skip to content

Why does cloning a 125 kHz proximity badge work, and which control class removes it?

level: seniorimportance: should knowfreq 34%

answer

  1. passive, powered by the reader's field
  2. the identity is the transmission
  3. no challenge, no freshness, no key
  4. a longer number is still a fixed number
  5. frequency is not the security property

basics

~20 s

The card is a passive transponder that answers any powering field with the same fixed number, with no key and no challenge. Anything that hears it once can replay it. Only a credential that never transmits its secret removes the copy.

solid answer

~50 s

A low-frequency proximity card holds no secret it can keep. The reader's field powers it and it replies with a fixed bit string — in the common 26-bit format, parity bits around an eight-bit facility code and a sixteen-bit card number. There is no cryptography, no per-card key and no challenge-response, so the identity is the transmission. A concealed reader held near the card in a lift or a lobby queue captures it, and the copy is written to a blank fob no door can distinguish. Both instinctive fixes fail: a longer card number is still a fixed number, and a shorter read range still leaks to anyone standing next to a person. The control class that works is mutual authentication with a key the card never puts on the air. Moving to 13.56 MHz is not automatically that class — a card read only for its serial number is just as copyable.

go deeper

for a junior

Know that a proximity badge answers any reader that powers it with the same fixed number, so someone standing close enough can copy it without touching the card.

for a middle

Explain the structure of the transmission and why the absence of a challenge means a replay is bit-identical to an original, then say why a longer card number changes nothing.

for a senior

Pick the control class on the property that matters — a key the card never transmits — and volunteer that a frequency change is not a security model and that readers, controllers and the wiring path all have to move with the credential.

for a principal

Own a phased re-badging programme under a budget that will not cover the estate: sequence by what is behind each door, name the residual you are accepting everywhere else, and get the acceptance recorded by the owner rather than assumed.

## What the card actually is A 125 kHz proximity card is a passive transponder. It has no battery. When it enters a reader's alternating field it harvests enough power to run, and it modulates a reply. That reply is a fixed bit string burned in at production or personalisation, and it is the same on every read, forever. The most common encoding is the 26-bit format: one leading parity bit, an **eight-bit facility code**, a **sixteen-bit card number**, and one trailing parity bit. The controller behind the reader checks that this facility code and card number pair appears in its permitted set for that door. Read the consequences off that description directly: - **The identity is the transmission.** There is nothing the card knows that it does not say out loud on every read. - **There is no freshness.** No nonce, no counter, no challenge from the reader that the card must answer differently each time. A replay is indistinguishable from an original because it is bit-identical. - **There is no authentication of the reader either.** The card has no way to know whether the field powering it belongs to the site's door or to something in a bag. ## How the capture happens in practice The capture needs proximity, not standoff. Covert readers with enlarged antennas extend the range beyond the few centimetres of a door reader, but the realistic operating distance is still contact-adjacent: standing next to someone in a lift, in a coffee queue, on a crowded train, or setting a bag down beside a jacket on a chair. The badge is usually on a hip lanyard or in a back pocket, at exactly the height of a bag held at the side. The copy is then written to a writable card or fob. Because the reader validates a number and nothing else, the copy is not a *forgery* in any meaningful sense — it presents the same bits, so it is the same credential as far as the estate is concerned. Nothing distinguishes it. This also means the original keeps working, so the target has no reason to think anything happened. ## Why the intuitive fixes miss - **A longer or more random card number** raises the cost of guessing a valid number, which was never the technique. Copying does not need to guess. - **Reducing read range** is a linear improvement against an adversary willing to stand closer, and there is always a moment in a working day when someone is standing right next to the badge. - **A photo printed on the card** is checked by humans at reception and by no reader anywhere. The clone can be a featureless blank fob that is never shown to anyone. - **The facility code** is sometimes mistaken for a shared secret. It is an eight-bit site identifier that reduces accidental cross-site collisions; anyone who has heard one valid card from the site already knows it. - **Anti-passback** is the one measure with any bite, and only in a narrow case: if the genuine card is already inside and has not exited, a clone presenting the same number at an entry reader can be refused. It fails if the clone is used before the original arrives, or on doors without directional readers. ## The control class that removes it The technique depends on one thing it cannot substitute: **a credential that reveals everything it knows on every read**. Remove that and there is nothing to copy. The class is a contactless smartcard that performs **mutual authentication with a per-card key held in the card's secure element and never transmitted** — the reader challenges, the card proves it holds the key by computing over the challenge, and each exchange is different. An eavesdropper records one useless conversation. Two caveats a senior candidate should volunteer: 1. **Frequency is not the property.** Describing a migration as *moving to 13.56 MHz* names the radio, not the security model. A 13.56 MHz card read only for its factory serial number is a fixed identifier over a different frequency, and several widely deployed card families of that generation used proprietary ciphers that were broken publicly years ago. What matters is whether a live cryptographic exchange with an unshared key takes place, and whether the readers are actually configured to require it rather than falling back to the serial number. 2. **Readers and controllers are half the migration.** The credential, the reader firmware and the controller all have to agree, and the wiring protocol between reader and controller may itself pass a bare number. A card upgrade that terminates in the same legacy path preserves the problem one layer down. ## Where this leaves an estate that cannot re-badge this year The honest interim is not a reader tweak. It is to shrink what a card alone opens: require a second factor that is not broadcast at the small number of doors that actually matter, and sequence the credential replacement by what is behind each door rather than uniformly by site. Say plainly that everywhere else the copy still works, so that the decision is a stated acceptance rather than an assumption.

  • Does a photo printed on the badge help?
    Only where a human compares the face to the card, which happens at reception and almost nowhere else on a floor. The reader never sees the print, and the clone can be a blank fob that stays in a pocket. Treat printed identity as a control on the human path, entirely separate from the credential path.
  • What does the facility code actually buy?
    Very little as a security property. It is an eight-bit site identifier that narrows which numbers a site's readers will accept, reducing accidental matches between neighbouring installations. Anyone who has captured one valid card from the site already holds it, so it adds nothing against copying.
  • The estate cannot replace twenty thousand credentials this year. What interim measure is worth doing?
    Not a reader tweak. Shrink what a card alone opens: add a second factor that is not broadcast on the handful of doors where presence buys something real, and sequence replacement by what sits behind each door rather than uniformly by site. Then state clearly that everywhere else the copy still works, so it is an accepted residual rather than a gap nobody named.

saying these in an interview costs you the question

  • Says 13.56 MHz is automatically secure
  • Thinks shortening reader range solves copying
  • Claims the facility code is a shared secret
  • Believes a printed photo protects the reader path
  • Assumes the clone can be told apart from the original card

context