A proximity card, or prox card, is a contactless access badge that works at 125 kHz (low frequency). When held near a compatible card reader, it powers up from the reader’s radio field and sends back a fixed ID number, which the access control system checks against its list of who may enter. Prox cards have been the default office badge for decades and are still widely installed, but because the number is typically unencrypted and unchanging, they are widely reported to be easy to copy.
At a glance
- Prox cards work at 125 kHz and typically send the same number each time they are read.
- They are cheap, durable and supported by a very large installed base of readers.
- Inexpensive tools are widely reported to be able to read and copy many prox cards from a short distance.
- Migration usually means multi-technology readers plus a phased move to smart cards or mobile credentials.
- Key fobs and stickers can use the same technology, so the risk is not limited to badges.
What problem it solves
Prox cards solved the problems of keys and magnetic stripe cards: no physical key to cut, no stripe to wear out, and a quick tap (or near-tap) at the door. They let organizations issue, disable and audit access per person, which is why they spread so widely.
The problem buyers face today is the reverse: the same simplicity that made prox cards cheap makes them weak. Because a typical prox card answers a compatible reader with the same number each time, someone who briefly gets close to a badge, for example in a lobby, elevator or café, may be able to capture it and make a working copy. That makes prox a common finding in physical penetration tests and a reason auditors ask about badge technology. It is the physical cousin of social engineering: the attacker doesn’t break the door, they become an authorized badge.
How it works
The card. Inside is an antenna coil and a small chip with no battery. The reader’s field powers the chip, which transmits its stored data. That data typically includes a card number and a facility code, a site or customer number meant to reduce collisions between cards from different installations.
Card formats. The bits a prox card sends are arranged in a format that defines where the facility code and card number sit. Some formats are open and widely used; others are proprietary to a manufacturer or reserved for one customer. Proprietary or controlled formats can make it harder to order duplicate blank cards through normal channels, but they do not encrypt the data, so they do not by themselves stop a determined copier.
The read. The reader passes the number to the door controller, which looks it up and unlocks the door if that card is allowed at that time. Read range at a standard door reader is short, usually a few inches or less, but readers with longer range exist, which is part of the cloning concern.
Migration. Because so many readers and cards are in place, few organizations switch overnight. A common path is to install multi-technology readers that read prox and newer credentials, issue smart cards or mobile credentials in phases, sometimes on dual-technology cards that carry both, and then disable prox acceptance at the readers once migration is complete. Leaving prox enabled indefinitely keeps the weakness in place.
When it matters for buyers
- When a penetration test or audit flags badges. Prox cloning is a common finding.
- When replacing readers or controllers. It is the natural time to choose a stronger credential.
- When moving to cloud access control. Some access control as a service (ACaaS) platforms support legacy prox for transition; check how long.
- When protecting sensitive rooms. Server rooms, pharmacies and labs may need a stronger credential or a second factor such as a PIN even before a full migration.
- When reordering cards. Ask whether you should keep buying a format you plan to retire.
Questions to ask vendors
- What card technology and format do we use today, and who controls the format?
- Can your readers read our existing prox cards and the replacement credential at the same time?
- What is the recommended replacement, and why is it more resistant to copying?
- How do we turn off prox acceptance once migration is done, site by site?
- What does a phased migration cost in readers, cards and labor?
- Can sensitive doors require a PIN or second factor during the transition?
How it differs from a smart card
A proximity card works at 125 kHz and typically sends a fixed, unencrypted number. A smart card works at 13.56 MHz and has a chip that can store data and perform cryptographic authentication with the reader, so a well-configured modern smart card is much harder to copy. Some older smart card formats also have publicly documented weaknesses, so “smart card” alone is not the goal; a current format with properly managed keys is. They often look identical, so check the technology, not the plastic. For help planning a migration, see our door access controls overview.
