← The Signal Report Work with me

Report 137 · Luxury Home Security

What your gate fob actually says

The card in your pocket, the fob on your keyring and the tag on your windshield mostly do one thing at the reader: they offer a number. They do not prove they know a secret. Federal guidance on access control says this plainly about legacy credentials, and it is the whole explanation for why a copy works. The second half of the question, the one nobody asks, is how close an attacker has to stand to take that number in the first place.

An estate gate is usually the most expensive-looking part of a property's security and one of the least examined. The pillars, the automation, the camera on the call box and the intercom all get specified carefully. The credential that actually opens it, the thing a resident or a landscaper or a housekeeper waves at the reader, tends to be whatever the installer had in the van.

That credential is worth ten minutes of your attention, because the design question it answers is not "how strong is this" but "what does it say." Those are different questions, and the second one has a short answer with large consequences.

The credential offers a number, not a secret

The clearest published statement of the problem is not in a vendor datasheet. It is in NIST Special Publication 800-116 Revision 1, the federal guidance on using government identity cards in physical access control systems. In the appendix comparing those cards to the legacy card technology already installed in buildings, NIST writes:

Legacy PACS cards can provide an identifying number, but in most cases, they cannot respond to a cryptographic challenge. Many non-PIV PACS cards can be copied easily.

PACS is a physical access control system. Read that sentence as a description of the fob on your keyring, because for a large share of installed residential and commercial access control it is one. The credential's entire contribution to the transaction is an identifier. The reader's job is to receive it. Nothing in the exchange requires the credential to demonstrate that it holds anything the copy would lack.

That is the difference between an identifier and an authenticator, and it is the whole ballgame. An identifier says who I claim to be. An authenticator proves it. A number does the first and cannot do the second, no matter how well built the gate around it is.

The number is smaller than you would guess

NIST also describes what that identifier typically contains:

Many of the legacy PACS use an ID number based on a 26-bit standard, which is comprised of an 8-bit site code and a 16-bit unique card ID number with 2 bits assigned to parity (the parity bits add confidence that the data transmission has no errors).

Do the arithmetic, which NIST then does for you: 8 bits of site code is 256 possible sites, and 16 bits of card number is 65,536 users per site. Two bits are spent on error checking, not identity. So the credential presented at a gate is, in the common case, a 24-bit statement, and 8 of those bits identify the property rather than the person.

The consequence NIST draws from that is the one worth carrying to a residential context:

When two sites use compatible legacy card technology, the risk of duplicate site identifiers for cards is always present. Without government-wide coordination of identifiers, the same identifier could be used on multiple cards at different sites.

NIST is writing about federal facilities and the absence of government-wide coordination. There is even less coordination in residential access control. If your gate reads a 26-bit credential and a neighboring community's gate reads a 26-bit credential, nothing in the format prevents a card issued over there from carrying the same site code and card number as one issued here. That is not an attack. It is an accounting collision, and it is the sort of thing that surfaces as a mysterious entry log rather than as a break-in.

Why a copy passes

Once you accept that the credential's job is to present a number, cloning stops being surprising and becomes arithmetic. A device that presents the same number is not an imitation of the credential. As far as the reader can tell, it is the credential.

NIST makes the same point about the one deprecated mechanism on federal cards that works this way, the CHUID, a data object the card hands over on request:

The CHUID is a free read object on the PIV Card; and thus, it can be read or cloned easily. Because of the risk of cloning, the CHUID authentication mechanism provides "LITTLE or NO" confidence in the identity of the cardholder.

"LITTLE or NO" is a formal assurance level in the federal standard, not a figure of speech, and that mechanism was deprecated because of it. Compare the mechanism NIST recommends instead, where the card signs a challenge with a private key it never releases:

the PKI-CAK authentication mechanism is highly resistant to cloning, since cloning would require obtaining a copy of the private key.

That is the whole architectural difference, stated by the standards body in one sentence each. One credential says a number. The other performs a calculation that only the genuine card can perform. Everything else, the housing, the frequency, the branding on the reader, is secondary to which of those two things is happening when someone drives up to your gate.

How close does someone have to get

This is where the coverage usually goes wrong in the other direction, toward the idea that a credential can be lifted from across the street. Here the physics is on the owner's side, and it is worth understanding precisely, because it tells you which scenarios to actually worry about.

A passive credential has no battery. The reader powers it, by inductive coupling, and that power requirement sets the range. NIST states the constraint directly:

The range of a skimmer is limited primarily by the requirement for the skimmer to supply power to the PIV Card by inductive coupling.

How far does that get you in practice? The reference NIST cites is a 2006 USENIX Security paper by Ilan Kirschenbaum and Avishai Wool, who built the thing rather than modeling it. Their starting observation was that these systems are designed for contact-range use: "A key feature of RFID-based systems is their very short range: Typical systems are designed to operate at a range of 5-10cm." Their result:

Our skimmer is able to read ISO-14443 tags from a distance of ≈25cm, uses a lightweight 40cm-diameter copper-tube antenna, is powered by a 12V battery—and requires a budget of ≈$100.

Twenty-five centimeters, from a 40-centimeter loop antenna. Note the ratio: to roughly triple the nominal read range they needed an antenna wider than a dinner plate. The authors expected about 35 cm with more effort, on a theoretical curve their earlier modeling had predicted. That is the shape of the problem. Powering a passive tag at distance is a brutally unfavorable trade, and the antenna grows faster than the range does.

There is a second attack with different physics that NIST separates carefully, and the distinction matters:

A sniffer can operate at greater distance than a skimmer (sniffing at a distance of about 10 m has been reported), because a legitimate reader powers the PIV Card at the nominal distance of a few centimeters, while the sniffer's RF receiver is farther away.

A sniffer does not power anything. It listens while your own reader does the work. That is why it reaches roughly ten meters where a skimmer reaches tens of centimeters, and it is why the moment your credential is most exposed is the moment you use it. Nobody has to approach you at all if they can be near the gate when you present the card.

So the honest threat model is not a van at the end of the driveway harvesting fobs from pockets. It is proximity: a bag set down next to a jacket, a valet holding a keyring, a guest's card in a coat at an event, someone in the queue behind you, or a receiver parked near a reader that gets used forty times a day.

What this changes at the gate

Three practical consequences follow, and none of them involve buying a taller fence.

First, the question to ask an integrator is not how secure the system is. It is whether the credential performs cryptographic authentication or presents an identifier. That question has a yes or no answer, the installer either knows it or can find it in ten minutes, and the answer determines whether copying is a locksmith-grade problem or a hobbyist-grade one.

Second, credential handling deserves the discipline you would give a key, because functionally that is what it is. A number that opens a gate is a key that can be duplicated without being taken. The copy leaves the original in your pocket, which is precisely why nothing looks wrong afterward.

Third, and this is the one people resist: revocation is the actual control. If a credential cannot prove it is genuine, then your defense is a current, curated list of which numbers are allowed, and how quickly a number comes off that list when a contractor's engagement ends. I wrote about the failure mode there in Report 035, on what happens when revoking access does not revoke it, and about the broader habit of buying hardware instead of a system in Report 024. The gate credential is the same lesson wearing different plastic.

Why this beat cares

I help design the AI security systems for a veteran-owned (SDVOSB) home-security company run by fellow veterans. I do not own that company and earn nothing from this link. Full policy here.

The range question is the part I keep coming back to, because it is the same question I was paid to answer in a much less forgiving setting. My background before any of this was electronic warfare and counter-IED, where a claimed threat was only a threat once you knew the standoff distance and the effect at that distance. A capability with no range attached to it is a rumor. The link budget decides whether it is real.

Access credentials are the domestic version of that arithmetic, and the answer is unusually clean because the attacker has to supply the power. That constraint is not a policy or a patch. It is coupling physics, it does not expire, and it puts a real floor under how far away someone can be. Which is also why the passive listener at ten meters deserves more of your attention than the imaginary one at a hundred.

What I could not confirm

The measured skimming range above is for 13.56 MHz contactless smart cards, specifically ISO/IEC 14443 tags. A great deal of legacy access control, including a great deal of residential gate hardware, runs at low frequency instead, commonly 125 or 134 kHz in the United States, per NIST's own RFID guidelines. I did not find and did not open a primary measurement of extended-range skimming at those low frequencies, so I am not transferring the 25 cm figure to them. Do not read this report as saying your specific fob can be read at 25 cm, or that it cannot.

I also did not verify how common any particular credential technology is on residential or estate gates. Trade sources assert that legacy proximity credentials dominate that market. I could not confirm that with a primary source I was willing to cite, so the claim is absent from this report. What NIST supports is a statement about legacy credentials as a class, not a market share.

NIST SP 800-116 Rev. 1 is federal guidance about federal facilities and federal identity cards. Its appendix on legacy systems is the part I am relying on, and I am applying it by analogy to residential access control, which is my inference and not NIST's. The Kirschenbaum and Wool result is twenty years old. Component costs have only fallen since, so the direction of that error is knowable, but I have not verified a current replication.

I did not test any product, read any specific reader's firmware, or evaluate any vendor. Nothing here is a recommendation for or against a manufacturer. This is not my research: my published work is in microwave spectroscopy. The assurance-level framework is NIST's and the skimmer measurement is Kirschenbaum and Wool's.

The signal

The credential at your gate is either presenting an identifier or proving possession of a secret, and those two things fail in completely different ways. If it presents an identifier, then copying it is not a defeat of the system, it is a use of the system, and no amount of hardware around the gate changes that.

The reassuring half is that taking the number is a near-field problem for the attacker, governed by the awkward business of powering someone else's card from a distance. The unreassuring half is that listening while your reader does the powering is a far easier problem, and it happens at the exact moment you were not thinking about it.

Ask which one your credential does. It is one question, it has a one-word answer, and almost nobody with a gate has asked it.

Sources

  1. National Institute of Standards and Technology, "Guidelines for the Use of PIV Credentials in Facility Access," NIST Special Publication 800-116 Revision 1, June 2018. DOI 10.6028/NIST.SP.800-116r1. (PRIMARY, full PDF opened and read locally. Source for: the legacy-PACS description in Appendix E, quoted verbatim as "Legacy PACS cards can provide an identifying number, but in most cases, they cannot respond to a cryptographic challenge. Many non-PIV PACS cards can be copied easily."; the 26-bit format, quoted verbatim as "Many of the legacy PACS use an ID number based on a 26-bit standard, which is comprised of an 8-bit site code and a 16-bit unique card ID number with 2 bits assigned to parity (the parity bits add confidence that the data transmission has no errors)."; the 256-site and 65 536-user arithmetic; the duplicate-identifier warning quoted verbatim; the skimming constraint in Section 3.4, quoted verbatim as "The range of a skimmer is limited primarily by the requirement for the skimmer to supply power to the PIV Card by inductive coupling."; the sniffing comparison in Section 3.5 quoted verbatim; the CHUID free-read and "LITTLE or NO" confidence passage in Appendix A; and the PKI-CAK cloning-resistance sentence. The four assurance levels, LITTLE or NO, SOME, HIGH and VERY HIGH, are defined in FIPS 201 and described in this document.)
  2. Ilan Kirschenbaum and Avishai Wool, "How to Build a Low-Cost, Extended-Range RFID Skimmer," Proceedings of the 15th USENIX Security Symposium, Vancouver, 31 July – 4 August 2006, pp. 43–57. (PRIMARY, full paper opened and read locally. This is the reference cited as [SKIMMER] by NIST SP 800-116 Rev. 1. Source for: the nominal-range statement quoted verbatim as "A key feature of RFID-based systems is their very short range: Typical systems are designed to operate at a range of 5-10cm."; and the built result quoted verbatim as "Our skimmer is able to read ISO-14443 tags from a distance of ≈25cm, uses a lightweight 40cm-diameter copper-tube antenna, is powered by a 12V battery—and requires a budget of ≈$100." The paper also states the authors' expectation of reaching ≈35cm with the same skills, tools and budget, and reports a measured 170 mA supply current to the power amplifier matching the earlier Kfir and Wool modeling. All measurements in this paper are for ISO-14443 tags at 13.56 MHz.)
  3. National Institute of Standards and Technology, "Guidelines for Securing Radio Frequency Identification (RFID) Systems," NIST Special Publication 800-98, April 2007. (PRIMARY, PDF opened and read locally. Used only for the frequency-band description in Table 2-1, which identifies low frequency as 30–300 kHz with "125 or 134 kHz (common US RFID usage)" and high frequency as 13.56 MHz, the worldwide ISM band.)
  4. Onur Oncer, "When revoking smart lock access doesn't," The Signal Report 035, and "Why more gear won't protect your estate," The Signal Report 024. (Earlier reports in this beat on credential revocation and on integration as the actual control.)

Scope note: this report describes how a class of access-control credential behaves, using federal guidance and one peer-reviewed measurement. It is not an assessment of any specific product, manufacturer or installation, contains no instructions for copying a credential, and makes no claim about the security of any particular gate. The quoted skimming range applies to ISO/IEC 14443 tags at 13.56 MHz and is not transferable to other credential technologies. Disclosure: the author helps design AI security systems for a veteran-owned home-security company, as stated in the body of this report, and does not own that company.

Onur Oncer
Onur Oncer

U.S. Army combat veteran (Counter-IED / Electronic Warfare), peer-reviewed researcher in microwave spectroscopy, and founder & CEO of Shroombiosis. Consults on laboratory operations, AI, and supplement formulation.

← All reports