Smartcard Copier Tested (13.56MHz)

Author: Brian Rhodes, Published on Jul 05, 2017

Copying 125kHz cards is certainly easy, as our test results showed, but how about 13.56MHz smart cards? Are they more secure?

IPVM focused on the risk of Hacking Your Access Control With This $30 HID 125kHz Card Copier, but are more advanced 13.56 MHz 'smartcard' formats more secure?

We bought a smart card cloner, the unit shipped to us shown below:

The seller is undoubtedly polite, but would it work?

We tested the following card formats:

  • HID iClass Legacy and iClass SE (13.56 MHz)
  • MIFARE Classic 1K (13.56 MHz)
  • MIFARE DESFire EV1 (13.56 MHz)
  • HID ProxII and ISOProx (125 kHz)
  • Kantech XSF (125 kHz)
  • EM 4100 Generic Format (125 kHz)

Full results, videos and analysis inside.

******* ****** ***** ** ********* ****, ** *** **** ******* showed, *** *** ***** **.***** ***** *****? *** **** **** secure?

**** ******* ** *** **** ********* **** ****** ******* **** **** $** *** ****** **** Copier, *** *** **** ******** **.** *** '*********' ******* **** secure?

** ****** * ***** **** ******, *** **** ******* ** us ***** *****:

*** ****** ** *********** ******, *** ***** ** ****?

** ****** *** ********* **** *******:

  • *** ****** ****** *** ****** ** (**.** ***)
  • ****** ******* ** (**.** ***)
  • ****** ******* *** (**.** ***)
  • *** ****** *** ******* (*** ***)
  • ******* *** (*** ***)
  • ** **** ******* ****** (*** ***)

**** *******, ****** *** ******** ******.

[***************]

Box *******

*** *** *** **** *** ******* ** ** ***** *****:

Fails ** **** **********

** *** **** ***** *****, ** ***** *** **** '**** advanced' **.** *** *** ****** ** ***** ** **** ******* credential ******* **** ** ****** ****** *******:

** *** ****, ** ***** ******** **.** *** *** *** kHz *******, *** **** *** **** ** ************ ***** *** write ******** *** ******* ** *** *** *********. ** ****, none ** *** *** ****** ******* **** ***** ******, *** even *** **** *****, ********* *** *** ****, **** **, and ******* ******* ******* ** ***** *****:

13.56 *** ****** **** ************

*** ********** ****** ** ********* ******** ******* ** *** **** ************ *******************. **** ****-*** ******** **** ********* ******************** **** **** $***, *** **** **** **** ** ** easy *** *********** ** *******, ********** *** ***** ** * risk ** ***** ** ********** ****** ******* ** ******.

*******, *** ******* ** **** ****, ************ **** **** **** does *** **** ** **********, **** *** ******** *** **** other ******* ******* *** *******. *************, *** ********** **** ** effective (********** ***** ****), *** *** ************** ** *** ******* *** ******* ** not. * **** ** ****** **** ************ ************ ***** ******** could ** * *** ******.

Eight ******* ******

** ****** ***** ****** ******* ** ******* **** **** ****, and **** *** ****** ************ ******. ** *** **.** *** formats ** *****, **** ****** ******* *** *** ****** *****, none **** ******. *** *** *** *** ****** *** **********, but *** ********** **** *** *** **** *********. *** ***** formats ****** ******** ****** *******, ****** ******, ****** **, ******* XSF, *** *** *******:

Most ****** ******* ************

***** **** ********** ****** *** ** * **** *** **** credentials ** ** ****, **** ***** **** ** *** ******, Meal *****, ** ******** ***** ******* ********, ** ****** ** ineffective *** ****** ******* *******. **** **** *** **** **** those ******* *** ****** ******* *** ********, *******, **** **** this ********** ****** ** *** * *** *******.

Blanks ********* ** ***

*** ********** ********** ** ***** ****** ********* '*********' ******* ** the ********** ** ******** ******** ***** ******** ***** ** **** stolen ***********.

********** ** ******* **** *** **** ** **** **** ****, finding * ***** ***** **** ** ***** ****** *********** ** is **** **** ****** *** ********* **** ******* ***** *** kHz **-******** ******* ** *** ********** **** *******. ***** ****** cost ** ****** ** $*.** ***** **** *** **** **** day, ***** ****** ** ****** ***** **** $** **** *** often *** **** ******* ********** ** ************ ** **** *********.

Comments (18)

* *** **** ** ***** ******* ** **** *** ****** it **** *** ****** ***** ** ****** ********** *** **. It ******'* **** *** ** ****. ** **** ** *** but **** ** ****** *** ***** **** ***** ******. ** would ******* **** *** ***** *** **** **** **** **** the ***. *'* ******* ** **** ** **** ** * flaw **** *** ****** ** ** *****'* ********* ** *** cards **** ******* **** **** ***** ****** ********.

* ***** *** *** $** ****** ** ****** ** * better ****** *** ******* ****. *******, **** **** ** ****, the **** ** *** *** ******* ***** ****** ** *** intersection ** ******* *******:

*. **** *** *** ******* *** ********* (**** **.** *** are)

*. ******* ********** ****** *** *** *** ******* ** ****/ cheap (*** **** **.** ***)

*. ***** '****** **********' ***** ***** ***** **********, *** ******** what ** ******** '******' ***** **** ** *****. *****'* * good ****** **** ** *** '******' **** **** ********* *** facility *****, ****, ** ***** ** ******* ***** *** *** most ****** '**********' *******, **** ***** *** **********.

******,

*** **** ****** ** ****?

*** ****** *** *****-******!

*** **** *** ***** * *********** ****, **/**** ******* ******* times ********* ** **** **** * ******** **. *******, ** was **********. *'** ****** ** ********** *** **** **** ***********.

***** ***********. ****** *** ******* **** *********** *******.

***** ****** :) * ** ********** ** *** **** *** card ** ****** ******** *** **** *** ****** ** ********** security ... ***** ** ***** ****** *** ***** ****.

** ********** ** **** ******* ***** ** *** **** ********* codes *** ********* ** ******* ** *** ****** *** **** is. **** *** ***** (*** *** ***) *** *** ********** by ******* *** *** * **** *** ******** "*" *********** that **** **** ***** *** ******** "*". **** *** ******* about *********** ***** ****** ** *** ****** ** ********** ******* compromised.

******

***

***** *****:

* ** ********** ** *** **** *** **** ** ****** security *** **** *** ****** ** ********** ********

*'* ******* ************** ** ****** * ****** ** **** ****.

**** ** ********* *** **-***********, ***** ******* ** *********** *** pushes **** ** *** ********* ****.

***** *** ********** *********** ****** *** ******, ** ******* ***** whatever ********** ** ******** *** **** ** *** ********, ** OSDP ****** **** ******** ** *** '********** *******'.

* ***** *** **** ***** *** ******** * ** ********* building *'* *********** ** **** ****** ** ***** *****. * really ***'* ***** *** ***** ********* *** *'* ********* ******* would **** **** ******. ** ***** **** *** **** **** number ******* *** ***** ****** **** **** **** *******. ("*** should *** ** ******* ** *** *** ****'*") *** ********** data, **** ** ******, ********, ****** ** *******. ******** *** mean **** **** ****** ******* **** *** ** ***. ******** might **** **** ******* *** ******* ***** ** ****** *********** and **** *** ****** ***** ** *** ****** ** *** panel ********* *** ***** * ****** *** ** ******* ***** conduit **** *** ***** *** **** ** *** ****** ****.

*** **** **** ***** ** *** ***** *** *** * similar **** *** ***** ***** .... ****. *** **** **** were ****** **** *** ..... ****. * *** **** ****** pointing *** **** ************* ******* ***** ****** *** ****** ***** ***** ** ***** facilities ** ********* ***** (*** *** **** ** **** *****).

*** **** ********* ********** **** ***** ** * ********* ** security ******* ... *** **** ** ** * *** *********** ahead ** ******** ******** ** ********* ** ***** ***************. *** fact ** **** **** **** ** ** * ****** ***** barrier ** ***** *** * ***-****** *** **** ************* ******* with ***** *******. * ********* *** **** *** ******** ** Engadget *** **** **** $** ******** (****** **** ** ** haha). ** ******* ****** * **** ****** **********. ********** ******* of *** ************* ** * ****** *************. **** *** *** risk. *** **.

**** *** ****** *** *******. ******* ** *** **** *** bus **** ***** ** ***********. **** **** ****** ******* ******* to **** ****** *** *** * ***. ***** ******* *** metal ******* **** ***** *** ******** ** *** **** ******* out.

******* ******* **** *** ****** **** **** ******** * *** years *** ** *** ******** ** * ***** **** *** physical ******** *******. ** ******* **** *** **** ******* **** 6 ****** ** ******** *** ** ********* ******. ** ******* ... ****** *** **** *** **** ***** ** * **** to ******* ************. *** **** *** ******** ******** ********* *** getting ** *** **** **** ** "*** *** ****" **** are ******** *** ******* ** ** **** * ****** *** .... *** * *******!!

*** ****** **** ** ****** *** ******** ******** ******** ************* standards, ******* ** ** ******* ** ******* ** **** **** to *** **** **** ****** ****** ** *** ***.

**** * ***** ***

*****

** ***** ** ****** *** **** ******** ***** ***** ** not ******!

****** *** *** ********** *******. +* ***********

***** ** ********** ** **** **** **** ***** ** ****'** encountered *** ******* **** *** **** ******** **** **** ***, even ** *** **** ** ******. **** * **** ** Amazon *** *** * ******, ***** **** * *** ****** out *****, *** ********** **** ** **** *** *** *******, or **** *** * ****** ********.

*** $******* *************** *** **** **** ** ***** **** **.** *** *******, although ** ** **** * ******-***** ****** *** *** * merchandised ******.

***** ** ***** ******** *********** ********* *** ***** ************ ****** and ** *** * ****** '***** '* *****' **** ** copier.

* **** **** ****** **** ** ****** *** ***** * weeks *** **** ****.

* ***** *** ********* ** *** ** ** *** ******* is **** ****** ****.

*** ***** ** *** ****** ** **** ***** ** ******** media *** ***** *** ** ** ******** ** ***** * device ** ***** ** **. ** *** ***'* **** *** thing ** ****** **** ** ***********.***.

***** *** ********** **** ** ******* ***** *** **** ****** number (***) ** **********. ***** ****** ** ** *** ******* out *****. **** ***** ***** ** ***** ***** ** *** writable ***** ** ** ** *** **** *** *** ***'* be ******* ******* *** *******. **** *** ***** ***** (**** saying **.**, *** ***** **** * ***** ** ****** ******** in **** ******* ****** ** *** ***** ***** ** *** Old **********'* ****.) **** * *** *** ** *** ***** "clone * **.** ****" **** ** **** ***'** **** ******* the ***.

** *** *** ******* ** **** ********* **** (*********) ****** crypto *** *** ******** ****.

*** ******** ** ********* ******* **'* ***** ** *** ** a ******** ******* *****. ** ******* ** ** **** ** crack ****** ******* ******* ****'* * ***** ****.

***'* *** ***** **** *** ** ******. ***'* "**** ****** to **** ************" (***'* ******* **** ******* *** *** ******* that **** ****** ******* ** ****...) **** ******** ******* **** card **** ** ****. ***'* *** *** *** (* **** on **** ********** **** ****. **** **** ** ****** *** lawn ***** **** ** **** ********* **** **** * ******* CSN ******.)

**** ** ***********.***

* *** * *** ***** ******://***.***********.***

* *** ** *******://***.**********.***/***-****-*******-*******-****-*********/***** ***** *******:

*** ******** * ** * **** **** ********* ******, *** can *** ********* *** *** ******* ****** *****, **** *** exception ** **** & **** *****, ** *** **** *** known. ** *** ******* **** **** **** **.***** ******* **** the ********* ** *** *** ****. *** ************ ** *** windows ******** *** ********* **** ********* *** ******* ************.

******* ****** ** *** ************ ** "***** *****" ***** *** be ********** ************ ********* *** ***.

*** **** ********* ***** ** ******** ***** ***** ***** ** that **** *** **** ** ****** ** ***** ****, ** how **** *** *********, ******, *** *** ***** **** ******* extremely *********, *** **** ******* ** *** ******** ****** **** which *** *** ***** **** *** *******!

* **** ****** * **$ ****** ****** ** **** *** our *****. * ****** ** * ********* ***** *** ****, one *** ****** **** ****, **** *** ****** ******'* ****.

** ****'* **** ** ****** ** *** ******** ** ***** cards, *** **'* * **** *********** ***** ** ****: ***'* leave **** ***** *** **** ****** ******.

***** *** * ***** *** *** ********* ************, ****** *** ATA55xx, ** * ****** *****'* *** ** **** **** ***(***** on *******), ** ** ********** ** ****** *** ** *****.

*** ******** ** **** ****, *** **** ****** ** *********** the ********, ********* **** **** *** ********* ** **** ****

****://***.*********.***/*********/*****.***?*********=************&*****=*****&***********=****&*****=**************************

* ****** *** ********* *******, ** *******, *** **** ****** and *** *** * ******** ** ****.

** ***** **** * **** ****** *****, **,*** ******* *** 6000+ ***********, ** ** *** ***** ******* ** *** ********* on * ***** *****, *** *** ******** ********. **** ** what * *** ** "****** *****" *** ** ***** ** your *** *** ******* ** ** *******, ** *********** ********* cards **** *** ******** ****** ** ****** $** ** ***** for * *** ****.

** ** ******** ** ***** **** ***** ********* ** ******** card ***** *** *** **** *** **** (** *** **** the ****), ** *** ******* **** **** ****** *** ****** (based ****** ******** *******) *** ****. ** *** **** ******* all *** *****. ** *** *** **** ** **** ** use *** ** * ******* **, ******** * ****** ** run ** ***** ******

***** **** *** **** ****** ** *** ************ ** **** cards ***** *** ** ********** ********* *** ***, ******* ******** encrypted *****.

** ** ***** **** ******** ** *** *** ***** *** management, *.*. *** **** *** *******, *** ***** *** ****, where **** *** ****** ***.

*** ******** * ***** *** ***** ** : "*** ***** your ****, *** *** ** *** ******* **** **** ******** process?, ***** **** *** ** *** ***** **** *******?"

****** **** ****** ******* ******* *** ******* ** * ***** with *** **** ****** ****** ** *** ******, **** *** prevent *** ******** ** *** * *****, **** ***** *** be ***** ** *** ******, *** *** ****** ****** *** later ***.

Login to read this IPVM report.
Why do I need to log in?
IPVM conducts unique testing and research funded by member's payments enabling us to offer the most independent, accurate and in-depth information.

Related Reports

Favorite Request-to-Exit (RTE) Manufacturers 2018 on Sep 19, 2018
Request To Exit devices like motion sensors and lock releasing push-buttons are a part of almost every access install, but who makes the equipment...
Door Fundamentals For Access Control Guide on Sep 12, 2018
Assuming every door can be secured with either a maglock or an electric strike can be a painful assumption in the field. While those items can be...
Access Control Course Fall 2018 on Sep 06, 2018
Registration IS CLOSED ends this Thursday. Register now. If you are looking to strengthen your ability to design and deploy access systems or...
Drain Wire For Access Control Reader Tutorial on Sep 04, 2018
An easy-to-miss cabling specification plays a key role in access control, yet it is commonly ignored. The drain wire offers protection for readers...
Directory Of 110+ Video Management Software (VMS) Suppliers on Aug 30, 2018
This directory provides a list of Video Management Software providers to help you see and research what options are available. Listing...
Exit Devices For Access Control Tutorial on Aug 28, 2018
Exit Devices, also called 'Panic Bars' or 'Crash Bars' are required by safety codes the world over, and become integral parts of electronic access...
Hikvision FIPS 140-2 Cybersecurity Certification Examined on Aug 27, 2018
A week after the US government passed a law banning Hikvision, Hikvision announced it had obtained a FIPS 140-2 certification from the US...
Assa Aperio Wireless Access Reader R100 Tested on Aug 23, 2018
Wireless access control is frequently promoted by manufacturers as a way to cut installation costs. Perhaps the biggest proponent of this is mega...
Synology Surveillance Station VMS Tested on Aug 22, 2018
With so many low-cost NVRs and enterprise VMSes, is there any place in the market for NAS-based VMSes? Recently, IPVM bought a Synology NAS for...
Backup Power For Maglocks Guide on Aug 20, 2018
When the main power fails, many believe maglocks must leave doors unlocked. However, battery backed up maglocks are allowed according to IBC /...

Most Recent Industry Reports

Avigilon Announces AI-Powered H5 Camera Development on Sep 19, 2018
Avigilon will be showcasing "next-generation AI" at next week's ASIS GSX. In an atypical move, the company is not actually releasing these...
Favorite Request-to-Exit (RTE) Manufacturers 2018 on Sep 19, 2018
Request To Exit devices like motion sensors and lock releasing push-buttons are a part of almost every access install, but who makes the equipment...
25% China Tariffs Finalized For 2019, 10% Start Now, Includes Select Video Surveillance on Sep 18, 2018
A surprise move: In July, when the most recent tariff round was first announced, the tariffs were only scheduled for 10%. However, now, the US...
Central Stations Face Off Against NFPA On Fire Monitoring on Sep 18, 2018
Central stations are facing off against the NFPA over what they call anti-competitive language in NFPA 72, the standard that covers fire alarms....
Chinese Government Praises Hikvision Following Xi Jinping on Sep 17, 2018
The Chinese government council responsible for managing China's state-owned companies praised Hikvision’s obedience to China’s authoritarian leader...
Amazon Ring Spotlight Cam Tested on Sep 17, 2018
Amazon's Ring has released their latest camera entry, the Spotlight Cam, which we bought and tested in our Consumer IP Camera Analytics...
European Mega Security Firm Verisure Pushing Security Fog on Sep 17, 2018
The European mega security firm Verisure (Securitas Direct), with a reported 2 million customers, is pushing security fog, as shown in this BBC...
IP Camera Cable Labeling Guide on Sep 14, 2018
Labeling cables can save a lot of money and headaches. While it is easy to overlook, taking time to label runs during installation significantly...
Favorite Intercom Manufacturers 2018 on Sep 14, 2018
Intercoms are certainly increasing in popularity, driven by the integration of video and IP networking. But who is the favorite? On the one side,...

The world's leading video surveillance information source, IPVM provides the best reporting, testing and training for 10,000+ members globally. Dedicated to independent and objective information, we uniquely refuse any and all advertisements, sponsorship and consulting from manufacturers.

About | FAQ | Contact