[00:02.540 --> 00:05.460] So, if I don't make sense, please excuse me. [00:05.780 --> 00:06.760] Speak louder. [00:07.040 --> 00:07.680] No, you. [00:10.700 --> 00:11.460] Okay, fine. [00:34.630 --> 00:39.650] Should have probably prepared a little bit better, but I'll be in a moment. [00:44.020 --> 00:45.980] It was fine. [00:47.220 --> 00:56.160] The way I'm doing this presentation, there's actually a story-based narrative that goes along with this, where there's a protagonist that uses a lot of the techniques that I'm talking about. [00:56.440 --> 00:59.170] I'm trying to give some sort of practical example for these things. [00:59.890 --> 01:13.820] So, I'm trying to find a way that I can read the story and have the presentation up at the same time, but OpenOffice really seems to fail at that, because everything else seems... all the windows just seem to go away when I put in a presentation mode. [01:22.860 --> 01:24.980] I have it. [01:34.020 --> 01:38.460] You need to flip around so you can see the screen and then you'll be able to do it. [02:22.920 --> 02:25.000] And we're going to start, finally. [02:42.060 --> 02:42.980] Is this mic working? [02:43.160 --> 02:43.300] Great. [02:47.740 --> 02:50.520] Let me make sure that I can actually... [02:50.520 --> 02:51.260] Oh, thank God. [02:51.580 --> 02:52.100] Thank God. [02:53.300 --> 02:54.180] Okay, so... [02:55.900 --> 02:59.340] So, the title of this talk is Lock Bypass Without Lockpicks. [02:59.480 --> 03:04.140] I'm going to explain a little bit why I chose to talk about this topic in a moment. [03:04.380 --> 03:08.620] But, like I said, this is going to be partially a story-based narrative. [03:10.260 --> 03:12.160] But, let's get into it. [03:14.580 --> 03:22.440] So, before we start into the story, I want to first talk a little bit about the topic itself and myself just a tiny bit. [03:22.660 --> 03:26.080] And then talk about some of the techniques that I'm going to be... [03:26.080 --> 03:28.480] that are going to be used by the protagonist. [03:28.860 --> 03:34.680] So, to start off, me, I'm a security nerd and I like to think I'm an artist sometimes. [03:35.280 --> 03:37.860] If the story sucks, I'm sorry. [03:39.640 --> 03:40.720] I'm not a writer. [03:40.980 --> 03:42.520] I work for Core Security. [03:43.900 --> 03:47.580] If you want to contact me, that's my email address and my Twitter account. [03:47.740 --> 03:48.280] But I'm boring. [03:48.940 --> 03:53.520] And you came here to listen to me talk about Lock Bypass and not about myself. [03:53.760 --> 03:54.460] So, let's move on. [03:55.920 --> 03:58.660] So, why Lock Bypass without Lockpicks? [03:59.040 --> 04:00.400] Lockpicking is sexy. [04:00.400 --> 04:01.680] Lockpicking is fun. [04:01.880 --> 04:05.340] There are lockpicking competitions and everybody's really excited about it. [04:05.400 --> 04:09.660] Lockpicking is in the movies, but it isn't really that big a threat. [04:09.920 --> 04:11.900] And I know everybody is like, No, it is! [04:12.060 --> 04:18.720] But really, if you get locked out of your apartment, are you going to bust out your lockpicks? [04:20.280 --> 04:22.680] Okay, but that's because you're hackers and it's fun. [04:25.280 --> 04:39.900] If you were a normal person, you'd probably go looking for an open window or a door that wasn't actually locked or you might even break a window or you might try a whole bunch of other things that don't involve lockpicking and will probably get you in faster than lockpicking will. [04:41.220 --> 04:42.900] Lockpicking generally takes a while. [04:43.820 --> 04:52.500] It takes a while to get good at lockpicking to the point where you can open a lock that you've never been exposed to in under five minutes. [04:52.500 --> 05:04.540] And I like to think that when you're talking about physical security, any attack that takes longer than five minutes is too dangerous to really consider if you're an attacker because there's a chance of being found. [05:05.860 --> 05:11.480] Under the five-minute mark, it starts to get more dangerous, it starts to be more of a threat. [05:11.800 --> 05:17.700] And the majority of these things that I'm going to talk about are going to take less than five minutes to achieve. [05:17.700 --> 05:19.440] They are easy techniques. [05:19.440 --> 05:23.160] Some of them are blatantly obvious, and you might want to throw things at me. [05:23.360 --> 05:28.820] Please refrain unless it's a Club-Mate, in which case please do because I would love one right now. [05:30.700 --> 05:41.680] But generally when lock manufacturers put security features into their products, it's to frustrate lockpickers or it's to frustrate people with bolt cutters. [05:42.280 --> 05:45.080] Other things aren't really considered very much. [05:45.240 --> 05:53.960] I'm not really going to talk about brute force, cutting locks off and things like that because that's a little bit too obvious for me. [05:55.480 --> 06:01.420] But I'd like to point out that that is a big concern, that cutting off a lock is really effective. [06:03.060 --> 06:04.360] Anyway, so... [06:04.360 --> 06:14.580] But security features mostly focus on things like lockpicking, which aren't actually threats, but because they're so sexy, it looks great for the lock manufacturer to be like, nobody can pick this lock. [06:16.140 --> 06:16.740] So... [06:17.500 --> 06:24.800] New tumblers, in the same vein, don't break old attacks when you're talking about things that don't involve actually manipulating the pin tumbler. [06:25.060 --> 06:26.800] It just sort of makes sense. [06:28.220 --> 06:40.560] Now, the big thing, the huge thing, and if you take nothing else home from this, lock manufacturers determine the quality of the lock. [06:41.620 --> 06:47.480] lock consumers, the people buying and using these locks, are determining how the locks are used. [06:47.700 --> 06:53.460] And poor lock usage is just as bad, if not worse, than a bad lock. [06:54.980 --> 06:56.660] So take that home, if nothing else. [06:57.300 --> 06:59.740] One big thing is that there's no need to carry lockpicks. [06:59.840 --> 07:02.080] If you're not picking locks, you don't have to carry lockpicks. [07:02.180 --> 07:05.740] You don't have to worry about the local laws around owning or carrying lockpicks. [07:06.560 --> 07:19.180] If an attacker is discovered, they're not going to be subject to further penalties for having bulgarious tools, or whatever the terminology is in the particular place you are. [07:19.600 --> 07:23.960] Because these tools are illegal to own or carry in some states, unless you have a license. [07:24.220 --> 07:26.200] Which, admittedly, is really easy to get. [07:26.320 --> 07:30.220] You can just go to a correspondence school and get that in a very short time. [07:30.400 --> 07:34.140] But anyway, like I said before, it's quickly learned and quickly performed. [07:34.360 --> 07:35.500] It's under that five minute mark. [07:35.640 --> 07:37.600] It's dangerous and anybody can pick it up. [07:38.120 --> 07:38.460] So... [07:40.480 --> 07:43.140] The character in this story is Waldo. [07:43.380 --> 07:44.920] He's a tribute to another Waldo. [07:45.280 --> 07:46.940] He's a very hard to find guy. [07:47.280 --> 07:48.600] He likes red and white stripes. [07:49.500 --> 07:50.660] A bit of a MacGyver. [07:50.800 --> 07:51.820] He's very resourceful. [07:52.060 --> 07:54.900] And, as you'll see, he's a physical security ninja. [07:56.440 --> 08:01.880] So, if the trademark holder for Waldo is in the room, I'm really sorry. [08:02.440 --> 08:03.580] Please don't sue me. [08:03.780 --> 08:04.960] And, also, thanks for coming to HOPE. [08:07.340 --> 08:08.060] That's great. [08:10.880 --> 08:13.240] So, let's talk about the techniques a little bit. [08:14.020 --> 08:17.700] So, the first thing I want to talk about is abusing ineffective lock usage. [08:18.560 --> 08:25.060] Now, the first bullet is intensely obvious and I almost did not put this on the slide at all. [08:25.780 --> 08:32.160] But, there are some situations, certain locks may look like they're locked, but might actually not be. [08:33.720 --> 08:36.180] This actually might be of use to an attacker. [08:36.380 --> 08:46.720] If you can physically enter the premises at one time and then sort of put the lock in a state where it looks locked, but really isn't, that might be of use to you. [08:47.160 --> 08:50.400] And that's actually one of the big reasons why I still kept this on the slide. [08:50.400 --> 09:03.960] One example is if you take a business card and put it in between the hasp and the receiving portion of the door frame for the hasp, there is, as long as the business card is of the right size and the door frame is of the right size, you won't be able to see the business card at all. [09:04.160 --> 09:08.220] The lock is essentially completely useless, even if it's locked. [09:09.980 --> 09:16.320] Now, in some cases, having the hasp pushed into the door will actually cause the lock to be unlocked. [09:16.320 --> 09:26.060] So it won't always appear locked, but there's a sort of backdoor danger with that a little bit. [09:26.300 --> 09:29.380] But sometimes people are just stupid or absent-minded. [09:30.020 --> 09:31.500] So keep that in mind. [09:31.660 --> 09:32.700] Useless lock placement. [09:33.260 --> 09:46.420] We're going to see some examples of this in just a moment, but if you put a lock onto a part that moves and you can get around this, maybe the assets that you're trying to protect aren't really quite so protected. [09:47.440 --> 09:50.420] Or if there's a removable part, even better. [09:50.720 --> 09:52.920] Again, we're going to see examples of this. [09:53.040 --> 10:09.940] But another very important thing is if you're locking a container or you're mounting this lock to something, you need to be very sure, and I see this a lot, that you cannot destroy, disassemble, or manipulate this container or this mounting hardware to the point where your assets are no longer protected. [10:10.120 --> 10:11.760] And this is a big concern. [10:12.680 --> 10:23.720] A lot of times you'll see locks that are placed onto something with mounting brackets that are screwed in with screws that are exposed. [10:24.820 --> 10:26.060] So that's cute. [10:28.520 --> 10:29.940] So here's an example. [10:30.140 --> 10:39.660] So this is a lock placed by a repo guy on a house that the tenant was forcibly evicted from. [10:40.500 --> 10:43.880] You'll notice that there are exposed Phillips head screws. [10:45.820 --> 10:50.880] An attacker would not need to break this, although it looks like it would break pretty easily. [10:51.680 --> 10:54.580] You wouldn't need to cut the lock, you wouldn't need to pick the lock. [10:55.660 --> 11:01.080] You can unscrew the screws and take the bracket off, and maybe you have yourself a new lock to play with as well. [11:02.160 --> 11:04.120] And also a new house to play with. [11:07.140 --> 11:08.920] So that's also cute. [11:10.680 --> 11:11.560] So here's... [11:16.210 --> 11:18.970] Yeah, I had the same reaction when I saw this too. [11:20.830 --> 11:22.830] So, sweet, free dirt bike. [11:25.690 --> 11:32.810] So, to a very, very casual and possibly drugged observer, this looks fine. [11:33.090 --> 11:40.310] But, you know, it very quickly becomes obvious when you take a moment to look at it, that it could just be lifted off. [11:41.130 --> 11:46.730] You're certainly not driving that dirt bike away, but if you have a pickup truck, well, you... sweet, free dirt bike. [11:48.010 --> 11:52.270] So, that's an example of where a lock might look locked, but not actually. [11:52.490 --> 11:56.330] I wish I had a better example of that, but this is... well, this is funny anyway. [11:58.510 --> 12:00.910] So, here's another good example. [12:01.650 --> 12:12.650] This looks okay, because you're sort of mounted... it's sort of mounted to the frame with a U-lock, which are a little bit hard to break unless you're using liquid nitrogen in a pry bar or bolt cutters or something like that. [12:13.210 --> 12:17.510] The problem is that this wheel comes off with a quick flick and pull. [12:17.930 --> 12:21.050] It's one of the quick-release wheels that you see on bicycles frequently. [12:21.690 --> 12:24.450] Even if it wasn't, you could take off the wheel with a wrench. [12:26.130 --> 12:32.370] So, this bike you could actually ride away, and then there's going to be a U-lock sitting on a bike rack. [12:32.970 --> 12:33.950] Very lonely. [12:36.450 --> 12:38.250] So, bye-bye bicicleta. [12:40.690 --> 12:47.970] So, this is sort of under the lock affixed to removable part category. [12:51.010 --> 12:53.150] So, this wheel is very secure. [12:55.210 --> 12:56.350] Nobody's taking this wheel. [12:57.550 --> 13:00.070] The rest of the bike, though, I don't know. [13:00.210 --> 13:04.830] Maybe somebody's just gotten... maybe they thought a unicycle was too easy. [13:06.190 --> 13:07.770] And this is what they're riding around. [13:07.910 --> 13:12.290] But I think it's more likely that there was a bike attached to this at some point. [13:12.290 --> 13:18.090] I found another picture of just a bike frame, and that was really funny, but I couldn't justify putting both in. [13:18.370 --> 13:21.270] So, just visualize that for a second. [13:22.430 --> 13:23.270] But anyway, so... [13:23.970 --> 13:27.310] So, again, the lock is attached to a removable part. [13:27.570 --> 13:30.370] I also see a lot of bikes that are locked up in Boston. [13:31.270 --> 13:37.110] Also, by the way, bike theft in Boston is incredibly common, and I'm not surprised in the least. [13:39.330 --> 13:43.790] But another thing that I see frequently is a lock attached to the bike spokes. [13:44.210 --> 13:46.410] I don't know if you are... any of you are bike enthusiasts? [13:46.650 --> 13:46.790] Anybody? [13:48.010 --> 13:48.470] Hey! [13:48.770 --> 13:49.050] All right! [13:49.290 --> 13:49.410] Great. [13:49.770 --> 13:50.670] Infinite gas mileage. [13:50.830 --> 13:51.190] That's great. [13:52.430 --> 13:56.250] So... but bike spokes are really easy to break. [13:57.150 --> 14:07.430] They're also really easy... there's a lot of bicycle... bicycle wheels where you can pull the spoke out without damaging it, and then pop it back in. [14:08.250 --> 14:10.210] So, it doesn't make sense to lock to that. [14:12.730 --> 14:13.530] And finally... [14:15.610 --> 14:16.890] What are you... what are you doing? [14:18.270 --> 14:21.450] Like, that's... that chain lock I could probably chew through. [14:22.650 --> 14:25.810] A lock is... it looks like you bought it at a convenience store. [14:26.310 --> 14:31.890] And... and it's... it just... there's no way that somebody could see this and not think, well, I could just lift that off. [14:31.890 --> 14:34.230] And it's not even like it's attached to a wheel. [14:34.430 --> 14:39.030] So, somebody could literally just pick this up and ride it away in under a minute's time. [14:40.710 --> 14:41.210] So... [14:42.470 --> 14:44.090] Egregious security fail aside. [14:44.910 --> 14:47.090] Let's talk about shimming attacks for a second. [14:47.570 --> 14:51.650] If you guys have stopped by the lockpick village, you've certainly heard something about shimming. [14:51.830 --> 14:54.730] If you haven't stopped by the lockpick village, why not? [14:55.310 --> 14:55.810] Go! [14:57.230 --> 15:04.230] Anyway, so shimming attacks basically involve a shim or some... something... [15:04.230 --> 15:09.470] The... the... the most basic definition of a shim is something that you stick in between two other things for some purpose. [15:09.870 --> 15:10.650] Very descriptive. [15:11.150 --> 15:21.810] In this... in this particular case, in the term of... in the sense of lock bypass, you're talking about changing the way that a lock operates by sticking some piece of something in between two parts. [15:21.810 --> 15:25.830] Usually the hasp and the... the receiving portion of the hasp. [15:25.990 --> 15:33.850] So in the case of a padlock, sticking it down in... around the shackle to push away the hasp and to release the shackle and... [15:34.650 --> 15:37.030] Effectively make the... the lock useless. [15:38.250 --> 15:43.310] So frequently you're talking about a thin sheet of metal or plastic or something like that. [15:43.610 --> 15:44.970] Some rigid material. [15:45.630 --> 15:50.470] And frequently when you're talking about locks, you're talking about targeting the hasp because that's really what you want to go after. [15:50.470 --> 15:54.330] And this can be done with all sorts of types of locks, padlocks, door locks. [15:54.470 --> 16:00.150] If any of you have heard of the credit card trick, that's just shimming a door-mounted lock. [16:01.630 --> 16:05.130] And then handcuffs are also pretty easy and fun to shim. [16:06.610 --> 16:12.410] With the more high-end handcuffs, and actually with the... with higher-end versions of any of these, except the door-mounted lock... [16:12.410 --> 16:16.530] With padlocks and handcuffs, the higher-end versions have... generally have shim protection. [16:17.530 --> 16:25.210] Door-mounted locks, sometimes you'll see a bracket placed over the... right next to the doorknob so that you can't shim it. [16:26.310 --> 16:29.070] But oftentimes that's just screwed on as well. [16:29.790 --> 16:30.790] So that's cute. [16:32.850 --> 16:36.910] But with door-mounted locks, there's a lot of ways that you can... [16:36.910 --> 16:40.810] Because this is mostly up to the lock consumer to prevent shimming attacks. [16:41.010 --> 16:47.370] Because the shimming attacks on door-mounted locks are mostly enabled by the door frame and how that's working. [16:47.370 --> 16:51.690] If the hinges are on the wrong side, even if they're, you know, totally... [16:52.210 --> 17:00.230] Like, melted onto the door, you can still get quite a bit of purchase if you're on the wrong side of the door trying to shim it. [17:01.370 --> 17:02.330] French doors... [17:02.890 --> 17:03.690] I don't... [17:03.690 --> 17:08.110] I don't really know how you can prevent shimming attacks on French doors because... [17:08.110 --> 17:13.050] You know, even if you put a bracket this tall on it, you could still, like, maybe take a guitar string and... [17:13.050 --> 17:15.990] Just curve it a little bit, stick it through, and just pull. [17:16.470 --> 17:18.770] Just sort of floss a little bit with the door. [17:20.950 --> 17:23.910] So that's another really big concern. [17:24.110 --> 17:25.490] And shimming attacks are really easy. [17:25.650 --> 17:28.330] If you've never shimmed a padlock, seriously. [17:28.350 --> 17:29.770] Go to the lockpick village. [17:32.310 --> 17:32.790] So... [17:34.310 --> 17:37.870] So here's what a shim looks like on a padlock. [17:38.430 --> 17:42.290] You can see it's just a little piece of metal from a beer can in this case. [17:42.910 --> 17:48.270] And if you take a look at the shackle, there's the little receiving part for the hasp. [17:48.710 --> 17:53.690] And basically all you're doing is just pushing that little piece of metal out to keep... [17:53.690 --> 17:56.850] That's keeping the shackle in there so you can pull it right out. [17:59.050 --> 18:05.530] And here's a little picture of the credit card trick, as it were, shimming a door-mounted lock. [18:07.130 --> 18:11.030] So it works in a very, very similar way to the padlock shimming. [18:13.130 --> 18:16.970] So there's a whole class of locks called passage locks. [18:17.130 --> 18:23.350] Now passage locks are different from most locks in that they can only be locked and unlocked from one side. [18:23.490 --> 18:26.790] Unless there's a fail-safe in the case of, like, pop button locks. [18:27.110 --> 18:31.870] Pop button locks, by that I mean the kind where you just push the button in and then there's... [18:32.630 --> 18:35.670] You know, when you jiggle the doorknob, it just unlocks itself. [18:35.810 --> 18:39.590] Or there's a hole on the other side where you can just stick a screwdriver in and it opens it up. [18:39.730 --> 18:41.750] And you can scare the person who's in the bathroom. [18:41.890 --> 18:45.870] Because really, I don't know if you're using this for anything except bathroom. [18:45.870 --> 18:48.890] I don't know what you're doing in security. [18:50.390 --> 18:52.970] But anyway, so they're not really... [18:52.970 --> 18:56.110] So passage locks, for the most part, are not meant for anything except privacy. [18:56.550 --> 18:59.230] A lot of times you'll see these in conjunction with normal locks. [18:59.290 --> 19:07.510] It can be locked and unlocked from both sides such that when somebody's on the inside of something, they can maintain their presence as the only presence in the room. [19:08.890 --> 19:15.030] So things like chain locks that you'll see on hotel doors are the more recent, like, little... [19:16.910 --> 19:18.890] This looks kind of weird. [19:20.730 --> 19:22.390] I feel like I'm in fifth grade. [19:24.690 --> 19:29.410] But a lot of these can be manipulated from the wrong side. [19:29.590 --> 19:31.290] Again, based on lock usage. [19:31.990 --> 19:33.810] One big thing that I wanted to mention. [19:34.390 --> 19:36.550] A lot of RFID sensors. [19:37.190 --> 19:39.150] They want people to be able to get out. [19:39.490 --> 19:52.630] So if there's like a visitor who does not have an RFID card, and they go into the building with somebody who does have an RFID card as a visitor, and then their RFID card carrying buddy leaves, you don't want them to be stuck there. [19:52.890 --> 19:54.030] That's kind of a problem. [19:55.050 --> 20:01.270] So what you do is you put a motion sensor on the other side of the door, which is called a request to exit sensor. [20:01.490 --> 20:03.210] And there are a couple different ways to trigger this. [20:03.750 --> 20:12.770] One of the best and kind of funniest is to take a balloon and stick it under the door, and blow it up and let it go. [20:12.870 --> 20:13.870] And the balloon goes... [20:14.870 --> 20:17.850] And the motion sensor goes, Hey, you can go now. [20:18.030 --> 20:19.630] And you're like, going in. [20:20.550 --> 20:21.950] So that's cool. [20:22.250 --> 20:23.210] I like that. [20:24.710 --> 20:33.030] But you find these on practically every RFID sensor protected door ever. [20:34.610 --> 20:35.990] So that's funny. [20:37.470 --> 20:45.650] But, you know, aside with the problems of credential copying with RFID keys, the request to exit motion sensor is a big problem. [20:45.990 --> 20:48.130] And it's a very easy attack to launch. [20:48.330 --> 20:58.290] And, you know, if somebody stops you and you get detained with a balloon, they'll be like, oh, I guess he was just secretly a party clown. [20:59.390 --> 21:00.230] Or something. [21:00.630 --> 21:00.930] I don't know. [21:03.390 --> 21:11.490] But chain locks are an example of a passage lock that can actually be really easily manipulated through a door jam. [21:11.730 --> 21:15.770] And actually, I have a video that I recorded about this. [21:16.990 --> 21:18.210] Where are you, video? [21:26.800 --> 21:28.240] It's really dark. [21:29.560 --> 21:32.540] But, so, here's a... [21:33.400 --> 21:35.040] That's a plastic folder. [21:36.320 --> 21:40.140] This chain lock is really, really old. [21:40.420 --> 21:42.320] I live in a crappy apartment building. [21:42.640 --> 21:45.920] And this was installed probably at least 100 years ago. [21:47.880 --> 21:54.560] So, basically, the idea is that you take both sides of the folder and you can manipulate it, sort of bending back and forth. [21:54.560 --> 22:05.180] And you can, through the door jam, with a very small amount of space, you can actually manipulate the chain lock and then curve it the other way sharply when you have it in the right position. [22:06.620 --> 22:08.100] And this will happen. [22:13.850 --> 22:15.050] So, that's fun. [22:19.750 --> 22:21.050] Definitely try this at home. [22:21.370 --> 22:22.430] It's great fun. [22:24.230 --> 22:26.690] But it's also pretty simple to do. [22:27.150 --> 22:29.690] This is edited down a little bit for time reasons. [22:29.930 --> 22:34.250] But this attack took about 3 minutes, 30 seconds in total. [22:34.550 --> 22:36.010] But I cut it down by about 2 minutes. [22:36.470 --> 22:38.130] Again, it's under the 5 minute mark. [22:38.410 --> 22:44.430] And I had always sort of known that this was possible, but never really tried it before. [22:44.810 --> 22:47.350] So, again, it's really easy to learn. [23:04.790 --> 23:09.530] So, the last thing I want, or maybe the last thing I want to talk about, is an alternate point of entry. [23:09.870 --> 23:11.390] And this is pretty straightforward. [23:11.830 --> 23:16.390] But roof access, not many people think about roof access. [23:17.770 --> 23:20.990] Windows, again, with the apartment thing. [23:20.990 --> 23:24.070] You know, people frequently leave windows unlocked. [23:24.250 --> 23:26.750] Especially if you're talking about on the second story or higher. [23:26.930 --> 23:29.690] Because they're figuring, well, no one's going to be on the second story. [23:30.090 --> 23:31.330] Unless they have a ladder. [23:33.230 --> 23:34.970] Or unless they're on the fire escape. [23:35.110 --> 23:36.630] Now, interesting thing about fire escape. [23:36.790 --> 23:47.330] Because of fire code, generally, doors have to open, to be able to open without any sort of locking mechanism from one side. [23:47.330 --> 23:51.530] So, generally, you have something somewhat akin to a passage lock. [23:51.710 --> 23:53.270] It's sort of a one-way door. [23:54.410 --> 23:57.870] But frequently, these have the problem of being shimmable. [23:58.830 --> 24:06.450] Some door-mounted locks cannot be shimmed, because the hasp is locked in place when the lock is locked. [24:07.330 --> 24:09.370] So, it's not exactly possible to shim it. [24:09.510 --> 24:16.510] But with this type of thing, you can't have a lock, due to city planning regulations, fire code. [24:17.670 --> 24:23.610] So, frequently, fire escape doors are an interesting point of entry. [24:24.070 --> 24:26.690] The one thing about that is that they're usually alarmed. [24:27.130 --> 24:29.270] So, that might not be a great idea for an attacker. [24:30.730 --> 24:35.250] One really huge thing is drop tile ceilings and raised floors. [24:35.450 --> 24:43.390] Very popular in server rooms for HVAC reasons, and for preventing flooding damage, things like that. [24:43.390 --> 24:57.110] The problem is that if you have two adjacent rooms, both with drop tile ceilings or raised floors, there is a very good chance that the wall does not actually extend to the real floor. [24:57.350 --> 25:03.690] So, there might be a crawl space underneath which you can completely bypass some locked door. [25:05.430 --> 25:07.190] So, that's kind of funny. [25:11.170 --> 25:16.490] So, this is a grappling hook, 25 foot rope, available on SouthOrd.com. [25:16.790 --> 25:19.010] I haven't ordered one yet, but one day. [25:19.390 --> 25:21.190] One day I'm going to get one of these puppies. [25:21.730 --> 25:30.110] But this would be perfect for getting onto a roof, or onto a fire escape, or some high window, or just, I don't know, being a weirdo, I guess. [25:32.650 --> 25:34.850] Oh, yes, credential theft or copy. [25:35.070 --> 25:36.870] This is important stuff, too. [25:37.890 --> 25:49.190] Because any time you're talking about any sort of key of any sort, there's always the chance that it can be copied in some way. [25:50.010 --> 25:54.910] Now, magnetic stripe cards are actually, I'd say, one of the best options. [25:55.350 --> 26:01.930] Because they cannot visually interpret the data being used to authenticate. [26:03.290 --> 26:08.990] You actually have to get access to the card, or some place where a copy of the card data is stored. [26:10.090 --> 26:15.730] So you need, in order to copy one of these, you not only need access to the card, but also to a reader. [26:16.030 --> 26:29.530] So in order to copy one of these without somebody knowing, you need to somehow get access to the card without them knowing, and then have access to a mag stripe reader, which you swipe it through, and then get it back without them knowing. [26:29.530 --> 26:32.250] So that's actually pretty good. [26:32.990 --> 26:48.610] As far as what can be copied, you can't read it from afar like you can with RFID cards because vendors will tell you, they'll swear up and down that you cannot read an RFID chip from more than about five inches away. [26:48.790 --> 26:50.630] And that's simply not true. [26:51.510 --> 26:54.010] It depends on the antenna that you're using. [26:54.170 --> 26:56.850] If you're using the standard hardware, sure. [26:57.090 --> 26:59.510] Yeah, you can't read it from more than about five inches away. [27:00.930 --> 27:12.890] But anybody seen the Hacking the Charlie card presentation from DEFCON a while back with the guys from MIT, the one that got silenced and then eventually released anyway? [27:13.110 --> 27:14.350] Because that always happens. [27:15.210 --> 27:23.290] Yeah, so they built a work cart and it just had a whole bunch of things like a fog machine and they had like a megaphone. [27:23.390 --> 27:25.330] They were saying, you know, we are stealing your data. [27:25.330 --> 27:32.390] But they also had a big antenna built into this shopping cart that was grabbing RFID data from all the cards around it. [27:32.650 --> 27:37.230] So you could theoretically put a large antenna like this into a cabinet or something in some office. [27:37.490 --> 27:44.930] And then as everybody walks by with their PROX cards or HID cards or bank cards, it's all going to get captured. [27:46.190 --> 27:46.890] Not good. [27:47.730 --> 27:52.670] Certain cards do have sort of cryptographic protection on them, but that's not terribly common. [27:52.670 --> 27:58.650] And a lot of the cards that do have that cryptographic protection, like the Charlie card, it's in crapto. [28:01.810 --> 28:04.090] So, enough about RFID stuff. [28:04.730 --> 28:07.250] Pinned Tumblr keys are actually pretty easy to copy too. [28:07.470 --> 28:14.410] You can either get physical access... you need physical access to the key, although you can impression a lock. [28:15.210 --> 28:19.550] Which is basically using the properties of the lock to get an idea of what the key actually is. [28:20.670 --> 28:28.850] But in terms of just talking about the keys, you can press the key into some malleable material like clay, play-doh, gum, whatever you have on you. [28:29.330 --> 28:33.570] Gum is actually really great for this because it's a pack of gum. [28:33.570 --> 28:41.730] Again, you get caught with a pack of gum and a balloon, and people might just think you carry around odd things. [28:44.910 --> 28:57.110] Anyway, this is great if you have a high security lock, like a Medeco lock, where you have a multi-dimensional pin Tumblr, where the pins are going to have to be rotated to a certain degree. [28:58.110 --> 29:07.090] Because there's an attack that's possible on one-dimensional keys, where you can actually just take a picture of the key, and then decode it visually from the photo. [29:07.990 --> 29:16.170] And we all know how much time taking a picture takes, and how many stealthy digital cameras are available. [29:16.430 --> 29:21.390] I think on ThinkGeek there's like a pair of glasses that's a digital camera. [29:21.390 --> 29:25.030] There's a Zippo lighter replica that's also a digital camera. [29:25.270 --> 29:27.810] There's a whole bunch of things, and that's just ThinkGeek. [29:28.470 --> 29:29.170] But anyway. [29:31.950 --> 29:33.930] So here's a blank slide, I made it myself. [29:34.350 --> 29:36.050] Not sure why it's in the presentation. [29:36.370 --> 29:36.850] Yeah! [29:40.330 --> 29:42.690] Oh, this is the storytime slide. [29:42.950 --> 29:48.270] So this is supposed to say storytime, but this is where I'm going to read the story to you. [29:49.990 --> 30:00.310] So if you didn't read the little abstract at the beginning of the presentation, our hero Waldo has been trying to infiltrate the Jalak Corporation, no relation to any real company. [30:00.630 --> 30:01.910] That's a total sham. [30:04.070 --> 30:04.630] Anyway. [30:05.230 --> 30:08.250] So Waldo has been clubbed and thrown in a room. [30:08.730 --> 30:09.210] So... [30:13.080 --> 30:17.400] Dazed and blurry, Waldo finally roused from his drug and blunt trauma-induced nap. [30:17.780 --> 30:24.660] His surroundings, unfamiliar and hostile, reminded him of why he was here, and more importantly, why his head hurts so much. [30:25.360 --> 30:36.680] With his arms unresponsive to his attempts to touch what felt like a goose egg growing right about where the corporation's goons clubbed him under his unmistakable red and white hat, Waldo noted that they were chained to his sides, which, additionally, [30:36.900 --> 30:38.600] were chained to the chair he was sitting in. [30:39.000 --> 30:49.400] The bulky, ancient padlock holding the chain together made a faint grinding sound in chorus with the links as its rusted exterior brushed the chain, tinkling as he strained to see just how bad his situation was. [30:50.340 --> 30:56.980] Waldo was beginning to regret that the usual hiding place for his picks was inside his hat, as he determined that his hands were not going to reach his head anytime soon. [30:58.320 --> 31:01.940] Waldo could tell that he hadn't been dosed very hard, given that his wits were still with him. [31:02.340 --> 31:07.960] He wriggled around and tried to stretch, noting that the chain did not seem to be looped through the rickety chair he'd been bound to. [31:08.620 --> 31:13.380] Sliding the chain up and off the back of the chair might be enough to free him. [31:14.260 --> 31:17.700] Waldo stood up, wobbly at first, and took a moment to steady himself. [31:18.620 --> 31:26.500] Attempting to hook the chair onto the handle of the door, keeping him in what appeared, somewhat ironically, to be a poorly maintained maintenance closet, proved unsuccessful. [31:27.260 --> 31:30.020] He began to wriggle and pull the chair out from the links of chain. [31:30.820 --> 31:35.280] After some amount of pulling and tugging, the chair popped out, sending Waldo into a nearby wall. [31:36.360 --> 31:39.940] Moments later, after shaking the chain from his torso, it lay beneath him, defeated. [31:40.760 --> 31:41.980] In a heap of old metal. [31:43.300 --> 31:50.460] Being a fan of old Sierra adventure games, Waldo reasoned that the chain used to bind him may prove useful in his escape, even if only as a makeshift weapon. [31:56.500 --> 31:58.880] Waldo slung the chain over his shoulder and reached for his hat. [32:02.200 --> 32:03.620] Shit, thought Waldo. [32:04.140 --> 32:05.440] The pic set wasn't there. [32:12.140 --> 32:17.220] So, Waldo escaped from the chair because the lock was affixed to the chain, but the chain was not wrapped through the chair. [32:17.460 --> 32:29.540] Now, if the chain was only wrapped through the chair once or twice, he might be able to wriggle around, manipulate the chain, so that there was more give on one side and he could pull it off his head or try to turn upside down and shake it off. [32:30.940 --> 32:34.740] But anyway, so that's an example of the lock-not-locked problem. [32:46.030 --> 32:50.070] Waldo removed his hat and ran his hands through his hair and the inside of his hat, just to be sure. [32:50.630 --> 32:52.030] Did they leave him anything at all? [32:53.290 --> 32:57.030] Starting to build a mental inventory of the things at his disposal, Waldo reached into his pockets. [32:57.610 --> 32:59.150] Something had to get him out of this mess. [33:00.150 --> 33:00.510] Lint. [33:01.750 --> 33:02.530] An old receipt. [33:04.290 --> 33:04.930] More lint. [33:06.150 --> 33:06.790] A penny. [33:08.490 --> 33:12.270] Waldo sighed and probed the bump on his head, wondering if he was really going to make it out of this. [33:12.730 --> 33:18.590] Gloomy and dusty, the room was lit only by a flickering light from an ancient, dying fluorescent bulb. [33:19.050 --> 33:21.290] There were no windows and only one door. [33:22.770 --> 33:24.310] Waldo jiggled the handle on the door. [33:24.870 --> 33:30.810] It stirred only barely, clicking and bumping against the metal frame, which was covered in a sickly green paint, flaking with age. [33:31.570 --> 33:35.310] Pressing against the door frame, Waldo could tell that the frame wasn't flush with the wall it covered. [33:35.870 --> 33:40.990] Bending the frame would be enough to allow for manipulation of the hasp, meaning freedom from this dusty, makeshift prison. [33:42.070 --> 33:46.710] Unfortunately, Waldo had nothing remotely like a pry bar available to him, so this wasn't an option. [33:48.330 --> 33:52.690] Matching the scenery, a closet secured with a padlock rusted away in the corner of the room. [33:53.250 --> 34:01.070] Running out of options, Waldo inspected the closet, noting the padlock and trying to figure out if he could swing the chain at it hard enough to break the padlock. [34:01.710 --> 34:05.410] Upon further inspection, Waldo realized brute force might just be unnecessary. [34:06.110 --> 34:11.890] The padlock was affixed to the closet with metal brackets, screwed in with none other than flathead bolts. [34:13.150 --> 34:15.070] His fingers gripped the penny in his pocket. [34:16.650 --> 34:21.610] Finally, a reason to carry around pennies, mused Waldo as he fumbled to unscrew the brackets from the closet doors. [34:22.170 --> 34:27.130] With a clank, the padlock and detached brackets swung uselessly to the side. [34:27.470 --> 34:30.310] As the closet doors creaked open, Waldo saw his ticket out. [34:30.530 --> 34:31.530] A tool belt. [34:32.210 --> 34:37.410] In that tool belt was a flathead screwdriver of sufficient size and girth as to be used as a decent pry bar. [34:37.410 --> 34:40.490] It seemed as though things were starting to finally look up for Waldo. [34:43.930 --> 34:47.610] Waldo eagerly approached the door, screwdriver in hand and a smile on his face. [34:48.470 --> 34:53.910] Wedging the screwdriver between the frame and door, he levered back and nudged the door with his shoulder, popping the door out from the frame. [34:54.870 --> 34:58.390] The door stopped short, attached to a chain lock on the other side. [34:59.270 --> 35:05.150] Waldo reached around the door and jiggled the doorknob, disengaging the doorknob's lock so at least he wouldn't have to deal with it again. [35:05.990 --> 35:09.870] Being so close to escape was at the same time motivating and frustrating. [35:11.150 --> 35:13.610] Frustration alone, however, was not going to get him anywhere. [35:14.210 --> 35:16.530] On the other hand, the closet might have something to help. [35:17.310 --> 35:22.170] Among the mess of things in the closet was an old gelat janitor outfit bearing the name Greg E. Waldo thought the name sounded familiar, but thought the jumpsuit needed more red and white stripes. [35:29.190 --> 35:31.190] Still, it worked as a nice disguise. [35:31.810 --> 35:38.150] People tend not to pay attention to cleaning staff and Waldo, of all people, knew the value in hiding in plain sight. [35:39.810 --> 35:42.810] At the bottom of the closet was a box of discarded folders. [35:44.610 --> 35:47.930] Waldo immediately took one of the folders and practically ran back to the door. [35:48.510 --> 35:58.850] Opening the door slightly, he stuck the folder in between the door and the frame and manipulated the edges of the folder to curve the fold around through the door jamb and touch the tip of it to the end of the chain. [35:59.730 --> 36:01.930] Closing the door caused the chain to slide to the side. [36:02.470 --> 36:04.930] With a flick of the folder, he popped the chain out of the door. [36:06.830 --> 36:09.210] Waldo pulled the folder back into the room and threw it on the floor. [36:09.810 --> 36:18.090] Not wanting to go gallivanting around gelat headquarters without a proper disguise again, he put on the jumpsuit and tool belt, then reluctantly put his hat inside it. [36:18.670 --> 36:24.010] He almost walked out without noticing the chain that he was carrying around with him and decided it wasn't terribly janitorial. [36:25.930 --> 36:28.550] Finally, Waldo was out of the room and into the basement of the building. [36:33.180 --> 36:43.920] So, Waldo was able to get past the lock on the cabinet because it was attached with flat head screws to a metal bracket, which he was able to open with a penny. [36:45.620 --> 36:53.660] So, after that, he was able to use a... he was able to manipulate the door frame because it was not flush with the wall that it was covering. [36:53.880 --> 36:57.400] So, he was able to bend it out a little bit and just simply push the door in. [36:59.260 --> 37:03.140] Then he... I think this slide is wrong. [37:03.320 --> 37:07.660] I originally had him shim the door knob, but he just pushed it in the end. [37:07.660 --> 37:09.380] So, never mind. [37:09.560 --> 37:09.720] Whoops. [37:10.720 --> 37:14.600] But then he also manipulated the chain lock, as you saw in the demonstration video earlier. [37:21.220 --> 37:24.960] From earlier recon, Waldo knew that the server room was on the second floor. [37:25.440 --> 37:33.140] Sensing that the Jalat goons would return soon, Waldo relocked the freshly installed chain lock and engaged the lock on the doorknob, then hit the elevator call button. [37:33.880 --> 37:41.180] Shortly afterwards, the door slid open and an old man in a suit followed by two muscle-bound thugs stepped out from the elevator and approached the maintenance door. [37:41.940 --> 37:46.020] As the elevator door closed with Waldo inside, the old man disengaged the locks. [37:46.360 --> 37:57.920] The maintenance room's door swung open, revealing an empty overturned chair, a scratched door frame, a piece of chain with a lock on it, a discarded folder, and an open closet. [37:58.420 --> 37:59.520] And no Waldo. [38:00.540 --> 38:03.400] The old man walked into the room slowly, inspecting the mess. [38:04.060 --> 38:07.880] Suddenly, he grabbed the chair and threw it across the room, startling his muscle-bound cohorts. [38:07.880 --> 38:16.340] He whipped around to face them, a bulging vein on his forehead, his eyes smoldering with anger, lips twisted into a snarl, revealing his crooked, yellowed teeth. [38:17.220 --> 38:20.920] Shaking with rage, he shouted, Where's Waldo?! [38:28.660 --> 38:31.360] The server room hummed audibly from outside the door. [38:31.820 --> 38:35.720] A soft yellowish-orange glow emanated from the LED on the RFID sensor. [38:36.480 --> 38:37.920] Waldo hadn't planned for this. [38:38.100 --> 38:39.460] He had expected a keyed entry. [38:40.280 --> 38:41.860] Looks like his recon was wrong. [38:42.980 --> 38:50.000] Then again, he hadn't planned to be kidnapped or drugged, so he was already in something of an improvisational mood. [38:50.540 --> 38:56.840] It was a pretty safe bet that there was going to be a request-to-exit motion sensor on the other side of the door. [38:57.080 --> 39:04.360] It would just be a matter of triggering it, but the crack on the underside of the door was too small for him to fit anything that he had with him through. [39:07.080 --> 39:10.140] Waldo checked the frame of the door to see if he could force it open with a screwdriver. [39:11.140 --> 39:11.800] No such luck. [39:11.960 --> 39:17.160] It was reinforced and he doubted he'd be able to open it without a car jack or some other extreme measure. [39:18.300 --> 39:23.820] Waldo tapped his foot idly, determined to get in and thinking about where he could get or copy a card to gain entry. [39:26.700 --> 39:33.120] Waldo looked down, where his foot was making a very odd noise, and noticed that the floor was making a rather hollow sound. [39:34.660 --> 39:37.440] Putting a screwdriver to work, Waldo pried up a floor panel. [39:38.120 --> 39:39.320] The floor was raised. [39:40.340 --> 39:44.500] A quick glance revealed that the wall of the server room didn't extend past the raised floor. [39:45.080 --> 39:54.440] Only a half a foot or so of space existed between the wall and the real floor, so Waldo wouldn't be able to crawl through without getting stuck, and his goose egg reminded him that he wasn't keen on being caught again. [39:55.360 --> 40:01.140] Waldo popped a panel out in the server room from the underside and tried to wave his hand on the other side of the door. [40:01.640 --> 40:02.360] No luck. [40:02.580 --> 40:05.420] The motion sensor was pointing too high. [40:06.780 --> 40:10.920] He took a pair of vice grips from the tool belt he was wearing and chucked them up past the inside of the door. [40:11.340 --> 40:13.500] A beep sounded, and the door clicked unlocked. [40:14.080 --> 40:18.760] Waldo stood up and reached for the door handle, only to find it locked again right before he could open it. [40:19.280 --> 40:22.700] It took a few more tools from the tool belt before he finally caught the door in time. [40:23.540 --> 40:28.620] Waldo stepped through and placed the tools back in his tool belt, chuckling slightly at the damage caused to the raised floor. [40:30.320 --> 40:31.380] Serves him right, he said. [40:32.680 --> 40:43.460] After replacing the floor panel he'd pushed up to throw things through, Waldo began the process of exfiltrating the data with just a couple quick keystrokes and grabbed the backups left carelessly in the corner, just in case. [40:44.280 --> 40:45.580] Now it was time to skedaddle. [40:46.180 --> 40:49.440] Waldo had already been here longer than he wished to and was looking for an exit now. [40:50.040 --> 40:55.340] He dumped the backups into the trash can in the corner and took out the bag, thinking it would look fairly janitorial. [41:01.480 --> 41:03.540] Better take the stairs this time, thought Waldo. [41:04.120 --> 41:07.660] He slung the trash bag over his shoulder and descended the stairs to the first floor. [41:08.180 --> 41:11.020] In one direction was a break room and a hallway to the front entrance. [41:11.340 --> 41:14.980] In the other direction was a cubicle farm and a door leading to a loading dock. [41:15.200 --> 41:22.560] Since the loading dock seemed like a good exit point, he decided he'd go for it, feeling he'd probably be fairly unobstructed. [41:24.100 --> 41:25.020] He was right. [41:25.880 --> 41:32.880] Stepping outdoors out of the unlocked exit and off onto the loading dock, Waldo started to scour the parking lot. [41:33.240 --> 41:39.160] One car stood out, the back of the car smattered with bumper stickers which said things like, Honk if you like stuff. [41:39.820 --> 41:43.080] And if you can read this, it's because you can read. [41:44.700 --> 41:50.380] Waldo checked for surveillance cameras and witnesses and, finding none, started to feel under the car. [41:51.360 --> 41:55.860] Checking under the front driver's side wheel well, Waldo found a hide-a-key box. [41:56.020 --> 42:00.400] Oh, actually, I didn't... sorry, I didn't talk about the... getting ahead of myself here. [42:00.520 --> 42:07.860] So, he got entry to the server room because there was a raised floor on both sides of the wall and the wall didn't extend down far enough. [42:08.040 --> 42:13.320] And he was able to trigger the request to exit motion sensor with some heavy tools. [42:16.960 --> 42:20.680] So, checking under this car, Waldo found a hide-a-key box under the wheel well. [42:22.360 --> 42:25.140] Likely a backup key, it fit the door. [42:25.740 --> 42:27.480] It also managed to start the car. [42:28.480 --> 42:31.480] Waldo threw the trash bag into the back of the car and climbed into the front seat. [42:31.760 --> 42:40.840] He took the fuzzy dice off of the mirror and threw them into the glove box, checked the mirrors, secured his seat belt, safety first, you know, and drove off into the sunset. [42:44.920 --> 42:55.460] So, finally, somebody was dumb enough to store their backup key to their car in the most obvious place that you could hide it, in the most obvious way that you could hide it. [42:56.260 --> 43:02.520] So, you know, here's an example of credential theft because somebody just didn't put the key in a very good place. [43:06.320 --> 43:08.140] So, that's the end of the story. [43:09.500 --> 43:12.100] Are there any questions, comments, suggestions? [43:13.140 --> 43:13.720] Hatred? [43:24.940 --> 43:27.980] I took a look at that a while back. [43:29.300 --> 43:33.320] The question is, what do you know about rolling codes for garage door openers? [43:34.280 --> 43:38.340] I know that infrared transmissions are very vulnerable to replay attacks. [43:39.720 --> 43:46.420] Depending on how fast the codes roll, you might be able to use a replay attack in the sort of scenario where that's in use. [43:47.280 --> 43:49.800] One thing you might want to look up is... [43:50.420 --> 43:58.320] I think it's called, like, fun with infrared or infrared hacking or something like that from a guy named Major Malfunction given at an old DEFCON conference. [44:20.090 --> 44:23.250] Yeah, so there's a comment from the gentleman in the front row here. [44:24.010 --> 44:32.730] There's a trick that a lot of people use to steal bicycles when they're secured to stop signs where they just lift the stop sign out of the cement because they're not always cemented in. [44:33.710 --> 44:51.210] Another thing that could be done in that scenario, frequently somebody in the past has driven straight through that stop sign, and so they take a new stop sign and they bolt it on to the old one that they cut off the top of, and frequently you can just undo that bolt and take the stop sign off and do something similar. [44:51.210 --> 44:52.870] Typically it's an A16. [44:53.490 --> 44:53.850] Sorry? [44:54.050 --> 44:54.810] Typically it's an [44:58.610 --> 44:59.430] A16. [44:59.470 --> 45:00.890] So, oh, got another question. [45:07.740 --> 45:09.360] I'm wondering if you've ever tried that. [45:09.440 --> 45:12.100] Have you ever tried that when you weren't holding it? [45:15.770 --> 45:16.290] Yeah. [45:16.770 --> 45:17.520] If it... [45:17.520 --> 45:26.560] The question was about the usage of the technique for copying a key visually by taking a photo of it, and yeah, you need a good picture of it. [45:26.560 --> 45:30.040] So holding the key while you try to do it generally doesn't work out terribly well. [45:30.830 --> 45:34.360] It's nice to be able to put it down on something that gives a little bit of contrast. [45:35.310 --> 45:35.750] Sorry. [45:36.250 --> 45:36.360] Go ahead. [45:36.440 --> 45:37.120] But I'm [45:46.620 --> 45:47.160] saying... [45:47.160 --> 45:48.080] Oh, okay. [45:48.840 --> 45:49.280] Yeah. [45:49.600 --> 45:58.120] So the comment was that he's seen this technique used while the key is in somebody's hand while they're about to use it about 10 feet away. [45:58.760 --> 45:59.540] And the attack still worked? [45:59.740 --> 46:02.540] The attack still the camera did. [46:02.800 --> 46:03.020] Yeah. [46:15.920 --> 46:16.340] Yeah. [46:16.960 --> 46:17.160] So... [46:18.920 --> 46:19.340] Okay. [46:19.480 --> 46:21.120] So the attack still worked. [46:22.520 --> 46:23.540] That's great to know. [46:23.860 --> 46:24.940] Well, depending on who you are. [46:32.510 --> 46:43.830] I've seen the rubber band trick on chain locks, but that, as far as I can tell, requires the door handle to be of a certain type that it will pull down when you pull on the other side of the handle. [46:44.190 --> 46:45.210] And I just... [46:45.210 --> 46:50.270] I don't think that's as reliable or as easy as the trick with the plastic folder. [46:50.850 --> 46:51.230] And [46:54.510 --> 47:01.710] rubber band and duct tape, you duct tape the thing to the opposite side of the door so that it closes as the... [47:02.270 --> 47:06.830] The left over, the rubber band will, you know... [47:10.700 --> 47:18.680] See, that's, I think, the other problem with the rubber band attack on chain locks is that you need to be able to reach your hand through the door jam. [47:19.420 --> 47:29.120] If you only have a very minimal amount of space, if the chain lock is properly installed, or the chain is just short enough, generally, that's not possible. [47:29.460 --> 47:30.520] And that's why I don't like that attack. [47:30.680 --> 47:32.060] There was actually a gentleman who had a... [47:32.060 --> 47:32.800] Did you still have a question? [47:33.040 --> 47:33.380] Yeah. [47:39.230 --> 47:40.110] All the time. [47:40.630 --> 47:40.710] All the time. [47:40.710 --> 47:50.450] Like I was mentioning earlier, there's the problem where if you have a visitor come in who doesn't have an RFID sensor to get out, an RFID key to get out, they could be stuck there for the night. [47:51.170 --> 47:53.230] And that's something that a lot of companies want to avoid. [47:53.390 --> 47:57.230] So, yes, I see request to exit motion sensors very, very frequently. [47:57.810 --> 47:58.170] You in the back? [48:02.770 --> 48:03.170] Yeah. [48:25.340 --> 48:26.000] Fair enough. [48:28.640 --> 48:29.380] Right, yeah. [48:29.380 --> 48:32.640] And infrared security is actually god-awful. [48:32.820 --> 48:36.500] Again, I'd like to mention that talk by Major Malfunction because it's really killer. [48:36.760 --> 48:38.040] He talks about the rolling codes. [48:38.180 --> 48:40.760] He talks about brute forcing infrared signals. [48:41.040 --> 48:49.980] He actually owns an entire hotel network through a hotel TV by reverse engineering the remote control codes just through brute force. [48:50.200 --> 48:52.180] It's a very small space to brute force. [48:52.300 --> 48:53.200] And it's great. [48:53.380 --> 48:55.220] I definitely recommend you take a look at the talk. [48:55.220 --> 48:58.460] But infrared security is pitiful. [48:59.100 --> 49:00.000] Absolutely pitiful. [49:00.580 --> 49:01.100] Is [49:07.450 --> 49:09.110] it a push to exit button? [49:09.810 --> 49:11.190] That would probably be better. [49:11.510 --> 49:14.270] You still have the problem that that can't be locked. [49:14.670 --> 49:16.410] So, you still have the shimming thing. [49:16.570 --> 49:22.110] But as long as you can put a bracket or something in place so that shimming attacks are difficult, if not impossible. [49:22.750 --> 49:26.850] I mean, I don't like to think that anything is impossible, especially when you're talking about physical security. [49:27.050 --> 49:31.150] But I think a push to exit would be better. [49:32.990 --> 49:33.390] Yeah. [49:33.850 --> 49:34.250] Absolutely. [49:35.950 --> 49:36.630] You in the back? [49:40.470 --> 49:40.990] I'm sorry. [49:41.070 --> 49:41.470] Can you speak up? [49:44.830 --> 49:46.030] I still can't hear you. [49:46.030 --> 49:46.890] Have you dealt [49:51.710 --> 49:52.130] with... [49:52.130 --> 49:52.850] Sure. [49:53.270 --> 49:53.710] Brute... [49:53.710 --> 49:56.110] So the question is, have I dealt a lot with brute force attacks? [49:57.610 --> 50:04.270] I don't really deal with them much because I can't really test that stuff out without destroying the equipment. [50:04.610 --> 50:06.570] And I try to avoid doing that. [50:06.750 --> 50:08.750] But brute force attacks are really effective. [50:08.750 --> 50:12.570] I mentioned earlier that in Boston, there's a huge problem with bike theft. [50:12.830 --> 50:20.370] And generally, what I see happening is all brute force attacks. [50:20.850 --> 50:29.750] Chain locks, you can't buy them without getting your locks stolen because people will come by with bolt cutters or they'll pour liquid nitrogen on the chain and then... [50:30.890 --> 50:32.010] Is that a really common attack? [50:32.290 --> 50:34.090] It's much more common than you would think. [50:34.330 --> 50:35.310] Especially in Boston? [50:37.810 --> 50:39.710] I don't know how else they would do it. [50:40.250 --> 50:44.250] And that's what I've heard from most of the people who generally deal with the bike theft. [50:44.450 --> 50:44.750] I'm sorry, what? [50:44.790 --> 50:46.410] Are they using the spray or really? [50:47.990 --> 50:51.210] I'm honestly not sure about how they actually apply the liquid nitrogen. [50:52.250 --> 50:52.690] But... [50:53.810 --> 50:54.250] Yeah. [50:54.690 --> 50:58.470] But it really weakens the crap out of pretty much anything. [50:59.510 --> 50:59.950] So... [51:09.900 --> 51:12.020] Well, I know some of the... [51:12.020 --> 51:13.440] Some of the alarm... [51:13.440 --> 51:17.880] So the question was, is there any way to bypass a fire alarm on a fire escape door? [51:18.920 --> 51:20.520] I know a lot of the... [51:20.520 --> 51:21.440] Or at least some. [51:21.680 --> 51:24.800] I won't say a lot because I actually don't know that for sure. [51:24.960 --> 51:27.560] And so I don't want to propagate false information by mistake here. [51:27.720 --> 51:36.080] But a lot of them work on the same principle as some of those burglary alarm locks where there's just two magnets right by each other. [51:36.080 --> 51:36.980] And that sort of... [51:36.980 --> 51:39.320] You know, as long as there's still... [51:39.320 --> 51:42.020] As long as they're close enough to each other, there's... [51:42.020 --> 51:46.640] There's a circuit that gets affected by that moving away. [51:46.800 --> 51:48.460] And so that triggers the alarm. [51:50.360 --> 51:50.920] It's... [51:50.920 --> 51:56.840] There's a sort of magnet shimming attack that works on a lot of those where you can still keep the... [51:56.840 --> 51:59.980] Keep that sort of in place because they're... [52:00.400 --> 52:00.840] They... [52:00.840 --> 52:01.740] You know... [52:01.740 --> 52:02.560] Um... [52:02.560 --> 52:05.660] So that can keep the alarm from triggering in certain circumstances. [52:07.120 --> 52:07.600] Um... [52:07.600 --> 52:08.280] Other than... [52:08.280 --> 52:09.000] You know, it's... [52:09.520 --> 52:10.000] It's... [52:10.000 --> 52:10.700] It's similar to... [52:10.700 --> 52:16.740] To working with tamper-proof seals where you're trying to prevent some sensor from going off. [52:17.700 --> 52:18.180] Um... [52:18.180 --> 52:18.800] So, uh... [52:18.800 --> 52:19.180] If you... [52:19.180 --> 52:20.820] If you take a look into that, there's actually... [52:20.820 --> 52:23.080] I think there was a talk at ShooCon this year... [52:23.080 --> 52:23.480] Um... [52:23.480 --> 52:27.160] About tamper-proof seals and how they all are terrible and suck. [52:27.760 --> 52:28.680] And, um... [52:28.680 --> 52:30.740] And what a better solution might be. [52:31.220 --> 52:31.400] Um... [52:31.400 --> 52:32.180] An interesting talk. [52:32.300 --> 52:34.160] I definitely recommend taking a look into it. [52:34.280 --> 52:35.000] But that might... [52:35.000 --> 52:37.740] Looking into that might give you some more clues on how to... [52:37.740 --> 52:39.620] How to go further in your testing. [52:53.600 --> 52:54.080] Uh... [52:54.080 --> 52:54.440] So is... [52:54.440 --> 52:56.020] Is there a chain lock where, uh... [52:56.760 --> 52:58.260] The metal can't be cut with a bolt cutter? [52:59.280 --> 52:59.940] Or grinder. [52:59.940 --> 53:00.060] Or grinder. [53:00.620 --> 53:01.100] Mmm... [53:02.660 --> 53:03.140] Uh... [53:03.140 --> 53:03.640] Theory... [53:03.640 --> 53:03.840] Yeah. [53:03.840 --> 53:05.600] If you had, uh... [53:05.600 --> 53:07.080] If it was made out of diamond, maybe. [53:07.440 --> 53:11.100] I mean, theoretically, anything can eventually be broken with enough brute force. [53:11.280 --> 53:12.540] That's the great thing about brute force. [53:12.680 --> 53:14.600] Is that if it's not working, you're just not using enough. [53:16.700 --> 53:17.140] Um... [53:17.140 --> 53:19.000] So, um... [53:19.000 --> 53:23.340] So, in terms of brute force attacks, they will always work if you're using enough brute force. [53:23.420 --> 53:25.160] If you have a big enough set of bolt cutters. [53:25.280 --> 53:26.720] If you have a diamond... [53:26.720 --> 53:28.400] Diamond-tipped grinder. [53:29.620 --> 53:30.060] Um... [53:30.060 --> 53:31.320] Whatever you're talking about. [53:31.980 --> 53:33.340] Enough brute force will work. [53:44.900 --> 53:45.420] Sorry, what? [53:52.900 --> 53:54.000] Yes, that's right. [53:57.480 --> 53:59.200] I think it would depend on the placement. [53:59.920 --> 54:05.600] I mean, I think most of the attacks that you could probably launch on that would be the sort of thing where it's not installed properly. [54:05.840 --> 54:12.500] I mean, if you have that bracket installed at the bottom of the door and the doorknob's right in the middle of the door, obviously it's, you know, you can see how that's not gonna work. [54:13.320 --> 54:22.600] I can't think of a good way to bypass that otherwise, except maybe using, if the doorframe was just really shitty, maybe like the guitar string thing I was talking about. [54:28.280 --> 54:43.080] Yeah, I mentioned that earlier in the talk, and basically you can visually decode it by sort of measuring the distance in pixels, and so you can get an idea of the key... [54:45.560 --> 54:49.400] Ah, the word's completely escaping me, but the way the key is shaped. [54:54.180 --> 54:54.580] Bidding. [54:54.580 --> 54:54.980] Bidding. [54:55.240 --> 54:55.760] The key bidding. [54:56.020 --> 54:56.360] Thank you. [54:56.440 --> 54:57.020] Thank you, Deviant. [54:59.800 --> 55:00.980] Another person with a question? [55:10.570 --> 55:11.290] So the... [55:15.510 --> 55:16.830] No, not exactly. [55:19.850 --> 55:21.670] So this has to be the last question. [55:21.810 --> 55:22.950] I'm being told time's out. [55:23.250 --> 55:29.830] So the question was about copying a key, that you need to take a picture of both sides and you have the problem of the key blank. [55:29.830 --> 55:31.970] Key blanks are readily available. [55:32.370 --> 55:38.210] As long as you know the type of lock, you can figure out the key blank really easily. [55:38.670 --> 55:43.610] It's information that anybody can look up, pretty much regardless of what type of lock it is. [55:43.770 --> 55:45.030] So that's actually not a problem. [55:46.710 --> 55:48.310] So thank you, everybody, for coming. [55:49.070 --> 55:49.310] Okay, thanks,