Mutual authentication is optional
Xavier Zhang
DEF CON 32 Main Stage · Day 1 · Main Stage
Overview
In the DEF CON 32 talk "Mutual authentication is optional," security researcher Xavier Zhang delves into critical vulnerabilities within HID iClass SE physical access control systems, demonstrating how various iClass credentials, including the supposedly secure iClass SE, can be bypassed or cloned to gain unauthorized entry. The presentation provides a comprehensive technical overview of HID's iClass ecosystem, from legacy systems to the modern Secure Identity Object (SIO) enabled credentials, highlighting their inherent weaknesses and the practical exploits that leverage them.

Key moments
- 0:00 Introduction to HID iClass SE vulnerabilities and agenda
- 1:10 Overview of cloning, downgrading, emulation, and firmware exploits
- 4:50 History of iClass Legacy vulnerabilities and Heart of Darkness attack
- 6:00 Introduction of iClass SE and Secure Identity Object (SIO)
- 6:50 Exploiting building readers to compromise security
- 7:50 iClass SR transitional credential vulnerabilities and downgrading
- 8:15 Emulating secure credentials via reader firmware bugs (Signo/Rev E)
- 10:05 Practical and cheap iClass SE downgrade method using HID reader
Mutual authentication is optional
Speakers: Xavier Zhang
Conference: DEF CON 32
YouTube: https://www.youtube.com/watch?v=zH6qbJuqhOM
Overview
In the DEF CON 32 talk "Mutual authentication is optional," security researcher Xavier Zhang delves into critical vulnerabilities within HID iClass SE physical access control systems, demonstrating how various iClass credentials, including the supposedly secure iClass SE, can be bypassed or cloned to gain unauthorized entry. The presentation provides a comprehensive technical overview of HID's iClass ecosystem, from legacy systems to the modern Secure Identity Object (SIO) enabled credentials, highlighting their inherent weaknesses and the practical exploits that leverage them.
Zhang, an RFID researcher and HID credential enthusiast, outlines four distinct attack vectors: straightforward cloning of legacy cards, a downgrade attack transforming secure credentials into insecure ones, advanced emulation techniques for transitional cards, and a significant exploit targeting reader firmware to bypass iClass SE's enhanced security features. His work underscores a fundamental flaw in how many organizations implement physical security, often relying on legacy configurations or unpatched firmware even when deploying supposedly robust solutions.
The talk is crucial for anyone involved in physical security, access control system design, or cybersecurity, as it exposes the often-overlooked vulnerabilities in systems meant to protect physical infrastructure. By detailing the methods to compromise these widely deployed systems, Zhang provides actionable insights for defenders to fortify their installations against sophisticated attackers who understand the nuances of RFID and access control protocols.
Background
▶ Watch: Introduction to HID iClass SE vulnerabilities and agenda (0:00)
Physical access control systems (PACS) are ubiquitous, regulating entry into buildings and restricted areas through the use of credentials like RFID cards. At their core, most PACS installations rely on a reader, a door controller, and a credential. The Wiegand protocol, developed by John Wiegand in 1975, remains the dominant signaling protocol between the reader and the controller. Despite its age, it's a simple, two-wire system transmitting binary data. Crucially, the door controller, for the most part, is "pretty dumb"; it simply receives the credential data and determines access, often unable to differentiate between credential types or their security posture. The reader's primary role is to read the credential and pass the data along.
HID Global has been a leading provider of these systems, evolving its credential technologies over time. Initially, Prox cards offered basic low-frequency identification. Around 2000, iClass Legacy emerged, introducing 64-bit encryption. However, this encryption was famously broken in 2010 by Milos Mariac in the "Heart of Darkness" paper. This groundbreaking research involved destructively attacking two iClass readers to dump their firmware and derive the master authentication keys, effectively compromising the entire iClass Legacy ecosystem.
Following this compromise, HID introduced iClass SE (Secure Identity Object enabled) credentials around the 2010s, aiming to enhance security. SIOs were designed to provide a more secure, object-oriented approach to identity data, making cloning and unauthorized access significantly more challenging. iClass SR (transitional credentials) were also introduced to facilitate migration, allowing cards to function with both older iClass Legacy readers and newer iClass SE readers by indicating the presence of an SIO. Despite these advancements, the presentation highlights that real-world implementations often fall short, leaving organizations vulnerable to attacks that exploit weaknesses in reader firmware, configuration, or the transitional nature of some credentials.
Key Findings
▶ Watch: History of iClass Legacy vulnerabilities and Heart of Darkness attack (4:50)
Xavier Zhang's presentation unveils several critical findings regarding the security of HID iClass credentials, ultimately demonstrating that "mutual authentication is optional" in many real-world deployments. The core discovery is the ability to bypass the enhanced security of iClass SE readers through a firmware bug, enabling the emulation of high-security SIO-only credentials. Beyond this, the talk details a spectrum of attacks, from the trivial to the sophisticated:
- Trivial Cloning of iClass Legacy: Reaffirming the decade-old compromise, Zhang highlights that most iClass Legacy credentials use a standard authentication key, publicly known since the "Heart of Darkness" paper. Even for custom-keyed systems, keys can be extracted via a Low Class attack, making cloning "extremely trivial" due to leaked cryptography and the irrelevance of the card serial number (CSN) in the PACS payload.
- Downgrade Attack on iClass SE: A significant finding is the ability to take a secure iClass SE credential and extract its payload, then "move" it to an insecure iClass Legacy credential. This effectively turns an SE card into a Legacy card, exploiting the fact that both types often send the "same PACS payload on a different type of media." This bypasses the security of the SE card by forcing the reader to interpret it as a less secure credential.
- Advanced Emulation of iClass SR: For transitional iClass SR credentials, Zhang demonstrates a method to emulate a virtual credential. This involves dumping the publicly accessible parts of the card (CSN, Epurse, application instruction area), emulating this partial card against a reader, capturing a Message Authentication Code (MAC) from the reader's challenge, and then using this MAC to successfully "dump the card" and obtain its full secure contents, including the SIO. This attack specifically targets the reader's interaction with the transitional credential.
- Exploiting Reader Firmware for iClass SE Bypass: The most impactful finding is the discovery of a firmware bug in specific HID iClass SE reader models that allows for the successful emulation of a high-security, SIO-only secure credential without proper authentication. This bug, originally discovered by NVX and ported to the Flipper Zero, affects Signo readers with firmware 10.0.5.6 or older, and critically, Rev E readers are still unpatched at the time of the talk. This vulnerability directly undermines the "secure credential enforcement" that organizations believe they have implemented, enabling unauthorized access even when only secure SE cards are ostensibly required.
These findings collectively demonstrate that the security of HID iClass systems is often compromised not by the theoretical strength of the credential cryptography, but by implementation flaws, backward compatibility requirements, and unpatched reader firmware, making mutual authentication an optional, rather than mandatory, security measure.
Technical Deep Dive
▶ Watch: Exploiting building readers to compromise security (6:50)
The technical core of Zhang's presentation revolves around dissecting the various HID iClass credential types and exploiting their weaknesses, culminating in a bypass of iClass SE's secure credential enforcement.
iClass Legacy Cloning
The foundation of iClass vulnerabilities lies with iClass Legacy cards. These cards utilize a 64-bit encryption key, which, as established by the "Heart of Darkness" paper in 2010, is publicly known. Most installations employing iClass Legacy use this standard authentication key. For systems configured with custom keys, the Low Class attack can be used to extract these elite keys. The critical weakness here is that the Card Serial Number (CSN) is not relevant to the PACS payload transmitted to the door controller. This means that once the authentication key is known, the entire encrypted data block, which contains the access control information, can be trivially read, copied, and written to a new blank iClass Legacy card using tools like the Proxmark 3. The reader, being "dumb," simply passes this valid payload to the controller, which grants access.
Downgrade Attack (iClass SE to Legacy)
This attack vector targets the transition period and the backward compatibility features of HID systems. An iClass SE card, despite its enhanced security, still contains a PACS payload that can be interpreted by older iClass Legacy readers or even newer readers configured for backward compatibility. The attack involves:
- Reading the iClass SE card: Obtain the encrypted PACS payload from the secure credential.
- Writing to an iClass Legacy card: Transfer this payload to a readily available, insecure iClass Legacy credential.
The speaker notes that this can be done remarkably easily. For example, a standard HID reader purchased for approximately $130 on Amazon can be configured to perform this downgrade, effectively turning any standard-keyed iClass SE credential into a clonable iClass Legacy credential. The underlying principle is that the "cards are just an encrypted storage device," and if the data can be extracted and placed on a less secure medium that a reader will accept, the security of the original credential is nullified. The power efficiency, simple cryptography, and ISO 15693 protocol of iClass contribute to enhanced read ranges, further facilitating these card-only attacks.
Emulation Attack (iClass SR)
iClass SR (Secure Identity Object enabled, transitional) cards are designed to bridge the gap between legacy and SE systems. They carry an SIO (Secure Identity Object) but are also designed to communicate with older readers. The attack strategy here is more complex and involves interaction with the building's reader:
- Public Data Extraction: From an iClass SE or SR card, extract publicly accessible parts without authentication. These include the Card Serial Number (CSN), Epurse data, and the Application Instruction Area (AAI). The AAI, specifically byte
006, instructs the reader that an SIO is present. - Partial Card Emulation: Using a device like the Proxmark 3 or a Flipper Zero (with custom firmware), emulate this partial card, including the CSN and the SIO indicator, against the target building's reader.
- Trace Capture and MAC Extraction: The reader, upon receiving this partially emulated SIO-enabled card, will attempt to perform a challenge-response authentication. This interaction generates a trace of the communication. By intercepting this data, the attacker can extract the Message Authentication Code (MAC) that the reader sends back.
- Full SIO Dump: With the extracted MAC, the attacker can then execute a standard dump command on the emulated card. The MAC acts as the necessary authentication component, causing the card to "puke out all of its secure contents that's supposed to be secure," including the full SIO.
Eric Betts (Betsy) recently implemented this NR Mac dumping workflow on the Flipper Zero, making this sophisticated attack accessible with an intuitive interface. This method allows for reading publicly accessible parts, emulating them, using the reader's challenge to decrypt, and making a logical copy offsite.
Reader Firmware Exploit (iClass SE)
This is the most critical vulnerability presented, directly impacting the highest security tier of HID iClass. The attack leverages a bug in reader firmware that allows for the successful emulation of a high-security, SIO-only secure credential without the need for full mutual authentication.
- Discovery: The bug was originally discovered by NVX approximately a year and a half prior to the talk.
- Porting: It was subsequently ported to the Flipper Zero, making it a portable and accessible exploit.
- Targeted Firmware: This exploit specifically works on Signo readers running firmware 10.0.5.6 or older. Crucially, Rev E readers (a common HID reader model) are explicitly stated to be still unpatched against this vulnerability at the time of the presentation.
- Mechanism: The exact technical mechanism of the bug isn't fully detailed in the transcript, but the implication is that certain reader firmware versions fail to properly enforce the mutual authentication step required for SIO-enabled credentials. This allows a device (like a Flipper Zero) to present an emulated SIO that the reader accepts as valid, granting access.
- Reconnaissance: Attackers can use tools like Reader Manager to inspect Signo readers from a distance, identifying their firmware version without physical proximity, thus allowing for targeted attacks against vulnerable installations.
In essence, while HID has iterated on credential security, the talk demonstrates that the weakest link often lies in the deployment and maintenance of the readers themselves, where legacy configurations, transitional modes, and unpatched firmware can render even the most advanced credentials effectively insecure.
Demo / Proof of Concept
▶ Watch: iClass SR transitional credential vulnerabilities and downgrading (7:50)
While the talk primarily focuses on the technical explanation, Xavier Zhang describes several practical demonstrations and proof-of-concept scenarios that underscore the feasibility of these attacks.
One of the most straightforward demonstrations mentioned is the downgrade attack on iClass SE credentials. The speaker describes a scenario where an iClass SE card and an iClass Legacy card are used with a Proxmark 3. The process involves using the Proxmark to read the SE card and then write the extracted payload onto the Legacy card. He states, "The downgrade is done," emphasizing its simplicity. He further elaborates that this doesn't even require advanced tools like the Flipper Zero with an add-on board for the cheapest method. Instead, a readily available HID reader (e.g., purchased on Amazon for about $130) can be configured to perform this downgrade, allowing users to "load up that config and it's ready to downgrade any amount of standard keyed SE credentials." This highlights the accessibility and low cost of performing such an attack.
For the iClass SR emulation and SIO dumping, the process described is also a practical proof-of-concept. Zhang explains that to emulate an iClass SR with the correct Card Serial Number (CSN) and Secure Identity Object (SIO), one first needs to dump the SIO. This is achieved by getting the publicly accessible parts of an iClass SE card (CSN, Epurse, Application Instruction Area), populating these values into a dump file, and preparing them for emulation. The crucial step involves using the building's reader itself to generate a successful challenge. By emulating the partial card against the reader, a trace of the communication is captured, specifically looking for the Message Authentication Code (MAC). Once the MAC is obtained, a "standard dump command" is run, causing the card to "puke out all of its secure contents." He notes that while this was historically a command-line process on the Proxmark 3, Eric Betts (Betsy) recently implemented an "intuitive workflow" for NR Mac dumping on the Flipper Zero, making this advanced attack more user-friendly.
Finally, the talk implicitly demonstrates the iClass SE reader firmware exploit by stating that it allows for "iClass SE emulation" on vulnerable readers. While a live demonstration of this specific exploit isn't fully detailed in the transcript, the mention of Signo readers on firmware 10.0.5.6 or older and Rev E readers being "still not patched at the moment" serves as a strong indication that this is a proven method. The ability to use Reader Manager to inspect reader firmware versions remotely further supports the practical applicability of this vulnerability for targeted attacks.
Defensive Implications
▶ Watch: Practical and cheap iClass SE downgrade method using HID reader (10:05)
The findings presented by Xavier Zhang have significant implications for organizations relying on HID iClass physical access control systems. Defenders must move beyond the assumption that simply deploying "secure" credentials like iClass SE automatically guarantees security. The talk outlines several concrete actions to mitigate the identified vulnerabilities:
- Utilize High-Security Key Sets: The use of standard authentication keys for iClass Legacy and even iClass SE (in downgrade scenarios) is a critical weakness. Organizations should immediately transition to Elite custom keys for all iClass SE installations. This makes cloning and SIO dumping significantly harder, as attackers cannot rely on publicly known keys.
- Update Reader Firmware Regularly: The most impactful defensive measure against the iClass SE bypass is to ensure all readers are running the latest available firmware. Specifically, Signo readers with firmware 10.0.5.6 or older and Rev E readers are vulnerable to the authentication bypass bug. Regular firmware updates are essential to patch known exploits and ensure the reader properly enforces mutual authentication. Organizations should have a robust patch management program for their physical security infrastructure, similar to IT systems.
- Disable Legacy Technologies: To prevent downgrade attacks and the exploitation of transitional credentials, organizations should disable all legacy technologies on their readers and controllers wherever possible. If only iClass SE is required, readers should be configured to strictly accept only SIO-only secure credentials and reject any attempts to communicate using older iClass Legacy or even iClass SR protocols. This eliminates the attack surface that relies on backward compatibility.
- Issue Truly Secure Credentials: While iClass SE was an improvement, the talk demonstrates its vulnerabilities. For the highest security, organizations should consider migrating to credentials that offer stronger, more modern cryptographic protections, such as CLS (Contactless Smart Card), Desfire, or mobile credentials. These often incorporate more robust encryption, secure element technology, and dynamic authentication mechanisms that are harder to bypass.
- Regular Audits and Penetration Testing: Organizations should conduct regular security audits and penetration tests on their physical access control systems. This includes attempting the types of attacks described in this talk (cloning, downgrading, emulation, and firmware exploitation) to identify and remediate vulnerabilities before malicious actors can exploit them. Tools like Reader Manager can also be used by defenders to proactively inspect their own reader fleet for vulnerable firmware versions.
By implementing these defensive strategies, organizations can significantly enhance the security posture of their physical access control systems and ensure that mutual authentication is truly enforced, rather than being an optional security feature.
Key Takeaways
- iClass SE is not inherently secure: Despite its design, iClass SE's security can be undermined by reader firmware bugs, backward compatibility, and the use of standard keys.
- Reader firmware is a critical attack vector: Unpatched Signo (10.0.5.6 or older) and Rev E readers are vulnerable to an authentication bypass bug, allowing iClass SE emulation.
- Downgrade attacks are trivial and effective: Secure iClass SE credentials can be easily downgraded to insecure iClass Legacy cards, often with off-the-shelf HID readers, by transferring the PACS payload.
- Transitional credentials (iClass SR) can be fully dumped: By emulating public card data and capturing a reader's MAC, the full SIO of iClass SR cards can be extracted.
- Physical security requires constant vigilance: Organizations must use elite custom keys, update reader firmware, disable legacy protocols, and consider more advanced credentials like Desfire or mobile solutions.
- Tools like Proxmark 3 and Flipper Zero are powerful for both offense and defense: These devices facilitate the discussed attacks but can also be used by defenders for auditing and testing.
About the Speaker(s)
The primary speaker for this presentation is Xavier Zhang. He introduces himself as an individual passionate about physical security and an active RFID researcher. His specific interests lie in HID credential enthusiasm and NFC technologies. His expertise is evident in his detailed understanding of the various HID iClass credential types, their cryptographic underpinnings, and the practical methods for exploiting their weaknesses.
Xavier also made sure to acknowledge several key contributors from the RFID hacking community who played a significant role in the discoveries and tools mentioned:
- Eric Betts (Betsy): Recognized for his comprehensive documentation on iClass credentials and data layouts, as well as implementing the intuitive NR Mac dumping workflow on the Flipper Zero.
- NVX: Credited with originally discovering the critical authentication bypass bug that enables iClass SE emulation on vulnerable reader firmware, and for picopass emulation code for the Flipper Zero.
- Kate (Mistial Dev): Appreciated as a "genius on all things HID."
- Iceman: Thanked for encouraging Xavier to deliver this talk on iClass SE.
Reviews
Dr. Zero (Offensive Security Researcher) — MUST SEE
Xavier Zhang's "Mutual authentication is optional" is a brutal, necessary deep dive into the systemic failures of HID iClass SE physical access control systems. He not only re-validates decade-old compromises but introduces genuinely novel attack vectors, including a critical reader firmware bug that bypasses iClass SE's enhanced security and a clever SIO dumping technique for transitional cards. This isn't just theory; it's a live-fire demonstration of how easily physical infrastructure can be compromised, offering actionable intelligence for anyone serious about security.
Heather Calloway (CISO) — MUST SEE
This DEF CON talk by Xavier Zhang is a critical exposé of the practical vulnerabilities in HID iClass SE physical access control systems. It convincingly demonstrates that the enhanced security features of these credentials are frequently undermined by widespread issues such as unpatched reader firmware, reliance on legacy configurations, and the use of standard authentication keys. The presentation provides actionable insights into how attackers can bypass or clone supposedly secure access cards, forcing a necessary re-evaluation of physical security posture and the accountability for its integrity within organizations.