← All guides
TechnologyKoreKonnect team · 11 August 2026

What happens when the phone touches the wall

The half-second between tap and “You’re in”, explained without the jargon — and why a photo of the reader gets an attacker precisely nowhere.

A phone tapping a KonnectReader on a wall

The tap, step by step

The reader on the wall is not a computer. It contains a small NFC chip — the same secure-element family used in contactless bank cards — with no battery, no wiring and no network connection. It is powered, for a fraction of a second, by the phone that touches it.

When a phone taps, the chip wakes and hands it a web link. Inside that link the chip has stamped two things: an encrypted copy of its own identity, and a one-time cryptographic signature it generates freshly for this exact tap. The phone opens the link, the member of staff confirms on their own signed-in session, and the server checks the signature before recording anything.

That is the whole trick. The chip proves the tap happened at the wall; the person’s login proves who tapped. Neither proof works without the other.

Why copies, photos and replays all fail

Every tap’s signature is different, because the chip counts. Each read increments a counter sealed inside the chip, and the counter is baked into the signature. The server keeps track of the highest count it has seen; anything at or below that number is a replay and is refused.

So the obvious attacks all collapse. A photo of the reader contains no chip, so it produces no signature at all. A screenshot or forwarded link carries an old signature — already used, already refused. Even someone who records the exact link their phone opened yesterday holds a tap that will never be accepted again.

Compare that with a QR code on the wall, which is just a picture — photograph it once and clock in from bed forever — or a shared door PIN, which is only ever one favour away from being common knowledge. The NFC chip’s signature is the difference between a system that assumes honesty and one that can prove presence.

What this means day to day

Staff need no app installed — the tap opens the browser, and after the first sign-in the phone stays signed in. The reader needs no power, no Wi-Fi and no maintenance, because it has none of those things to go wrong. And the record needs no interpretation: every entry is a verified fact that a specific person’s phone met a specific wall at a specific moment.

The questions everyone asks next

Does the phone need internet at the moment of the tap?

The tap itself is contactless and instant; the confirmation needs a data connection, same as opening any web page. In practice a phone that works at the door for WhatsApp works for this.

Which phones can tap?

Any phone with NFC — which is essentially every iPhone since the 7 and almost every Android of the last decade. The phone reads the tag natively; no app is required.

What if two people tap one after the other?

Each tap is its own signature against its own signed-in session. A queue of five people tapping through the door produces five separate verified records.

Can the reader be moved or swapped?

Each chip has a unique, cryptographically-verified identity bound to a named location in the system. Move it and it still identifies itself; substitute a different chip and it simply is not yours.

Watch the half-second yourself

The live demo is a real organisation with real readers behind it.

Try the live demo