High frequency does not mean secure
Moving off 125 kHz prox to a 13.56 MHz "smart card" is often treated as the fix. Whether it is depends entirely on which smart card, and how the system uses it.
| Technology | Cryptography | Copied with commodity tools? | Notes |
|---|---|---|---|
| 125 kHz prox (HID Prox, EM4100, Indala) | None | Yes, in seconds | Fixed ID, no authentication |
| MIFARE Classic (1K/4K) | Crypto1, publicly broken in 2008 | Yes | Hardened variants resist some older attacks, not all |
| Legacy HID iCLASS (standard keys) | Proprietary, shared master key | Yes | The standard key was extracted and published years ago |
| MIFARE DESFire EV2 / EV3 | AES-128, secure messaging | No known practical attack | Security rests on key management |
| HID Seos | AES-128, secure messaging | No known practical attack | HID ecosystem; also used for phone credentials |
MIFARE Classic
MIFARE Classic uses a proprietary cipher, Crypto1, which researchers broke publicly in 2008. Keys can now be recovered from a card with inexpensive tools, and many deployments never changed the default or widely published keys in the first place. Later "hardened" versions closed some attacks, but others still work against them. Treat any MIFARE Classic badge as cloneable.
Legacy iCLASS
Older HID iCLASS cards using HID’s standard security key share one master key across customers. That key was extracted and published over a decade ago, so standard-key iCLASS is cloneable. iCLASS SE and Elite configurations with site-specific keys are a different case and need to be checked individually.
DESFire EV2/EV3 and Seos
Both use AES-128 with mutual authentication and encrypted communication between card and reader, and neither has a known practical cloning attack today. The real differences are commercial and operational:
- DESFire is made by NXP and supported by readers from many manufacturers, which keeps future hardware choices open.
- Seos is HID’s credential. It works best end to end in HID’s ecosystem and is widely used for phone-based badges.
- Either can be undone by poor key management: one key for every card, keys shared with an integrator’s other clients, or no plan for rotating them.
The setting that matters more than the card
Many readers can be configured to read only a card’s serial number (its UID or CSN) instead of authenticating it. The serial number is not secret and can be emulated. A DESFire EV3 card read this way gives you little more protection than prox. Ask your integrator, in writing, whether each reader performs a cryptographic authentication with site-specific, diversified keys.
Choosing what to move to
- Find out what you have today, card and reader, door by door.
- Decide whether phone credentials are in scope, since that narrows reader choice.
- Pick a credential that supports diversified keys you control, not your integrator.
- Plan the cutover so the old technology is switched off at the reader, not just stopped at the badge printer.
Our reports name the credential and reader class we would move you to, and why, with a price range. We take no referral fee or commission on any product we name. How the assessment works.
Last reviewed September 23, 2026.