** *********** *** reach.

*************, ****** ***** *** '*** *** cannot ** ********' ** *** ***, potentially ******* ******* ********** ** ******* detailed ** **** **** ****** ******* **** **** $30 *** ****** **** ******:

BLE *****

*** ******'* *** *********** **** ** manually ******** ***, **** ****** ***** may ************* ****** ******** ** ****** users.

*********** **** *************:

** *** ******’* ********* ********* ******** is *** *** ****,
** *** ************* **** **** ** employee’s ****** ******
*** ***** ************ ***** **** *** building ****** **
******* * **** ****, ** ********, the ******.

** ****** ***** ***-*** *******, ** additional ************* **** ** ****** *** BluePass **** ********* ** ******** **** risk.

Wiegand *****

******* *** **** ** **** **** is *** ********* ** ********, **** Wiegand, *** ************** **** ******* *** unit *** **** *********** *** ** intercepted.

*** **** ** ********** ** '*** in *** ******' ******** ***$** ****** ** ******* ******* **** **** ** ********** ********* and ****** ** *** ***** ** reader *****:

******** ***** *** **** **** ******* by ******** * ****** ****** ** sensor ** *** ******, ** ********** such * ****** ***** *********** ** undetected ** *** ******.

Middleware ********** **********

******** ********** ********** ******** *** ********** **** *** ****** management ******** *** **** ****** * separate **** ** ****** *** ***** data *** **** *****.

***** ********* *** ***** *** ********* credentials ** ***-*****, *** ** *** trial ***********, **** ** *** ** does **** ** ***** **** ** required. *** ******* **** ******** ******** creating * ********** ****** ** *** access ****** *** **** ******* ********* record ** ******** ** ******'* ******.

************ **** ****** ** ******* ** their ********* ****** ****** ********** **** done ** *** ****** ******, *** in ***** ** ********** ****** ** turn-off * ****** **********, ** **** be **** ** *** *** ******.

Versus *** *****/****** ***********

*** **** ** ******** ** ****** to ** ****** **** *** ** used ** ***** ******* **** **** users **** ******** ****** ****** ********.

*** ******* ******** **** ****** ** mobile *********** *** ***-************ *** ****** be ******** ** **** **** *** device, ****** *** ********** ******* ** ***** ** '*** ****'. So ****** ********, ******** ******* *** be ****** ***** *** ***** *********** for * ****** ***** ** ***** $7 *** ****.

*******, **** ******, *** ****** ********** ** a ***-**** ******** **** *** ** used *** *** **** ** *** device ** *** ********, ***** *** is ** ****** ****.

Versus ********

**** ** *** **** '**** ******' features ********* ** ******* ********'* ******* are ******* ** ********, ********* *** 'Touch' ** **** ******* *** ************* with **** *** *** ******* *******.

******, ******** ********* **** ** *** 125 *** *** ******* ************ **** BluePass *** ** ********** **** **.** MHz ******* *** ********** **** **** the ****** ** **********.

** ***** ** *** ******** ****, **** ******'* *********** *******, *** ********* ****** ** ~$*** each, *** *** ***** *** *********.

**** ********, ***** ** ** ****** credential ******** ********. *******, ****** ******, Openpath ******* **** **** **** ******** controllers *** *** ****** ****** **** be **** *** * ******* *** purchased ******* *** *********** ** ** valid.

Versus ******** *** *** *******

******** ** *** ***** ** '***-***' 125 *** *******, ******'* **** ** quite ****. **** *** ******* *** HID **** ******** **** **** ******* ~$130 ****** ** ******'* ~$*** *****:

***** **** *******, ********'* *** *** compatibility ***** ***** *** '******' ********* credentials, *** ** ******* *** ********* using ***** ******** *********** ****** **** mobile, **** ****** *** *** ******* are ******** *********.

UniKey *****

**** ********, ****** ** ******* ** significant ******** *********** *** *** ****** platform. *************, **** ******* ** **** of * *********** **** '****** ***********' developer******:

** ***** ** ********* ***********, **** ******* *** ********* *** 'mobile ***********' ***** *** **** ******** from ****** **** ******* (*** *** **** **** ****), ****, ****, *** *********.

Comments (11)
U
Undisclosed #1
Feb 13, 2019

**** ***** **** *** ****** ** my ***** **** ***** ******.

UI
Undisclosed Integrator #2
Feb 14, 2019

**** ***** ** ** *********** *******. A *** ******:

*** ***'* **** *** * ***** motion ** *** ********** ** **** the ****? **** ***** ** ****** passing ** *** ******* * **** is * **** ** *** ****** in ** *******.

*** ***** ** *** *********** ** a ******* ********. *** **** **** at ************* *** **** ***** ... or **** *****

**** ** **** ***** ** *** a *** ********* ** ********* *** system. *********** **** ** ******** ****** becomes ***** ********** **** ********** *********** of ********...

***** **** ** **** ** ***** BLE ******** ** *** *** ******. This ** ** ***** ******** , not ******** *** ***. **'** **** and ***.

JH
John Honovich
Feb 14, 2019
IPVM

*** ***'* **** *** * ***** motion ** *** ********** ** **** the ****?

******* *** *** * ****** ** that.*** ****** ***** **** ** *** Era ** ******** *** *********** **** HID ****** ******:

*** ******** **** ***** ** ******** for ***** ** ****** ***** *** open ***** **** * ******** ***** thecompany’s ******** “***** *** **” ******* technology.  [emphasis added]

****'* ** *****. * ** ******* if *** ******** ** ***? ***** can *** *****?

Avatar
Brian Rhodes
Feb 14, 2019
IPVMU Certified

**** **** ********, *** '*****' ******* activation ** ** *** ******: *** '***** *** **' ****** *******.

************, ****** *** ***-*** ******** ** general ****** *** **** ** ******* is ****** ** * *******, *** a ********.  **** ********* **** ******* doors ***** ******* **** ***** ** your ****** *** *****-**** ******. 

*******, **** ***** ** ********** ******* and ********* ********* ** * **** will ****** ******* ** **** ****-******** deployments. 

*'** *** *** *** ******* ** licensing *** *******.

SD
Shannon Davis
Feb 18, 2019
IPVMU Certified

**** **** ** *** ************* *** doing ** ***** *** ********** ***** into **** **********. **** ***** *** learn *** *** ****, **** "****", so **** *** **** ** ** the **** *** *** ***** ** is ***. ***** *********** **** **** with ***** ****** ******* *** ***** very ****. *** *** **** ***** the **** *** **** ******** **** when ******** ** **** ******** ** it **** **** ****** ***** ***** applicable.

********* ******* *** ***** * **** off *** *** *** ******* ****** everyday, ********** **** ***** ***** ** technology **** ******* ****** ** *** phone ******* ** *********** *** *****.

UE
Undisclosed End User #3
Feb 14, 2019

*** **** ******* *** ******** *** comparison?:

******** - ********* *** *** *******

****://***.***-******.***/********/********

Avatar
Brian Rhodes
Feb 14, 2019
IPVMU Certified

** * ******* **** ******** ** proprietary/ **** ********* **** *** ******?

Avatar
Cary Menage
Feb 14, 2019
IPVMU Certified

* ***'* ***** **, *** * am **** *** ***** ****** ****. It *** ****** ** ** *** am ****** ******* **** *** *** of ** **** ********* ** **** at *** ****.

RL
Randy Lines
Feb 14, 2019

***** ****** :) ****** **** ** at ****** *** ** ****. *** credential ** *** ****** **** ** a ****** ***** *** ** ***'* be **** ****** ****** *** ** clients. 

***

(2)
UI
Undisclosed Integrator #2
Feb 14, 2019

**

****** ***** ** **** **** ******* on ***** **-** *** **-* ******* ... ******* **** *** *** ******* ... *****'* ***** ** ***.

(1)
Avatar
Brian Rhodes
Mar 17, 2020
IPVMU Certified

******* ** ********* ******** ***********: