Informational

Can HID® Prox Cards Be Cloned? Security and Safe Replacement

By American Key Cards

Yes. Legacy HID Prox credentials have known duplication risks. HID itself discusses unauthorized duplication of legacy credentials in its security guidance on legacy technology. The useful response for a building owner is to manage issued identities carefully and plan any security upgrade around the complete installed system.

American Key Cards is independent and is not affiliated with or endorsed by HID Global. This is security and replacement guidance, not a card-copying service or instructions for bypassing access controls.

“HID” is not a security specification

A manufacturer’s name can appear on several credential technologies. HID’s Seos® + Prox product, for example, combines two technologies in one card so that organizations can migrate existing installations. A single badge may therefore be accepted differently at different doors.

Confirm what each reader actually uses. The card’s printed appearance, the number of bits in the controller record, or the fact that a reader is new does not settle that question. Ask the integrator for a written description of the credential application and reader configuration.

If a card is lost, replace its access record too

Buying another card does not revoke the missing one. Our recommended replacement process is:

  1. Report the loss to the site’s authorized administrator promptly.
  2. Have that administrator disable the old credential under the site’s access policy.
  3. Issue a replacement using an approved, unused identity unless the administrator’s documented procedure requires otherwise.
  4. Assign only the doors and schedules needed by the user.
  5. Check the access record and retain the replacement details for the next administrator.

Do not put full card numbers, facility codes or credential-box labels into public posts while asking for help. Share any information required for a legitimate order through an approved private channel.

What a stronger migration should verify

A move to stronger credentials needs more than a new card order. Work with the integrator to verify which reader technologies remain enabled, how the reader communicates with the controller, how credentials are issued, and how obsolete identities are revoked. Request a test plan for the doors that matter to your organization.

HID recommends disabling legacy acceptance once migration is complete; its guidance explains why leaving it enabled preserves legacy risks. Treat that final configuration check as part of commissioning, with a named owner and a recorded completion date.

Avoid absolute promises that any branded credential or complete door system is impossible to compromise. Credential technology is one part of a system that also includes hardware, configuration, issuance procedures and physical access to equipment. Ask for evidence that the proposed combination meets your requirements.

Before a legitimate reorder

Identify the exact credential technology and format, the installed reader model and the administrator’s approved number allocation. Do not assume a supplier can determine the complete specification from a short printed number or a photograph of the card body.

For an upgrade discussion, the iCLASS® SE™ and Seos comparison explains how to separate credential selection from reader configuration. Secure HID credentials should be ordered through the site’s approved HID issuance channel.