Home › Card, Fob & Mobile Credentials
Your access cards may be cloneable in seconds
Cards, fobs and mobile credentials for buildings across Miami-Dade. We audit what your readers actually accept, then migrate you to credentials that authenticate cryptographically instead of just announcing a number.
Book a credential audit
Tell us roughly how many doors and readers. A dispatcher calls you back.
The uncomfortable part
Most buildings are still running credentials with no cryptography in them at all.
If your cards are thick white or grey, print a number on the back, and the reader beeps the moment they get close, you are probably on 125 kHz proximity. That technology carries no cryptographic security. A credential like that can be read from a short distance and written to a blank card in under ten seconds, with hardware that costs less than dinner. Your system cannot tell the copy from the original, because there is nothing to tell apart: the card announces a number and the reader believes it.
The generation that replaced it is not automatically safe either. MIFARE Classic moved to 13.56 MHz and added a proprietary cipher called Crypto-1, which has since been broken. Systems that authenticate only on a card serial number are in the same position regardless of what frequency they run at.
What actually resists copying is a credential with a secure element and a challenge-response exchange: MIFARE DESFire EV2 or EV3 with AES, HID Seos, or a mobile credential on a phone. The reader issues a random challenge, the credential answers with a key it never transmits, and a recording of yesterday's exchange is worth nothing today.
Where you probably are
Credential technologies, honestly compared
Find your cards in this table. Most Miami-Dade buildings we audit are in the top two rows.
| Technology | Security | What it means for you |
|---|---|---|
| 125 kHz prox (HID Prox, EM4100) | None | No cryptography. Readable and copyable in seconds. Fine for convenience, not for security. |
| MIFARE Classic (13.56 MHz) | Broken | The Crypto-1 cipher has been compromised. Better than prox, not a security control. |
| MIFARE DESFire EV2 / EV3 | Strong | AES mutual authentication and a secure element. The sensible default for new systems. |
| HID Seos | Strong | AES with a certified secure element and data binding. Common in enterprise estates. |
| Mobile credentials | Strong | Phone-based, using the handset secure element. Issued and revoked remotely, and people do not lend their phone the way they lend a fob. |
| Reader to controller | Wiegand vs OSDP | Wiegand sends the number in the clear. OSDP Secure Channel encrypts and supervises the link. |
What we do
Credential work, start to finish
Audit what you actually have
Readers get replaced piecemeal over a decade, so most estates are a mix. We identify the technology in use per door before anyone talks about buying anything.
Supply and encode credentials
Cards, fobs, wristbands and tags, encoded to your facility code and format, delivered ready to issue rather than as a box of blanks.
Mobile credential rollout
Issue to a phone, revoke from a browser. Particularly useful for contractors and short-term staff, where the fob never comes back.
Reader replacement and OSDP
Multi-technology readers let you run old and new credentials side by side during a migration, then drop the legacy format when the last card is out.
Phased migration planning
Nobody swaps 400 credentials in a weekend. We sequence it door by door so the building keeps working throughout.
Integration with the openings
Credentials are only useful if the gate, door or barrier responds. We wire the release into gate operators, door operators and intercom entry as one system.
What we find
Common findings on a credential audit
Cards issued to people who left years ago
The credential database is a staff list nobody maintains. Every unrevoked card is a working key somewhere.
One shared fob for the whole building
Convenient until it is copied at a hardware kiosk, and there is no audit trail to tell you who went where.
Mixed formats across doors
Different readers accepting different technologies, so the estate is only as strong as its weakest door.
Strong cards, Wiegand wiring
An expensive credential upgrade undermined by the unencrypted link behind the reader.
Readers mounted where they can be pulled
On an unsupervised link, removing a reader exposes wiring that can open the door directly.
Nobody knows the facility code
Which becomes an urgent problem the day you need more cards and the original installer is gone.
Where we work
Access credentials across Miami-Dade
Residential buildings, offices, warehouses and gated communities, dispatched from two South Florida locations. Get in touch to arrange an audit.
- Brickell
- Downtown Miami
- Coral Gables
- Doral
- Aventura
- Hialeah
- Kendall
- Miami Beach
- Sunny Isles Beach
- North Miami Beach
- Homestead
- Countywide Miami-Dade
Questions
Before you order more cards
How do I tell what technology our cards are?
Look at the card itself. Thick, plain white or grey, with a printed number and possibly the words HID Prox or 125 kHz, usually means legacy proximity with no cryptography. Thinner cards branded MIFARE, DESFire or Seos are 13.56 MHz smart cards, though that alone does not tell you whether the system authenticates properly or just reads the serial number. That distinction needs a look at the reader and panel, which is what the audit is for.
Do we have to replace everything at once?
No, and you should not try. Multi-technology readers accept legacy and modern credentials at the same time, so you can replace readers on a schedule, issue new credentials as people cycle through, and switch the legacy format off once the last old card is out of circulation. A migration usually runs over months, not over a weekend.
Are mobile credentials actually more secure than a card?
In practice, usually yes, for two reasons that have nothing to do with cryptography. People notice a missing phone within minutes and a missing fob within weeks. And nobody hands their phone to a colleague to borrow, which is how a large share of credential sharing happens. The underlying security is strong too, but the behavioural difference is what shows up in the audit trail.
What is OSDP, and do we need it?
It is the modern replacement for Wiegand, the wiring protocol between reader and controller. Wiegand sends the credential number in the clear, and inexpensive inline devices can capture and replay it. OSDP with Secure Channel encrypts that link and supervises it, so the panel knows if a reader is disconnected. If you are already replacing readers, doing it in OSDP costs very little extra. Retrofitting it later means touching every reader again.
Can you work with our existing access control software?
Usually. Most credential and reader work is independent of the management platform, and the panel is what constrains the options. We identify the panel and the formats it supports during the audit, and if a platform is genuinely at the end of its life we will say so rather than sell you credentials for a system about to be replaced.
Related services
Related access services
Find out what your readers accept
One site visit tells you which credential technology is in use, whether it can be copied, and what a migration would actually involve. No obligation to change anything.