Rocks vs Wiegand: Access Control Risks

Published Jul 14, 2021 15:53 PM

Wiegand is an access control security risk but so are rocks. How should security professionals handle such risks?

IPVM Image

Access control manufacturer PDK's founder talked about their new OSDP enabled product while emphasizing that other fundamental risks still exist, such a simply throwing a rock through glass to break in.

Inside this report, we share:

  • PDK Founder contrasts Wiegand vulnerability to rock smashing risks
  • Comment on how OSDP used to segment access market
  • Why exploiting Wiegand does not take great complexity
  • OSDP importance as 'Industry Standard'
  • Examining how OSDP fixes Wiegand risk

For background, see OSDP (vs Wiegand) Access Control Guide.

PDK ******* '*** **** ****' ********* ****

****** ******* **** ****** ****, ** ****** ************ **** **** while **** ******** ******* ******** *******, physically ******** * ****** ** * major **** ******:

** *******, *** *** ********** *** new, ****** ******** ****-******* ******** ********* ***. *** *******'******-****** ******** **************** ******* **** *** ** *** support ****.

IPVM Image**** *****, ********* *** **-******* ** PDK (**********)****:

************'***********'.*******,************************,*'******************,***,******************? (*******?)*****,****,***'****************************************.*******,******'***************************************.********,*******,*************************************************************,******************.

**** **** '** ******* ******'

***** **** **** **** **** ** used ** ************* *** ******** ********** to ************ '******* *** ******' ** exclude ****** ********* **** ** *** have **:

****, ***** **** ** ***** ** the **** ****, *** ****, ***** in **** *****, *'* * ****** bit ** * ******** **** ****** like ****. ***, *** **'** *** a ***** ** *********** ****** *** organization **** *** *** **** ***** this ********** *** *** ** ********* what's **** *********.

*****'* ** ******** **** *****'* ********** in *** ********, ****'* ********* ** large ************* ** ******* *** ******, right?

*** ** ******* ******

*** ********* ********** *** '*******-********' ** using********(************* ****) ******* **** ***** *** doors ** *** *****:

**** ***'** ********* ** **** (******* door **********) ******, *** *'** *** my ********** *** ** *** ****, and *'* ******* ** ****, ***** three, ****, ** **** ****, **** the ******* ** **** ****, ** really ** *** ******* **** ******** is ***** ** *** * ******* and *** *** **** ***, *****, and ***** ***, *** ****, *** wires *** ******* ** **.

*******, ******** ********** *******'* ******** ** not ******* ******* ** ******. ** fact, ***** ******* ******* ****** **** than * *********** *** * *** minutes ** ***.*** ***** ***** ***** *** ******* are ********* *********:

******* ******** *** **** *** *********** to ***, **** **** **************** ~$** - $** ******.

OSDP ********* ** '******** ********'

***** ****** **** '********* *********' *** to ** ******** '** ******** ********' for ******, *** ******* ***** ** saying ** *** ******* ** ***** security:

**, *** ****, *'* *** ***** say **** * ***'* ******* ** OSDP, * ***** **** **'* ********* important. *** *** ***, ** *** the **** ** ***** ********* ******* it *** *** ***** ***** ** do *** ******* ********* *** ***** it. *** ****'* **** ** *** is ********* *** ****** ** ****. And *** ******* ** ****** **** out *** ***. *** **** ** truly ********** *** *** **** **** that **** **** *** **********. *** there *** ********* ***** ***** ** features **** *** **** ** **** adjustments ** ******* ** ******* ** becomes ** ******** ******** ** ******** specific.

OSDP **. ******* ****

**** ** ********* ******* ** **** security ** *** **** *********** ** access ******* ** ***********.

******** ******** ******* *.*.*, ***-*** *** ********** ** **** on **** ******* ****** *** **********. Previous ******** ** **** *** *** support **********, ** ** *** *** defined ** '*********' ***** ****.

**** **** ****** *******, *** ******** between ****** *** ******** ********** ** encrypted ******* **** ************ *** ********* copying **** '*** ** *** ****** devices.

******* **** *** ******* ******* ****. For *******,*** $** ******** ***$** *** **** ************ *** ********** **** (********** ** how ****** *** ****** **) *** makes ** **** ** ****, ******, or ********* ****** **** **** ** break **** ** ****** ******:

IPVM Image

****** ***** ****** ****** ** ********** to *** **** ** ******* ******* when ******** *** ********* ** *** reader. *** **** *********** **** ********* can **** ** **** ** ****** identical ****** ** ***** ***** ** to ****** ***** ******* ******* ** systems ********* ******* ********.


Comments (14)
Randy Lines
Jul 14, 2021

***** !! ** ****** ** *** still * ****** ** ******* ****** on ****** *******. ***** **** * one-down-man-ship ******** ** ******** ******** *** we ***'* **** ********* **** * tamper ** *******.


Brian Rhodes
Jul 14, 2021
IPVMU Certified

******** *** ** ***'* **** ********* have * ****** ** *******.

** **** * ****** ******, ** is *** ********** ** *********!

Undisclosed Manufacturer #1
Jul 14, 2021

*** * **** *****, ****. ** can ********** ****** * ****** ****.

IPVM Image

Michael Silva
Jul 14, 2021
Silva Consultants

********, *** ******* ************* ** **** access ******* ******* ** **********. ** need ** ***** * **** ******* the ******, **** **** *** ******* to ***** ** ***** *** ******** and **** **** ***** **. **** people **** **** ******** **** *** door **** *** *** **** *****. During ** ******** ***********, * **** that * *** *** **** * building ***** **** ********* **** **% of *** ****.

**** ********** ** **** ******* ******* of *** * ***-*******, ****-***** ******** to ******** **** ** *****. *** level ** **** ****** ******* **** facility ** ******** *** **** ** mandatory ** *** ******** ** *********** at *******.

******* ***** ** ********** *** *********** to ******** ***** ** ******* **** as ******* **** ************** ***** *** networks ** ************** ***********. *******, ** most **********, ***** *** *** ********** cases ** ** ******** ******* ****** using ***** *******. ***** *** *** easier **** ** ***** * ********: tailgating, ******** * *****, ** ****** looking *** * **** **** *** failed ** ***** ********.

**** **** ***** ****, * ***** that ** ** ************* *** * manufacturer ** ******** ** ***** ******** that **** ***** ******** *************** **** more ****** ******** *** ** ******** at ****** *** **** ****. **** consumers *** ***** *** ********** (******* false) **** *** ******** ******* **** by * * ********* ************ **** indeed ******* ********. ******* * ******* with ***** ******* ******* ** ********** in ** *******.

Shannon Davis
Jul 14, 2021
IPVMU Certified

* *****'* **** **** ** ***** types ** ******* ** *** ***** anymore. *** **** ***** ** *** easiest ** ******* *** ****** *** you ***** ** **** ******* ** find ***.

* ******* *** **** ** ******** to ** ********* *** **** **** don't ****** ****. ***** ******* ** to ******* * *** ****** **** a *** ********** *** **** ***** are *** ******** **** ***** ********* cards ****. **** ******* * ******** to *** * ********** **** ** even * **** *** ** *** extra ****.

**** ** ****** *********** ** ****** bid ***** ******* *** *** **** readers.

Kyle Folger
Jul 14, 2021
IPVMU Certified

* *** ******* ******* *** *** comments *** *** ********* **** * was ********. * ***** *** **** question ****** **, "*** **** ** your ********* **** ***** ******** *****?"

*** ** *** ****** * ******* the ******** ***** ** *** ********* at *** **** ** *** *** don't ****** ******** ** **** ** more ******. *** *** ******* *** a ***** ******* *** * *** floored **** **** ********* ****. * have **** *** *** **** **** installed ** *** **** *** *****. I ********** *** ******** ************** *** the **** *****, *** ***** ** no ****** *** ** ******* **** didn't **** ****** ******* ******.

** ******* *********, *** ******* ** often **********. ****** ***** ******* * mullion ** ********* **** ** ****.

* **** ****** ****** **** **** I **** ******* ***** ** ******* just ** *** *** ******** **. I **** ***** **** ** *** area ** ******* *** ****** *** as ****** *'* ******** ** ** there *** ********* ** *** **** anything. **** ** ****** **** ***** when *** ********* ***'* ********* **. If *** *** ******* *** *** part *** ******* **** ********* ********, people ********* ***'* ******** ***. **** when *** **** ********** **** ** raise ******. ****** **** ***'* ****** true. * *** ********* ******* ***** ago ***** * ****** *** *** back ******* * ******* **** ****** a ***** ** * **** ****. He *** ******** *** *** ***** time ** **** *** *** ******* and ** * ***** *** ****. The ***** **, ** ***** ***** for ****** ** **** *** ** employee **** * *****.

**** **** **** ******** *******, **** asked ***** *** **** ***. * said *** **** ******* ** ***** they ********* ****..."**, *** **** ********." This ********* **** **** ******* *** used ***** *** *** **** ****** at *** **** *** ***** **** the ***** *******.

Undisclosed Integrator #2
Jul 15, 2021

* ******* *** ******* "****" ******** risk *** ******* ****** ******* ***-***** remains *** ********* *********** *** *** ability *** **** ** ** ********** in ** ******* ** *** ***** grocery *****.

**** ** **** *** ******* ***** recognize **** ***** *********** *** ******** WORSE **** **** (******* **** *** spoofing * **** ****-****** *** ****** it **** **** **** ******* *** a **** ****** **** **** *** not) **** ********** ** ** **** to **** *** ****** *** ******* readers *** ***********.

********** *** ****** ****--*** *******--*** ******* way ** ******** * **** ****** entry *****.

******** ******* **** * **** *** gain ******* *****, *** ****'* **** a ********** ***** ****** ** *** (layered ********), ** * ***'* ***** it ** * ******* ***** ** PDK.

**** ** ********* *** ******-******** **********, "checks *** ***" *** * ******** manager *** ***** ** **** **/*** is ********* ****-*********, *** ************ **** the ******** ******** ** ******** *** tech.

Undisclosed Manufacturer #3
Jul 15, 2021

* ***** *** ***** ***** ***** a **** *********** ** **** *** may *** ** ***** ** *** intrusion *** * **** ****, ** ever. ** ** ** ******** ****** sensitive *********** *** *** *** ** aware. **** * **** ** **** be ****** ******* *** *** *** can ***** ** *** **** **** accessed ***** ******.

Shannon Davis
Jul 15, 2021
IPVMU Certified

********** *** ****** ****** *** **** actually **** ** ***** ** * duplicated **** ** ****. ********** ********* on *** *** **** *** ****** there ** ** ***** *** ** the *** ****** ******** ** *** non ****** ****. * **** *** seen **** ** ** ****** ************* though.

Brian Rhodes
Jul 15, 2021
IPVMU Certified

* *** *** ***** ****. ***********. I **** *** *** *** ******** and **** ** ****.

Shannon Davis
Jul 15, 2021
IPVMU Certified

**** *** **** * ***** *** so ***'* **** *** **** ** the ****!

Billy Guthrie
Jul 27, 2021

* ******* **** ** **** **** the *** ******* ******.

Undisclosed #4
Jul 15, 2021

*****, *** ** ****** **** ** saying **** * ******* ****** ** alerting ********* *** ** ******** ****** is ****** **** *** ****** ** alerting ****** *** ** ******** ******.

*******, ** **** *****'* ********* *********** the ********* ** *** ******** ** much ** *** ********, * ***'* know **** *****.

************: "***, ***** ** * *********** flaw ** **** ******, *** **'** provided ** ***** ** *** ***** know ** **'* **** *********!"

********: "***...*** ***'* *** **** *** the ****? **** ** **** * lot ** *****?"

************: "**...**..."

********: "**, **** ** **** ** really, ****** ********* ** *********, *****?"

************: "*** ** ****..."

** ***********...*****, ***** ** *** *** actually ****** * ********, *** *** fact **** *** ******** ** * whole *** *** ********* **** ** such ** ********** ** ** ***...

Wanchai Siriwalothakul
Jul 22, 2021
Smart Entry Systems • IPVMU Certified

********* ** *** ********, ****** ******* is **** ** * ********** ** actual ********. ** **** * ******** that ********* *** ****** *** ****'* want ** **** *** **** ** register *** ** *** ********* ** the **** ** *** ****** ****-***. So **** ********** *** ****** ********** to **** *** **** **** ** an ************ **** *** *********. **** was **** **** * ****** *** and *** ******* ***** ****'* ******* even ***** **'** ********* **** ***** it ** ******** ********* ******** **** to *** *** *****.