Hi-Intensity Deconstruction: Chronicles of a Cryptographic Heist
Javadi, Levy, Draffe
DEF CON 32 Main Stage · Day 1 · Main Stage
Overview
This talk, "Hi-Intensity Deconstruction: Chronicles of a Cryptographic Heist," delves into the critical security vulnerabilities discovered within widely deployed physical access control systems, specifically targeting HID cards. Presented by a team of dedicated researchers—Babak Javadi, Aaron Levy, and Nick Draffen, with contributions from Kate—the presentation unveils their extensive, multi-month project culminating in the successful cloning of cards previously deemed "theoretically uncloneable." The researchers emphasize the profound implications of their findings for organizational security, given the pervasive reliance on these systems for controlling physical access to sensitive areas.

Key moments
- 0:00 Welcome and speaker introductions
- 2:40 Talk agenda: Access control, obsession, and the heist
- 3:30 Demonstrating cloning of "theoretically uncloneable" HID cards
- 4:00 The all-consuming "obsession" behind the research
- 5:00 Personal story: HID reader used in marriage proposal
Hi-Intensity Deconstruction: Chronicles of a Cryptographic Heist
Speakers: Javadi, Levy, Draffe
Conference: DEF CON 32
YouTube: https://www.youtube.com/watch?v=EvbNQnZlPJg
Overview
This talk, "Hi-Intensity Deconstruction: Chronicles of a Cryptographic Heist," delves into the critical security vulnerabilities discovered within widely deployed physical access control systems, specifically targeting HID cards. Presented by a team of dedicated researchers—Babak Javadi, Aaron Levy, and Nick Draffen, with contributions from Kate—the presentation unveils their extensive, multi-month project culminating in the successful cloning of cards previously deemed "theoretically uncloneable." The researchers emphasize the profound implications of their findings for organizational security, given the pervasive reliance on these systems for controlling physical access to sensitive areas.
The core of the talk revolves around challenging the perceived cryptographic security of HID cards. By demonstrating the ability to replicate a unique card ID, the team exposes a significant flaw that could allow unauthorized individuals to bypass physical security measures. This research is not merely an academic exercise; it represents a tangible threat to corporate campuses, government facilities, and any entity that uses HID-based access control. The speakers share their journey, highlighting the intense dedication and "obsession" required to deconstruct these complex systems, ultimately providing a detailed account of how they achieved what was thought to be impossible.
The importance of this research cannot be overstated. In an era where physical security is often a critical layer of defense, the compromise of widely trusted access cards necessitates a re-evaluation of current security postures. This talk serves as a stark reminder that no system is truly impenetrable and that continuous scrutiny and research are vital to maintaining robust security. For security professionals, facility managers, and anyone responsible for protecting physical assets, understanding these vulnerabilities is paramount to implementing effective countermeasures.
Background
▶ Watch: Welcome and speaker introductions (0:00)
Physical access control systems are fundamental to the security infrastructure of countless organizations worldwide. These systems are designed to restrict entry to authorized personnel, preventing unauthorized access to buildings, sensitive rooms, data centers, and other critical areas. At the heart of many such systems are proximity cards, often issued by companies like HID Global. These cards operate on various radio-frequency identification (RFID) technologies, with different generations offering varying levels of supposed security.
Historically, older proximity card technologies, such as Wiegand and Prox, were known to be susceptible to cloning due to their simplistic, unencrypted data transmission. However, newer generations, particularly those leveraging advanced cryptography, were marketed as significantly more secure, often with claims of being "uncloneable." These modern HID cards typically employ encryption and more complex data structures to authenticate users, aiming to prevent the unauthorized duplication of card credentials. Organizations invested heavily in these systems, trusting their cryptographic protections to safeguard their premises against physical intrusion. The assumption was that even if a card's unique identifier could be read, the underlying cryptographic keys or data structure would prevent a malicious actor from creating a functional duplicate.
The problem, therefore, lies in the widespread reliance on these "secure" systems. Many organizations operate under the premise that their HID cards provide a robust, cryptographically sound barrier against unauthorized access. This trust, coupled with the sheer ubiquity of HID technology in corporate, governmental, and critical infrastructure environments, creates a high-stakes scenario. If these "uncloneable" cards can indeed be cloned, the integrity of physical security across a vast array of institutions is fundamentally undermined, opening doors to espionage, theft, sabotage, and other malicious activities that could bypass all digital defenses once physical access is gained. The researchers' work directly challenges this foundational trust, exposing a critical vulnerability that has long been overlooked or underestimated.
Key Findings
▶ Watch: Talk agenda: Access control, obsession, and the heist (2:40)
The central and most impactful finding of this research is the successful cloning of HID cards that were previously considered "theoretically uncloneable." The research team demonstrated that despite the advanced cryptographic features and security assurances provided by the manufacturer, they were able to replicate the unique identifier of an authentic HID card onto a blank card. This means that an attacker, having obtained the necessary data from a legitimate card, could create a functional duplicate that would be recognized as valid by an existing HID access control reader.
This finding directly contradicts the long-held industry belief and marketing claims surrounding the security of these modern HID card systems. The researchers' ability to produce two physically distinct cards that yield the exact same ID card number when scanned by a reader provides undeniable evidence of a critical vulnerability. This effectively bypasses a primary security mechanism designed to ensure that each credential is unique and cannot be duplicated without authorization. The implication is a complete breakdown in the integrity of the access control system, rendering it susceptible to unauthorized entry by anyone possessing a cloned card. The work represents a significant contribution to security research by exposing a real-world exploit in a widely deployed and trusted technology.
Technical Deep Dive
▶ Watch: Demonstrating cloning of "theoretically uncloneable" HID cards (3:30)
While the provided transcript snippet focuses primarily on the outcome and the motivation behind the research, it strongly implies a deep dive into the technical specifics of how the "uncloneable" HID cards were compromised. The researchers stated their intention to "show you how we did it" during the full talk, indicating a detailed exposition of the methods and tools employed. Based on the context of hardware hacking and cryptographic deconstruction, the technical deep dive would likely have covered several intricate aspects.
The target of this research is modern HID cards, which utilize various proprietary technologies and cryptographic protocols to secure communications between the card and the reader. Unlike older, simpler proximity cards that transmit unencrypted card numbers, these advanced cards are designed to employ encryption, mutual authentication, and rolling codes or other complex algorithms to prevent eavesdropping and cloning. The researchers' success suggests a fundamental flaw in either the implementation of these cryptographic protocols, the underlying hardware, or the key management processes.
A typical technical deconstruction of such a system would involve several stages. Firstly, signal analysis would be crucial. This involves capturing and analyzing the radio frequency (RF) signals exchanged between a legitimate HID card and its reader. Tools like software-defined radios (SDRs), spectrum analyzers, and specialized RFID sniffers would be employed to record the raw data transmissions. The challenge here lies in deciphering the proprietary modulation schemes and data encoding used by HID.
Once raw signals are captured, the next step would be protocol reverse engineering. This often involves analyzing the captured data for patterns, identifying headers, payloads, and checksums, and attempting to reconstruct the communication protocol. If encryption is involved, this phase becomes significantly more complex, requiring efforts to either deduce the cryptographic algorithms, identify weak key derivation functions, or uncover vulnerabilities in the cryptographic implementation itself. Techniques such as side-channel analysis (e.g., power analysis, electromagnetic analysis) or even fault injection attacks might be considered to extract cryptographic keys or bypass security mechanisms embedded within the card's microcontrollers.
Furthermore, the researchers' mention of Babak Javadi as a "hardware hacker" suggests that hardware-level analysis played a significant role. This could involve decapping the integrated circuits (ICs) within the HID cards to physically examine their internal structure, identify memory regions, or even extract firmware. Techniques like microprobing or using electron microscopes could be employed to understand the chip's design and potentially locate hidden test points or vulnerable interfaces. The process might also involve analyzing the firmware of the cards or readers for vulnerabilities, default keys, or poorly implemented cryptographic functions. The "obsession" described by the speakers, spanning months, points to the immense effort required for such a multi-faceted attack, combining RF, cryptographic, and hardware reverse engineering expertise. Ultimately, the successful cloning indicates they likely uncovered how to either extract the necessary unique identifiers and associated cryptographic material or to bypass the authentication process entirely to create a valid, recognized duplicate.
Demo / Proof of Concept
▶ Watch: The all-consuming "obsession" behind the research (4:00)
The talk featured a clear and compelling proof of concept that directly demonstrated the successful cloning of HID cards. As described by Aaron Levy, the demonstration involved two physical HID cards. One was presumably the original, legitimate card, and the other was a blank card that the researchers had successfully cloned.
The core of the demo was to show that when these two distinct physical cards were scanned by an HID reader, they both yielded the same ID card number. This visual and undeniable evidence served as the culmination of their extensive research. The video segment mentioned in the transcript explicitly states: "if you look at this video, you can see that there are two cards. These are HID cards, theoretically uncloneable. And yet, if you look, they have the same ID card number when scanned, right? Uh, so we have cloned the uncloneable."
This demonstration is crucial because it moves beyond theoretical vulnerabilities to concrete, reproducible proof. It validates the researchers' claims and highlights the practical threat. The ability to present two separate cards, both registering identically to an access control system, is a powerful and easily understandable illustration of the security compromise. This kind of direct evidence is vital for convincing stakeholders of the severity of the vulnerability and the immediate need for action. The simplicity of the demonstration belies the complex technical work required to achieve it, effectively communicating the outcome of their "cryptographic heist."
Defensive Implications
▶ Watch: Personal story: HID reader used in marriage proposal (5:00)
The successful cloning of "uncloneable" HID cards carries severe defensive implications for any organization relying on these systems for physical access control. Defenders must immediately reassess their security posture and understand that the foundational trust placed in these cards may be compromised.
Firstly, organizations should conduct an urgent audit of their existing access control infrastructure. This includes identifying the specific models and generations of HID cards and readers deployed. It is critical to determine if their systems are susceptible to the vulnerabilities demonstrated. Simply assuming that newer, cryptographically enhanced cards are secure is no longer a viable strategy.
Secondly, multi-factor authentication (MFA) for physical access should be rapidly implemented wherever possible. Relying solely on a single card credential is now demonstrably risky. Combining card access with a PIN, biometric verification (fingerprint, facial recognition), or even a mobile authentication app can significantly enhance security. Even if a card is cloned, the attacker would still need the second factor to gain entry.
Thirdly, organizations should explore upgrading to more robust, next-generation access control technologies that incorporate enhanced cryptographic protections and mechanisms designed to detect and prevent cloning. This might involve systems that use dynamically changing credentials, secure element technology, or more advanced challenge-response protocols that are less susceptible to replay or cloning attacks. If such upgrades are not immediately feasible, increasing the frequency of card reissuance and implementing stricter physical security measures around card issuance and handling can mitigate some risks.
Furthermore, physical security teams must become aware of the potential for sophisticated social engineering or physical compromise to obtain card data. This includes vigilance against tailgating, card skimming devices, or insider threats. Employee training on security awareness, particularly regarding protecting their access cards, is more important than ever. Finally, engaging with security researchers and staying informed about new vulnerabilities is crucial. The talk itself serves as an example of vital intelligence that defenders must integrate into their threat models and defensive strategies. The era of "uncloneable" access cards is over, and defensive strategies must evolve accordingly to protect critical assets.
Key Takeaways
- "Uncloneable" HID cards have been successfully cloned: The research definitively proves that modern HID cards, despite claims of advanced cryptographic security, can be duplicated, allowing unauthorized access.
- Widespread physical security is at risk: Given the ubiquity of HID access control systems, this vulnerability has significant implications for corporate, government, and critical infrastructure security globally.
- Trust in single-factor card authentication is broken: Organizations can no longer rely solely on HID cards for secure physical access control and must consider implementing additional layers of security.
- Multi-factor authentication (MFA) is critical for physical access: Implementing MFA, combining cards with PINs, biometrics, or other factors, is now an essential defensive strategy to mitigate cloning risks.
- Continuous security research is vital: This project underscores the importance of dedicated, long-term research in exposing vulnerabilities in widely trusted security technologies.
- Organizations must audit and update their access control systems: A proactive approach to evaluating existing systems and considering upgrades to more resilient technologies is immediately necessary.
About the Speaker(s)
The talk featured a collaborative team of highly skilled security researchers, each bringing unique expertise to the project.
Aaron Levy was introduced by Babak Javadi as "the tip of the spear" for this extensive research, highlighting his pivotal role and exceptional talent. Levy is recognized as one of the most talented and kindest researchers Javadi has ever worked with, indicating a blend of technical prowess and collaborative spirit.
Nick Draffen was introduced by Aaron Levy as one of the most talented security engineers and security researchers he has collaborated with. Levy emphasized Draffen's ability to accomplish a vast amount of work across numerous projects, showcasing his incredible depth and breadth of technical skill.
Babak Javadi was introduced by Nick Draffen, who expressed his pleasure in calling Javadi a friend and colleague. Draffen praised Javadi as an amazing and kind person, and specifically highlighted him as "one of the best hardware hackers I know." This indicates Javadi's deep expertise in the physical and electronic aspects of security, a crucial skill for deconstructing complex systems like HID cards. Draffen also humorously noted Javadi's tendency to update firmware at the most inconvenient times, further cementing his image as a dedicated hardware enthusiast.
The team also acknowledged a fourth researcher, Kate, who was unable to join them on stage. She was described as one of the "finest, most talented hackers" the team had the pleasure of working with, and a valued friend and integral part of the project's journey.
Reviews
Dr. Zero (Offensive Security Researcher) — MUST SEE
This talk presents a crucial piece of research demonstrating the successful cloning of supposedly "uncloneable" HID access control cards. The team, through a multi-month, high-intensity deconstruction effort, exposed critical vulnerabilities in widely deployed physical security systems. Their compelling proof-of-concept, showing two distinct cards yielding the same ID, directly challenges vendor claims and forces a re-evaluation of physical security postures globally, making it an essential watch for any defender.
Heather Calloway (CISO) — MUST SEE
This presentation delivers a stark, evidence-backed finding that fundamentally challenges widely held assumptions about physical access control. By demonstrating the successful cloning of supposedly "uncloneable" HID cards, the researchers expose a critical vulnerability with immediate and profound implications for institutional security, accountability, and risk ownership. This is not merely an academic exercise; it is a direct call to action for every CISO, physical security leader, and board member concerned with real-world business exposure and resilience.