mirror of
https://github.com/RfidResearchGroup/proxmark3.git
synced 2026-10-08 11:47:55 +00:00
secureChannel was the constant DACEV1, and there was no way to override it, so a card in LRP mode could never be authenticated - chk reported no keys on a card 'hf mfdes detect' handles fine. When the key settings were unreadable it gave up instead of probing. Work the channel out per AID: the key settings give the algo, and for an AES app one AuthenticateLRPFirst probe separates EV1/EV2 from LRP, which the settings byte cannot. When the settings are unreadable, fall back to DesfireCheckAuthCommands() the way detect does. --schann d40|ev1|ev2|lrp pins it and skips detection. Only AES is tried on an LRP channel. Also clear the session after a found key, so the next key number starts a first auth rather than an EV2/LRP non-first one. Co-Authored-By: Claude Opus 5 (1M context)