Smartcard Copier Tested (13.56MHz)

Author: Brian Rhodes, Published on Jul 05, 2017

Copying 125kHz cards is certainly easy, as our test results showed, but how about 13.56MHz smart cards? Are they more secure?

IPVM focused on the risk of Hacking Your Access Control With This $30 HID 125kHz Card Copier, but are more advanced 13.56 MHz 'smartcard' formats more secure?

We bought a smart card cloner, the unit shipped to us shown below:

The seller is undoubtedly polite, but would it work?

We tested the following card formats:

  • HID iClass Legacy and iClass SE (13.56 MHz)
  • MIFARE Classic 1K (13.56 MHz)
  • MIFARE DESFire EV1 (13.56 MHz)
  • HID ProxII and ISOProx (125 kHz)
  • Kantech XSF (125 kHz)
  • EM 4100 Generic Format (125 kHz)

Full results, videos and analysis inside.

******* ****** ***** ** ********* ****, ** *** **** ******* showed, *** *** ***** **.***** ***** *****? *** **** **** secure?

**** ******* ** *** **** ********* **** ****** ******* **** **** $** *** ****** **** Copier, *** *** **** ******** **.** *** '*********' ******* **** secure?

** ****** * ***** **** ******, *** **** ******* ** us ***** *****:

*** ****** ** *********** ******, *** ***** ** ****?

** ****** *** ********* **** *******:

  • *** ****** ****** *** ****** ** (**.** ***)
  • ****** ******* ** (**.** ***)
  • ****** ******* *** (**.** ***)
  • *** ****** *** ******* (*** ***)
  • ******* *** (*** ***)
  • ** **** ******* ****** (*** ***)

**** *******, ****** *** ******** ******.

[***************]

Box *******

*** *** *** **** *** ******* ** ** ***** *****:

Fails ** **** **********

** *** **** ***** *****, ** ***** *** **** '**** advanced' **.** *** *** ****** ** ***** ** **** ******* credential ******* **** ** ****** ****** *******:

** *** ****, ** ***** ******** **.** *** *** *** kHz *******, *** **** *** **** ** ************ ***** *** write ******** *** ******* ** *** *** *********. ** ****, none ** *** *** ****** ******* **** ***** ******, *** even *** **** *****, ********* *** *** ****, **** **, and ******* ******* ******* ** ***** *****:

13.56 *** ****** **** ************

*** ********** ****** ** ********* ******** ******* ** *** **** ************ *******************. **** ****-*** ******** **** ********* ******************** **** **** $***, *** **** **** **** ** ** easy *** *********** ** *******, ********** *** ***** ** * risk ** ***** ** ********** ****** ******* ** ******.

*******, *** ******* ** **** ****, ************ **** **** **** does *** **** ** **********, **** *** ******** *** **** other ******* ******* *** *******. *************, *** ********** **** ** effective (********** ***** ****), *** *** ************** ** *** ******* *** ******* ** not. * **** ** ****** **** ************ ************ ***** ******** could ** * *** ******.

Eight ******* ******

** ****** ***** ****** ******* ** ******* **** **** ****, and **** *** ****** ************ ******. ** *** **.** *** formats ** *****, **** ****** ******* *** *** ****** *****, none **** ******. *** *** *** *** ****** *** **********, but *** ********** **** *** *** **** *********. *** ***** formats ****** ******** ****** *******, ****** ******, ****** **, ******* XSF, *** *** *******:

Most ****** ******* ************

***** **** ********** ****** *** ** * **** *** **** credentials ** ** ****, **** ***** **** ** *** ******, Meal *****, ** ******** ***** ******* ********, ** ****** ** ineffective *** ****** ******* *******. **** **** *** **** **** those ******* *** ****** ******* *** ********, *******, **** **** this ********** ****** ** *** * *** *******.

Blanks ********* ** ***

*** ********** ********** ** ***** ****** ********* '*********' ******* ** the ********** ** ******** ******** ***** ******** ***** ** **** stolen ***********.

********** ** ******* **** *** **** ** **** **** ****, finding * ***** ***** **** ** ***** ****** *********** ** is **** **** ****** *** ********* **** ******* ***** *** kHz **-******** ******* ** *** ********** **** *******. ***** ****** cost ** ****** ** $*.** ***** **** *** **** **** day, ***** ****** ** ****** ***** **** $** **** *** often *** **** ******* ********** ** ************ ** **** *********.

Comments (18)

* *** **** ** ***** ******* ** **** *** ****** it **** *** ****** ***** ** ****** ********** *** **. It ******'* **** *** ** ****. ** **** ** *** but **** ** ****** *** ***** **** ***** ******. ** would ******* **** *** ***** *** **** **** **** **** the ***. *'* ******* ** **** ** **** ** * flaw **** *** ****** ** ** *****'* ********* ** *** cards **** ******* **** **** ***** ****** ********.

* ***** *** *** $** ****** ** ****** ** * better ****** *** ******* ****. *******, **** **** ** ****, the **** ** *** *** ******* ***** ****** ** *** intersection ** ******* *******:

*. **** *** *** ******* *** ********* (**** **.** *** are)

*. ******* ********** ****** *** *** *** ******* ** ****/ cheap (*** **** **.** ***)

*. ***** '****** **********' ***** ***** ***** **********, *** ******** what ** ******** '******' ***** **** ** *****. *****'* * good ****** **** ** *** '******' **** **** ********* *** facility *****, ****, ** ***** ** ******* ***** *** *** most ****** '**********' *******, **** ***** *** **********.

******,

*** **** ****** ** ****?

*** ****** *** *****-******!

*** **** *** ***** * *********** ****, **/**** ******* ******* times ********* ** **** **** * ******** **. *******, ** was **********. *'** ****** ** ********** *** **** **** ***********.

***** ***********. ****** *** ******* **** *********** *******.

***** ****** :) * ** ********** ** *** **** *** card ** ****** ******** *** **** *** ****** ** ********** security ... ***** ** ***** ****** *** ***** ****.

** ********** ** **** ******* ***** ** *** **** ********* codes *** ********* ** ******* ** *** ****** *** **** is. **** *** ***** (*** *** ***) *** *** ********** by ******* *** *** * **** *** ******** "*" *********** that **** **** ***** *** ******** "*". **** *** ******* about *********** ***** ****** ** *** ****** ** ********** ******* compromised.

******

***

***** *****:

* ** ********** ** *** **** *** **** ** ****** security *** **** *** ****** ** ********** ********

*'* ******* ************** ** ****** * ****** ** **** ****.

**** ** ********* *** **-***********, ***** ******* ** *********** *** pushes **** ** *** ********* ****.

***** *** ********** *********** ****** *** ******, ** ******* ***** whatever ********** ** ******** *** **** ** *** ********, ** OSDP ****** **** ******** ** *** '********** *******'.

* ***** *** **** ***** *** ******** * ** ********* building *'* *********** ** **** ****** ** ***** *****. * really ***'* ***** *** ***** ********* *** *'* ********* ******* would **** **** ******. ** ***** **** *** **** **** number ******* *** ***** ****** **** **** **** *******. ("*** should *** ** ******* ** *** *** ****'*") *** ********** data, **** ** ******, ********, ****** ** *******. ******** *** mean **** **** ****** ******* **** *** ** ***. ******** might **** **** ******* *** ******* ***** ** ****** *********** and **** *** ****** ***** ** *** ****** ** *** panel ********* *** ***** * ****** *** ** ******* ***** conduit **** *** ***** *** **** ** *** ****** ****.

*** **** **** ***** ** *** ***** *** *** * similar **** *** ***** ***** .... ****. *** **** **** were ****** **** *** ..... ****. * *** **** ****** pointing *** **** ************* ******* ***** ****** *** ****** ***** ***** ** ***** facilities ** ********* ***** (*** *** **** ** **** *****).

*** **** ********* ********** **** ***** ** * ********* ** security ******* ... *** **** ** ** * *** *********** ahead ** ******** ******** ** ********* ** ***** ***************. *** fact ** **** **** **** ** ** * ****** ***** barrier ** ***** *** * ***-****** *** **** ************* ******* with ***** *******. * ********* *** **** *** ******** ** Engadget *** **** **** $** ******** (****** **** ** ** haha). ** ******* ****** * **** ****** **********. ********** ******* of *** ************* ** * ****** *************. **** *** *** risk. *** **.

**** *** ****** *** *******. ******* ** *** **** *** bus **** ***** ** ***********. **** **** ****** ******* ******* to **** ****** *** *** * ***. ***** ******* *** metal ******* **** ***** *** ******** ** *** **** ******* out.

******* ******* **** *** ****** **** **** ******** * *** years *** ** *** ******** ** * ***** **** *** physical ******** *******. ** ******* **** *** **** ******* **** 6 ****** ** ******** *** ** ********* ******. ** ******* ... ****** *** **** *** **** ***** ** * **** to ******* ************. *** **** *** ******** ******** ********* *** getting ** *** **** **** ** "*** *** ****" **** are ******** *** ******* ** ** **** * ****** *** .... *** * *******!!

*** ****** **** ** ****** *** ******** ******** ******** ************* standards, ******* ** ** ******* ** ******* ** **** **** to *** **** **** ****** ****** ** *** ***.

**** * ***** ***

*****

** ***** ** ****** *** **** ******** ***** ***** ** not ******!

****** *** *** ********** *******. +* ***********

***** ** ********** ** **** **** **** ***** ** ****'** encountered *** ******* **** *** **** ******** **** **** ***, even ** *** **** ** ******. **** * **** ** Amazon *** *** * ******, ***** **** * *** ****** out *****, *** ********** **** ** **** *** *** *******, or **** *** * ****** ********.

*** $******* *************** *** **** **** ** ***** **** **.** *** *******, although ** ** **** * ******-***** ****** *** *** * merchandised ******.

***** ** ***** ******** *********** ********* *** ***** ************ ****** and ** *** * ****** '***** '* *****' **** ** copier.

* **** **** ****** **** ** ****** *** ***** * weeks *** **** ****.

* ***** *** ********* ** *** ** ** *** ******* is **** ****** ****.

*** ***** ** *** ****** ** **** ***** ** ******** media *** ***** *** ** ** ******** ** ***** * device ** ***** ** **. ** *** ***'* **** *** thing ** ****** **** ** ***********.***.

***** *** ********** **** ** ******* ***** *** **** ****** number (***) ** **********. ***** ****** ** ** *** ******* out *****. **** ***** ***** ** ***** ***** ** *** writable ***** ** ** ** *** **** *** *** ***'* be ******* ******* *** *******. **** *** ***** ***** (**** saying **.**, *** ***** **** * ***** ** ****** ******** in **** ******* ****** ** *** ***** ***** ** *** Old **********'* ****.) **** * *** *** ** *** ***** "clone * **.** ****" **** ** **** ***'** **** ******* the ***.

** *** *** ******* ** **** ********* **** (*********) ****** crypto *** *** ******** ****.

*** ******** ** ********* ******* **'* ***** ** *** ** a ******** ******* *****. ** ******* ** ** **** ** crack ****** ******* ******* ****'* * ***** ****.

***'* *** ***** **** *** ** ******. ***'* "**** ****** to **** ************" (***'* ******* **** ******* *** *** ******* that **** ****** ******* ** ****...) **** ******** ******* **** card **** ** ****. ***'* *** *** *** (* **** on **** ********** **** ****. **** **** ** ****** *** lawn ***** **** ** **** ********* **** **** * ******* CSN ******.)

**** ** ***********.***

* *** * *** ***** ******://***.***********.***

* *** ** *******://***.**********.***/***-****-*******-*******-****-*********/***** ***** *******:

*** ******** * ** * **** **** ********* ******, *** can *** ********* *** *** ******* ****** *****, **** *** exception ** **** & **** *****, ** *** **** *** known. ** *** ******* **** **** **** **.***** ******* **** the ********* ** *** *** ****. *** ************ ** *** windows ******** *** ********* **** ********* *** ******* ************.

******* ****** ** *** ************ ** "***** *****" ***** *** be ********** ************ ********* *** ***.

*** **** ********* ***** ** ******** ***** ***** ***** ** that **** *** **** ** ****** ** ***** ****, ** how **** *** *********, ******, *** *** ***** **** ******* extremely *********, *** **** ******* ** *** ******** ****** **** which *** *** ***** **** *** *******!

* **** ****** * **$ ****** ****** ** **** *** our *****. * ****** ** * ********* ***** *** ****, one *** ****** **** ****, **** *** ****** ******'* ****.

** ****'* **** ** ****** ** *** ******** ** ***** cards, *** **'* * **** *********** ***** ** ****: ***'* leave **** ***** *** **** ****** ******.

***** *** * ***** *** *** ********* ************, ****** *** ATA55xx, ** * ****** *****'* *** ** **** **** ***(***** on *******), ** ** ********** ** ****** *** ** *****.

*** ******** ** **** ****, *** **** ****** ** *********** the ********, ********* **** **** *** ********* ** **** ****

****://***.*********.***/*********/*****.***?*********=************&*****=*****&***********=****&*****=**************************

* ****** *** ********* *******, ** *******, *** **** ****** and *** *** * ******** ** ****.

** ***** **** * **** ****** *****, **,*** ******* *** 6000+ ***********, ** ** *** ***** ******* ** *** ********* on * ***** *****, *** *** ******** ********. **** ** what * *** ** "****** *****" *** ** ***** ** your *** *** ******* ** ** *******, ** *********** ********* cards **** *** ******** ****** ** ****** $** ** ***** for * *** ****.

** ** ******** ** ***** **** ***** ********* ** ******** card ***** *** *** **** *** **** (** *** **** the ****), ** *** ******* **** **** ****** *** ****** (based ****** ******** *******) *** ****. ** *** **** ******* all *** *****. ** *** *** **** ** **** ** use *** ** * ******* **, ******** * ****** ** run ** ***** ******

***** **** *** **** ****** ** *** ************ ** **** cards ***** *** ** ********** ********* *** ***, ******* ******** encrypted *****.

** ** ***** **** ******** ** *** *** ***** *** management, *.*. *** **** *** *******, *** ***** *** ****, where **** *** ****** ***.

*** ******** * ***** *** ***** ** : "*** ***** your ****, *** *** ** *** ******* **** **** ******** process?, ***** **** *** ** *** ***** **** *******?"

****** **** ****** ******* ******* *** ******* ** * ***** with *** **** ****** ****** ** *** ******, **** *** prevent *** ******** ** *** * *****, **** ***** *** be ***** ** *** ******, *** *** ****** ****** *** later ***.

Login to read this IPVM report.
Why do I need to log in?
IPVM conducts unique testing and research funded by member's payments enabling us to offer the most independent, accurate and in-depth information.

Related Reports

Access Control Records Maintenance Guide on Jan 16, 2019
Weeding out old entries, turning off unused credentials, and updating who carries which credentials is as important as to maintaining security as...
Access Control Cabling Tutorial on Jan 15, 2019
Access Control is only as reliable as its cables. While this aspect lacks the sexiness of other components, it remains a vital part of every...
Avigilon Favorability Results 2019 on Jan 15, 2019
Since IPVM's 2017 Avigilon favorability results, the company was acquired by Motorola and has shifted from being an aggressive startup to a more...
Winter 2019 IP Networking Course on Jan 10, 2019
Today is the last day to register for the Winter 2019 IP Networking course. This is the only networking course designed specifically for video...
Wavelynx Access Control Manufacturer Profile on Jan 10, 2019
Denver-based WaveLynx is not well known as an access reader manufacturer, but OEMs for big industry brands including Amag, Isonas (Allegion),...
Combating Vaping Epidemic - Halo Smart Sensor Profile on Dec 21, 2018
Youth vaping has become an epidemic, according to the US Surgeon General, while the market leader, Juul, just received a $12.8 billion investment...
Bosch VDOO 2018 Vulnerability on Dec 20, 2018
Security research firm VDOO has discovered a critical vulnerability in Bosch IP cameras. Inside, we cover the available details of this new...
Genetec UL Cybersecurity Certificate (2900-2-3) Examined on Dec 19, 2018
Proving a company is cybersecure has become a major concern for security companies. But how trustworthy are these certificates? Earlier in 2018, a...
ACRE-Acquired Open Options Access Company Profile on Dec 17, 2018
Who is the company ACRE is acquiring? In this note, we examine Open Options line for best customer fit, key features, pricing, and main...
Open Options Acquired By ACRE on Dec 17, 2018
ACRE is doing deals again. A year after they sold Mercury, they are buying another access control company - Open Options. In this note, we...

Most Recent Industry Reports

The IP Camera Lock-In Trend: Meraki and Verkada on Jan 18, 2019
Open systems and interoperability have not only been big buzzwords over the past decade, but they have also become core features of video...
NYPD Refutes False SCMP Hikvision Story on Jan 18, 2019
The NYPD has refuted the SCMP Hikvision story, the Voice of America has reported. On January 11, 2018, the SCMP reported that the NYPD was using...
Mobile Surveillance Trailers Guide on Jan 17, 2019
Putting cameras in a place for temporary surveillance where power and communications are not readily available can be complicated and expensive....
Exacq Favorability Results 2019 on Jan 17, 2019
Exacq favorability amongst integrators has declined sharply, in new IPVM statistics, compared to 2017 IPVM statistics for Exacq. Now, over 5 since...
Testing Bandwidth Vs. Low Light on Jan 16, 2019
Nighttime bandwidth spikes are a major concern in video surveillance. Many calculate bandwidth as a single 24/7 number, but bit rates vary...
Access Control Records Maintenance Guide on Jan 16, 2019
Weeding out old entries, turning off unused credentials, and updating who carries which credentials is as important as to maintaining security as...
UK Fines Security Firms For Illegal Direct Marketing on Jan 16, 2019
Two UK security firms have paid over $200,000 in fines for illegally making hundreds of thousands of calls to people registered on a government...
Access Control Cabling Tutorial on Jan 15, 2019
Access Control is only as reliable as its cables. While this aspect lacks the sexiness of other components, it remains a vital part of every...
Avigilon Favorability Results 2019 on Jan 15, 2019
Since IPVM's 2017 Avigilon favorability results, the company was acquired by Motorola and has shifted from being an aggressive startup to a more...
Gorilla Technology AI Provider, Raises $15 Million, Profiled on Jan 15, 2019
Gorilla Technology is a Taiwanese video analytics manufacturer that recently announced a $15 million investment from SBI Group, saying this...

The world's leading video surveillance information source, IPVM provides the best reporting, testing and training for 10,000+ members globally. Dedicated to independent and objective information, we uniquely refuse any and all advertisements, sponsorship and consulting from manufacturers.

About | FAQ | Contact