{"id":905,"date":"2020-10-31T22:25:35","date_gmt":"2020-11-01T02:25:35","guid":{"rendered":"https:\/\/dc540.org\/xxx\/?p=905"},"modified":"2020-10-31T22:25:36","modified_gmt":"2020-11-01T02:25:36","slug":"no-hello-kitty-fobs-for-daughter-for-now","status":"publish","type":"post","link":"https:\/\/dc540.org\/xxx\/2020\/10\/no-hello-kitty-fobs-for-daughter-for-now\/","title":{"rendered":"No Hello Kitty fobs for daughter&#8230; for now."},"content":{"rendered":"\n<p>I recently blogged about obtaining Chinese UID-writable magic backdoor Hello Kitty MIFARE fobs to test cloning HF RFID cards. My hope was that I&#8217;d be able to clone my kid&#8217;s college card, so she wouldn&#8217;t have to dig out a card every time she enters a space, just use a fob on her keyring, just like I cloned my LF HID card to a fob for work.<\/p>\n\n\n\n<p>At the time I ordered them, she was away at school, so I had no way of knowing what format her card was. If her student card was MIFARE, I&#8217;d probably have a fighting chance. I believe I have successfully cloned MIFARE cards. I say I believe, because I don&#8217;t have access to a testing platform until my next hotel stay.<\/p>\n\n\n\n<p>Alas, it seems like schools (at least her school) are a bit ahead of the RFID game compared to hotels. Rather than simple MIFARE, it&#8217;s DESFire EV1 2K, and from the searching I&#8217;ve been conducting tonight, it doesn&#8217;t seem like DESFire has been cracked as far as retrieving the master key.  DESFire EV1 is not bleeding edge, though.  According to MIFARE, it&#8217;s not recommended for new designs. Instead, MIFARE recommends DESFire EV3.<\/p>\n\n\n\n<p>In any case, it&#8217;s a hell of a lot of fun to learn the ins and outs of the various formats, protocols, etc., and how these cards and readers work.<\/p>\n\n\n\n<p>I&#8217;ll keep on it on the sideburner. I suspect if I do nothing and someone cracks it, it will make its way into the PM3 firmware rather quickly.<\/p>\n\n\n\n<p>I did read something on the forums indicating that the master key might be derived through side-channel attacks involving response speed.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I recently blogged about obtaining Chinese UID-writable magic backdoor Hello Kitty MIFARE fobs to test cloning HF RFID cards. My hope was that I&#8217;d be able to clone my kid&#8217;s &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/dc540.org\/xxx\/2020\/10\/no-hello-kitty-fobs-for-daughter-for-now\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;No Hello Kitty fobs for daughter&#8230; for now.&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":906,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[46,73],"tags":[],"class_list":["post-905","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-crypto","category-rfid"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/dc540.org\/xxx\/wp-content\/uploads\/2020\/10\/Screen-Shot-2020-10-31-at-10.02.33-PM.png","jetpack_likes_enabled":true,"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/dc540.org\/xxx\/wp-json\/wp\/v2\/posts\/905","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dc540.org\/xxx\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dc540.org\/xxx\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dc540.org\/xxx\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dc540.org\/xxx\/wp-json\/wp\/v2\/comments?post=905"}],"version-history":[{"count":1,"href":"https:\/\/dc540.org\/xxx\/wp-json\/wp\/v2\/posts\/905\/revisions"}],"predecessor-version":[{"id":907,"href":"https:\/\/dc540.org\/xxx\/wp-json\/wp\/v2\/posts\/905\/revisions\/907"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dc540.org\/xxx\/wp-json\/wp\/v2\/media\/906"}],"wp:attachment":[{"href":"https:\/\/dc540.org\/xxx\/wp-json\/wp\/v2\/media?parent=905"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dc540.org\/xxx\/wp-json\/wp\/v2\/categories?post=905"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dc540.org\/xxx\/wp-json\/wp\/v2\/tags?post=905"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}