All posts
Field Notes July 9, 2026 · 10 min read

Your Badge Reader Trusts Me More Than It Trusts You.

The badge on your hip is a serial number broadcasting to anyone standing next to you in an elevator. Cloning it takes a five-dollar antenna, a fifty-dollar tool, and about a second of proximity. Here's how the attack actually works — and the small handful of controls that make it expensive.

The Card Isn't a Key. It's a Number Read Aloud.

Last post I walked into a building with a clipboard and a work order. This one is about the thing on your hip that you think is protecting the door: the access badge. Because for a depressing majority of the buildings I test, that badge isn't a key at all. It's a small plastic card that, when it gets near a reader, shouts a number. The reader hears the number, checks a list, and opens the door. That's the entire security model.

The problem is that "shouts a number" is not a metaphor. The most common badge technology still bolted to doors across corporate America is 125 kHz low-frequency proximity — HID Prox, EM4100, Indala, and their cousins. These cards have no processor, no cryptography, and no concept of a secret. They store a fixed number and transmit it, in the clear, to anything that energizes their coil. There is no challenge. There is no response. There is no "prove you're a real reader before I tell you who I am." The card simply cannot say no.

So if I can get a reader-shaped thing within a few inches of your card for about a second, I get the number. And once I have the number, I can write it onto a blank card that is, as far as your door is concerned, molecularly identical to yours. Same number, same behavior, same green light. Your reader has no way to tell my copy from your original, because there is nothing to tell apart. They both say the same thing.

A 125 kHz prox card doesn't authenticate to the reader. It confesses to it.

The Fifty-Dollar Skeleton Key

The tool that does this is called a Proxmark3. It's a small board — the RDV4 is the nice one, but a $50 Easy clone off any electronics site does the job — with a low-frequency antenna and a high-frequency antenna, driven by a command-line client. It is, without much competition, the single most important device in a physical pentester's RFID kit. The Flipper Zero I mentioned in the clipboard post handles the easy 125 kHz reads and is wonderful for its size, but when a card gets interesting the Proxmark is what comes out of the bag.

The workflow against a basic prox card is almost insultingly short. I hold the Proxmark's LF antenna near the card and run one command:

lf hid read

The client prints the facility code and card number in a second or two. To make a working duplicate, I drop a rewritable T5577 card on the antenna and write the same values back:

lf hid clone -w H10301 --fc 12 --cn 3456

That's it. That's the attack. A T5577 costs about a dollar in bulk and can be rewritten thousands of times, so one blank becomes whatever badge I read last. There's no cracking, no brute force, no waiting. The card was designed in an era when "someone might build a reader in their garage" was not part of the threat model, and it shows.

Engagement rules

Everything here happened on authorized engagements with signed scope, a get-out-of-jail letter in my pocket, and a named point of contact who knew I was coming. Reading and cloning a badge you were not hired to test is not a gray area. It's the same felony as picking the lock would be.

Getting Close Enough

The whole attack hinges on proximity, and this is where people assume it falls apart. "You'd have to press a reader against my chest," they say. Not really. There are three reliable ways to get the read, and none of them look like an attack.

1. The stand-up read.

A Proxmark tucked in a padded envelope or a laptop bag will read a card through fabric at a few inches. Elevators are the classic setting: everyone stands close, everyone stares at their phone, and everyone has a badge clipped to the hip or hung on a lanyard at exactly bag-height. I set the read running, hold the bag naturally, and step in next to my target. A crowded lunch line, a shared revolving door, a packed shuttle — anywhere people cluster and nobody watches the person beside them. One good second is all it takes.

2. The long-range reader.

If a second of intimacy is too much to count on, you buy distance. There's a well-known build in this field based on a commercial long-range reader (the community calls it a Tastic RFID Thief) that stuffs a high-powered prox reader and a battery into a slim case or a backpack. It reads standard 125 kHz cards from roughly a foot or more away and logs every capture. Now I don't need to spoon you in an elevator; I need to walk past you in a hallway, or set the bag on the floor next to the smoking-area bench, or lean it against the wall by the badge-in turnstile at 8:55 a.m. and let the morning rush read itself into my logs.

3. The card left on the desk.

Half the badges I clone were never on a person at all. People drop their badge on the desk when they sit down, leave it clipped to a bag hung on a chair, or toss it in the cupholder of a car in the parking garage. The clipboard-and-work-order routine from the last post gets me onto the floor; a badge sitting unattended on a desk while its owner is in a meeting gets me the credential. Ten seconds with the Proxmark and I've copied a card whose owner never knew I was in the room.

"But We Use the Secure Cards"

Here is where the conversation gets interesting, because a lot of organizations did upgrade. They moved to 13.56 MHz high-frequency cards — MIFARE, iCLASS, DESFire — and were told these were secure. Some of them are. Most of the deployments aren't, for reasons that have nothing to do with the chip and everything to do with how it was rolled out.

MIFARE Classic is the poster child. It's a high-frequency card with actual encryption, which sounds great until you learn that its Crypto-1 cipher was broken more than fifteen years ago. The Proxmark runs attacks — darkside, nested, and the newer hardnested — that recover the keys from a card in anywhere from seconds to a few minutes. Once the keys are out, the card is an open book: read it, clone it onto a magic MIFARE card that allows writing the normally-locked block zero, done. A "secure" card that is trivially cloned is arguably worse than a dumb prox card, because it comes with a false sense of having solved the problem.

HID iCLASS in its original "legacy" flavor had its keys extracted and published years ago; the Proxmark clones legacy iCLASS about as easily as it clones prox. The genuinely strong options — iCLASS SE / SEOS and MIFARE DESFire EV2/EV3 with properly managed diversified keys — are real cryptographic systems that I cannot clone by standing next to you. But two things keep undercutting them in the field:

The uncomfortable summary

The card technology on the box almost never tells you whether you're safe. A reader that also accepts legacy prox is a legacy-prox reader wearing a nicer bezel. Ask what your readers accept, not what your newest cards are.

What the Clone Actually Buys Me

A cloned badge isn't the end of the engagement — it's the part that makes everything after it boring. With a working copy of a real employee's card, I stop being a stranger who has to talk his way through every door and start being, electronically, a person who belongs.

The clone gets me through the turnstile without a tailgate. It gets me into the stairwell, the server-room floor, the parking garage after hours when the lobby is locked and the only entry is the badge-gated side door. Better still, every one of those entries writes an authorized-looking line in the access-control log — badge #3456, granted, 7:42 p.m. — under the name of an employee who was home eating dinner. The logs that are supposed to catch me instead alibi me. When the client reviews the door records after the engagement, the most unsettling slide in the debrief is the one where I show them their own access report showing "Sarah from accounting" entering the building three times on a night she wasn't there.

That's the finding that lands hardest. Not "your badges can be copied" in the abstract, but "here is your access log, and here is proof it's fiction."

What Actually Raises the Cost

Defenders want a product to buy. As with most of this work, the fixes are mostly discipline, and only some of them cost money. In rough order of impact:

Why This Matters

The badge system is the control people feel the most — you tap it a dozen times a day, it clicks, the door opens, and that little ritual quietly convinces everyone that the building is locked. It's the most visible security control most employees ever touch, which makes it the most trusted, which makes it the most dangerous when the trust is misplaced.

And for a large share of the buildings I walk into, it is misplaced. The card is a number read aloud, the reader still answers to a protocol from the 1990s, and fifty dollars of hardware turns one second of proximity into a permanent copy of someone's identity. That's not an exotic attack. It's a solved one, running on tools you can buy openly, against technology that was never designed to resist it.

The good news is the same as it always is in this work: the fixes are mostly known, mostly boring, and mostly things you already have the hardware to do. Turn off the old protocols. Use real keys. Put a PIN on the doors that matter. Watch your own logs for the impossible. Do those four things and the elevator clone that used to end your engagement in a second becomes a problem the attacker can't solve standing next to you — which, most of the time, is the only place they get to stand.

If you read the last post and got someone into your lobby to test it, get them to clone a badge on the way out. The look on the IT lead's face when their own access report shows a ghost is worth more than any slide I could build.

By Wes Hardcastle · WesCastle Tags: physical security, RFID, access control, pentesting, red team, field notes