
Our founder and CEO provides a history of access control attacks and explains how Allthenticate can eliminate most of them in one fell swoop. If you want to learn more about physical security bypass, our friends at the Physical Security Village gave a great DEFCON talk.

Internal “Controllers”

Credentials

Cloud Infrastructure

Magnetic Lock (Maglock)

Electric Strike

Exit Button

Motion Detector

Wiegand Protocol

Open Supervised Device Protocol (OSDP)


Man-in-the-Middle (MitM)
Wires between the reader and controller are susceptible to physical implants that can steal and replay employee credentials

Card Cloning
Cards with no or broken encryption schemes can be trivially cloned by walking nearby and employee and wirelessly reading their badge

Physical Bypass
Mechanical means like using smoke trip the motion sensor, a wire to hit the exit button, or a lockpick can be used to bypass the system entirely. We recommend checking out the courses at Red Team Alliance if you’re interested in learning more
Historically, standard encryption like HTTPS could be bypassed through SSL stripping downgrade attacks. Today, even two-factor authentication can be intercepted by a Web Relay MitM or by leveraging a compromised Certificate Authority. Every HTTPS site is one compromised CA and a DNS attack away from completely broken.
VULNERABILITY
Tools to Exploit








WIRE PROTOCOL
VULNERABILITY
Tools to Exploit


TECHNOLOGY
WHY WE LIKE IT

Reader on the inside of the office
Our ALL-IN reader/controller is installed on the secure side of the building as a single unit, leaving no reader or wires exposed to a Man-in-the-Middle (MitM) attack.

Secure by Design
Your private keys are stored in the Secure Element (SE) on the phone — the same technology in DoD-grade smartcards. Bluetooth connections reduce friction while maintaining best-in-class security. Additionally, TrustZone and biometrics are leveraged to prevent relay attacks, software exploits, physical tampering, and device theft.

