High frequency does not mean secure

Moving off 125 kHz prox to a 13.56 MHz "smart card" is often treated as the fix. Whether it is depends entirely on which smart card, and how the system uses it.

TechnologyCryptographyCopied with commodity tools?Notes
125 kHz prox (HID Prox, EM4100, Indala)NoneYes, in secondsFixed ID, no authentication
MIFARE Classic (1K/4K)Crypto1, publicly broken in 2008YesHardened variants resist some older attacks, not all
Legacy HID iCLASS (standard keys)Proprietary, shared master keyYesThe standard key was extracted and published years ago
MIFARE DESFire EV2 / EV3AES-128, secure messagingNo known practical attackSecurity rests on key management
HID SeosAES-128, secure messagingNo known practical attackHID ecosystem; also used for phone credentials

MIFARE Classic

MIFARE Classic uses a proprietary cipher, Crypto1, which researchers broke publicly in 2008. Keys can now be recovered from a card with inexpensive tools, and many deployments never changed the default or widely published keys in the first place. Later "hardened" versions closed some attacks, but others still work against them. Treat any MIFARE Classic badge as cloneable.

Legacy iCLASS

Older HID iCLASS cards using HID’s standard security key share one master key across customers. That key was extracted and published over a decade ago, so standard-key iCLASS is cloneable. iCLASS SE and Elite configurations with site-specific keys are a different case and need to be checked individually.

DESFire EV2/EV3 and Seos

Both use AES-128 with mutual authentication and encrypted communication between card and reader, and neither has a known practical cloning attack today. The real differences are commercial and operational:

  • DESFire is made by NXP and supported by readers from many manufacturers, which keeps future hardware choices open.
  • Seos is HID’s credential. It works best end to end in HID’s ecosystem and is widely used for phone-based badges.
  • Either can be undone by poor key management: one key for every card, keys shared with an integrator’s other clients, or no plan for rotating them.

The setting that matters more than the card

Many readers can be configured to read only a card’s serial number (its UID or CSN) instead of authenticating it. The serial number is not secret and can be emulated. A DESFire EV3 card read this way gives you little more protection than prox. Ask your integrator, in writing, whether each reader performs a cryptographic authentication with site-specific, diversified keys.

Choosing what to move to

  1. Find out what you have today, card and reader, door by door.
  2. Decide whether phone credentials are in scope, since that narrows reader choice.
  3. Pick a credential that supports diversified keys you control, not your integrator.
  4. Plan the cutover so the old technology is switched off at the reader, not just stopped at the badge printer.

Our reports name the credential and reader class we would move you to, and why, with a price range. We take no referral fee or commission on any product we name. How the assessment works.

Last reviewed September 23, 2026.

Contact

Want to know how your sites would hold up?

Twenty minutes is enough to know whether an assessment is worth it. We’ll be honest either way.