"A starter's map to 13.56 MHz: PN532, Chameleon Ultra and Proxmark3, and where the law sits"
A starter's map to 13.56 MHz: PN532, Chameleon Ultra and Proxmark3, and where the law sits
Everything from your office door fob to your credit card to your passport speaks on 13.56 MHz. It is the most well-mannered corner of the RF spectrum: short range (a few centimetres, by design), low power, and everywhere. It is also the corner of hardware security where the tooling gap between "curious" and "capable" is widest, which makes a map of the territory genuinely useful. This guide compares the three tools most Australian hobbyists end up choosing between, the PN532, the Chameleon Ultra and the Proxmark3, and sets out plainly what the law allows. The short version: research your own cards, never copy anyone else's, and know that unauthorised access using a cloned credential is a crime regardless of how the clone was made.
The three tools, in one line each
- PN532 (~A$36): a reader/writer chip on a breakout board. Reads card UIDs and data on common card types, writes to blank cards, and acts as a card emulator at a basic level. This is the "learn the protocol" tool.
- Chameleon Ultra (~A$59): a battery-powered card emulator. It impersonates high-frequency cards (MIFARE Classic, DESFire, and more) so you can test readers and experiment with how a card responds under controlled conditions. Developed openly by the RFID Research Group, with documentation covering its capabilities.
- Proxmark3 RDV4 (~A$119): the full-stack research instrument. It sniffs traffic between a real reader and a real card, decodes, reads, writes, emulates and cracks weak crypto on legacy cards. The RfidResearchGroup/Proxmark3 repository is the maintained home of the firmware (the "iceman" fork lineage) and its extensive wiki.
They are not competitors so much as a ladder. Most people should start at the bottom rung.
What each tool is actually for
The PN532 answers "what is this card and what does it say?" Plug it into any microcontroller or USB-UART bridge, run an open-source client, and you can read the UID, dump the memory of a MIFARE Classic card whose keys you know, and write to blank cards. It cannot sniff live traffic and its emulation is shallow, but for understanding ISO 14443 framing, NDEF tags on posters, and how your library card is structured, it is the correct first purchase. It also pairs naturally with an ESP32: the RFID-fob corner of our flipper companion builds covers the reader-as-peripheral pattern.
The Chameleon Ultra answers "how does a reader behave when the card is under my control?" Emulation is the security-research heart of the 13.56 MHz world: to test whether a door reader actually validates anything beyond a UID, you need a device that can present arbitrary credentials. The Ultra runs proper card operating-system behaviour rather than the toy emulation of older Chameleons, charges over USB-C, and works standalone or over Bluetooth from a phone app. Our Chameleon Ultra ships with firmware set up for exactly this class of work.
The Proxmark3 answers "what is the reader and card saying to each other, and why?" It is an analysis instrument first and an emulator second. Sniffing a live session reveals which authentication scheme a system uses, which is the first step in assessing it, and the iceman client's scripting layer makes repeatable test procedures possible. The RDV4 revision added swappable antennas, which matter more than the marketing suggests: LF (125 kHz) and HF (13.56 MHz) research on one device means one tool covers a building's entire badge ecosystem. Our Proxmark3 Easy RDV4 is the accessible entry into this tier.
Where the law sits in Australia
This section is not legal advice, but the principles are clear enough to state.
Cloning a credential you are not authorised to hold is where offences begin. The critical legal fact is that the offence attaches to what you do with a copied credential, not to owning the hardware. Duplicating your own gym locker fob so you do not carry two is a different universe from duplicating a colleague's building access card. Under Commonwealth law, unauthorised access to (or modification of) data in a computer with intent to commit a serious offence is covered by the Criminal Code (Part 10.7, the cybercrime provisions), and state trespass and unlawful-entry offences can attach to using a cloned badge to get through a door you were never entitled to pass. Possession of an emulator or a Proxmark3 is not an offence; using either to gain unauthorised access is.
Payment cards are separately and aggressively protected. Card-skimming offences carry their own dedicated criminal provisions across every Australian jurisdiction, with penalties well above general unauthorised access. Do not experiment with anything payment-adjacent beyond reading your own card's balance-checking data, and ideally not even that.
Venue rules exist independently of criminal law. Even where a technical experiment is arguably lawful, testing against a live system you do not own (a transport gate, a hotel lock, a workplace reader) without written permission will end your access, and possibly your weekend, without any charge being laid. The same permission-first discipline we apply to RF testing in wifi-testing-law-australia applies here: written authorisation or your own equipment, nothing in between.
The lawful-use playground is bigger than it sounds: your own cards and fobs, blank cards you own, readers you buy yourself, and lab setups you build. That is enough to learn ISO 14443 inside out.
What a first lab setup looks like
Skill builds from equipment, so it helps to picture the lawful bench before spending. The core setup is one reader and a pile of cards you own: a PN532 or the reader side of a Proxmark3, blank MIFARE Classic and NTAG cards, and the fobs from your own gym and transit accounts (where terms of use permit reading; most transit operators do not, so check before you tap anything with a contract attached). From there the standard progression is: dump a card whose keys you know, write a copy onto a blank you own, then test that copy against a reader you bought. That closed loop exercises every skill the commercial tools use, without ever touching a system that belongs to someone else.
The second addition is a log. Every professional engagement in this field lives or dies on documentation, and the habit transfers: record what card type, what authentication scheme, what result, what timestamp. Six months in, that log is the difference between "I think I tried that" and a body of evidence about which credential technologies in your own life are weak. It is also the artefact that turns a hobby into something you can show an employer.
Choosing: a decision path
- "I want to understand the cards in my wallet and door fob." PN532 (our kit includes the breakout, cable and header set). Total spend under A$40.
- "I want to test my own readers and experiment with emulation." Chameleon Ultra (A$59.01), plus a few blank cards; a fob multipack (A$19.90) gives you practice material.
- "I want to sniff, analyse and do it properly." Proxmark3 Easy RDV4 (A$119.00). Budget a weekend for the client setup; the wiki is excellent but assumes you read it.
The ladder is real: skills from the PN532 transfer directly, the Ultra's workflows make sense once you understand card structure, and the Proxmark3 rewards every hour you spent on the cheaper tools.
Parts list, AU-priced
- PN532 NFC kit - A$36.48 - protocol learning
- Chameleon Ultra - A$59.01 - emulation and reader testing
- Proxmark3 Easy RDV4 - A$119.00 - full analysis instrument
- RFID fob multipack - A$19.90 - practice material you own
Affiliate disclosure: products linked are our own store.
Start with what you own, get permission for everything else, and the 13.56 MHz world is one of the most rewarding corners of hardware security going.