Why the traditional proximity card is a security risk, and how to choose between card, PIN and facial biometrics depending on the type of installation.
The white proximity card your company has used for the past ten years can be cloned in under five seconds with a device costing less than €20. You do not need to be a professional hacker: reader-copiers designed for exactly this are freely on sale, and a good share of the access control installed in offices, industrial units and residential developments across Alicante and Murcia still uses the technology such a device can read.
At DDR360 we install Hikvision access control systems from Torrevieja across the whole province of Alicante and the Region of Murcia. In this article we explain, with the technical detail it deserves, why classic cards are vulnerable, what really changes with DESFire encryption, and how to choose between card, PIN and facial biometrics depending on the type of installation you need to protect.
Most access cards installed in Spain over the past twenty years use low- or high-frequency RFID technology with chips such as EM4100 or MIFARE Classic. The underlying problem is not the radio frequency itself, but that these chips were designed more than two decades ago with a level of security that is now technically obsolete.
The best-known case is MIFARE Classic, which uses a proprietary encryption algorithm called Crypto1. In 2008, security researchers published practical attacks that break that encryption in a matter of minutes, and since then hardware tools have existed (the best known is the Proxmark, but there are far cheaper and simpler copiers) capable of reading the card's contents at a distance, computing the internal keys and writing an exact duplicate onto a blank card. With the right equipment the whole process takes seconds, and the owner of the original card never knows: you simply have to get close enough — walking past someone in a café, for example.
On top of this comes a management problem, not merely a technical one: when cloning is this easy, the access log stops being reliable. If two identical cards can open the same door, the "who came in and when" log no longer establishes with certainty whether it was the legitimate employee or someone with a copy. For a company that has to demonstrate access control over sensitive areas (server room, valuable goods store, archive holding customer data), that loss of traceability is as serious as the physical intrusion itself.
The technical answer to that problem is MIFARE DESFire with AES128 encryption, the same encryption standard that protects EMV chip credit cards and much of online banking communication. The difference from the Crypto1 of classic cards is not one of degree, it is a whole technological generation.
AES (Advanced Encryption Standard) with a 128-bit key is a public algorithm, reviewed over years by the entire global cryptographic community, and to date there is no known practical attack capable of breaking it in a reasonable time with commercially available hardware. Each DESFire card can also be configured with a master key unique to each installation: even if someone managed to compromise another company's system, that key is useless against yours. The €20 reader-copiers that clone a MIFARE Classic card in seconds simply do not have the computing power, nor access to the cryptographic key, needed to replicate a properly configured DESFire credential.
In practice this means that replacing a stock of old cards with DESFire credentials is not over-engineering for its own sake: it closes the cheapest and most commonly used way in for anyone wanting to enter premises without authorisation.
There is no universally superior access method, only the right method for each situation. These are the real advantages and limitations of each:
| Method | Advantages | Limitations |
|---|---|---|
| DESFire card | Fast, requires no physical contact with the reader, easy to revoke if lost, works with gloves | Can be left at home, or voluntarily lent to a colleague |
| PIN / keypad | Nothing to carry, useful as a second factor combined with a card | The code can be shared or observed over the shoulder (shoulder surfing) |
| Facial biometrics | Impossible to lend or share, reads in 0.2 seconds, cannot be forgotten or lost | Requires a reader at each access point, higher initial cost than a card |
The distinctive advantage of facial biometrics over card and PIN is not merely speed: it solves the one problem neither of the other two methods can solve by design — an employee clocking in, or opening the door, on someone else's behalf. Not even the most secure card on the market stops its owner lending it to a colleague running late; a person's face cannot be lent. That is why, in the most sensitive areas (server rooms, staff entrances at night, time and attendance), many companies combine a DESFire card for everyday use with a facial reader at critical points.
The design of an access control system varies considerably with the type of installation. These are the most common patterns we see in Alicante and Murcia:
Offices. The most common case: a DESFire card at the main entrance and in communal areas, with facial biometrics reserved for the server room or the management office. Centralised management makes it possible to register a new employee across every door at once in seconds, and to revoke their access instantly the day they leave, without physically collecting any key.
Industrial units and warehouses. On the area's industrial estates (around Elche, San Vicente del Raspeig or Cartagena, for example) the challenge is usually different: not just controlling who enters the building, but managing the flow of supplier and haulier lorries. That is where automatic number-plate recognition comes in: the barrier opens by itself when it recognises an authorised vehicle on the list, with no need for the driver to get out of the lorry or for a guard to be physically stationed in the gatehouse. For people on foot, DESFire card turnstiles prevent anyone unauthorised slipping in amid the movement of goods.
Residents' associations. This is a particularly relevant use case on the Costa Blanca and Costa Cálida, where developments and associations with high owner turnover abound (seasonal residents, holiday lets) and there is often a vehicle barrier at the entrance. Number-plate reading lets owners drive in without a remote or a card, while QR codes or temporary access can be generated for the gardening, pool cleaning or maintenance service, valid only on the agreed day and time slot. This solves a recurring problem in associations whose committee changes every year: nobody has to physically collect or hand out remotes when a service provider changes.
All of the above (DESFire cards, facial readers, barriers with number-plate reading) needs a brain to coordinate it, and that is where HikCentral comes in, Hikvision's centralised management platform. From a single console, accessible by web or mobile app, whoever runs the installation can add or remove users across every door simultaneously, define different access schedules per person or per group (cleaning staff only able to enter between 7:00 and 9:00, for instance), and consult the complete access history with date, time and exact point of entry.
The feature our clients value most day to day is one-tap access revocation from a phone. When an employee leaves, there is no need to change locks or collect keys: their credential is deactivated from the phone and, at that very moment, they lose access to every door on the system. And if a card is lost the procedure is identical: that specific credential is cancelled without affecting any other — unthinkable with a physical key shared across a whole building.
Can the new system work with the doors and locks I already have?
In most cases yes. DESFire and facial readers integrate with the existing electric lock or turnstile; the lock only needs replacing entirely when it is purely mechanical with no electric release.
What happens if there is a power cut or the internet connection drops?
The door controllers store authorised credentials locally and keep working autonomously even if the internet connection is lost; what is temporarily lost is remote management and synchronisation of the log, which is restored automatically once the connection returns.
Does facial biometrics store an identifiable photograph of each person?
Not in the traditional sense. The system extracts and stores a mathematical template (a set of facial reference points) from which a photograph cannot be reconstructed, following the same principle other biometric systems on the market use to protect data privacy.
How long does installation take in an existing office or unit?
It depends on the number of doors and whether new cabling has to be run or existing infrastructure can be reused. On most medium-sized installations the work is completed in one or two days, including HikCentral configuration and staff training.
Can I have different permission levels for different employees?
Yes. HikCentral allows as many access profiles as needed: administration reaching every area during office hours, production staff only entering the unit, and the cleaning service limited to one specific time slot, for example.
We analyse your current access system, explain the real risks clearly and propose a tailored solution. No obligation.
Request an Audit →Further reading: DDR360 Access Control · AI CCTV · Alicante and Murcia coverage · Free Audit