- Home
- Null
Showing 0 products
Frequently Asked Questions
Is a shared door code ever acceptable?
Only where the door protects very little and the audit trail does not matter - which is a much smaller set of doors than shared codes are actually used on.
A shared code cannot be attributed. The log records that the code was used, not who used it, which removes the main reason for having an electronic system.
It also cannot be revoked for one person. A leaver knows the code until it is changed for everyone, and changing it for everyone is disruptive enough that it rarely happens.
Codes spread. They are told to contractors, shouted across corridors and written near the door.
Individual PINs solve all three and cost nothing extra if the system supports them.
Where a shared code genuinely is appropriate - a store cupboard, an internal gate - set a change schedule and actually follow it.
How long should a PIN be?
Long enough that guessing is impractical, short enough to be entered reliably - and chosen to avoid the obvious patterns.
Every extra digit multiplies the search space, but the real weakness is rarely brute force. It is predictable codes: years, repeated digits, sequences and the building's own street number.
Systems should reject the obvious patterns at the point the code is set rather than relying on policy.
Rate limiting matters more than length. A keypad that locks out after a handful of wrong attempts defeats guessing regardless of code length.
Where a PIN is a second factor alongside a card, it can be shorter, because an attacker needs the card as well.
Do not enforce frequent changes on a door PIN. It drives people to write the code down, which is a far bigger exposure than an old code.
How is shoulder surfing prevented?
With a shroud or a restricted viewing angle, a keypad sited away from public sightlines and, where the risk is high, a randomised key layout.
Observation is the realistic attack on a keypad. It requires no equipment and leaves no trace.
Physical shrouds and privacy filters restrict the angle from which the keys can be seen, and are cheap.
Position matters as much. A keypad facing an open public area, a stairwell or a window is exposed no matter what shroud is fitted.
Scrambling keypads present the digits in a different arrangement each time, so watching the finger positions reveals nothing. They are slower to use and suit a small number of high-value doors.
Cameras covering the keypad are a double-edged tool: useful for investigation, and a recording of every code entered unless the view is deliberately restricted.
What is a duress code?
An alternative code that opens the door normally while silently signalling an alarm - so a person forced to open a door can do so without visible resistance.
The door behaves exactly as usual. Nothing at the keypad indicates anything has happened.
The alarm goes to a monitoring centre or security team, who respond according to a pre-agreed procedure.
Common implementations are a separate code or the normal code with a digit added or altered in a defined way.
It only works if staff are trained on it and if the response procedure genuinely exists. A duress alarm nobody acts on is worse than none, because it creates a false expectation.
Consider false activations too, since a stressed user may enter it by accident. The response should begin with discreet verification rather than a visible intervention.
Should the keypad be used with a card?
On any door where the consequence of a copied card is unacceptable, yes - the combination is genuine two-factor authentication.
A card can be copied or stolen; a PIN can be observed or shared. Requiring both means an attacker needs one of each, which is a substantially harder problem.
Most access systems can require the second factor on a schedule, so a busy entrance uses card only during the day and card-plus-PIN at night.
It can also be applied by area rather than by door, which is usually easier to administer.
The cost is time. Every entry takes several seconds longer, so it should be applied where it is earned rather than universally.
Combined card-and-keypad readers keep this to a single device on the wall, which is neater than two.
Do keypad legends wear out?
They do, and a worn keypad shows which digits are in the code - which is a real disclosure, not a cosmetic problem.
Printed legends rub off and plastic keys polish where they are pressed. On a door with one shared code used thousands of times, the four worn keys are visible from a distance.
Even without knowing the order, the attacker's search space has collapsed to a handful of permutations.
Metal keypads with engraved or laser-etched legends resist this, as do sealed membrane and capacitive glass surfaces with no moving keys.
Individual PINs distribute the wear across all the digits and largely remove the problem as a side effect.
For outdoor keypads, add ultraviolet stability and a wide temperature range to the specification - and check whether the keypad remains usable in gloves, since many capacitive panels do not.
Are keypads suitable outdoors?
Yes, with the right rating - but the environment adds requirements that indoor units do not have.
Ingress protection against driven rain and dust comes first, followed by a temperature range that covers the site's extremes rather than its average.
Backlighting is not a luxury outdoors. A keypad that cannot be read at night will be mis-entered constantly.
Vandal resistance matters on any keypad reachable in a public area, and so does the fixing method - visible screws mean the unit can be removed.
Glove operation is a common requirement and rules out some technologies. Mechanical and membrane keys work with gloves; many capacitive panels do not.
Consider heating and condensation. A sealed keypad that fills with condensate in a temperature swing fails as surely as one that lets rain in.