PROUDLY CANADIAN· BRITISH COLUMBIA · SINCE 2015CALL A LOCAL TEAM — (604) 360-7400
(604) 360-7400Book a free site walk-through

New access cards, same old risk: the upgrade step buildings skip

If your building still runs on beige proximity fobs, the card is the easy part — and upgrading the cards alone fixes nothing.

Guard Nation Security7 min read

New access cards, same old risk: the upgrade step most buildings skip

A great many commercial buildings in BC still run the same card. Beige or white, credit-card thin or a plastic teardrop on a keyring, a number printed on the back in small black digits. It was issued somewhere around 2005, the system has worked every day since, and nobody has thought about it in twenty years.

That card is a 125 kHz proximity credential. It holds a number, it broadcasts that number to anything that asks, and it has no way of knowing who is asking. That is not a defect — it is what the technology was designed to do in an era when the reader was the only thing in the world listening. Handheld tools that listen are now ordinary. We are not going to name them, price them, or explain how they work, and you do not need any of that to make the decision in front of you. What matters is that copying one of these credentials is fast and requires no skill worth describing, and that the fix is not the one most building owners assume.

The number on the card is a password

The clearest way to think about this comes from HID Global — one of the largest manufacturers of these credentials, writing about the risk in its own product line. In its technical note on legacy technology, HID puts it plainly:

"Credential numbers serve the same purpose as a password: secret values that identify a user to a system."

Read that again with your own building in mind. The number that opens your lobby is a password. On a legacy proximity credential, that password is transmitted in the clear to anything within range, printed on the outside of the card, often assigned in a sequence, and frequently listed on the box the cards arrived in.

HID notes that credential numbers can sometimes be reconstructed without anyone ever touching a card — from a photograph of the printed number, from the predictability of sequential numbering, or from the packaging labels. This matters more than the technical attack for most strata councils, because it means a card left face-up on a desk during a site tour is a disclosure event.

There is one more piece of the picture worth knowing the name of. The reader on your wall does not decide anything. It reads the credential and passes the number down a wire to a controller in a back room, historically using a protocol called Wiegand. The reader is a microphone; the controller is the brain. Keep that split in mind, because the real fix lives at the reader, not on the keyring.

The upgrade trap: why new cards alone change nothing

This is the part almost nobody is told when they buy an upgrade, and it is the single most useful thing in this article.

Suppose you do the responsible thing. You issue everyone a modern, encrypted credential — Seos, MIFARE DESFire, or similar. New cards, new expense, a memo to residents. You now believe you are secure.

You are not, if the readers still accept the old cards.

Modern readers can run in a migration mode that accepts more than one credential type at once. That mode exists for a good reason: it lets a 400-suite building phase in new credentials over months instead of re-badging everyone on a single Saturday. But it can be used in reverse. HID calls this a downgrade attack: an attacker who cannot replicate a high-security credential does not have to. They read the number that credential presents and write that same number onto a card with weaker protection, or none at all. HID describes the mechanism directly:

"…third-party tools are used to create a legacy credential with the same data on cards with fewer security features (like MIFARE Classic and legacy iCLASS Elite), legacy iCLASS, or cards with no electronic security at all (classic Prox)."

The counterfeit is a cheap old card. It does not need to imitate the encryption on your new credential, because your reader is still willing to accept a card that has none. The expensive credential in your pocket became decoration the moment the reader kept its back door open.

HID's own instruction is unambiguous, and it is the sentence to quote when you are getting quotes:

"Once the upgrade phase is complete, less secure credentials such as HID Prox, legacy iClass, and MIFARE Classic should then be disabled within the reader preventing these credentials from being accepted."

And on the interim period, while both are still accepted:

"While legacy credential support is enabled, the risks of legacy and insecure credentials remain, including unauthorized duplication and use."

Migration mode is a temporary state, not a configuration you leave running for five years. In practice, that is exactly what happens: the installer enables it, the new cards go out, the last few stragglers never hand in their old fobs, and nobody ever goes back to close the door. A migration that is never finished is not a migration. It is a more expensive version of the system you had.

One thing to be fair about: HID is describing a weakness that applies to every legacy proximity credential, not something peculiar to its products. The physics is the same regardless of whose logo is on the card. HID is simply one of the few manufacturers willing to write it down about its own catalogue, which is precisely why it is worth citing.

How to work out what you have, without calling anyone

You can get most of the way to an answer in ten minutes.

Look at the card itself. Legacy proximity cards are usually plain, slightly thicker than a bank card, often beige or off-white, and frequently have a printed number and a facility code on the back — sometimes two numbers, one long and one short. A printed number is a strong hint you are looking at a legacy credential, because modern encrypted credentials generally do not need to advertise anything.

Check whether it has contacts or a chip window. A gold contact pad, or a card also used for photocopier or transit-style functions, points toward a smart card rather than plain prox.

Look at what it does at the reader. A legacy prox card typically reads at a distance — you can wave it near the reader without touching, sometimes through a wallet, sometimes without taking it out of a bag. Credentials that require a deliberate tap, or a firm touch to the reader face, more often indicate the shorter-range smart card technologies.

Check the age of the system. If the readers, the controller, and the card stock all date to the same installation and nobody has touched the head end since, you almost certainly have whatever was standard the year it went in. And if nobody in the building can open a door with a phone, that is worth asking about — though mobile credentials are optional, so their absence proves nothing on its own.

Now the honest caveat: none of that is proof. The only certain answer comes from someone reading the credential and the reader configuration directly, because two identical-looking cards can be entirely different technologies, and a building can be running a mixture without anyone realizing. Treat the checks above as a way to decide whether the question is urgent — not as a verdict.

What to ask for when you get a quote

Ask for three things, in this order.

An audit before a proposal. What credential technology is actually in use, what technology the readers support, and whether the readers can be reconfigured or must be replaced. Plenty of buildings discover the readers were already capable and only the cards and configuration needed to change. That is a much smaller job than a rip-out, and you will not find out unless someone looks first.

A migration plan with an end date. New credentials issued, a defined window in which both old and new are accepted, and a specific date after which the old ones stop working. Ask what happens to residents or staff who miss the deadline — a plan without an answer to that question is a plan that will quietly stay in migration mode forever.

Legacy credential support disabled at the reader on completion. This is the deliverable that actually buys you the security. Put it in writing, ask to be shown the reader configuration afterwards, and treat the project as unfinished until it is done. If a vendor treats this step as optional, or cannot explain a downgrade attack when you raise it, you have learned something useful about the vendor.

While you are at it, do the free part. Pull the credential list and compare it against your current residents, staff, and contractors. Deactivate everything you cannot account for. A copied card and a card belonging to someone who moved out in 2019 are the same problem, and one of them costs nothing to solve.

What we can actually support

You will see a lot of numbers attached to this — how many seconds a copy takes, what a tool costs. We are not going to give you any of them, because we cannot source them, and a security company inventing a statistic to frighten you is doing the same thing as a security company inventing a threat.

Here is what we can support. Your credential number is a password. On legacy proximity technology it is broadcast openly, and it is frequently printed on the outside of the credential. Duplicating it is a known and documented risk, described by the manufacturers themselves. And upgrading the cards achieves nothing until the readers are told to stop accepting the old ones.

That last sentence is the whole article. Most buildings that think they have solved this have done everything except the step that matters.

Written by the Guard Nation Security team — from the sites we install, monitor, guard and investigate across British Columbia, and have since 2015.
Sources

Sources

  • HID Global, Safeguarding Against Legacy Downgrade Attacks — https://doc.origo.hidglobal.com/common/rm/Safeguarding_Against_Legacy_Technology.pdf

Want a second opinion on your doors?