Assistance in implant selection?

Hi all, im looking for some guidance on what implant would be best suited to my requirements.

  1. I would like to have people scan it with their phone and get a link to my Facebook or contact card for work stuff. Ideally, I would like to be able to program this directly from my phone on the go if I’m going to a meeting etc, I can just update the information and its good to go.
  2. I would like to be able to use this for things in my smart home (door locks, lights etc.., whatever I program home assistant to do with it on a reader) I’m not setup for this yet in terms of rfod in hass. But am looking into it.
  3. I have a zeekr 7x ev, I would like to register the rfid part of the implant to the car so that I can use it (like a tesla). But my understanding is that this is quite a complex thing, and may need a Java applet or something. I’m also not sure what type of card the 7x has, so maybe it does not need that. Based on my DT diagnostic card, the zeekr is 13.56mhz. But im open to taking my card somewhere for someone to scan with a proxmark and tell me if it can or can’t be done. There was a chap nearby when I was asking some questions last year as im based in Brisbane Australia. But time got the better of me, and I have not purchased anything.

Many thanks.

4 Likes

This can be done by a lot of the x series and flex series. The flex series has better range.

  1. I would like to be able to use this for things in my smart home (door locks, lights etc.., whatever I program home assistant to do with it on a reader) I’m not setup for this yet in terms of rfod in hass. But am looking into it.

If you can enroll the chip ID you can use any of the HF chips. But if you go with a LF system you’ll need a T5577

  1. I have a zeekr 7x ev, I would like to register the rfid part of the implant to the car so that I can use it (like a tesla). But my understanding is that this is quite a complex thing, and may need a Java applet or something. I’m also not sure what type of card the 7x has, so maybe it does not need that. Based on my DT diagnostic card, the zeekr is 13.56mhz. But im open to taking my card somewhere for someone to scan with a proxmark and tell me if it can or can’t be done. There was a chap nearby when I was asking some questions last year as im based in Brisbane Australia. But time got the better of me, and I have not purchased anything.

Java apps require the ApexFlex of FlexSecure. Apex is a productized version. FlexSecure is a DIY. ApexFlex is less customizable but easier to set up.

I would recommend Apex Flex and a NeXT v2.

1 Like

Thanks for that. I assume the NeXT is for the access control and data sharing, and the Apex is for the car?

How would I determine what may be involved to make the implant work with my EV? Before getting to deep into that. I’m only speculating that it will need something complex like the tesla. But I don’t know.

Do you have a card / fob already registered to the vehicle?

use TagInfo to find out details of the Chip, this will help determine what implant may be compatible.

Also, if you can provide the procedure on how you enroll a new card.

Here is some more info

Also, your car is on this list, but lite on info

2 Likes

Data sharing and it has a UID that can be registered to a system and it has a t5577 that lets you clone other LF chips and it has an LED!!! (Green is bright! I have a blue xSIID)

It’s for that, it can be a TOTP authenticator app, it can hold a large ndef partition. For example, I have my contact information with a picture in an ndef container on my flex secure. So people can tap and import it as a contact. I also have it on a xDF3 but the range is not so great compared to the flex. But the storage is a good size.

On the EV point, it may help to split your requirement 3 into two separate questions before spending anything. First: does the car’s reader actually accept a credential you can provision yourself, or is enrolment locked to the manufacturer’s own key card stock? That is a car-side question, not an implant-side one, and it decides everything else. Second: if enrolment is open, what does the reader expect on tap — a plain UID it stores, or an applet-backed exchange?

If it turns out the car only stores a UID, that is a much smaller problem than a Java applet. If it needs a proper secure element conversation, then no amount of picking the right implant helps until you know the spec.

A cheap way to find out before buying: take your existing key card and the car to someone with a Proxmark, and log a normal unlock at the reader. That tells you the protocol the reader is really speaking rather than what the frequency alone suggests. Given you’re in Brisbane, asking in the local biohacking/RFID meetup crowd for a Proxmark session is usually easier than shipping hardware around.

Also worth deciding your priority order early. Requirement 1 (contact/NDEF sharing) and 2 (home automation reader) are well-trodden and predictable. Requirement 3 is the speculative one. If you buy for 1 and 2 and treat the car as a maybe, you won’t end up disappointed with an install you chose for a use case that never worked out.

@Pilgrimsmaster thanks for that Wiki page, Yes the Zeekr does support apple wallet using UWB, and this support is supposed to be coming to android in the near future. But nothing yet.

@optedoblivion perfect. thanks for that. From my resesarch, there is no functional difference between the NeXt and the NeXT2. I’m not sure how i feel about the LED, so might go the NeXt. But am undecided on this specifically yet. I guess that the LED at least gives an indication that its all working as expected.

@HelenMarsh Thanks for that detailed answer.

I agree on your approach. That does make sense. I will need to look into what the car will accept. A cursory search on aliexpress shows that i can just get NFC cards from there, and local Zeekr groups have mentions from people who have done this and added their cards to the car with success. But I have not tested this personally. The car came with 1 RFID card that was paired already. But there is a section in the menu that allows you to add more cards in. you just tap it onto the phone charger when in pairing mode (based on my reading of the owner manual)

Unfortunantly, there are no RFID / biohacking type groups that im aware of in Brisbane. Im happy to drive to someones place if they have a proxmark and are able to assist in determining what its doing.

Im happy to pull the trigger on the NeXT / NeXT2 and cross the EV bridge afterwards.

Is there any real differences between the genuine proxmark units, and the clones on Ali? Also, is there any real benefit to going the non-lite? and stepping it up to some of the more expensive units?

unlocking my computer would be handy also. From my reading, because this is done by just reading the serial number of the card and the KBR1, this should be fine to do with a populated ndef partition also?

This is the output from TagInfo when i scan it. I guess, i can just order a card and try writing it into the car. Do i just get a java card? what would be some ideal suggestions i can purchase and see what the car does with it?

** TagInfo Scan (version 6.2.0) 01-Sep-26 21:31:12 **
Report Type: -- IC INFO ------------------------------

# IC Manufacturer:
NXP Semiconductors

# IC Type:
Unknown IC implementing ISO/IEC 14443-4

# Card OS type:
Java Card

# Application information:
Global Platform card manager present
Visa card manager

-- NDEF ------------------------------

# No NDEF Data Storage Populated:

-- EXTRA ------------------------------

# ATS historical bytes details:
ISO/IEC 7816-4 coding
Category: [RFU]

# Global Platform information:
Java Card version 2.2
Global Platform version 2.1.1
GP Secure Channel Protocol: 02 option 15
Max. length APDU data field: 255 bytes
Visa card manager
* FCI: 0x6F108408A000000003000000A5049F6501FF |o..............e..|

# Card Production Life Cycle data (CPLC):
IC Fabricator: [not set]
IC Type: [unknown]
OS ID: [unknown]
OS release date: [not set]
OS release level: 0x0000
IC Fabrication Date: [not set]
IC Serial Number: 0x00000000
IC Batch Identifier: 0x0000
IC Module Fabricator: [not set]
IC Module Packaging Date: [not set]
ICC Manufacturer: [not set]
IC Embedding Date: [not set]
IC Pre-Personalizer: [not set]
IC Pre-Perso. Equipment Date: [not set]
IC Pre-Perso. Equipment ID: 0x00000000
IC Personalizer: [not set]
IC Personalization Date: [not set]
IC Perso. Equipment ID: 0x00000000
IC Personalizer: [unknown]
IC Personalization Date: [not set]
IC Perso. Equipment ID: 0x00000000

# File Control Information:
Default selected AID
0x6F108408A000000003000000A5049F6501FF |o..............e..|

# TagInfo Version:
Version :6.2.0

# Device Info:
Device Model :samsung ( SM-G965F )
Android OS Version :10

-- FULL SCAN ------------------------------

# Technologies Supported:
ISO/IEC 7816-4 compatible
ISO/IEC 14443-4 (Type A) compatible
ISO/IEC 14443-3 (Type A) compatible


# Android Technology Information:
Tag description:
* TAG: Tech [android.nfc.tech.IsoDep, android.nfc.tech.NfcA]
* Maximum transceive length: 65279 bytes
* Default maximum transceive time-out: 2000 ms
* Extended length APDUs supported
* Maximum transceive length: 253 bytes
* Default maximum transceive time-out: 618 ms


# Detailed Protocol Information:
ID: 6E:38:F4:AD
ATQA: 0x0800
SAK: 0x20
ATS: 0x6F00
* Max. accepted frame size: 16 bytes (FSCI: 0)
* Supported receive rates:
	- 106 kbit/s
* Supported send rates:
	- 106 kbit/s
* SFGT: 302.0 us
* FWT: 4.833 ms
* NAD not supported
* CID supported
* Historical bytes: [none]

--------------------------------------


Many thanks

The LED is a field finder. So you will be able to find the NFC point physically on your phone or other phones. I.e. an indication of when the tag is about to be read. Vs with the NeXT you just rub the phone on your hand until it vibrates.

1 Like

Ok, so I have do e some testing and the Next / NeXT2 will do most of what I want. I will order these from DT tonight / tomorrow.

In relation to the Java card thing for my car. How would I best go about determining what’s happening? I also asked about the PM3 vs its clones on ali etc. Any real difference with them?

Ideally, I would like to order a plain card and try what I need to and getting that working, and then order the implant.

But need to get some direction on how to best determine what’s needed etc.

Many thanks

ok, order placed. i have also added a javacard so that i can experiment with it with some assistance.

Hopefully one of the brisbane based peeps on here will be able to assist. But happy for any guidance i can get in the mean time. I have connected my ACR122U reader and installed the globalprotect java tools and got the information below from the ev card.

# gp --info SHA256 = 3ef423166b2938e79d4ba4351b3e25fa02571e2117d3dacb55d0ad229a219c7d # GlobalPlatformPro 26.09.01-SNAPSHOT # Running on Linux 7.1.10-200.fc44.x86_64 amd64, Java 25.0.4.1 by Red Hat, Inc. WARNING: A restricted method in java.lang.System has been called WARNING: java.lang.System::load has been called by com.sun.jna.Native in an unnamed module (file:/home/jason.bates/GlobalPlatformPro/tool/target/gp.jar) WARNING: Use --enable-native-access=ALL-UNNAMED to avoid a warning for callers in this module WARNING: Restricted methods will be blocked in a future release unless native access is enabled CPLC: ICFabricator=0000 ICType=0000 OperatingSystemID=0000 OperatingSystemReleaseDate=0000 (invalid date format) OperatingSystemReleaseLevel=0000 ICFabricationDate=0000 (invalid date format) ICSerialNumber=00000000 ICBatchIdentifier=0000 ICModuleFabricator=0000 ICModulePackagingDate=0000 (invalid date format) ICCManufacturer=0000 ICEmbeddingDate=0000 (invalid date format) ICPrePersonalizer=0000 ICPrePersonalizationEquipmentDate=0000 (invalid date format) ICPrePersonalizationEquipmentID=00000000 ICPersonalizer=0000 ICPersonalizationDate=0000 (invalid date format) ICPersonalizationEquipmentID=00000000 KDD: CF0A746A6A74260206000776 SSC: C1020000 Card Data: Tag 6: 1.2.840.114283.1 → Global Platform card Tag 60: 1.2.840.114283.2.2.1.1 → GP Version: 2.1.1 Tag 63: 1.2.840.114283.3 → GP card is uniquely identified by the Issuer Identification Number (IIN) and Card Image Number (CIN) Tag 6: 1.2.840.114283.4.2.21 → GP SCP02 (i=15) Tag 66: 1.3.6.1.4.1.42.2.110.1.2 → JavaCard v2 Card Capabilities: Version: 1 (0x01) ID: 1 (0x01) type: DES3 length: 16 Version: 1 (0x01) ID: 2 (0x02) type: DES3 length: 16 Version: 1 (0x01) ID: 3 (0x03) type: DES3 length: 16 # Warning: no keys given, defaulting to 404142434445464748494A4B4C4D4E4F

WARNING: A restricted method in java.lang.System has been called WARNING: java.lang.System::load has been called by com.sun.jna.Native in an unnamed module (file:/home/jason.bates/GlobalPlatformPro/tool/target/gp.jar) WARNING: Use --enable-native-access=ALL-UNNAMED to avoid a warning for callers in this module WARNING: Restricted methods will be blocked in a future release unless native access is enabled # Warning: no keys given, defaulting to 404142434445464748494A4B4C4D4E4F Failed to open secure channel: Card cryptogram invalid! Received: 2E3BC53988FA1F4E Expected: 170252B2CD2B1963 !!! DO NOT RE-TRY THE SAME COMMAND/KEYS OR YOU MAY BRICK YOUR CARD !!! Read more from Keys · martinpaljak/GlobalPlatformPro Wiki · GitHub

But based on the error above, im going to pul up stumps until i can get further guidance. Does this counter live on the card? It sounds like it does, and that when it reaches a point, the card will brick itself?

Are you running @tac0s version?

More information jhere

You should have a simple GUI

You simply highlight the applet you want and click install

Fucken brilliant tool, it made using my FlexSecure so much easier

1 Like

Looks like it doesn’t have default keys–who did you order it from?

2 Likes

The card i scanned is the actual one that came with my EV.

I have ordered a J3R452 from DT, and I will see if I can just program it on the car when it arrives. And see what the car says. But failing that, I will be back for some more assistance.

If this fails, I assume its where I will need a proxmark also. Can I just sit that between the card and the reader and capture all the bytes that transfer between them?

If they aren’t using secure comms, sure, but they almost certainly are. You can’t clone your EVs card, I can tell you that right now.

Yeah, I figured that would be the case. Here is hoping I can just program the card from the card and as it will have a known key I can access the data.

Or am I dreaming, and that won’t work either?