Research, development and trades concerning the powerful Proxmark3 device.
Remember; sharing is caring. Bring something back to the community.
"Learn the tools of the trade the hard way." +Fravia
You are not logged in.
Time changes and with it the technology
Proxmark3 @ discord
Users of this forum, please be aware that information stored on this site is not private.
Pages: 1
Hey 0xFFFF,
since you decapped a iclass tag, how about you do one of these? Mifare s50 1k w hardend prng?
Maybe its useful for someone?
Offline
Never considered looking at the newer S50.
I doubt that I have any on hand.
Any suggestions on a good (cheap) supplier to obtain a few from?
Offline
Hey mate -
I could probably get some from our factory. I could get them doped, or maybe even un-doped, right off the wafer..
Let me know what you'd prefer.
Offline
...the documents describing the wafer?
Offline
Most probably this would be a waste of time because there will be no PRNG at all. NXP claims that their Mifare Classic EV1 has a True RNG. A True RNG would be made of a noisy PN junction and an amplifier. Reverse engineering wouldn't help.
Offline
...claiming or knowing, such a difference
Offline
kwx - Message sent.
...NXP claims that their Mifare Classic EV1 has a True RNG...
...claiming or knowing, such a difference
I'm willing to bet that you're right piwi but until someone can confirm either way, we can't be absolutely certain.
Offline
kwx - Message sent.
piwi wrote:...NXP claims that their Mifare Classic EV1 has a True RNG...
iceman wrote:...claiming or knowing, such a difference
I'm willing to bet that you're right piwi but until someone can confirm either way, we can't be absolutely certain.
Let me know specifically what you'd want or need, and I'll chat with my suppliers.
I'm pretty sure I could get you undoped chips right off the wafer (probably with the UID unfused as well.)
Offline
Update:
Thank you to kwx for supplying the silicon!
I have some photos I'll upload later. Nothing exciting just yet.
I have been trying to arrange a suitable time to visit a lab. Time and money have been preventing me from getting this done sooner.
Offline
its a start!
Offline
Thanks. I suppose it is.
Not having much fun at all. I swapped the camera module on my microscope and something has gone horribly wrong. My X axis has stopped working and focus hasn't been 100%. The table appears to have been knocked out of alignment. Very frustrating!
I've been talking to a few labs to try and arrange access to an SEM. As much as I'd like to go ahead with this, I can't justify the expense.
A new microscope is first on my list which is more that I can afford right now.
Offline
So in the case does NXP claim these cards are compatible with all CRYPTO1 implementations but will not be vulnerable to nested or hard-nested?
Didn't the original paper which showed hard nested attack theory show that there were vulnerabilities besides the PRNG that could be exploited? Does anyone know if the EV1 is out yet and this can be looked at?
Offline
those pics 0xFFFF has, should be Mifare Classic EV1 dies...
Offline
So in the case does NXP claim these cards are compatible with all CRYPTO1 implementations but will not be vulnerable to nested or hard-nested?
I have not looked in to the vulnerabilities just yet.
The Classic EV1 'behaves' the same way as the older S50s.
7 Byte UID version supports random UIDs.
True random number generator.
The 4 Byte version appears to be a non unique UID.
Didn't the original paper which showed hard nested attack theory show that there were vulnerabilities besides the PRNG that could be exploited?
I have not looked in to this.
Does anyone know if the EV1 is out yet and this can be looked at?
See photos above.
They are terrible but you can just make out that the die is a S50 EV1.
7MF1S50XV0A
I would like to get a 4 Byte and a 7 Byte card.
Offline
Mifare Classic EV1 is out since years. You most probably get one if you order "Mifare Classic" today. Compared to the old Mifare Classic it has a true RNG instead of the broken PRNG but otherwise no difference. Which means that it still should work for all applications but the attacks based on the broken PRNG (Darkside, "nested") won't work any more. "Hardnested" however does work.
Offline
Pages: 1