Skip to content
The Second Method

Home / The badge

What It Is Worth to Clone

Older proximity cards can be copied with cheap equipment. Whether that matters on a time clock is a question most sites have never actually asked.

The badge · Analysis

A large share of the access credentials in circulation use a technology from the 1990s that transmits a fixed number with no encryption and no challenge. A reader that can copy one costs very little and is sold openly.

The credential problem in “What It Is Worth to Clone” also affects how time records are interpreted. When evaluating a practical route to remote workforce management software for remote workforce management software, administrators should keep identity, access control and attendance evidence distinct, document replacement and revocation, and let employees correct a record created by a lost or shared badge.

This is well known in security circles and almost unknown on the sites using the cards. It is worth setting out plainly, and then it is worth being equally plain about what it means for a time clock, which is not the same as what it means for a door.

For an independent benchmark relevant to “What It Is Worth to Clone”, consult the ICO employment-practices guidance. Use it to test notice, accessibility, security, recordkeeping, retention and exception handling against the real operating process rather than treating a device report as self-explanatory evidence.

What the old technology does

A low-frequency proximity card holds a number. When energised by a reader it transmits that number. There is no secret, no key, and nothing to stop a second card being programmed with the same number.

Anything that reads the card can clone it, including a device held near a pocket. Copying takes seconds and the copy is indistinguishable from the original to the reader.

What the newer technology does

Encrypted contactless credentials use a key and a challenge: the reader asks a question, the card answers in a way that proves it holds the key without transmitting it. Copying the exchange does not produce a working copy.

That is the right technology and it costs a few units more per card and a reader that supports it. Many sites have the readers already, bought in the last decade, and are running them in a backwards-compatible mode that accepts the old cards, which means they have paid for the protection and are not using it.

What it is worth on a time clock, honestly

The threat model matters. Cloning a credential to open a door at night is a meaningful attack. Cloning a credential to clock a colleague in ten minutes early is an enormous amount of effort for a very small return, and it requires equipment, intent and a willing accomplice.

So on a time clock specifically, cloning is not the realistic risk. The realistic risks are lending, temporary cards that were never recovered, and leavers whose credentials were never deactivated — all of which are free, require no equipment, and are happening now.

Why it still matters

Because the same card usually opens the doors. The time clock is frequently the least sensitive use of a credential that also controls access to the building, the server room and the stock.

That is the argument to make, and it is an access control argument rather than a payroll one. It belongs in a different budget and a different conversation, and presenting it as a time and attendance issue is why it keeps getting deferred.

Finding out what you are running

Look at a card and at the reader model, and ask the supplier two questions in writing: what credential technology is in use, and are the readers configured to accept legacy formats.

The second question is the one that matters. A site that migrated to encrypted credentials three years ago and left legacy acceptance enabled for the stragglers has the security of the weakest format it accepts, which is the one it thought it had retired.

The proportionate response

If the credential only operates a time clock, the cloning question is close to irrelevant and the effort belongs on the register, the leavers and the temporary stock.

If it opens doors, migrate, and do it as an access project with an access budget. In the meantime, turn off legacy acceptance on any reader where every active card is already a modern one, which is frequently most of them, and finish the migration for the remainder. That is a configuration change and a list, and it is a great deal cheaper than the project it is usually bundled into.

The simpler attack nobody mentions

Before worrying about cloning equipment, consider what a determined person would actually do: ask to borrow a card, pick one up from a desk, or use one of the unreturned credentials already circulating.

None of that requires hardware or skill, and all of it is defeated by the same unglamorous work — a reconciled register, prompt deactivation and a numbered temporary stock. A site that has done none of that and is discussing card encryption is reinforcing the strongest part of its perimeter.