Why higher education’s 125 kHz prox card problem is not going away. For years, organizations viewed physical security and cybersecurity as two separate disciplines. One team managed doors, cameras, and alarms. Another protected networks, endpoints, and cloud applications. That separation no longer exists.
Every fall, as a new class arrives on campus an old vulnerability comes with it. A student discovers how easily a legacy proximity card can be copied, often out of curiosity rather than malicious intent, and word spreads. For campus security leaders, it is another reminder that credential migration cannot remain a project for ‘next year.’
Across higher education, students, faculty and staff use campus credentials thousands of times each day to enter residence halls, laboratories, libraries and administrative buildings. The experience is fast and familiar. But on campuses that still rely on legacy 125 kHz proximity technology, that convenience may rest on a credential that provides a significant amount of vulnerability.
Higher education’s early lead became security debt
Higher education was an early and enthusiastic adopter of electronic access control. Open campuses, large resident populations and constant turnover made card-based access a practical alternative to rekeying buildings and managing thousands of mechanical keys.
That early adoption created a long tail. Many institutions built their programs around the credential technology of the time, 125 kHz proximity credentials, and then expanded those systems building by building for years. The technology proved reliable enough that replacement never felt urgent. Today, however, reliability and security are no longer the same thing. A system can operate exactly as designed and still provide too little assurance that the credential presented at a door is genuine.
Why legacy prox is fundamentally vulnerable
A typical 125 kHz proximity credential presents a fixed credential number to the reader in the clear. It does not provide the kind of cryptographic challenge-and-response technology used by modern secure credentials. If that credential number is captured and reproduced on another device or credential, the access control system generally sees the copy as the original.
Tools capable of reading and emulating many legacy prox formats are now inexpensive and widely available. The exact read range and method vary by credential and equipment, but the practical point is unchanged: cloning is no longer a specialized laboratory exercise, the tools to achieve it can be inexpensively purchased by anyone who has access to the internet, and inquisitive college students are a main buyer of these types of technology
That creates an attribution problem as much as an access problem. A cloned credential can generate a normal-looking event under the authorized cardholder’s name. Unless the event conflicts with another system, violates an access rule or is reviewed alongside video, the log alone may not reveal that the person at the door was not who it appeared to be in the system.
The risk extends well beyond residence halls
Residence halls are the most visible concern, but the institutional exposure is broader. The same credential ecosystem may control access to research laboratories, data centers, records offices, pharmacies, hazardous-material storage, executive areas and infrastructure spaces. On a modern campus, a single credential can represent access to environments with vastly different levels of risk. That makes credential security an institutional security issue, not simply a card-office or access control issue.
The impact also rises with privilege. Credentials assigned to senior administrators, researchers, IT personnel, facilities teams and public-safety staff may open more doors or more sensitive locations than a typical student credential. That makes privileged cardholders and high-consequence spaces logical priorities for a phased migration.
The objective is not to suggest that every cloned card will lead to a major incident. It is to recognize that legacy prox provides weak proof of possession precisely where the institution may need stronger confidence in identity.
Why campuses keep deferring the decision
Most campus security and card-office leaders already understand the weakness. The barrier is rarely awareness; it is execution and on a university campus, execution can be quite complex.
Scale. A university may have hundreds or thousands of readers, multiple platforms utilizing the credentials and a large population of active credentials.
Competing capital priorities. Reader replacement and rebadging compete with visible investments in housing, classrooms, research and student services.
Fragmented one-card environment. The campus credential may support access, dining, printing, libraries, recreation, parking, vending and other services managed by different departments and vendors.
Installed-system dependencies. Older controllers, interfaces, locks and downstream systems may constrain credential and reader choices.
A low visible compromised rate. Because a copied credential can look legitimate in the access log, the absence of a detected incident can be mistaken for evidence that the risk is low, and you will not know how many of your credentials have been copied and compromised.
A realistic migration path
For most campuses, an overnight replacement is neither financially realistic nor operationally necessary. A better approach is a realistic plan, including a governed transition with a defined end state and measurable milestones.
- Define the secure target architecture. Select a modern credential technology and key strategy based on security, interoperability, lifecycle and ownership, not frequency alone. Some 13.56 MHz technologies may be legacy or poorly configured, so ‘moving to smart cards’ is not a sufficient requirement by itself, selecting the right credential technology is key, and it will define the path for selecting card readers, locks, and other authentication devices.
- Prioritize by consequence. Upgrade high-risk buildings and high-privilege populations first, including research, information technology areas, sensitive records, residence halls and critical infrastructure.
- Use transition technology deliberately. Multi-technology readers and dual-technology credentials can support legacy and new populations during migration. But the transition needs a sunset date. If 125 kHz remains enabled indefinitely, the original attack path remains open. Most multi-technology readers allow you to turn off the less secure, lower frequency technology, when you’ve completed the credential migration, reducing this as a potential attack vector.
- Add stronger verification where warranted. For the most sensitive areas, combine the credential with a PIN, biometric factor, staffed verification or video-supported operating procedure, based on policy and applicable privacy requirements.
- Improve detection and response. Use anti-passback where operationally appropriate, investigate impossible or unusual travel patterns, correlate access with video and other systems, and make lost-credential reporting and revocation fast and simple. The use of AI allows for identifying unusual travel patterns, or the same credential number appearing twice on campus in different areas within a short period of time, and provide a notification of such an occurrence.
- Create campus-wide governance. Establish an accountable steering group spanning security, IT, the card office, facilities, student affairs, dining, libraries, finance and procurement. Credential modernization is a program, not a reader purchase, and involves buy-in from many stakeholders
Higher education’s built-in migration advantage
The annual academic cycle that exposes the problem also creates one of the best opportunities to solve it. Every fall, campuses already issue credentials to an incoming class, transfer students, graduate assistants and new employees. The workflow, staffing and communication channels already exist.
A campus can use that moment to begin the transition without launching a disruptive mass rebadging event:
Issue the secure credential to every new class. Incoming users start on the target technology and never need a legacy prox credential.
Upgrade readers ahead of the academic cycle. Transitional readers can support returning users while the secure population grows.
Let normal turnover reduce the legacy base. Graduation, employee turnover and replacement-card events steadily retire older credentials.
Measure progress. Track the percentage of secure credentials, upgraded readers, high-risk spaces completed and legacy technology disabled.
This approach does not eliminate coordination with dining, libraries, bookstores, vending, parking and other services. It does, however, turn a daunting one-time replacement into a planned lifecycle program.
Smart cards, mobile credentials—or both?
Modern secure smart cards
A modern contactless smart card can preserve the familiar tap experience while adding cryptographic authentication and stronger protection against simple capture-and-replay attacks. Technologies such as HID Seos and appropriately configured MIFARE DESFire are common examples, but the product name alone is not the security design. Campuses should understand who owns the credentials encryption keys, whether keys are unique to the institution, how readers are configured, how credentials are diversified and how compromised media can be replaced.
Physical cards also remain important for accessibility, user choice, continuity and populations that cannot or do not want to use a compatible mobile device.
Mobile wallet credentials
Mobile credentials provision an institutional ID to a compatible phone or wearable and communicate with supported readers through NFC. They can simplify issuance and revocation, reduce card-printing demand and provide users with a credential on a device they already keep close and monitor carefully. Depending on the credential architecture and implementation, they can also provide encrypted communication.
They are not a hardware-free shortcut. Reader compatibility, device eligibility, wallet and platform support, privacy, help-desk capacity, offline behavior and fallback procedures all matter. Security also depends on the credential architecture and implementation; ‘mobile’ should not be treated as a security specification by itself. They do provide a modern way of issuing and managing credentials, and leveraging a piece of technology in the phone or wearable that students keep with them at all times and monitor consistently.
The most successful migrations start with understanding the entire credential ecosystem, not just the cards and readers, but the systems, stakeholders, dependencies and operational requirements surrounding them. That is where an experienced security integration partner can help a campus establish the end state, identify priorities and build a migration roadmap that is both technically sound and operationally realistic.
For many campuses, the practical answer is a hybrid model: modern encrypted physical credentials plus mobile wallet credentials, both operating on a reader infrastructure designed for the institution’s long-term architecture.
The decision is not whether to replace prox. It is when to start.
Higher education did not make a mistake by adopting electronic access control early. The industry simply learned more about credential security, while the tools used to exploit older technology became easier to obtain.
The right response is not panic and it is not an indefinite rip-and-replace proposal. It is a phased, risk-based program with a secure end state, a funded lifecycle, cross-campus governance and a date when the legacy credential path will finally be disabled.
Campuses that begin now can use normal construction, renovation, contract renewal and annual card issuance to manage the transition. Campuses that continue to defer may eventually make the same investment under the far less favorable conditions of an incident.