Why the traditional proximity card is a security risk, and how to choose between card, PIN or facial biometrics depending on the type of site.
The white proximity card your company has used for the past ten years can be cloned in under five seconds with a device costing less than €20. You don't need to be a professional hacker: off-the-shelf reader-cloners designed exactly for that are freely available, and a large share of the access control installed in offices, industrial units and communities across Alicante and Murcia still uses technology those devices can read.
At DDR360 we install Hikvision access control systems from Torrevieja across the whole province of Alicante and the Region of Murcia. In this article we explain, with the technical detail it deserves, why classic cards are vulnerable, what DESFire encryption actually changes, and how to choose between card, PIN or facial biometrics depending on the type of site you need to protect.
Most access cards installed in Spain over the last twenty years use low- or high-frequency RFID with chips such as EM4100 or MIFARE Classic. The underlying problem isn't the radio frequency itself, but that these chips were designed more than two decades ago with a security level that has become technically obsolete.
The best-known case is MIFARE Classic, which uses a proprietary encryption algorithm called Crypto1. In 2008, security researchers published practical attacks that break that encryption in a matter of minutes, and since then hardware tools have existed (the best known is the Proxmark, but there are much cheaper and simpler cloners) capable of reading a card's contents at a distance, computing its internal keys, and writing an exact duplicate onto a blank card. The whole process, with the right equipment, takes seconds and the original cardholder never notices — all it takes is getting close enough, for instance walking past someone in a café.
On top of that there's a management problem, not just a technical one: when cloning is this easy, the access log stops being reliable. If two identical cards can open the same door, the "who entered and when" log can no longer say for certain whether it was the legitimate employee or someone with a copy. For a business that needs to demonstrate access control over sensitive areas (server room, high-value stock room, archive with client data), that loss of traceability is as serious as the physical intrusion itself.
The technical answer to that problem is MIFARE DESFire with AES128 encryption, the same encryption standard that protects EMV chip credit cards and much of online banking communication. The difference with the Crypto1 used in classic cards isn't a matter of degree, it's an entire generation apart technologically.
AES (Advanced Encryption Standard) with a 128-bit key is a public algorithm, reviewed for years by the entire global cryptography community, and to date there is no known practical attack able to break it in a reasonable time with commercially available hardware. Every DESFire card, moreover, can be configured with a a unique master key per installation: even if someone managed to compromise another company's system, that key is useless for yours. The €20 reader-cloners that copy a MIFARE Classic card in seconds simply lack the computing power and access to the cryptographic key needed to replicate a properly configured DESFire credential.
In practice, this means replacing an old card fleet with DESFire credentials isn't over-engineering for its own sake: it's closing the cheapest and most commonly used entry point for anyone trying to access a site without authorisation.
There's no universally best access method, there's the right method for each situation. Here are the real advantages and limitations of each:
| Method | Advantages | Limitations |
|---|---|---|
| DESFire card | Fast, no physical contact with the reader needed, easy to revoke if lost, works with gloves | Can be left at home, or voluntarily lent to a colleague |
| PIN / keypad | Nothing to carry, useful as a second factor combined with a card | The code can be shared or observed over someone's shoulder (shoulder surfing) |
| Facial biometrics | Impossible to lend or share, reads in 0.2 seconds, cannot be forgotten or lost | Requires a reader at each access point, higher initial cost than a card |
The distinctive advantage of facial biometrics over card and PIN isn't just speed: it solves the one problem neither of the other two methods can solve by design — an employee clocking in or opening the door for someone else in their name. Not even the most secure card on the market stops its owner lending it to a colleague running late; a person's face can't be lent out. That's why, in the most sensitive areas (server rooms, night-shift staff access, time tracking), many businesses combine a DESFire card for everyday use with a facial reader at critical points.
The design of an access control system changes a lot depending on the type of installation. These are the most common patterns we see in Alicante and Murcia:
Offices. The most common case: a DESFire card for the main entrance and common areas, with facial biometrics reserved for the server room or the management office. Centralised management lets you register a new employee on every door at once in seconds, and revoke their access instantly the day they leave the company, with no key to physically collect.
Industrial units and warehouses. On the area's industrial estates (for example, around Elche, San Vicente del Raspeig or Cartagena) the challenge is usually different: not just controlling who enters the building, but managing the traffic of supplier and haulier lorries. That's where automatic number-plate reading: the barrier opens on its own when it recognises an authorised vehicle on the list, with no need for the driver to get out of the lorry or for a security guard to be posted at the gatehouse. For staff on foot, DESFire card turnstiles stop unauthorised people slipping in while goods are being moved.
Residents' associations. It's a particularly relevant use case on the Costa Blanca and Costa Cálida, where developments and communities with a high turnover of owners (seasonal residents, holiday lets) are common, often with a vehicle access barrier at the entrance. Number-plate reading lets owners drive in without a remote or a card, while QR codes or temporary access can be generated for gardening, pool cleaning or maintenance staff, valid only for the agreed day and time slot. This solves a common problem in communities where the board changes every year: nobody has to physically collect or hand over remotes when a service provider changes.
All of the above (DESFire cards, facial readers, number-plate reading barriers) needs a brain to coordinate it, and that's where HikCentral, Hikvision's centralised management platform. From a single console, accessible via web or mobile app, the person in charge of the installation can add or remove users on every door at once, set different access schedules per person or group (for example, letting cleaning staff in only from 7am to 9am), and check the complete access history with date, time and exact door.
The feature our clients value most day to day is one-click access revocation from a phone. When an employee leaves the company, there's no need to change locks or collect keys: their credential is deactivated from a phone and, at that exact moment, they lose access to every door in the system. And if a card is lost, the process is identical: that specific credential is cancelled without affecting any other, something unthinkable with a physical key shared across an entire building.
Can the new system work with the doors and locks I already have?
In most cases, yes. DESFire and facial readers are integrated onto the existing electric lock or turnstile; it's only necessary to replace the whole lock when it's purely mechanical with no electric release.
What happens if there's a power cut or the internet connection drops?
Door controllers store authorised credentials locally and keep working independently even if the internet connection is lost; what's temporarily lost is remote management and history syncing, which resumes automatically once the connection is restored.
Does facial biometrics store an identifiable photo of each person?
Not in the traditional sense. The system extracts and stores a mathematical template (a set of facial reference points) that doesn't allow a photo to be reconstructed, following the same principle used by other biometric systems on the market to protect data privacy.
How long does installation take in an existing office or industrial unit?
It depends on the number of doors and whether new cabling needs to be run or existing infrastructure can be reused. In most mid-sized installations, the work is completed in one or two days, including HikCentral configuration and staff training.
Can I have different permission levels for different employees?
Yes. HikCentral lets you create as many access profiles as you need: for example, admin staff accessing all areas during office hours, production staff only accessing the unit, and cleaning staff limited to a specific time slot.
We analyse your current access system, explain the real risks clearly, and propose a tailored solution. No obligation.
Request an Audit →Further reading: DDR360 Access Control · AI CCTV · Alicante and Murcia coverage · Free Audit