Rocks vs Wiegand: Access Control Risks

Published Jul 14, 2021 15:53 PM

Wiegand is an access control security risk but so are rocks. How should security professionals handle such risks?

IPVM Image

Access control manufacturer PDK's founder talked about their new OSDP enabled product while emphasizing that other fundamental risks still exist, such a simply throwing a rock through glass to break in.

Inside this report, we share:

  • PDK Founder contrasts Wiegand vulnerability to rock smashing risks
  • Comment on how OSDP used to segment access market
  • Why exploiting Wiegand does not take great complexity
  • OSDP importance as 'Industry Standard'
  • Examining how OSDP fixes Wiegand risk

For background, see OSDP (vs Wiegand) Access Control Guide.

PDK ******* '*** **** ****' ********* ****

****** ******* **** ****** ****, ** ****** ************ **** **** while **** ******** ******* ******** *******, physically ******** * ****** ** * major **** ******:

** *******, *** *** ********** *** new, ****** ******** ****-******* ******** ********* ***. *** *******'******-****** ******** **************** ******* **** *** ** *** support ****.

IPVM Image**** *****, ********* *** **-******* ** PDK (**********)****:

************'***********'.*******,************************,*'******************,***,******************? (*******?)*****,****,***'****************************************.*******,******'***************************************.********,*******,*************************************************************,******************.

**** **** '** ******* ******'

***** **** **** **** **** ** used ** ************* *** ******** ********** to ************ '******* *** ******' ** exclude ****** ********* **** ** *** have **:

****, ***** **** ** ***** ** the **** ****, *** ****, ***** in **** *****, *'* * ****** bit ** * ******** **** ****** like ****. ***, *** **'** *** a ***** ** *********** ****** *** organization **** *** *** **** ***** this ********** *** *** ** ********* what's **** *********.

*****'* ** ******** **** *****'* ********** in *** ********, ****'* ********* ** large ************* ** ******* *** ******, right?

*** ** ******* ******

*** ********* ********** *** '*******-********' ** using********(************* ****) ******* **** ***** *** doors ** *** *****:

**** ***'** ********* ** **** (******* door **********) ******, *** *'** *** my ********** *** ** *** ****, and *'* ******* ** ****, ***** three, ****, ** **** ****, **** the ******* ** **** ****, ** really ** *** ******* **** ******** is ***** ** *** * ******* and *** *** **** ***, *****, and ***** ***, *** ****, *** wires *** ******* ** **.

*******, ******** ********** *******'* ******** ** not ******* ******* ** ******. ** fact, ***** ******* ******* ****** **** than * *********** *** * *** minutes ** ***.*** ***** ***** ***** *** ******* are ********* *********:

******* ******** *** **** *** *********** to ***, **** **** **************** ~$** - $** ******.

OSDP ********* ** '******** ********'

***** ****** **** '********* *********' *** to ** ******** '** ******** ********' for ******, *** ******* ***** ** saying ** *** ******* ** ***** security:

**, *** ****, *'* *** ***** say **** * ***'* ******* ** OSDP, * ***** **** **'* ********* important. *** *** ***, ** *** the **** ** ***** ********* ******* it *** *** ***** ***** ** do *** ******* ********* *** ***** it. *** ****'* **** ** *** is ********* *** ****** ** ****. And *** ******* ** ****** **** out *** ***. *** **** ** truly ********** *** *** **** **** that **** **** *** **********. *** there *** ********* ***** ***** ** features **** *** **** ** **** adjustments ** ******* ** ******* ** becomes ** ******** ******** ** ******** specific.

OSDP **. ******* ****

**** ** ********* ******* ** **** security ** *** **** *********** ** access ******* ** ***********.

******** ******** ******* *.*.*, ***-*** *** ********** ** **** on **** ******* ****** *** **********. Previous ******** ** **** *** *** support **********, ** ** *** *** defined ** '*********' ***** ****.

**** **** ****** *******, *** ******** between ****** *** ******** ********** ** encrypted ******* **** ************ *** ********* copying **** '*** ** *** ****** devices.

******* **** *** ******* ******* ****. For *******,*** $** ******** ***$** *** **** ************ *** ********** **** (********** ** how ****** *** ****** **) *** makes ** **** ** ****, ******, or ********* ****** **** **** ** break **** ** ****** ******:

IPVM Image

****** ***** ****** ****** ** ********** to *** **** ** ******* ******* when ******** *** ********* ** *** reader. *** **** *********** **** ********* can **** ** **** ** ****** identical ****** ** ***** ***** ** to ****** ***** ******* ******* ** systems ********* ******* ********.

****/****

Comments (14)
RL
Randy Lines
Jul 14, 2021

***** !! ** ****** ** *** still * ****** ** ******* ****** on ****** *******. ***** **** * one-down-man-ship ******** ** ******** ******** *** we ***'* **** ********* **** * tamper ** *******.

***

(2)
Avatar
Brian Rhodes
Jul 14, 2021
IPVMU Certified

******** *** ** ***'* **** ********* have * ****** ** *******.

** **** * ****** ******, ** is *** ********** ** *********!

(2)
UM
Undisclosed Manufacturer #1
Jul 14, 2021

*** * **** *****, ****. ** can ********** ****** * ****** ****.

IPVM Image

(5)
Avatar
Michael Silva
Jul 14, 2021
Silva Consultants

********, *** ******* ************* ** **** access ******* ******* ** **********. ** need ** ***** * **** ******* the ******, **** **** *** ******* to ***** ** ***** *** ******** and **** **** ***** **. **** people **** **** ******** **** *** door **** *** *** **** *****. During ** ******** ***********, * **** that * *** *** **** * building ***** **** ********* **** **% of *** ****.

**** ********** ** **** ******* ******* of *** * ***-*******, ****-***** ******** to ******** **** ** *****. *** level ** **** ****** ******* **** facility ** ******** *** **** ** mandatory ** *** ******** ** *********** at *******.

******* ***** ** ********** *** *********** to ******** ***** ** ******* **** as ******* **** ************** ***** *** networks ** ************** ***********. *******, ** most **********, ***** *** *** ********** cases ** ** ******** ******* ****** using ***** *******. ***** *** *** easier **** ** ***** * ********: tailgating, ******** * *****, ** ****** looking *** * **** **** *** failed ** ***** ********.

**** **** ***** ****, * ***** that ** ** ************* *** * manufacturer ** ******** ** ***** ******** that **** ***** ******** *************** **** more ****** ******** *** ** ******** at ****** *** **** ****. **** consumers *** ***** *** ********** (******* false) **** *** ******** ******* **** by * * ********* ************ **** indeed ******* ********. ******* * ******* with ***** ******* ******* ** ********** in ** *******.

(20)
(1)
SD
Shannon Davis
Jul 14, 2021
IPVMU Certified

* *****'* **** **** ** ***** types ** ******* ** *** ***** anymore. *** **** ***** ** *** easiest ** ******* *** ****** *** you ***** ** **** ******* ** find ***.

* ******* *** **** ** ******** to ** ********* *** **** **** don't ****** ****. ***** ******* ** to ******* * *** ****** **** a *** ********** *** **** ***** are *** ******** **** ***** ********* cards ****. **** ******* * ******** to *** * ********** **** ** even * **** *** ** *** extra ****.

**** ** ****** *********** ** ****** bid ***** ******* *** *** **** readers.

Avatar
Kyle Folger
Jul 14, 2021
IPVMU Certified

* *** ******* ******* *** *** comments *** *** ********* **** * was ********. * ***** *** **** question ****** **, "*** **** ** your ********* **** ***** ******** *****?"

*** ** *** ****** * ******* the ******** ***** ** *** ********* at *** **** ** *** *** don't ****** ******** ** **** ** more ******. *** *** ******* *** a ***** ******* *** * *** floored **** **** ********* ****. * have **** *** *** **** **** installed ** *** **** *** *****. I ********** *** ******** ************** *** the **** *****, *** ***** ** no ****** *** ** ******* **** didn't **** ****** ******* ******.

** ******* *********, *** ******* ** often **********. ****** ***** ******* * mullion ** ********* **** ** ****.

* **** ****** ****** **** **** I **** ******* ***** ** ******* just ** *** *** ******** **. I **** ***** **** ** *** area ** ******* *** ****** *** as ****** *'* ******** ** ** there *** ********* ** *** **** anything. **** ** ****** **** ***** when *** ********* ***'* ********* **. If *** *** ******* *** *** part *** ******* **** ********* ********, people ********* ***'* ******** ***. **** when *** **** ********** **** ** raise ******. ****** **** ***'* ****** true. * *** ********* ******* ***** ago ***** * ****** *** *** back ******* * ******* **** ****** a ***** ** * **** ****. He *** ******** *** *** ***** time ** **** *** *** ******* and ** * ***** *** ****. The ***** **, ** ***** ***** for ****** ** **** *** ** employee **** * *****.

**** **** **** ******** *******, **** asked ***** *** **** ***. * said *** **** ******* ** ***** they ********* ****..."**, *** **** ********." This ********* **** **** ******* *** used ***** *** *** **** ****** at *** **** *** ***** **** the ***** *******.

(1)
UI
Undisclosed Integrator #2
Jul 15, 2021

* ******* *** ******* "****" ******** risk *** ******* ****** ******* ***-***** remains *** ********* *********** *** *** ability *** **** ** ** ********** in ** ******* ** *** ***** grocery *****.

**** ** **** *** ******* ***** recognize **** ***** *********** *** ******** WORSE **** **** (******* **** *** spoofing * **** ****-****** *** ****** it **** **** **** ******* *** a **** ****** **** **** *** not) **** ********** ** ** **** to **** *** ****** *** ******* readers *** ***********.

********** *** ****** ****--*** *******--*** ******* way ** ******** * **** ****** entry *****.

******** ******* **** * **** *** gain ******* *****, *** ****'* **** a ********** ***** ****** ** *** (layered ********), ** * ***'* ***** it ** * ******* ***** ** PDK.

**** ** ********* *** ******-******** **********, "checks *** ***" *** * ******** manager *** ***** ** **** **/*** is ********* ****-*********, *** ************ **** the ******** ******** ** ******** *** tech.

(2)
UM
Undisclosed Manufacturer #3
Jul 15, 2021

* ***** *** ***** ***** ***** a **** *********** ** **** *** may *** ** ***** ** *** intrusion *** * **** ****, ** ever. ** ** ** ******** ****** sensitive *********** *** *** *** ** aware. **** * **** ** **** be ****** ******* *** *** *** can ***** ** *** **** **** accessed ***** ******.

(1)
SD
Shannon Davis
Jul 15, 2021
IPVMU Certified

********** *** ****** ****** *** **** actually **** ** ***** ** * duplicated **** ** ****. ********** ********* on *** *** **** *** ****** there ** ** ***** *** ** the *** ****** ******** ** *** non ****** ****. * **** *** seen **** ** ** ****** ************* though.

Avatar
Brian Rhodes
Jul 15, 2021
IPVMU Certified

* *** *** ***** ****. ***********. I **** *** *** *** ******** and **** ** ****.

SD
Shannon Davis
Jul 15, 2021
IPVMU Certified

**** *** **** * ***** *** so ***'* **** *** **** ** the ****!

(1)
Avatar
Billy Guthrie
Jul 27, 2021
ZMANA

* ******* **** ** **** **** the *** ******* ******.

U
Undisclosed #4
Jul 15, 2021

*****, *** ** ****** **** ** saying **** * ******* ****** ** alerting ********* *** ** ******** ****** is ****** **** *** ****** ** alerting ****** *** ** ******** ******.

*******, ** **** *****'* ********* *********** the ********* ** *** ******** ** much ** *** ********, * ***'* know **** *****.

************: "***, ***** ** * *********** flaw ** **** ******, *** **'** provided ** ***** ** *** ***** know ** **'* **** *********!"

********: "***...*** ***'* *** **** *** the ****? **** ** **** * lot ** *****?"

************: "**...**..."

********: "**, **** ** **** ** really, ****** ********* ** *********, *****?"

************: "*** ** ****..."

** ***********...*****, ***** ** *** *** actually ****** * ********, *** *** fact **** *** ******** ** * whole *** *** ********* **** ** such ** ********** ** ** ***...

(1)
Avatar
Wanchai Siriwalothakul
Jul 22, 2021
Smart Entry Systems • IPVMU Certified

********* ** *** ********, ****** ******* is **** ** * ********** ** actual ********. ** **** * ******** that ********* *** ****** *** ****'* want ** **** *** **** ** register *** ** *** ********* ** the **** ** *** ****** ****-***. So **** ********** *** ****** ********** to **** *** **** **** ** an ************ **** *** *********. **** was **** **** * ****** *** and *** ******* ***** ****'* ******* even ***** **'** ********* **** ***** it ** ******** ********* ******** **** to *** *** *****.