OSDP was supposed to make it harder to break in to secure facilities. It failed
arstechnica.com
arstechnica.com
Also, Did anybody else read the headline in the Babylon 5 voice-over style?
Somehow the control panel and the reader must authenticate each other. I'm no security expert but only way I can think of is to use some pre-shared key. A key set via a trusted side channel, or at a time when the osdp channel is known to not be intercepted.
I do work with OSDP devices and I have heard this argument from manufactures, like "we only support setting a new key while using the default key, it's more secure that way". While it, at best, will just obfuscate the process.