The case against prox cards is straightforward: the 125 kHz proximity card protocol is unauthenticated, one-directional, and trivially cloneable with hardware that costs less than a lunch. A bad actor with a long-range reader concealed in a backpack can capture a valid prox credential from a few feet away without the cardholder noticing. That credential can be replayed indefinitely until explicitly revoked. The attack has been documented for decades, the tools are commercially available, and the protocol has no mechanism to prevent replay.
Mobile credentials — BLE or NFC-based credentials delivered to a smartphone via a mobile access management platform — solve the cloning problem. The phone participates in a cryptographic handshake with the reader; the credential is bound to the specific device and user; the session is unique each time. For buildings where the Wiegand reader-to-controller protocol is still in use, migrating to OSDP readers is a prerequisite for mobile credential deployments that actually gain security on the controller side. A BLE credential is more secure at the reader, but if the reader outputs a static Wiegand number to the controller, the controller still has no authentication.
The BLE attack surface — relay attacks and their actual risk
BLE mobile credentials have a known attack class: relay attacks. A relay attack uses two devices — one near the legitimate credential holder and one at the reader — to transparently forward the BLE handshake over a longer distance than the credential is intended to work. The authorized user might be in an elevator lobby; the attacker’s relay device reads the BLE signal and forwards it to an accomplice at the door, who triggers the unlock.
The practical risk of relay attacks in commercial buildings is lower than lab demonstrations suggest. Most enterprise mobile credential platforms limit BLE range to 1–5 meters intentionally, implement anti-replay protections in the handshake, and require device proximity verification (screen-on, user authenticated to the phone). HID Mobile Access and Allegion Engage both add application-layer checks that make relay exploitation harder than raw BLE scenarios. That said, the risk is not zero, and it is higher in environments where legitimate credential use happens at predictable proximity — elevator banks, parking entrances, and lobby turnstiles where crowds provide cover for relay hardware.
The prox card attack surface — cloning and what it costs
125 kHz prox card cloning requires no specialized skill. The Proxmark3, the Flipper Zero, and several commercial-grade long-range readers all clone standard 26-bit Wiegand prox cards reliably. The cloned credential is functionally identical to the original. Most access control systems cannot distinguish a cloned card from the original because Wiegand provides no challenge-response authentication — the reader just passes the card number to the controller.
High-frequency smart cards — iCLASS, MIFARE DESFire, Seos — are meaningfully harder to clone. They use mutual authentication between the card and the reader and bind credentials to a specific card serial number. A building on iCLASS Elite or Seos cards is not in the same threat category as a building on 125 kHz prox.
Revocation speed — where mobile credentials win clearly
The operational advantage of mobile credentials that gets less attention than the cloning comparison: revocation. Revoking a physical card requires knowing a card was lost, reporting it, and disabling it in the system. From loss to revocation, the window is often measured in hours. During that window, the lost card is a valid credential for anyone who finds it.
Mobile credentials can be revoked in real time from the access management platform, take effect within seconds at the next reader transaction, and can also be wiped remotely from the device via MDM. The total revocation window for a lost mobile credential in a well-managed deployment is minutes, not hours. For buildings with high-value access zones — server rooms, pharmaceutical storage, research facilities — that difference is material. The cloud vs. on-prem platform decision is what determines whether revocation propagates in seconds or requires a local sync cycle; the cloud vs. on-prem access control post covers that tradeoff.
Deployment friction — the honest accounting
Mobile credential deployments have real friction that vendor sales cycles understate:
- Readers must be BLE/NFC-capable. Existing 125 kHz readers do not support mobile credentials. A mobile credential deployment requires replacing readers — the bulk of installation cost. Typical commercial reader pricing is $200–$500 per door before labor; in a building with 100 doors, this is a significant capital line item.
- OSDP controllers required for full security posture. BLE readers that output Wiegand to legacy controllers are only partially secure. The full security benefit requires OSDP readers communicating to OSDP-capable controllers. Legacy controllers may require replacement or module upgrades.
- User enrollment and device management. Mobile credential deployment requires an MDM or mobile credential management platform, user enrollment, and ongoing management of device transitions. Organizations without structured IT device management have higher operational overhead with mobile credentials than with physical cards.
- Visitor management gap. Physical visitor badges remain simpler for short-duration visitors. Mobile credential delivery to a visitor’s phone requires app installation, credential delivery, and a compatible device. In high-visitor-volume environments, this leads to hybrid deployments — mobile credentials for employees, physical badges for visitors.
Which deployment profile fits which building
| Building profile | Recommended credential approach | Reason |
|---|---|---|
| Corporate office, 50–500 employees, structured IT | Mobile credentials with OSDP readers | Revocation speed and no lost-card risk outweigh reader replacement cost |
| Multitenant commercial, high visitor volume | Hybrid: smart card (Seos) for employees, physical for visitors | Visitor friction limits full mobile deployment; smart card solves cloning risk |
| Industrial / manufacturing, varied workforce | Smart card (iCLASS Elite or Seos) | Device management overhead; outdoor reader durability considerations |
| Small commercial (< 20 doors, budget-constrained) | iCLASS SE readers minimum; avoid 125 kHz prox | Reader replacement at small scale is affordable; prox risk is not justified by cost savings |
Upgrading access control in Atlanta or the Southeast?
We design and install access control systems for commercial buildings in Atlanta and the Southeast — from reader replacement to full platform migrations to OSDP and mobile credentials.