I have an empty Mifare Classic card and want to encrypt memory in just one sector by changing the key for that sector.
However since this is an empty card all sectors have the default key FF FF FF FF FF FF.
Should I change the key for all the other sectors as well even though they are unused and empty?
已解决! 转到解答。
Hello!
Yes, it is advised to change ALL keys on MIFARE Classic cards away from the default values (even the key for Sector0)
Please refer to the document "AN11302 - End to end system security risk considerations for implementing MIFARE Classic" which describes possible attacks and countermeasures on MIFARE Classic.
Please be also aware that for storing sensitive data, its not advised to use MIFARE Classic, but rather a more secure MIFARE card like DESFire Light.
Best regards,
Florian
Hello!
Yes, it is advised to change ALL keys on MIFARE Classic cards away from the default values (even the key for Sector0)
Please refer to the document "AN11302 - End to end system security risk considerations for implementing MIFARE Classic" which describes possible attacks and countermeasures on MIFARE Classic.
Please be also aware that for storing sensitive data, its not advised to use MIFARE Classic, but rather a more secure MIFARE card like DESFire Light.
Best regards,
Florian
Hi @Florian_Mikulik ,
First of all thanks for your message.
I was able to find the referred "AN11302 - End to end system security risk considerations for implementing MIFARE Classic" in the NXP website, but i'm unable to download it - a username/password is required.
Please, can you try the link below:
https://www.nxp.com/restricted_documents/53420/AN11302.pdf
Can you share this document or point out how to get the credentials?
Thank you.