Public Transport Conversion by
Feasibility
Throughout the world There are many and varied Public Transport Infrastructures utilising a wide range of RFID technology, fortunately for some, there are some older / less secure systems such as Mifare Classic (There are a few examples here on the Forum) and fortunately for people with access to those systems, Dangerous Things have some âoff the shelf optionsâ .
But, The odds are, Most Public Transport Companies will be using more secure protocols such as DESFire(r).
The likelihood of a compatible implant is still possible, but it probably wonât be as simple as grabbing an âoff the shelf optionâ
My First thought
[details=" Dangerous Things âOff the shelf DESFireâ ( Failed attempt )"]
As the Dangerous Things DESFire(r) Range do not have modifiable UIDs, ( It will require more than a simple UID anyway, see below) Therefore, it would likely require some significant social engineering to get your implant enrolled and applet installed through the Transport Agencyâs system ( I have not yet tried approaching anybody for mine yet )
It is protected to transport use only, I have attempted a few things to try and work out how to free up memory to make it multifunctional all unsuccessfully.
WHAT I COULD STILL TRY
Approach Auckland transport about enrolling a DT Flex Implant, and convince them to allow me to âBring my ownâ
My options are
xDF2 But I donât think an xSeries would be optimal for this purpose
FlexDF The DESFire is closest to a one for one swap
FlexDF2 The DESFire2 is backward compatible, and the Newer more capable chip, so ideally this is my first choice
[/details]
My Second thought
DESFire(r) Modifiable cards (failed attempt)
MIFARE DESFIREÂź COMPATIBLE UID MODIFIABLE EMULATOR CARD I got mine from KSEC
There are two variations of card, 7-byte UID and 4-byte UID .
Please note, this card does not emulate any other MIFARE DESFireÂź features.
Modification of the UID is incredibly simple, thanks to a raw 14443 command.
Using your Proxmark 3, you can issue the following command:
hf 14a raw -s -c 02 00 ab 00 00 07 xx xx xx xx xx xx xx
Where xx xx xx xx xx xx xx is your target UID. ( In my case 04 7F 3B 72 47 50 80 )
For 4-byte cards, your UID will be 4-bytes, for 7-byte cards, the UID will be 7-bytes
IMPORTANT:
The UID of MIFARE DESFireÂź Compatible UID Modifiable tags is comprised of two parts: the UID itself , and the BCC . The BCC is a checksum value calculated from the UID . If the BCC is incorrect, tag will be rejected by the reader.
Most RFID tools, such as the Proxmark, LibNFC, MCT etc automatically calculate the BCC when the UID is modified. If you are modifying the UID by hand, it is vital that the BCC is correctly calculated.
There is NO support or refunds under any circumstances for cards that were âbrickedâ due to incorrect UID/BCC configuration.
WHAT ARE THE ATS VALUES?
The card responds with 06 75 77 81 02 80 02 F0
CAN I MODIFY THE ATS / ATQA / SAK VALUES ?
No, the ATS / ATQA values are fixed.
SAK values can be modified upon request at the factory.
I wrote my UID to the card and tested it on a reader, and not surprisingly, it did not work.
My third thought, and valid attempt
Which brings us to the reason for this thread:
I have done some work around the feasibility of POTENTIALLY getting my official Public Transport card converted to an implant.
Below are the steps I followed: (your experience may differ, but the process may be similar)
In Auckland, New Zealand, we have one transport agency
That covers Bus, Train and Ferry
Form Factors
- Cards
These âcardsâ come in 2 types ( Gold for those over 65 who get free public transport )
- Fob / Keyring
Approx 60mm x 30mm x 5mm
- 3rd Unofficial Potential option from DT Conversion
DO NOT DO WHAT I DID SEND YOURS TO AMAL IN ITâS ORIGINAL STATE
Acetone vs. Tag
I know, I know, I really should have taken better photos
This is from another thread, But it is worth putting this here
DO NOT DO WHAT I DID SEND YOURS TO AMAL IN ITâS ORIGINAL STATE
MY analysis
- To me, the chip looks viable for conversion
- The card is a DESFire(r) EV1 4kB
- 17pF version of the chip
- Surprisingly ( To me any at least ) the remaining space is only 928 bytes
- However that remainder of the memory is protected
THE CARD DETAILS
CARD NUMBER ( 19 Digits ) Printed on the card / fob and used to register the card
CARD UID ( 7 BYTE )
ID: 04:7F:3B:72:47:50:80
ATQA: 0x4403
SAK: 0x20
ATS: 0x1C
.
.
BALANCE TOP-UP
There are 4 ways to check and top up balance:
-
- AT Customer Service Centres
-
- Retail Agents (Requires Human interaction, Can be problematic with not a consistent nor predictable reaction)
-
- Top up Machines
Unfortunately due to the design of the Top Up machines, they require the card or Fob to be dropped into the receptacle, which would be difficult to do whilst the implant remains inside you
- Top up Machines
-
- Online, With an implant, the âbestâ / âeasiestâ way is Online
EXPIRY
I believe the card / fob does not expire UNLESS no value is loaded onto it for a continuous period of six years. With the minimum topup being $1 (in person, or at machine ) or $5 online
.
.
.
LEGAL STUFF, Boring but important
Legal
( I have highlighted to save you the pain of reading )
5.5. take proper care of the AT HOP card to avoid damage including keeping the AT HOP card flat and not bending it (as that may damage the AT HOP card);
5.6. not misuse, deface, modify, or destroy, the AT HOP card;
5.7. not tamper, or allow anyone else to tamper, with the AT HOP card;
5.9. not alter, remove, or replace any notices, trade marks, or artwork on the AT HOP card; and
- Right to Retain: We, the Retail Agents and Public Transport Operators will be entitled to confiscate or retain any AT HOP card which:
6.1. we (or a Retail Agent or Public Transport Operator) suspect or have reason to believe has been fraudulently issued, stolen, tampered with, or used in breach of the Terms;
8.3. we retain the right to manage and change the software and data on the AT HOP cards at any time; and
8.4. On-demand by any employee or representative of us or of any Retail Agent or Public Transport Operator at any time, you must produce for inspection all AT HOP cards in your possession or control.
- Suspension: We may suspend any AT HOP card or AT HOP online account (Online Account) if you breach any of these Terms and such breach amounts to what AT determines to be fraud or fare evasion. In the event that we suspend any AT HOP card or Online Account:
tamper
verb
- interfere with (something) in order to cause damage or make unauthorized alterations.
confiscate or retain any AT HOP card which:
[âŠ] believe has been [âŠ] tampered with , or used in breach of the Terms;
you must produce for inspection all AT HOP cards in your possession or control.
Good luck with that
TESTING TIME
PERFORMANCE / FUNCTION / RANGE
Amalâs AMAL-YSIS
Therefore, if I choose to get this converted, with one of DTâs tuned 13.56MHz antennas, this should improve the range and performance over the official fob antenna.
Feasibility
The conversion is % feasible, even though factory performance is poor due to being off frequency, but with the âcorrectâ DT antenna from the conversion service it SHOULD be a great little performer.
My Decision
If I could have also utilised the remaining 928 bytes of memory then it would be much more worthwhile, So at this stage I am leaning toward a NO⊠but I may change my mind
RECOMMENDED?
As with my payment conversion, Absolutely, I highly recommend considering any conversion service from Dangerous Things, including a Transport conversion like this one.
If you are interested in this service, FIRST Contact Dangerous Things for their opinion of the feasibility