Cloning the Deutschlandticket/JavaCard applications

So, I’m looking to get a flexSecure sooner or later, and I was wondering.

Here in Germany, there’s this ticket called the Deutschlandticket, it allows you to use any public transit anywhere. It also uses Java Cards, just like the flexSecure.

Does anyone know what it’d take to get the necessary application and so forth onto a flexSecure? Also, primers on JavaCards similar to Deviant Ollams RFID talk are highly appreciated too

Any business charging for their apps like this will not let their product onto the flexSecure because that would potentially bypass all paid features as you, the holder of the master keys, have supreme power over the smart card. If you can convince them to move their app to Fidesmo it might be Apex deployable, however :slight_smile:

Typical approach to this is to convert the existing credential into an implant.

3 Likes

I considered researching into this as I also use the Deutschlandticket, but I decided against it, purely because of the ergonomics - I don’t want to deal with the hassle of explaining the poor conductors that they have to scan my hand only for the scan to be wonky with their handhelds.

Also, the Deutschlandticket Smartcards have their keys in their internal secure storage, so they are impossible to clone without first party support.

For primers, read flexsecure-applets/docs at master · DangerousThings/flexsecure-applets · GitHub .

5 Likes