The Insecure Verkada Access Control System

Published Jun 25, 2020 15:33 PM

While Verkada touts the security of its system and that how their new door controller was "built from the ground up", one particularly surprising and insecure element is its dependence on Wiegand and lack of OSDP.

IPVM Image

Inside this note, the company answers why they made the choice and we examine how Wiegand represents a risk that most Verkada competitors have taken steps to mitigate.

[Update June 30, 2020 - Verkada tells IPVM they now plan to support 3rd party readers via OSDP "over the next 3-4 months."]

Verkada ****** ******** *******

*******'***** ************** ***** ***** *** ***** ******* are ********* *** *******:

IPVM Image

******* ** *********** *** **************, ********* in *** *****. **** ****** ********* now ***** *********, *** (*************) *********************** ** *** ***-*****.

**** ***** *****-***** ****** ********* ******* OSDP. *** *******, ******, *****, *** Feenics ******* ****, ** **** ******* and *******.

Points ** *** **** ***** ** *************

******* ********* ** **** ****** **** chose ** ***** ******* ** ******** Wiegand ***** ** ****** ***:

*****, ** ******* ******* ** **** is *** **** ****** ******** **'** seen ** *** *****.

**** ***** *** ******** ***** ** 'secure' **** ** *** ******, ******* to** **** ******:

** *****'* **** *********** ******** ** OSDP (**** ** *****:*****://****.***/*******/****-**) *** *** ******** ** ******* 3rd ***** **** *** * ******** update ** *** ****** ***** ** customer ******.

****** **** ***** ******** ********** ******** hardware *********, *** ** ******* ***** requires ******* **** **** * '******** update', ** ******** ********* *** ******* to **** ** * ******** ******.

OSDP **** ** ****-******** ******

***** ******* ****** ** *** ******* OSDP ***, *** ******** ** ****************** used **** ********** **** ********** *** high-security ********** *********.

** ********** ******* *** *** ****, many ** *******'* ******** ********* **** not ** **** ** ******** ** use *** *******'* ****** ******.

Wiegand ******* ****

*******'* *******-**** ******* ******** ** *********** to ***** *** **** **** *********** using ********** *** *********** ******* *******.

**** *******, *** **** ******* *** reader *** ********** ** *** ********* and '***-**-***-******' ************ ******* *** **** to *******.

** ******* ~$** ******,*** ******, ************ ***** ***** ** *******, can ** **** **** *** ******/********* side ** *** ****, *** ** undetectable ** *** ****** *** ****** managers.

IPVM Image

*** *********** ******* **** *** **** be **** ** ****** ********* ****** of ***** ***** ** ** ****** stolen ********** **** ***** **** ******, bypassing ******* ********.

*** ***** ***** ***** *** ***** skimmers *** ********* *********:

******* ******** *** **** *** *********** to ***, **** **** **************** ~$** - $** ******.

Verkada's **** ******* ** ******* ****** *******

****$** ******* ******* ****** ** ******* 2020, *** ******* *** ***** ********* to ******* **** ******* ** *** access ****.

***** *** '***-***' ********** ****** ** not * *******-******* *******, *** ******* has ******* ******* *********** *** ******* development ** *** *******, *** ** OSDP ******* ********* * **** ** market ***********, *** * ******* ** constrained *********.

Fundamentally, ******* ** * ************* ****

******* ******** *** ******** ** ***** offerings, ******* ** '*******-******** ** **** **** **** ****** and ****'.

****** ** *** *******'* '************* **********' *****, ******* ***** ***** ********** to ********, ******** * ******** ** 'Removing ******** ***************'. *******, ******** **** support ****** ********* **** * **** documented *** ******** *************.

Verkada, *** ****

** ******* ** ** ***** ********* to ************* ** **** *****, *** company ****** *********** **** ******* *** add **** *******.

UPDATE, ******* ** *** **** *** ***** *******

***, ******* **** **** "****** ** roll *** ******* *** *** ***** OSDP ******* **** *** **** *-* months." **** **** ****** **** ******* on ***** **** ********, ****** *****:

1OSDP *******: We have built the hardware to support OSDP (we have a 4-wire input next to the 6-wire input for Wiegand, designed for OSDP readers). To be clear about what we support initially, we informed you and our partners that we do not support OSDP in the first version of the product. We have always planned to launch OSDP for all devices (third party devices and a potential Verkada reader) in the near future.

** *** **** **** ** **** - *** *** **** ****** ** the ******** ***** ** **** *** developers ** ***. ** **** ***** in **** ******* **** *** *******. In *** ******* ********** ** ****, you'll ****** * *-**** ***** ***** beside *** *-**** ***** *** *******. That ** ******** *** **** *******. We *** ********* ** ***** ****** protocols, ** *** **** ********* *** a *****-***** ******** ****** **** ******** access ******* *** ***** *** ****-**** verification ** ****.

*'* **** ***'** ***** **** ******** of *** ************ - **** ****** ones, ***** **** ******. *** **** majority ** ********* **** ******** ******* infrastructure, *** ********** ***** **** **** Wiegand ************** ** ****. ******* ** this, ** **** **** * ********* decision ** ******* **** ******* *** OSDP *********. **** ** **-******* ** purchasing ***-*** ******* ** ***** ****** not ** *** ****** - *** we ***'* ***** **** ****** ******* folks **** ********** **** ********** ********! For **** ** *** *********, ** are **** ** **** ***** ******** access ************** **** ****** *** ****** resistant. *** ******* ******* ************ **** the ****** *** *****, ******* *** person *** ****** ******** ************ ** can ****** ******** ***** ***** *** tampering ****** *** ***** ** **** a ****** ** ******** *** **** identified. ** **** **** *** ********** analysis ** ***** ****** ************* ****** as *** ******** ** *** ******* lines ****** * ******** ****** ****** would ** **** ******* *** ********* through ******* *******.

Comments (31)
UI
Undisclosed Integrator #1
Jun 25, 2020

****** ** **** *** **********. **** anyone **** ***** *** *** *** one ** *****?

U
Undisclosed #2
Jun 25, 2020

***** *** *** *** **** **** at ***************. * **** ** **** easier ** *** **** *** *** interface **** **-** *** ** **** not ******* * *******.

(2)
U
Undisclosed #6
Jun 26, 2020

* **** ***, ******* ** *** mirror ******* *** *** **** ** me * ******** ** * ***** really *** **** ** ****** * vulnerable ****.

** ****** ****** ** *** *** dark ****** ** ** *** ********* scrub ******* *************.

*** ********* ** *** **** ****** are *** *********. *** ******* ** the **** *** ***** ******** ****** are *** *********. ** **** * reader ** * ******* ** * perimeter **** ** *** ******** ********?

****: * ****** **** ****** ***** up ** *** ********, ******** *** reader ** *** ***** **** *** then ******** ** **** *** ****** world. ****** ******.

********? *********...*** *** *** **** ******** this *******?? ** *** **** * comment ****** **? ** ** *** REPLY ****** ** *****. ****** **** all *** ********** ***** ** **** been ***** **** ** ** ***** group ** ****** ******* ***** **** actually ******** *** ****.

**???? ****** ****? ***! ** *** implementation ****? ******* *** *** ****** you **** ** ** ****! ***...***** layers.

***** ** *** ******* ** *********. Somewhat **** *** ******** *******. ******* to ****, *** **** ********* ******** forum ********* ** **** ***********, **** YOU.

**** ** *** **** ****?

******* ****** ** * **** ******* and ******* **** ********** *** **** never **** *********** * ********** **** technology ********** **** ***** ***** **********. Yes * ****** ** **** ***** minute(no *** *********)..** * *** **** upside. ******* *** **** ******* ** market * ********** ******** ********** **** defaults **** ****** ********* ********* ** the ****** ***** ** *** ****** security ** ***.

****** **** ****** ****** *** **** forthright *** *** **** **** ********* on ***** **********. ****! ********! ** NOT ****** *** **** ** ****** of *******.

******* **** ******* ** **** *** pressure ** *** ***** *****, ******* thermal ****** ******* ***** *** **** new ***** ******* ** **** ***** chops **** ***** **** ** ******** angst.

*** ****** ** **** ***** ** nigh, ***** *....*****!!!!!

********.

Avatar
Travis Willis
Jun 25, 2020

**** ** * ****** ******* *** I ** ************ *** *** ********* at ***. **** *** **** ** money **** ****** **** *** ******* capable ** ***** ******. **** ************ of *** *** ********** ** ******* was ****** **** *** ** ***** you ****** **** **** *** *** skip **** ** *** ** ******?

(2)
U
Undisclosed #3
Jun 25, 2020

*** ***, **** ********** ** *****-***** with ** ******* ************. ********* ** employee, *** **** *** ** ****** issues? **** **** ** ******* ******.

************, *** **** ** *** */* ports **** * *** ** ******** on *****-***** ******. ***** *********, **** release *******, **** *********, *********.

(12)
(2)
(2)
Avatar
Daniel S-T
Jun 25, 2020

*'* ** ******* ** **** * response **** *** ****** *** *********. Why **** *********, ** **** ***** they ********* ****.

(4)
MM
Michael Miller
Jun 25, 2020

** *** ******** * ****** ***** rep ****** ** ****** *** **** a ***** **.

(2)
(13)
U
Undisclosed #3
Jun 25, 2020

*** *** ** ****, ******. *'* curious ** *** ** **'* * disagreement **** *******, * ***** **********, or *********.

****'** ****** *** ******** ** *** attention, *** **** ****** ******* ******* is... *** ** ** *** ****...

****.

(2)
(4)
UD
Undisclosed Distributor #4
Jun 26, 2020

***...*** ** ****. **** **** ** 'epic ****' ** **. **** ****** (US)$80 *** ?*** ******** ***** ***** for **** **** ** ***** ****** in. **** ** *******, *** *****'** done ****** **** ****!

(3)
UI
Undisclosed Integrator #11
Jun 27, 2020

**** ***** ***** ** ***** *** any *** ***** **** *****'* ****** on *** *** **** *** **** end ******. ** **** *** ** down **** ****** ********* **** ****'* going ** ** ******* ******* ******* they **** ** **** ** *** cloud ** **** **** ********** ***.

******* ***** ** **** ****** *****. The ****** ** ****-***** *** ************ beyond * **** ******* *************.

***** ** *** "***** *** ********" option :)

UI
Undisclosed Integrator #14
Jun 29, 2020

*** **** **** *** **** ******** to ******** ** **** ** ** is ** *** **** ******* ******* as *** ****** (********) *** *** using. * **** *** **** ********* in *** ****** *** **** **** using ** *** ***** * ****. While * ** **** ***** **** be **** ** ***** *** ** any ***** *** *******, ************* ******* is ***** ** *** ****.

U
Undisclosed #3
Jun 29, 2020

******, ** #** - **** ******* from **** * ******* **** ****.

*** *** ******* ** *** *** add/remove *********** ** ****** ****** ******* internet ************?

U
Undisclosed #5
Jun 26, 2020

******* ******* (**** **) **** *****:

********: ** *** ******* ****?

********: ****, ** ******* ******* **** for *** *** ******* **'** ** extending **** ******* *** *** ***** readers **** *** ****

(****** *****, *** *** ***** **********)

(1)
Avatar
Brian Rhodes
Jun 26, 2020
IPVMU Certified

*** '*' ** **** ****** *** 'Open', ***** ***** ** ** ************* and *** *********** ** **** ******* readers.

** *** (*** **********) ******* ****** does *** ****, **** **** ***** the ********** **** ******* ***** *** party **** ******* ** ****, ** the '********* **** *** ****' ********* contradicts *** *****.

(3)
(1)
UM
Undisclosed Manufacturer #7
Jun 26, 2020

** ** ***** ? **** ***** doesn’t ***. ****** ******* *****’* **** UL *******.

Avatar
Jacob Hengel
Jun 26, 2020
YourSix

*** ***** *** * ****. ***** massive ********** *** ***** **** ** understanding ******/******** ******** *** *** ******.

******* ** ** **** **** **** pushing ***** ******* ******* **** ********* chips *** ******* **** *** **** cybersecure ******** ** *** ******.

**** **** ** ***** ** *-* years **** **** *** ***** **** underneath ****. ** ***** ** **** will ** ****-*** ** ****.

(2)
(1)
UE
Undisclosed End User #8
Jun 26, 2020

*** ******* ******** ****** ******* ******* this **** *** * ******** **** and ******* **** * **** ***** Sales *****. * ******* ***** ** minutes ***** *** **** *** ** talk ***** *** ***** **** ***, how **** ********* **** **** *** how **** ****** ****** ** *** the *******.

**** * **** **** ** *** include **** ******* *** *** ****, I *** **** **** ****** **** still **** ******* ** ** ***** the **** ** *****-*******.

#***************

(4)
(2)
Avatar
Ross Vander Klok
Jun 26, 2020
IPVMU Certified

* ***** ** *** ******* "**** car *****" **** ** *******. ***** frankly * *** ******* ********* ** it. *******, ********** ****** ***** ****** wise, ********** **** *** **** *** polished, **** *** * ******** ******** and ** *** *** *** **** any ****** ** ***** ** **** to ** ****** **.

** *** **** * ***** ** the ******** **** ***** **** ****** and ******* ** *** *** **** thing ***** ****** ***** **** ****** they **** ******* ***** ****** ** first ***** ****** ***** **.....

(3)
Avatar
Daniel S-T
Jun 26, 2020

***** * ***'* ******** **** ******** anyone *** **** ***** ****, ** aren't ******* ***** ****** ********.

*** ** *** ***** ****? *** do ******** ******* ********* ****? ** they **** **** **** **** **? Do **** ****? **** ******, *** that's *** *** ********.

(6)
UM
Undisclosed Manufacturer #9
Jun 26, 2020

*** ****** **** ** ******* ******** asset **** *** ** ***** ********* on ** ******** ********** ** ******* is ** **** *** ********** ** enterprise ********** **** * ******** *** reliability **********.

(1)
Avatar
Spencer Cayer
Jun 26, 2020

******* ****** **** * *********** ***** system **** **** *** ******* ******** would ** * ****** **** ** swallow; ********** ** *** ***** ***** they *** ********. ****** *** ** the **** **** ******* *** * bad ****.

(1)
UI
Undisclosed Integrator #10
Jun 27, 2020

**** **** **** **** *** ********* not ** *** **** ********, **** have **** **** *** * **** time ** **** ******* ***** *********** who ***** ********* * ****** ** their **** *** *** ******* ***** they *** ****** ****** *** ****** rookie ******** *** ***** ** ******** security ****** ** *** *******, *** all **** **** ** ** ** sell, ****, ****. **** *** ** their ***** **** ** *** ****, the **** *** **** **** *** changes ** ** ******* ***** *** says "*'* ***** ** ******** * amount ** ******* *** **********, * want **** ******* ** **". ************* for ****, **** ***'* ********** **** they *** ******* *********** *** **** in *** ******** ********, *** ****** their *** ******* *** *** *** looking ** ********* *********. **** **** to **** ******** **** **** *** a ******** ******* *** **** **** a ******** ********...............***** *** *** **** will *** *** ***** **** *** security ******** ** * ***** ********* animal..

(2)
(1)
Avatar
Daniel S-T
Jun 27, 2020

**** ***'* ********** **** **** *** loosing *********** *** **** ** *** security ********, *** ****** ***** *** dealers *** *** *** ******* ** different *********.

***** **** ** ********** *** ***'* care ******* **** *** ***** ****** money. ***** *** ***** ***** ******* is ****'** ********* **** *** "***********" members ** *** ******** ********, ***** has **** ********* *** ****** *** haven't **** ***** ** **. **** and **** *** ******** ****** *** being *** ** ****** ** ********. Mostly ** ******. *** ** ***** and ******** ***** ****** ** ****** tight, *** **** *** ** ****** different. ** **** ************, ****** ** do *** **** *****, **** ** different ******* ** *** ********. *** so **** *** **** **** *****, even ***********.

*'** ****** **** ******* ** **** typical ** *******. ********* ** ****** seem ** ****, ** ******* ** the **** **** ******** ** **** sales *** *****. ** ****** ***'* always ***** ********. **** ****** ***** threat *** ** ******* ** * firewall ****, ** **** ************. * am ************ * ***, *** * am ****** *** **** *** ***. The ****** ** ** ****** *'** seen ** ** *** **** ****** prop ***** ****, *** ****** **** rooms ******* ********, **** ***** *** critical ************** ***** (**** *******/*****).

******** **** ***** ** ** ******* Verkada, *** *'* *** *** ** say **** ****'* ** *****, *** I ***'* ***** *** ***** ****** land ****** ** ****. ** ** the ******** ******** **** ***** ***** the ******** ** ******* *** * long ****. *** ** **** ***** continue ** **** **.

** **** ****** ** **** ********* we *** ****** **** ******* ******* we *** ****, *** *** ****'* survey **** ** ***'*. ** ** we **** ******* ** *** ******, maybe ** **** ** *** ****** first. ******* ******. ******* ********* ******* you **** *** * **** *** of ** ** ***. **** *** results **** * ** ******, **** of ****** *** **** ******* **, but **** *** ** ******* ** customers ***'* **** ** *** *** extra *** ****. ** ** ***'** already ***** **** **** **** *** customers, *** ***** ******* ** *** different?

* *** ****** ****-******* **** **** first ****** **. ***** ****** *** a **** ***, *** ******** ** see * *** ** ********* **** people ******* **** ***. ***** * bit ** ********, * ***'* ****.

(6)
(3)
RL
Randy Lines
Jun 27, 2020

*** ******** ******** ***** ******** ** folks ***** **** * *** **** credibility ** **** ** ******* ** readers ** *** ***** **** * simple ****** ****** ** ******** *** BLE ******. * ***** *** ****** will ** **** ******** ** *** reader. ****** ** *** *****. ******** down-time ******* ** *** ****** ** opposed ** *** **** **********.

***

UD
Undisclosed Distributor #12
Jun 28, 2020

* ******** *****. *** ****** **** is **** ** *** ****** ***** the ******** ** *** ******, **** the ******* ***** (*****) **** **** typically ** ** *** ******. ** that ** ** **** **** **** the ****** *** *** **** & you **** ****** ****** ** *** lock ***** & **** *** **** the ****.

U
Undisclosed #5
Jun 29, 2020

@**** -- ***** *** ****** ** systems **** ***** ****** ***** ******* so *** ***** ** *** ** the *********** ******. ****** ***** ********* is * ***** **** ****** ** you *** ***** ** ****** **** from *** **** **** *** ********* wiring ** **** *****.

**** ***** ****, ***** *** **** cases **** **** *** *********** ******, some **** *** **********. **** ** to *** * ******** ****** **** supports **** ************ *******.

UD
Undisclosed Distributor #12
Jun 30, 2020

**** ** ****, ** **** **** them, ******* ** ** **** ******* bit ** **** **** **** ** mounted *******. * ********* **** ***** get ******* ** *** **** ****** behind *** ******, **** **** ** pull *** *** **** ***. **** in ******* *** ****** ****** *** NOT ********* **** *** ******* ****** to *** ***** ******. **** ********* just **** ** '****' *******.

U
Undisclosed #5
Jun 30, 2020

**** ****.. **** *** * ************ to **** ****** *************. *** *** what **'* ***** ** ******* *** previous **** **** ********* ************* ** the ****** *****, ********* * ******'* call ** ****** ****** :)

(1)
UM
Undisclosed Manufacturer #13
Jun 29, 2020

**** ** *** **** ** *** Industry ****? ********* ** ******* ** are *** "*********"!!

Avatar
Travis Willis
Jul 01, 2020

* ***** *** ***** **** ** lost **** ** **** *******'* ******** and ****** ********* ** *** **** most **********'* **** *** ******* *** how ** **** **. **** ** the *********** ***** *** ***** ** is *********. **** *** ********* **** customers ********. ******* *****'* **** ** need **********'* ***********, **** **** ********** and **** ** * *** **********. I **** ** *** ** ** suck ** ** ******** ** *******. They ********* **** ** * *** deficiency *** *** ********** **.

**** **** ******* *** ******** *** they **** **** **** ******* **** do *** ******. ***** **** **** one *** ****** ** ****** *** brand **** *** *** ***** ** listen ** ** "*********". *** **** would ** ****** ***** ******* *** traditional ************* ******** ** *** ***** asses ** **** *** *** ** products ** *** ******* **** ** a ******* *******, ********* ** **** all ** ********** *** *******...** ****** or ******.

(1)
(2)
(1)
U
Undisclosed #15
Jul 06, 2020

**** ****** ****** * ********** ***. It's * ***** **** *** ********* to ***** **** **** ****** ******* have ******, ***** **** *** ******* adapt. **** ********* ** *********** ***** R&D.

(1)
UM
Undisclosed Manufacturer #16
Jul 22, 2020

* ****** ** '** ***** ****** when * ******** **** **** *** wave ** *** ****** ** ******* with *** ******** *****. * ***** it *** ** *** *** ******* flaw, * * ***** ********* ************.

*** **** **** *** '** ****** had * * ***** *** *** rest ** *******.

***'* ******* **** *** *********. ***** guys *** ***** *** ****. ***** access ******* ************ ***** *** ********** and **** *** ***** ***** *** game - ****, ********* *** *** Motorola.

*****'* ***** * **** ***** **** through *** *********** ******* **** * lot ** ********* *** **** ******* folks *** **** *** ** *** to ************* *** ***********.

(2)