Hacker News new | ask | show | jobs
by superuser2 3934 days ago
Most RFID systems are similarly vulnerable. All HID iClass systems (supposedly smart-card based) use the same cryptographic key, which you can dump out of the memory of any reader if you are so inclined. The ID numbers of badges are printed on them, and this is usually enough to program a new badge as a clone or do some SDR trickery to imitate it.

But let's not forget that tailgating will get you past pretty much anything that isn't a turnstile. Turnstiles are really only in elevator lobbies, so if you can find a legitimate reason to be in some other part of the building you can just follow a legitimate user through any door, no matter how secure its locking mechanism. And failing that, almost no one properly authenticates cleaning staff or contractors.