{
  "id": 1906893,
  "title": "How Android HCE Creates New Attack Surfaces for MIFARE DESFire",
  "url": "https://urgent.news/2026/08/19/how-android-hce-creates-new-attack-surfaces-for-mifare-desfire",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-19T07:00:04.000Z",
  "source": {
    "name": "HackerNoon",
    "slug": "hackernoon",
    "url": "https://hackernoon.com/how-android-hce-creates-new-attack-surfaces-for-mifare-desfire?source=rss"
  },
  "original_language": "en",
  "account": "Mifare DESFire keycards are highly secure and used in various sectors, including access control, transit, and payments. However, Android's HCE (Hardware Cryptography Engine) has introduced new attack surfaces for these cards. These keycards are nearly impossible to clone due to their strong security architecture. Android HCE enables the emulation of DESFire cards on smartphones, making distribution and management easier. This technology is exploited to acquire keys for DESFire cards. The provisioning process can be intercepted and decoded, revealing card data and keys. The DFname is used to call the card, allowing for regular DESFire commands. VCA (Virtual Card Architecture) is present on EV2 and above DESFire cards and provides more security features than VCA. Rooting an Android device is necessary to bypass Play Integrity, which ensures device security. However, this process is difficult and may change as Google updates its checks. Once the card has been provisioned on Google Wallet, the data can be captured using MITMproxy. After decoding the data, the card data and keys can be obtained, allowing for the creation of a clone and modification of card values. DESFire emulators are limited, but a new app, ZeroFire, is set to enable emulation of physical and VC DESFires. Despite the complexity and security of the Mifare DESFire, its continued use is a testament to its robust design.",
  "summary": "A security-focused look at MIFARE DESFire, Android HCE, virtual cards, mobile provisioning, and the expanding NFC attack surface.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}