[00:02.570 --> 00:03.370] No, I'm not wired. [00:05.690 --> 00:10.810] So it looks like despite asking for the little wireless mic, they didn't give us one or two. [00:11.270 --> 00:12.170] Oh, you got him. [00:14.030 --> 00:15.910] Not very good to us back there. [00:16.290 --> 00:17.050] Bring him up. [00:19.330 --> 00:23.290] I mean, I could yell that for him and then might hit the mic and that's it. [00:54.740 --> 00:55.540] Okay, hi. [00:55.700 --> 00:56.900] Can you hear this okay? [00:57.680 --> 00:58.140] All right. [00:58.720 --> 00:59.560] So I'm Mike. [00:59.720 --> 01:00.140] This is Eric. [01:00.400 --> 01:05.760] We're going to talk a bit about physical access control and some of the physical access control systems in particular. [01:06.520 --> 01:09.460] This should be a pretty broad talk. [01:09.680 --> 01:19.340] We're going to start off by talking a bit about some of the different criteria and some of the different metrics you use to evaluate security systems and what goes into making a good one and what you need to think about when you're designing this. [01:19.520 --> 01:26.980] And then we're going to go in and talk a little bit about a whole bunch of different access control techniques and different access control systems. [01:30.010 --> 01:38.290] So when you're starting off, when you're choosing an access control system, there are really sort of five main factors that you need to think about when you're designing it. [01:38.390 --> 01:39.690] You need to You have to worry about the error rate. [01:41.690 --> 01:45.870] You have to worry about whether or not you can afford to annoy your users with false rejections. [01:46.150 --> 01:58.270] You have to worry about whether or not it's okay to accept some people accidentally, even if someone puts in the wrong ID, just to minimize the annoyance rate. [01:58.590 --> 02:01.670] You need to worry about how robust the system has to be towards the environment. [02:02.350 --> 02:05.230] There are a lot of things you can do to make a system robust. [02:05.470 --> 02:10.070] But in a lot of cases, that can drive up cost and can drive up a lot of other difficulty factors. [02:10.350 --> 02:12.310] You have to worry about the cost, since everyone is on a budget. [02:12.410 --> 02:17.090] You need to worry about how vulnerable it is that the persistence of a system can introduce. [02:17.250 --> 02:18.810] You need to worry about the complexity of that system. [02:18.890 --> 02:20.730] You need to worry about any other sort of additional constraints. [02:21.170 --> 02:26.070] You need to think about what else you want to ask yourself or what else you want to ask the sales before buying a system. [02:26.770 --> 02:29.530] So one of the first things I want to talk about is the error rate. [02:29.690 --> 02:36.030] How do you quantify the ability of a system to detect or prevent intrusion? [02:36.530 --> 02:40.010] And the right way to do this is to think about the false accept rate and the false rejection rate. [02:40.290 --> 02:42.830] Banks call this stuff the insult rate and the fraud rate in some sense. [02:42.910 --> 02:44.170] Can you afford to piss off your user? [02:44.970 --> 02:45.690] And how much? [02:46.310 --> 02:48.850] How much is it worth it to you to make your users angry? [02:51.030 --> 02:55.570] And then... but, you know, these are really sort of true numbers and they represent different aspects of the spectrum. [02:56.530 --> 03:05.170] And one of the... a very typical way to come across a single number to sort of quantify the quality of a system is to look at the equal error rate. [03:05.170 --> 03:10.190] This is the point at which the false accept rate has been tuned to be equal to the false reject rate, essentially. [03:11.050 --> 03:14.050] And basically the lower that is to be a better system. [03:15.590 --> 03:26.610] So you know, looking at the environment, you have to worry about whether or not you can handle inclement weather, whether you can deal with cold, whether you can deal with someone banging out with a baseball bat, whether you can deal with all the other issues. [03:27.170 --> 03:28.350] There's a lot of things you can do. [03:28.510 --> 03:31.050] You can encase a reader in a pod of material. [03:31.230 --> 03:37.830] You can use a Prox card or a Wigan Stripe card or any kind of... or smart cards or any kind of system that's relatively resilient. [03:38.410 --> 03:47.450] But then in some cases, you know, you know, a system with a lot of moving parts like a fancy mechanical key lock might not be appropriate for, you know, a sub-Saharan desert. [03:48.210 --> 03:49.670] And of course, you have to worry about the cost. [03:49.750 --> 03:50.290] You're on a budget. [03:50.430 --> 03:53.430] You can buy all sorts of, you know, great, crazy, fancy systems. [03:53.770 --> 04:00.150] You know, people will be very, very willing to sell you, you know, unbelievably complicated physical access control. [04:00.690 --> 04:03.610] But the price will be out of this world. [04:03.770 --> 04:04.370] It will be unreal. [04:05.730 --> 04:15.030] And of course, you need to worry about what happens when you try introducing new systems or new parts of an access control system to an existing security protocol. [04:15.230 --> 04:19.790] Because in a lot of cases, you know, vulnerabilities are introduced at the borders between two things. [04:19.950 --> 04:31.310] So if you have a standard door with, for example, a with a typical lock set, typical handle set, it has a special little button that you press in and prevents you from opening the door with a credit card. [04:31.910 --> 04:31.990] Right? [04:33.030 --> 04:38.510] Because it essentially just locks everything in place while the door is closed. [04:39.030 --> 05:00.130] But a lot of typical electric strikes, these are sort of the electric-controlled door latches, a lot of those, they require you to use a... The strike is just too large for the... Is so large that the button that's depressed when the door is closed actually just sits in the strike. [05:00.370 --> 05:01.650] It actually doesn't actually close. [05:01.910 --> 05:11.410] So you need to really worry about the... You need to worry about all of the holes that are introduced at the borders of your system. [05:12.290 --> 05:25.230] And obviously, you need to worry about, you know, all sort of the obvious problems, you know, you have to worry about, you know, request exit centers can be defeated by sticking a balloon underneath it or waving a tape measure in front of the motion detector, [05:25.390 --> 05:25.950] things like that. [05:26.470 --> 05:28.630] And you need to think about any of these additional constraints. [05:28.930 --> 05:29.110] Right? [05:29.210 --> 05:30.910] So for example, how many users do you need to process? [05:31.090 --> 05:34.770] Is this a... What's your... How fast does it need to handle that? [05:34.970 --> 05:37.250] Does it need to handle different amounts of people at different times? [05:37.410 --> 05:41.230] Do you need to have, you know, what kinds of levels of access control do you need? [05:41.550 --> 05:45.290] And do you need to have the system interface with other things or is this a standalone system? [05:45.510 --> 05:51.510] All of these other things are, you know, important things to consider while choosing an access control system. [05:52.550 --> 06:06.270] Now, in a lot of cases... In a lot of cases, you know, you might be concerned because a single... A single access control technique can only... Can only improve the error so much. [06:06.570 --> 06:13.110] And in almost any case, there's always a tradeoff between the access... The accept rate and the false rejection rate. [06:13.450 --> 06:20.050] But it is possible to improve both of these things by stacking multiple systems together. [06:20.450 --> 06:26.350] So the typical... The typical security that people talk about is what you have versus what you know and what you are. [06:26.570 --> 06:30.510] So by combining these different types of authentication, you can improve both systems. [06:31.050 --> 06:36.890] But again, sometimes introducing multiple access control techniques can actually reduce security. [06:37.450 --> 06:49.050] For example, if you have a mechanical bypass on your fancy, fancy lock, then you've introduced this extra... You've increased the attack surface and introduced more problems. [06:49.470 --> 06:51.450] Now, a lot of these systems are centralized. [06:52.090 --> 06:57.070] You have to... So... And this introduces a whole other set of problems. [06:57.650 --> 07:11.710] Because the bottom line is that these centralized access control systems, these mag stripe readers or prox cards in some cases, in some cases, smart cards that use online verification, they boil down to a system that produces bit streams, right? [07:11.910 --> 07:16.210] And everyone here, I think, knows the problems with shuffling bit streams around buildings. [07:16.730 --> 07:20.630] They're vulnerable to all the sort of communications line tapping. [07:21.110 --> 07:22.650] You have to worry about the security of the servers. [07:22.810 --> 07:24.150] You have to worry about the security endpoints. [07:24.290 --> 07:30.890] You have to worry about all of the other aspects of the system that are introduced when you have this online centralized checking. [07:32.230 --> 07:39.750] In order to understand in more detail what's happening with these, you have to go towards what the actual bus protocols and what the formats are. [07:41.030 --> 07:44.650] In a lot of cases, you see really a bit of everything these days. [07:44.810 --> 07:50.350] There's some RS-232 based systems, some RS-485 or other serial protocols. [07:51.770 --> 07:56.070] And one of the most common, though, is the Wiegand bus protocol. [07:57.110 --> 07:59.510] It's a somewhat unfortunate naming convention. [08:00.230 --> 08:00.590] Hold on. [08:01.330 --> 08:03.390] Can people hear me when I'm talking here? [08:03.910 --> 08:04.490] Okay. [08:04.750 --> 08:04.930] Okay. [08:05.070 --> 08:05.130] Great. [08:05.270 --> 08:05.370] Thanks. [08:07.820 --> 08:10.950] The Wiegand bus protocol is probably one of the most common systems. [08:11.270 --> 08:13.630] It's a very, very simple bus protocol. [08:13.830 --> 08:15.070] It uses two wires. [08:15.750 --> 08:18.470] There's a data 1 wire and a data 0 wire. [08:18.930 --> 08:21.170] Under normal circumstances, they're both held high. [08:22.190 --> 08:25.230] And in order to send a 1, the 1 wire is pulled low. [08:26.050 --> 08:29.450] In order to send a 0 wire, the 0 wire is pulled low. [08:29.650 --> 08:31.750] And that's all there is to the Wiegand bus format. [08:31.890 --> 08:32.970] It's very simple. [08:33.110 --> 08:37.810] There's no fancy sort of inline encryption that goes into this. [08:38.810 --> 08:48.050] And this is sort of a very, very pervasive theme among centralized access control, you know, communication formats. [08:48.050 --> 08:58.890] is that there is very, very rarely any sort of encryption between the endpoint, the card reader, or the, you know, the card reader and the verification system. [09:00.650 --> 09:07.550] And I guess, last Defcon, I think, Guy released this really fantastic device. [09:07.910 --> 09:16.250] You know, it's amazing form factor that just fits completely inline in a typical, just a Wiegand wire. [09:17.250 --> 09:22.570] And can do interception and replay attacks just in a very straightforward manner. [09:22.810 --> 09:25.650] And this is sort of a still pervasive problem. [09:25.790 --> 09:40.010] Because even with new, you know, smart cards with onboard cryptographic modules and, you know, new, you know, FIPS 201 compliant readers, you know, you have this problem that there's all sorts of fancy, fancy authentication happening between your Prox card, [09:40.130 --> 09:41.230] your smart card, and the reader. [09:41.750 --> 09:46.230] But then the data is just sort of being shift in plain text. [09:46.830 --> 10:03.650] And if you have your wires running through drop ceiling or through an easily accessible wall, or if you don't have any sort of tamper detection on the reader itself, then this is a serious problem that some people... that tends to be ignored in a lot of cases. [10:04.510 --> 10:09.430] So now we're going to talk a bit about some of the different categories of access control system. [10:09.650 --> 10:14.990] So we're going to go through talking about, you know, the guards, token-based systems, knowledge-based systems, and biometric systems. [10:15.350 --> 10:17.090] Now Eric's going to talk a bit about guards. [10:17.930 --> 10:18.910] Can you guys all hear me? [10:19.990 --> 10:20.550] Testing one, two? [10:20.670 --> 10:20.810] Okay. [10:21.630 --> 10:24.430] So, the thing about guards is they're simple. [10:24.590 --> 10:29.090] I mean, it's a guy sitting at a counter with a radio and a donut in his hand, being like, can I see your ID? [10:29.170 --> 10:29.770] Can I see your ID? [10:29.870 --> 10:30.430] Can I see your ID? [10:30.530 --> 10:31.350] Can I see your ID? [10:31.550 --> 10:33.950] He does this all day long, and he only has to remember the one line. [10:34.470 --> 10:39.670] And so you pay him his nine bucks an hour, and you hope he doesn't take any bribes under the table, and you're good, right? [10:40.530 --> 10:55.070] I mean, it's nine bucks an hour, so easy to set up, doesn't cost very much for the first couple of years, but you have to keep paying that nine bucks an hour all the way out until he retires 60 years later, which over that 60 years is, you know, some very long time until you move to a computerized robot, [10:55.210 --> 10:56.870] which does the, can I see your ID? [10:56.930 --> 10:57.530] Can I see your ID? [10:57.610 --> 10:58.290] Can I see your ID? [10:58.370 --> 11:01.890] And doesn't have to eat donuts, which I guess is, you know, less money and donut money. [11:02.830 --> 11:05.250] And, of course, he's not affected by the environment. [11:05.450 --> 11:08.650] This means that if it gets cold outside, he puts on a down jacket. [11:08.890 --> 11:16.090] If it gets hot outside, he puts on a, you know, blue Hawaiian shirt or whatever it is, and, you know, a mesh cap as opposed to the wool one. [11:16.310 --> 11:19.790] But all in all, you can drop the guard into just about any environment. [11:19.790 --> 11:23.410] As long as he has, you know, his heater and his cable TV, he's happy. [11:23.810 --> 11:26.610] Not so much with a lot of access control systems. [11:27.370 --> 11:30.530] The problem with the guard is that he's checking ID all day. [11:31.530 --> 11:35.690] And he's looking at these IDs day after day after day after day, and he never sees a fake one. [11:36.750 --> 11:38.750] Which means it's very easy to counterfeit IDs. [11:39.650 --> 11:43.110] Because the problem with the human mind is we're creatures of habit. [11:44.450 --> 11:51.810] So if we see the same thing every day and we get used to saying, OK, OK, OK, OK, OK, OK, OK, OK, OK, OK, OK, OK, OK. [11:52.470 --> 11:54.410] Pretty soon we say that no matter what happens. [11:54.570 --> 12:05.790] And we're too busy thinking about what's going on on the cable channel and Anna Nicole Smith's vagina, then whether or not the ID the guy in the suit is actually holding up is actually accurate. [12:07.470 --> 12:16.790] It could be, you know, that the bad guy, the attacker, got his hands on a legit ID, he stole it, pickpocketed it, and it never got reported. [12:17.230 --> 12:19.350] Could be somebody left their ID lying around. [12:19.630 --> 12:23.610] Could be the guard doesn't care because he's much more fascinated with Anna Nicole Smith. [12:24.390 --> 12:32.010] And, of course, he's got a salary, so that's going to cost a lot over the 10, 20, 60 years that he's going to be in service. [12:32.910 --> 12:48.410] Now, the most significant problem with guards is, as I told you, this habituation thing, which means that, you know, even if you have a photo ID which is supposed to match the subject and, you know, it's all holographic and super hard to counterfeit, guards don't really look. [12:49.510 --> 13:11.310] The story goes that there was a military base somewhere in the gigantic U.S. Army system where, you know, the guy in charge of security on the base was, you know, thought to himself, this whole system is really great I've designed but, you know, I should probably check it just in case because the Iranians or the Chinese or the Indians or whoever it was that he was trying to defend against might try [13:11.310 --> 13:11.790] to get in. [13:12.010 --> 13:19.610] And so he went down to the bar where he met his buddies every day and he knew a couple of guys who worked in intelligence and he figured he could trust them. [13:19.610 --> 13:22.410] So he was like, you know, tell you what, guys, I want to try this experiment. [13:22.590 --> 13:24.650] Come to my office tomorrow morning and I'll get you set up. [13:24.790 --> 13:29.310] And, you know, for the next couple of months, you know, if you guys manage to get into the base, I'll buy you guys all round of beers. [13:29.790 --> 13:31.810] And they were like, hell yes, free beers. [13:32.190 --> 13:33.130] We know we can get in. [13:33.370 --> 13:42.570] So they showed up to his office the next morning and he handed them each set of new ID cards, all access, which had replaced their pictures with that of your average African baboon. [13:44.030 --> 13:48.710] And he figured, you know, it might last a week because the guys at the front are a little slow. [13:49.210 --> 13:57.790] But, you know, once they change out, once they get some new donuts or whatever, they'll probably, you know, start thinking about new things and they'll probably notice the IDs. [13:58.130 --> 13:59.270] It took them two months. [14:00.730 --> 14:10.150] And the only reason the guard caught on is because those intelligence guys were intelligence guys and, you know, not like snipers, people with actual dexterity. [14:10.150 --> 14:14.230] And when handing over their ID, they fumbled the card and dropped it to the ground. [14:14.490 --> 14:17.510] The guard reached down, picked it up, and was like, um... [14:19.890 --> 14:20.250] Yeah. [14:21.970 --> 14:28.710] So, you know, the more scientific version of this is a study that was done at the University of Westminster using photo credit cards. [14:28.830 --> 14:39.770] They went to a supermarket and asked these supermarket checkers after hours whose job it was to, you know, to check IDs all day, see whether or not people were old enough to buy alcohol. [14:39.770 --> 14:42.970] It was like, okay, we're going to send a whole bunch of college students through. [14:43.470 --> 14:45.030] Some of them are going to have real IDs. [14:45.590 --> 14:48.390] Some of them are going to have real IDs from other people. [14:49.030 --> 14:53.970] Some of them are going to have real IDs from other people that are completely different looking. [14:54.450 --> 15:06.250] You know, like, you know, Mike here has an ID from some Rastafarian dude from Sub-Saharan Africa who happens to be wearing the yellow, red, and green cap in the picture and long dreads. [15:06.710 --> 15:07.630] That kind of thing. [15:07.690 --> 15:09.770] That was considered the really wrong ID. [15:10.850 --> 15:14.850] Overall, the error rate was 32.6%. [15:16.650 --> 15:25.470] When the photo was blatantly wrong, the error rate went up to 34.09%. [15:27.390 --> 15:35.150] But fully half of the cashiers were so paranoid that they rejected a recent and accurate ID photo. [15:36.290 --> 15:40.110] Three out of six cashiers would be like, ah, this is fake. [15:40.350 --> 15:42.890] The guy would be like, dude, I just got that last week. [15:44.430 --> 15:49.870] And so overall, about 50% of the time, they let through a fake ID. [15:51.370 --> 15:53.630] 50% of the time, they also rejected a real ID. [15:53.630 --> 16:02.290] So when it came down to it, 63% of the time, they accepted a fake ID with a more or less good-looking picture. [16:02.470 --> 16:03.190] Not a baboon. [16:03.690 --> 16:04.750] 60% of the time. [16:08.890 --> 16:11.910] This is, in fact, the statistics which I forgot to click through to, sorry. [16:12.070 --> 16:15.090] But now you can write them down, scribble them down, memorize them. [16:16.130 --> 16:16.650] Bada bing. [16:16.710 --> 16:18.750] It's 63.64%. [16:20.630 --> 16:23.230] Next up is Mike talking about tokens. [16:23.850 --> 16:27.730] Now that you guys all realize that you need a better system than that photo ID card. [16:30.450 --> 16:36.050] Yeah, so token-based systems are just systems based around something that you carry around. [16:36.310 --> 16:40.730] You know, either your key or a mag stripe, a magnetic card or a barcode. [16:41.110 --> 16:43.110] Just something physical that you have. [16:43.350 --> 16:45.430] So first, mechanical key locks. [16:45.570 --> 16:47.190] Everyone's seen these, everyone's had these. [16:47.330 --> 16:50.930] I'm not going to spend too much time on them because they're pretty well covered in other talks. [16:51.310 --> 16:53.990] But, you know, they do have a lot of, you know, real advantages. [16:54.250 --> 16:55.390] You know, they can be made very reliable. [16:55.510 --> 16:56.530] They don't need a power supply. [16:56.750 --> 17:01.250] You know, if you have to worry about, you know, you don't have to worry about batteries running out. [17:01.770 --> 17:04.350] You know, but on the other hand, I mean, they have no audit trail. [17:04.650 --> 17:10.590] You know, without extra electronics sort of attached to that or with extra, you know, bureaucracy. [17:11.230 --> 17:16.950] And they have lots of well-known security issues that have, you know, been talked about for, you know, quite a while. [17:17.250 --> 17:17.990] You can pick them. [17:18.070 --> 17:18.870] You can bump them. [17:18.950 --> 17:20.830] You can decode them and make keys for them. [17:21.170 --> 17:22.550] You can impression keys for them. [17:22.910 --> 17:26.330] You know, and you can even attack, you know, the master key systems, right? [17:27.510 --> 17:40.490] You know, Matt Blaze published a great paper quite a while ago, or a few years ago, describing how to take a change key and enumerate, essentially decode the master key from the change key. [17:41.450 --> 17:47.930] And there are a lot of different sort of mechanical lock strategies you can use for breaking these. [17:48.590 --> 17:52.330] There are a lot of different strategies that you can use for breaking the master key system. [17:52.570 --> 18:03.950] You know, and even beyond just converting a change key to that, you can disassemble the lock and decode the master key system, The master key from the disassembly. [18:05.110 --> 18:07.630] And in some cases, that won't give you enough information. [18:07.890 --> 18:18.790] But even then, if you make some educated guesses about the way the master key system was constructed, then you can get pretty far pretty quickly towards the actual top master key. [18:19.190 --> 18:21.650] So there are a lot of problems that you need to consider. [18:21.830 --> 18:25.010] And you need to really be careful about who you're defending against. [18:26.210 --> 18:45.270] In a lot of cases, if you can't prevent someone from sitting in front of a door with a screwdriver and a lockpick for 10-15 minutes, then you need to really think about whether or not a mechanical key is going to be good enough at all. [18:46.330 --> 18:49.550] There are a lot of different mechanical lock technologies. [18:49.550 --> 18:53.430] And all that sort of is well-discussed, you know, other places. [18:53.790 --> 18:56.270] And it goes into the lockpick village. [18:56.810 --> 18:57.250] Yeah. [18:57.510 --> 18:58.390] Check out the lockpick village. [18:58.530 --> 18:59.110] Eric's running it. [18:59.330 --> 19:00.450] Or helping out running it. [19:02.930 --> 19:08.410] So this gets to a lot of other sort of more interesting, I think, access control systems. [19:08.610 --> 19:12.490] So, for example, one great one that you don't really see quite so often is Ving card. [19:12.490 --> 19:14.610] These are old mechanical key cards. [19:14.890 --> 19:16.990] You used to see a lot in hotels. [19:18.210 --> 19:20.770] Because they're very, very quick to rekey them. [19:21.470 --> 19:22.670] But they're kind of easy to copy. [19:23.390 --> 19:26.590] Oh, so the way this works is that all of these... [19:27.910 --> 19:29.770] The cards look sort of like that. [19:30.090 --> 19:31.710] And there are holes in them. [19:32.870 --> 19:35.570] And you can either read them mechanically or optically. [19:36.330 --> 19:38.990] And the reader just sort of checks to make sure that the holes are in the right place. [19:39.790 --> 19:41.850] Now, these things are sort of problematic. [19:42.030 --> 19:42.770] They're easy to copy. [19:42.970 --> 19:51.330] And there's one somewhat infamous ring of hotel thieves that went around watching the custodians open doors. [19:51.330 --> 19:57.310] And then they'd sort of go copy the key from observation, really. [19:57.430 --> 20:00.270] And then just go and steal everything from the hotel rooms. [20:00.370 --> 20:02.030] And this wasn't...not a great thing. [20:02.510 --> 20:06.630] And it's even worse because the mechanical locks of these...you have to think. [20:06.630 --> 20:09.910] There are these things sort of pressing down on the card. [20:10.930 --> 20:13.950] And it turns out that that's actually pretty easy to decode. [20:14.550 --> 20:21.050] In fact, you know, you just sort of put some little sensors on a sheet of...on a sheet of card about that size. [20:21.190 --> 20:23.510] And measure the electrical resistance change. [20:24.130 --> 20:31.110] Change when the measurement...when the pin in the reader comes down and decoded the card. [20:31.210 --> 20:32.550] And you can make it very easily. [20:32.550 --> 20:34.610] So these aren't really very high security. [20:34.870 --> 20:37.190] They're not...they're not used very often. [20:37.550 --> 20:40.670] Or, you know, there's a handful of legacy installations. [20:41.210 --> 20:42.050] But that's about it. [20:42.850 --> 20:47.110] So one of the most common ones, though, that you do see a lot still are mag stripe cards. [20:47.410 --> 20:50.850] And mag stripe cards have, you know, also been talked about a lot in other places. [20:50.930 --> 20:52.250] And I can spend a huge amount of time on them. [20:52.730 --> 20:54.250] But they're still...they're pretty fun things. [20:54.450 --> 20:55.830] You know, they come in a couple different varieties. [20:56.030 --> 20:58.030] There's low coercivity and high coercivity cards. [20:58.030 --> 21:06.930] Coercivity is just a measurement of essentially how much magnet...how much magnetic energy does it take to change...to change the card. [21:07.550 --> 21:11.310] Or to change the polarization of one of the magnetic domains in the card. [21:12.170 --> 21:18.610] Low coercivity cards, you know, just...to give you a ballpark figure, they're...they take about 300 URSTEDs. [21:19.210 --> 21:25.150] URSTED is the...the unit of measurement for coercivity to...to write. [21:25.390 --> 21:29.790] And this turns out to be a lot less than pretty much everything else. [21:30.050 --> 21:35.590] So, for example, just refrigerator magnets, other high coercivity cards. [21:35.810 --> 21:42.590] All this stuff can, you know, either rewrite or corrupt or mess up a mag stripe card. [21:43.510 --> 21:45.070] A low coercivity card. [21:45.070 --> 21:49.790] So, the low coercivity cards are generally made with just sort of run-the-mill ferric oxide. [21:50.410 --> 21:55.930] High coercivity cards, on the other hand, are made from barium ferrite and are more on the order of 3,000 URSTEDs. [21:56.050 --> 21:59.830] So, they're, you know, a solid order of magnitude more difficult to rewrite. [22:00.170 --> 22:05.750] This is one of the reasons why, you know, high coercivity writers are somewhat more expensive than low coercivity writers. [22:08.390 --> 22:17.750] You know, and it's...actually, this difference is so bad that high coercivity cards can...if you put them next to a low coercivity card, it can, you know, severely scramble the data frequently. [22:19.050 --> 22:20.810] And they're reliable, you know, they're nice to carry around. [22:21.030 --> 22:23.290] They're just sort of a...it's just a plastic card. [22:23.370 --> 22:25.970] So, they can be quite reliable as long as there aren't any other magnet trails around. [22:26.370 --> 22:28.430] Audit trail systems are just limited by the back end. [22:28.430 --> 22:34.650] So, you can...there's nothing sort of at the point of the lock, but you can do quite a bit if you want to. [22:34.910 --> 22:39.070] They're cheap, but they're also trivial to read, duplicate, and potentially modify. [22:39.390 --> 22:44.870] So, you know, they're not really considered a high security solution anymore. [22:45.050 --> 22:46.350] I don't think buy from anyone. [22:47.210 --> 22:51.910] So, max drive cards, or at least high coercivity max drive cards are a relatively recent invention. [22:52.310 --> 22:58.070] I mean, the high coercivity format wasn't standardized until, you know, in the late 90s, early 2000s, I think. [22:59.250 --> 23:03.930] And there was...these problems...the problems with low coercivity cards were certainly well known. [23:04.310 --> 23:06.770] And there were...you needed a solution to that. [23:06.990 --> 23:11.070] And so, the solution came in the form of generally custom barium ferrite cards. [23:11.390 --> 23:18.470] They look a lot...you know, the typical strategy looked a lot like a Ving card, but with the holes replaced with little sort of pieces of barium ferrite. [23:19.990 --> 23:30.230] And the magnets...the magnetic field from the barium ferrite would usually lift up pins or would be detected by Hall sensors or something to that effect in the reader to do this. [23:30.930 --> 23:33.290] And they had a lot of things going for them. [23:33.430 --> 23:34.270] They were quite tough. [23:34.430 --> 23:35.670] They were very weather resistant. [23:36.650 --> 23:42.070] They were...you know...but they were very easy to decode is the problem. [23:42.190 --> 23:45.510] Because you just sort of had this sheet of paper with magnets on there. [23:45.510 --> 23:52.330] And so, you know, iron filings, among other things, would sort of give away the...give away the code. [23:53.530 --> 24:00.290] Again, these are...this is more in sort of archaic realm, but probably last seen in an automated parking system in the middle of nowhere. [24:01.710 --> 24:07.610] So, continuing the strain of interesting but obsolete access control systems. [24:07.610 --> 24:14.850] Weakened wire is sort of one of my favorites just because the technology is sort of so neat, even though they're not used anymore. [24:15.450 --> 24:19.570] So, weakened wire itself is a process magnetic alloy. [24:19.970 --> 24:29.670] It's basically a...it's a wire with...it's been specially treated such that the...the core of the wire is soft and is being held in tension. [24:29.670 --> 24:33.610] And the outer shell of the wire is in compression. [24:33.890 --> 24:36.630] You can see the photo...the illustration here. [24:37.390 --> 24:39.750] And the...the soft core is low coercivity. [24:39.990 --> 24:41.690] The outer core is high coercivity. [24:42.010 --> 24:46.670] And what you end up with is this single apparent magnetic domain wall. [24:46.890 --> 24:52.150] Because you have just two magnetic domains with just a single domain wall throughout the entire sheet of wire. [24:53.210 --> 24:58.810] And this gives you this really cool effect such that...well, so first of all, let me back up for a moment. [24:58.810 --> 25:08.290] So, when you toggle the polarization of a magnetic domain in a ferromagnet, then that causes a flux change. [25:08.590 --> 25:09.590] A magnetic flux change. [25:09.730 --> 25:12.950] And if you have a coil nearby, that can...it'll induce current. [25:13.210 --> 25:14.810] And it'll induce current in the coil. [25:15.010 --> 25:24.390] So, a great way to just to sort of see this happening is to take a...take just a coil of wire attached to some speakers or a set of headphones. [25:24.390 --> 25:29.310] Place it next to a piece of iron or another ferromagnetic metal. [25:29.790 --> 25:32.030] And then take a magnet and sort of wave it next to the piece of metal. [25:32.230 --> 25:33.350] And you'll hear...you'll hear static. [25:33.630 --> 25:37.070] And that's being caused by the...by flux changes. [25:37.070 --> 25:40.830] By flux changes caused...when magnetic domains change polarity. [25:42.690 --> 25:48.770] And...in a typical...in a typical piece of ferromagnetic material, this effect isn't that strong. [25:48.770 --> 25:49.830] You'll...you hear static. [25:50.790 --> 25:53.230] But...in a weekend wire, there's only one domain. [25:53.510 --> 25:55.910] So, there's only one thing that's changing polarity. [25:56.670 --> 26:00.990] And that's what the...that's what the weekend wire access control system is based on. [26:01.270 --> 26:02.770] So, you'll have a... [26:08.500 --> 26:16.540] If anybody has any clue why occasionally NMBD tries to connect to random computers on the Internet and triggers a little snitch, please tell me. [26:17.100 --> 26:19.060] I've been having this problem for years now. [26:21.520 --> 26:21.920] Okay. [26:23.640 --> 26:24.040] So...continuing. [26:24.700 --> 26:27.960] So, a weekend wire card has two lines, right? [26:28.000 --> 26:29.800] It has a one line and a zero line. [26:30.120 --> 26:32.700] This might remind you of the weekend bus protocol. [26:33.080 --> 26:34.940] Because it's all sort of from the same place. [26:36.060 --> 26:40.620] It has a...if there's a weekend wire in the one spot, then it reads a one. [26:40.960 --> 26:43.540] If there's a weekend wire in the zero spot, it reads a zero. [26:44.800 --> 26:47.380] And these are run through a couple different magnets. [26:47.840 --> 26:53.620] So, first is run over one set of magnets that saturates all of the...all of the weekend wires in one polarity. [26:54.040 --> 26:58.560] Then it resets them in the...in a set of magnets right next to the reed head. [26:58.760 --> 27:00.340] And then it sets them right after the reed head. [27:00.980 --> 27:10.520] And this gives you this nice single big magnetic flux change, which triggers...which induces a, you know, nice pulse of current in the reed heads. [27:11.260 --> 27:16.600] And that's decoded as the...as a...as a code on the weekend card. [27:17.160 --> 27:23.500] And you'll see there's...there's a lot of sort of historical coincidence to the weekend bus protocol here related to this. [27:23.780 --> 27:33.440] Because if you'll notice, there isn't really anything preventing you from just taking the output almost straight from the reed head, calling one of those the data one wire and one of those the data zero wire. [27:35.380 --> 27:37.740] And...and just running that straight to your access control system. [27:37.980 --> 27:50.400] So, the fact that we're using this Wigan bus protocol in smart card readers and prox card readers, is all just sort of a side effect of this one...there's a physical...physical phenomenon. [27:51.560 --> 27:56.380] So, here's a photo of a Wigan card where you can actually see the one and zero Wigan wires. [27:57.020 --> 27:59.780] This is a magnetic...magnetic film on top. [28:00.180 --> 28:02.560] So, the way this was taken was just put the magnetic film on top. [28:02.640 --> 28:06.100] Wave a...weave a magnet across it to induce the flux change. [28:06.300 --> 28:07.880] And then that shows up on the film. [28:08.620 --> 28:09.500] Take a photo of that. [28:10.180 --> 28:12.300] So, what about breaking Wigan wire cards? [28:12.460 --> 28:16.920] So, the first attack on these things was released in 96 on the Cypherpunks list. [28:17.760 --> 28:21.800] And so, one of the problems with Wigan wire is that you can't buy it. [28:22.000 --> 28:23.780] Like, you can't buy it in bulk quantity. [28:24.080 --> 28:25.400] It's just not really possible. [28:25.540 --> 28:30.940] If you need it, they need to go find a specialty magnetic materials place and have them custom develop it for you. [28:31.820 --> 28:41.300] But, there's lots of good sources of sort of Wigan wires in just the right quantity and just the right size and shape for a Wigan wire card. [28:41.440 --> 28:43.480] There's just other Wigan wire cards. [28:43.480 --> 28:51.000] So, there isn't really anything preventing you from just cutting one up and sort of rearranging the wires and using that to clone these things. [28:51.280 --> 28:55.180] As you saw in the last photo, they're pretty easy to decode. [28:55.920 --> 28:57.400] And it's even worse than this. [28:57.560 --> 29:01.900] Because if you just hold one of these up to a bright light, then you can very clearly see where the wires are. [29:03.080 --> 29:10.420] And additionally, if you're not willing to actually do this, or you don't want to, these things are also vulnerable to emulation style attacks. [29:10.420 --> 29:21.160] Since it's not like this reader is actually detecting the Wigan wire, it's detecting a magnetic flux change, which is very easy to simulate with a solenoid. [29:22.340 --> 29:23.900] Okay, so moving on to barcodes. [29:24.140 --> 29:26.860] Barcodes, I don't think they're that interesting personally. [29:27.020 --> 29:29.640] They're cheap, they're low security, come in 1 and 2D versions. [29:30.220 --> 29:31.380] They're easy to duplicate. [29:32.620 --> 29:36.040] They're appropriate for some things, but not for most things. [29:36.040 --> 29:45.660] There have been some attempts at making sort of cheesy invisible barcodes, where you cover up the barcode with IR-sensitive ink, or using fluorescent inks and things like that. [29:45.960 --> 29:48.300] None of which really contribute to security much. [29:49.000 --> 29:50.140] So prox and RFID. [29:50.860 --> 29:53.200] Prox and RFID, lots of well-known issues. [29:54.100 --> 29:56.160] They're becoming more and more pervasive. [29:56.460 --> 29:57.760] And they're more and more common. [29:57.760 --> 30:00.160] And this is sort of one of the... [30:00.160 --> 30:01.540] One of the... [30:01.540 --> 30:04.600] Probably the next generation of access controller. [30:04.760 --> 30:06.360] What most people are deploying these days. [30:06.920 --> 30:07.940] They get a lot of well-known issues. [30:08.080 --> 30:08.740] You can clone them. [30:09.100 --> 30:09.900] You can track them. [30:10.080 --> 30:13.120] You know, it's another thing that's been talked about more than once in this talk. [30:15.020 --> 30:22.140] One of the things that I think is interesting to talk about, though, is how the RFID systems are integrated with existing legacy systems. [30:22.880 --> 30:27.800] Because this is another one of those sort of system borders where you get interesting vulnerabilities. [30:28.220 --> 30:33.780] So one of the things at MIT, for example, they introduced an RFID system with... [30:33.780 --> 30:39.480] that was on the same Magstripe cards they had before. [30:39.880 --> 30:48.300] And it turned out that there's actually a clear mapping between the RFID sort of token numbers and the things encoded on a Magstripe. [30:48.540 --> 30:52.340] And this meant that by sniffing or by... [30:52.340 --> 30:57.120] by sniffing in RFID, you could actually clone the Magstripe too. [30:58.340 --> 31:02.820] And, you know, you might think, maybe this isn't such a problem. [31:03.020 --> 31:06.320] I mean, if you can clone the RFID, then that's already enough of a problem. [31:06.540 --> 31:14.260] But I mean, it turns out that the Magstripe is what's used to control, say, your campus money for food, for example. [31:14.880 --> 31:25.420] So now someone's walking around, you know, sniffs your card and clones it, can access your food money as well. [31:27.080 --> 31:28.180] Not everyone... [31:28.180 --> 31:37.420] I should note that after the paper was released, that was linked earlier, some months, maybe years afterward, MIT got a clue and updated their system. [31:38.120 --> 31:38.840] Yay, full disclosure. [31:39.240 --> 31:40.360] Yeah, so it's... [31:40.360 --> 31:41.840] Yeah, they changed it a bit. [31:42.280 --> 31:45.480] So not everyone was happy about RFIDs at MIT. [31:45.480 --> 31:49.060] And in particular, Richard Stallman wasn't real happy about it. [31:49.780 --> 31:51.120] Here's his RFID key. [31:51.760 --> 31:53.640] It automatically spoofs one of... [31:54.520 --> 31:55.000] several... [31:55.000 --> 31:57.020] several of his co-workers' RFIDs. [32:00.040 --> 32:03.360] So, Prox cards are great, but they're kind of limited. [32:03.720 --> 32:05.440] I mean, there's only so much you can do on them. [32:05.500 --> 32:08.100] Most of them are pretty much dumb memory devices. [32:08.440 --> 32:10.360] Some of them are smarter, but really... [32:10.360 --> 32:17.840] really, if you're looking for high security, you know, you want a cryptographic protocol to talk to, you end up with these CPU tokens. [32:18.420 --> 32:19.980] Either smart cards or iButtons. [32:20.100 --> 32:21.660] This is a photograph of an iButton here. [32:22.440 --> 32:23.560] You know, the problem was just... [32:24.040 --> 32:29.500] you know, it's essentially a smart card in a button format, if you'd expect. [32:29.800 --> 32:35.520] You know, someone decided that they didn't really want to put cards on a keyring, so you ended up with CPU... [32:35.520 --> 32:37.680] with iButtons to do that. [32:39.420 --> 32:40.400] You know, these things... [32:40.400 --> 32:41.220] these things are cool. [32:41.220 --> 32:48.780] So, you know, it can be easy to make sort of a virtual token just by emulating that with other electronics, which is a problem. [32:50.160 --> 32:55.560] And again, you know, sometimes cryptographic authentication that they use isn't such good cryptography. [32:56.400 --> 32:59.880] And that's probably one of the single key things to worry about here. [33:01.020 --> 33:08.580] You also need to worry about power analysis, Direct TV spends... spent eons fighting hackers to prevent them from cloning their... [33:08.580 --> 33:13.300] from cloning their cards using, you know, differential power analysis and all those... [33:13.300 --> 33:14.320] and those techniques. [33:16.300 --> 33:17.480] But again, one of the... [33:17.480 --> 33:21.320] one of the more important issues when trying to integrate these for the system... [33:21.320 --> 33:25.900] integrate this in an existing system is to worry about sort of all of the... [33:25.900 --> 33:27.400] what's going on behind the scenes. [33:27.400 --> 33:33.740] Like, I mean, you have this crazy cryptographic authentication protocol that's using, you know, real... real techniques. [33:33.920 --> 33:37.740] You know, you got ACE or Diffie-Hellman or something between... between your CPU token and the reader. [33:38.240 --> 33:41.420] You need to make sure that that's actually propagated all the way back to the... [33:41.880 --> 33:43.740] to the actual access control panel. [33:45.100 --> 33:47.840] Okay, now Eric's going to talk a bit about knowledge-based systems. [33:48.700 --> 33:49.780] Yeah, you saw the... [33:49.780 --> 33:51.320] you saw the safe tracking talk. [33:51.660 --> 33:53.240] I mean, I know you guys were all there, right? [33:55.040 --> 33:55.840] That was... [33:55.840 --> 34:03.020] safes are one of the oldest knowledge-based access control systems because, well, you've got a dial in the front and you need to know the combination to get in the safe. [34:04.680 --> 34:08.360] They're still in use today in many cases for even physical access control. [34:08.500 --> 34:11.300] The government uses physical safe locks on some doors. [34:12.280 --> 34:29.380] But more common these days is, of course, electronic keypads and safe-type electronic locks which are electronic locks that are designed for use on safes and adapted to doors or electronic locks that look like safe locks and, again, can be used on doors or on vaults. [34:31.060 --> 34:32.420] Mechanical combination locks. [34:32.900 --> 34:37.360] There is one unique type that doesn't come from the safe world. [34:37.420 --> 34:38.400] That's the simplex lock. [34:38.600 --> 34:39.820] You guys have all seen these. [34:39.920 --> 34:45.480] Some of you guys, you know, may have looked online, how do I pick them and looked at the instructions being like, uh... [34:45.480 --> 34:47.100] and gone into brute force, everything. [34:47.240 --> 34:51.400] I know there's a 2600 article on going through all the possible combinations which really isn't very money. [34:53.160 --> 34:56.500] The reason they're used is they're pretty simple. [34:56.680 --> 34:57.880] They're mechanical devices. [34:57.880 --> 34:58.880] They don't need any power. [34:59.240 --> 35:00.200] They're very reliable. [35:01.240 --> 35:02.560] Pretty simple mechanism. [35:03.060 --> 35:09.240] Easy to understand from the perspective of the poor guy making, you know, nine bucks an hour who has to go in and reset the combination every time. [35:10.760 --> 35:13.860] Unfortunately, they don't have any audit trail so you can't tell who came in. [35:13.860 --> 35:24.980] You can't tell if the last guy that came in was, you know, your co-worker next to you and that's why, you know, your TV is gone or your computer screen is gone because he wanted the 30-inch back home to watch, you know, Unreal Tournament... [35:24.980 --> 35:25.940] play Unreal Tournament on. [35:27.500 --> 35:27.900] Um... [35:27.900 --> 35:31.920] You can manipulate them even if the instructions on the web aren't very clear. [35:32.140 --> 35:35.260] And, of course, they're quite easy to brute force. [35:35.480 --> 35:36.560] There aren't that many combinations. [35:36.560 --> 35:52.120] You can go on the web and find a list, sit there for 10 minutes with, you know, a chair and maybe some music playing on your iPod and go through all the possible numbers and open that FedEx box or, you know, whatever it is that behind that nondescript steel door with two guards outside it during the day. [35:54.580 --> 35:56.920] To understand how you manipulate these locks... [35:56.920 --> 35:58.180] Could you go back a little bit to copy that? [35:58.780 --> 35:59.440] Oh, sure. [36:01.020 --> 36:02.680] Let's see if I can get these guys here. [36:03.180 --> 36:03.820] There we go. [36:04.300 --> 36:05.740] This should be posted on the web. [36:06.420 --> 36:07.540] Where would it be posted? [36:08.440 --> 36:17.520] I'll have it on security.ericschmiedel.com security.ericschmiedel.com Bug me afterwards if you want to know how to spell my last name. [36:18.640 --> 36:20.800] If you Google me, you'll probably find it. [36:29.090 --> 36:31.150] Anyway, so how these things work... [36:31.150 --> 36:34.590] Well, you enter the combination and you turn the handle in the open. [36:34.870 --> 36:35.570] Real simple. [36:36.070 --> 36:38.590] How that works is you have... [36:39.830 --> 36:41.030] It's like a safe lock. [36:41.030 --> 36:47.650] You have a series of buttons that are connected via gears to a series of rotating tumblers. [36:48.050 --> 36:55.170] And instead of having them all on one single spindle and having a fence that drops in, you have a linear fence. [36:55.330 --> 36:59.670] This is basically that black metal thing on the bottom with a couple of fingers poking out of it. [37:00.010 --> 37:01.570] Five fingers, in fact. [37:01.570 --> 37:06.870] that have to all drop in two slots in those five tumblers. [37:07.250 --> 37:12.070] And if you look, you'll see that there's a couple of tumblers which are aligned. [37:12.250 --> 37:13.830] Those would be the right two. [37:14.170 --> 37:16.810] And then the left three aren't aligned. [37:16.810 --> 37:20.270] And those fingers couldn't slide in even if they wanted to. [37:21.850 --> 37:25.830] When you enter the combination and you can see this here in the video. [37:27.630 --> 37:30.570] You advance the tumbler by one. [37:31.370 --> 37:33.170] That is the tumbler that's linked to the key. [37:34.050 --> 37:44.890] When you press any button after that, not only do you advance the tumbler that is linked to the button you just pushed, but you also advance the previous tumblers that you already pushed. [37:45.530 --> 37:50.430] This is how each tumbler has five different positions, even though you can only press each key once. [37:50.970 --> 38:05.390] Because if you press the one key, then the two key, then the three key, first you advance the tumbler number one, then you advance tumbler number two and one, because you just press two, then you advance tumbler number three, and then advance again tumblers one and two. [38:06.270 --> 38:21.870] This sounds kind of complicated, but basically it means that the tumbler one can go all the way to position number five, But if it's the last number of the combination, it can only be at position number 1 or not be used at all if it's not a number of the combination. [38:22.570 --> 38:29.690] This is also how the locks know whether you entered the combination the right way or the wrong way if you entered 1, 2, 3 as opposed to 3, 2, 1. [38:31.470 --> 38:32.810] It'll make sense in a sec, trust me. [38:34.130 --> 38:38.530] So if you want to pick it, just like Gini lock, it's all about figuring out which ones are binding. [38:39.390 --> 38:44.350] If you look at the video, and I'm going to play this again so you can see it clearly, because this screen is way too small for that video. [38:47.190 --> 38:58.630] You'll see that as I apply a bit of torque to the handle of the lock, and then push on all the buttons, the first tumbler is binding and the rest aren't. [38:59.690 --> 39:03.130] The thing about these locks, normally you crank the handle. [39:03.270 --> 39:05.770] If you haven't had the combination, it goes all the way and the door doesn't open. [39:06.450 --> 39:09.010] But there's this one place. [39:10.190 --> 39:14.070] You turn the handle, there's this bit of resistance, and then it keeps going. [39:14.730 --> 39:24.430] If you stop that bit of resistance, you haven't triggered the little clutch that says, oops, no combination entered, or wrong combination entered, just let the guy keep going and don't open the door. [39:25.330 --> 39:33.470] If you stop and don't trigger that clutch, you'll actually be applying torque or tension to the internal mechanism, which lets you get information with the lock. [39:34.190 --> 39:42.410] So to figure out which tumblers are binding, you turn the handles until you feel resistance, and then just keep applying force without going too far. [39:42.830 --> 39:43.570] It's just practice. [39:43.730 --> 39:45.150] It takes about 30 seconds to learn. [39:46.090 --> 39:55.330] And you go through, and you look at all the tumblers, and you see that in this case, the first tumbler is binding because that button isn't pushing as far down. [39:55.790 --> 40:10.490] But the rest, the buttons are going significantly further down because those tumblers are moving around freely because once you're pushing on that fence, those tumblers, the tumbler that's binding can't move because it's destruction there. [40:10.870 --> 40:18.850] The other tumblers are free to go over wherever the hell they want to because the fence isn't touching them yet because there's mechanical imperfections in the lock, as with any lock. [40:18.910 --> 40:20.010] That's how we pick all of them. [40:21.010 --> 40:22.550] So we know the first tumbler is binding. [40:22.630 --> 40:23.470] What the heck should we do now? [40:25.070 --> 40:30.670] We push the first tumbler, and we figure out, are any other tumblers binding? [40:30.850 --> 40:37.210] Because once the first tumbler is pushed, you've now advanced that wheel one position. [40:38.330 --> 40:46.090] And the question is, is the gate in that wheel now under the finger in the fence, allowing it to bind to a different tumbler? [40:48.940 --> 41:02.800] The thing is, and here's the thing, if another tumbler is binding, and this is where it gets really cerebral, if another tumbler is binding, the logical thing to do isn't to push that second tumbler. [41:05.580 --> 41:15.840] Because what's happened is, if by pushing one, we put that first tumbler in the right position, pushing another button is going to throw everything out of whack, and that first tumbler is going to go back into a wrong position. [41:15.980 --> 41:16.600] It's going to go too far. [41:17.700 --> 41:24.580] So we want to make sure that first tumbler from now on is always in the right position, which happens to be in position one. [41:26.940 --> 41:34.240] In this case, however, after pushing one, we didn't find any more binding tumblers. [41:34.420 --> 41:42.120] That is, all the other pins we tried pushing all had about the same amount of sloppiness and weren't hard, weren't resisting at all, like tumbler number one was. [41:42.480 --> 41:44.380] Which means we know something else about the lock. [41:44.380 --> 41:56.040] We know that tumbler one is not supposed to be in position one because once it got to position one, no other tumbler was freed up, or no other tumbler started binding. [41:56.920 --> 41:59.020] So we advance another position. [41:59.600 --> 42:02.140] What we do is we push a throwaway button. [42:02.520 --> 42:04.200] In this case, I push five. [42:05.160 --> 42:07.980] And we see if any more tumblers are binding. [42:08.420 --> 42:13.000] By pushing five, we've advanced tumbler number one to the second position. [42:13.320 --> 42:18.240] And now we're going to see if it's in the right position because another pin is binding. [42:18.380 --> 42:21.200] I'm going to show this video again without talking so you guys can actually concentrate. [42:31.290 --> 42:35.230] And so we check for binding because there wasn't any binding. [42:35.510 --> 42:39.190] After pushing four, this was to advance tumbler number one to yet another position. [42:43.360 --> 42:45.580] And we find that tumbler number two is binding. [42:46.500 --> 42:54.060] Which means that tumbler number one, because we had to push two buttons after pushing one to get tumbler number one to the right position. [42:54.680 --> 43:01.620] We know that tumbler number one is three numbers before the end of the combination. [43:04.220 --> 43:18.660] So we're going to try the combination 152 and see if any tumblers are binding because now we have the tumbler number one in the third position which we know is right and we're going to see if tumbler number two is now in the right position. [43:19.300 --> 43:26.460] We reset the lock, and since that didn't work, try 1, 2, 5, and [43:31.780 --> 43:35.760] see if any more tumblers are binding, because I'll see if we put any more tumblers in the right position. [43:40.290 --> 43:42.410] At this point, we go back and reset the lock. [43:42.570 --> 43:48.390] Again, we know tumbler number 1 is supposed to be the first three positions away from the end of the combination. [43:48.530 --> 43:50.650] Try 1, 2, 3, and the lock opens. [43:51.730 --> 43:57.990] This is something that's a bit hard to understand, even when you're looking at the video. [43:58.550 --> 43:59.870] How many of you guys actually got it? [44:01.610 --> 44:03.310] Yeah, that's like, what, 30% of the room? [44:04.070 --> 44:15.430] Yeah, if you go online, there's a text file called The Hobbit's Guide to Simplex Locks, and that explains this in written form, so you can sit down with a lock and do this at home and learn how to do it. [44:16.650 --> 44:17.830] Hobbit as in the... [44:17.830 --> 44:18.650] The Hobbit. [44:19.750 --> 44:20.150] Hobbit. [44:20.150 --> 44:20.890] That's the guy's name. [44:21.870 --> 44:22.450] No, just Hobbit. [44:22.570 --> 44:23.090] Just Hobbit. [44:23.450 --> 44:24.490] No, just... Okay, just Hobbit. [44:25.090 --> 44:25.790] Are you him? [44:27.590 --> 44:27.990] Okay. [44:29.090 --> 44:29.850] Are you him? [44:30.250 --> 44:30.570] No. [44:30.810 --> 44:31.070] Okay. [44:31.110 --> 44:31.810] He's at a previous conference. [44:32.130 --> 44:32.730] Ah, too bad. [44:33.770 --> 44:34.630] Tell us what he said. [44:35.710 --> 44:36.390] Simplex locks. [44:36.870 --> 44:38.750] No, I mean, what's the name now? [44:39.970 --> 44:40.370] Hobbit. [44:41.050 --> 44:43.070] As in Lord of the Rings, all that? [44:43.330 --> 44:43.410] Yeah. [44:44.930 --> 44:48.490] Anyway, since I'm going to go real fast, since I've got, like, I don't know, not enough time here. [44:50.110 --> 44:54.650] Electronic keypads, these are the things you see all over the place, you go through your combination, door opens, bada-bing, you're good, how do you break them? [44:54.890 --> 45:06.590] Well, it used to be you could look at fingerprints, or you could dust it with UV powder and wait until the guy comes back, comes back into the combination, come back after him, shine a UV flashlight, look at which buttons he's pushed, and try all the possible permutations of those buttons. [45:06.590 --> 45:09.310] Great, but it takes you about a week if the thing is locking you out. [45:09.770 --> 45:10.690] So use a highlighter. [45:11.310 --> 45:16.670] Turns out that highlighter ink is tracked from key to key because it's sticky, and it doesn't really ever dry properly. [45:17.150 --> 45:19.810] You can also use a hidden camera if you're real tech-sophisticated. [45:20.210 --> 45:24.370] How the highlighter trick works is, well, look at this keypad, what's wrong with it? [45:25.670 --> 45:31.310] You know, if you look really closely, and this projector doesn't really show you it, maybe some kid scribbled the number one key with a highlighter. [45:31.770 --> 45:32.530] Yellow highlighter. [45:33.070 --> 45:33.390] It's too dark. [45:33.910 --> 45:34.210] Pardon? [45:34.350 --> 45:35.450] Yeah, it's too dark, sorry. [45:36.170 --> 45:42.510] But anyway, it's highlighted, doesn't look like a burglary attempt, doesn't look like someone's trying to get in, but under UV light you can see some evidence. [45:43.130 --> 45:55.390] What happens is our $9 an hour guard comes into work in the morning, he enters his combination, you come in after him with your UV light again, and you see that from the number one key to the number two key, he's tracked the highlighter ink. [45:55.930 --> 45:58.830] You know that the combination now contains the sequence one, two. [45:59.330 --> 46:06.350] So you come back the next day, you put the highlighter ink on the number two key, and you find that he's tracked it the next day to the number three key. [46:06.570 --> 46:16.870] You wash, rinse, repeat, and find out that pretty soon the combination is one, two, three, four, because after putting highlighter ink on the fifth key, just to be sure, it never got tracked anywhere. [46:17.610 --> 46:21.210] Ba-da-bing, you don't have to sit there all day for a week and get caught. [46:21.590 --> 46:26.210] You just come back for 30 seconds with your highlighter and your UV pen, and maybe you just wipe it off. [46:27.730 --> 46:29.930] Other way to do it, use cameras, hidden cameras. [46:31.110 --> 46:33.130] Watch Tiger Team, they do a great job of this. [46:33.490 --> 46:39.410] Hide the camera next to the keypad, watch the code entry, watch it on your little remote screen, come in, and ba-da-bing, you're in. [46:39.950 --> 46:50.330] The solution to all this is the Scramble keypad, which is the dynamically changing keypad, which fixes most of these problems because the keys change around kind of like Alice in Wonderland. [46:50.510 --> 46:54.050] Little LED things, everything gets scrambled every time the combination is entered. [46:54.470 --> 46:56.490] However, users can still tell their friend. [46:57.610 --> 47:00.550] Safe-type electronic locks, I talked about these in Safe Cracking Talk. [47:00.850 --> 47:01.890] Basically, they're really secure. [47:01.970 --> 47:04.070] This is the X08, I believe. [47:05.070 --> 47:07.410] The whole thing is they've usually got an audit trail. [47:07.890 --> 47:12.810] These are usually either got a dial on them or they've got keypad, which, of course, is vulnerable to the keypad trick. [47:14.190 --> 47:15.670] You usually get an audit trail. [47:15.850 --> 47:25.750] There's a Lagarde navigator, which is kind of cool because it's a cell phone safe lock, which means that your SEER safe is protected by the cellular phone network, which means you've got a great audit trail. [47:25.850 --> 47:28.970] You can see in real time who's going in, leaving your safe. [47:29.170 --> 47:30.170] You can give them access. [47:30.190 --> 47:31.270] You can deny them access. [47:31.490 --> 47:33.770] But, well, it's connected to the cellular phone network. [47:33.970 --> 47:38.990] And the Interwebs, which means that there's all sorts of guys out there, probably on 4chan, who are trying to get into your ATM. [47:40.890 --> 47:48.810] Of course, a lot of safe locks are vulnerable to spiking, which means drilling a hole or just pulling out the wires and applying voltage at the right place. [47:49.710 --> 47:50.870] Other tricks like that. [47:51.130 --> 47:54.270] You've got biometrics, which I'm going to see if I can get to before they cut me off. [47:54.810 --> 47:56.430] But I'm meant to talk really fast. [47:57.010 --> 48:00.410] You've got voice, face, fingerprints, hand geometry, retina scan, iris scan, signature. [48:00.670 --> 48:01.630] Voice pattern recognition. [48:01.830 --> 48:03.050] This is, you know, my voice is my password. [48:03.110 --> 48:04.670] You walk up and you look like James Bond. [48:04.870 --> 48:07.050] Easy to defeat because, well, you've got your tape recorder there. [48:08.010 --> 48:13.570] Face recognition, well, it turns out you can hold up a photo or your laptop if it's a thing with live checks. [48:13.830 --> 48:24.330] The laptop playing video of the guy that you filmed with your $200 HD super consumer records to whatever camcorder while he's walking down the street will let you in in his place. [48:25.110 --> 48:31.650] Fingerprints, well, your fingerprints leave behind fingerprints on the sensor, so let's take advantage of that by using gummy bears, breath-water-filled bags like condoms. [48:31.850 --> 48:32.950] Just plop it out on the sensor. [48:33.150 --> 48:34.950] And in many cases, that will work. [48:34.950 --> 48:37.290] Just breathe on the dead, breathe on the damn thing. [48:37.370 --> 48:37.750] Who would have thought? [48:38.810 --> 48:41.950] Nowadays, they try to fix that because everybody knows about it by using swipe-type sensors. [48:42.210 --> 48:48.070] You can still, of course, pick up fingerprints, photograph them, have them etched onto PCBs, then mold your own fingerprints. [48:48.470 --> 48:48.990] Kind of cool. [48:49.490 --> 48:51.190] The environment around the sensor has fingerprints. [48:51.470 --> 48:53.370] So the trick is, of course, to have a trained guard. [48:53.650 --> 48:59.330] This doesn't help if the attacker is using a fingerprint attached to his finger using something like Elmer's glue. [49:01.090 --> 49:06.510] Multispectral imaging is a trick that was invented by some crazy people, a company called LumaDime. [49:07.050 --> 49:19.010] The whole idea is that it uses different wavelengths which should go through the skin and therefore read out the blood vessels as well as the fingerprint on the surface, which means it would, in theory, look through the Elmer's glue, see if there's another fingerprint there, [49:19.070 --> 49:19.790] and be like, whoa! [49:21.650 --> 49:23.390] They claim it can do all these great things. [49:23.570 --> 49:24.670] Nobody's actually tested it. [49:25.530 --> 49:26.950] In theory, this is how it works. [49:27.810 --> 49:28.630] Different wavelengths. [49:28.970 --> 49:30.810] There are actually infrared wavelengths which will go through the skin. [49:31.170 --> 49:33.730] So they use those as well as visible wavelengths. [49:34.450 --> 49:35.690] Pull it all together in the computer. [49:35.890 --> 49:37.510] And so your finger looks like that. [49:37.670 --> 49:42.310] Your finger with a thin shell on it, like Elmer's glue, looks like that, which looks way different than a regular fingerprint. [49:42.670 --> 49:50.730] And if you're using a totally fake fingerprint like one you made out of gummy bear or Jello or whatever, it's going to look nothing at all like a live finger. [49:52.150 --> 49:52.730] In theory. [49:53.410 --> 49:54.930] Hand geometry is this kind of cool system. [49:55.430 --> 49:56.930] You see them at airports all the time. [49:56.930 --> 49:59.610] You put your hands on the platen and they get open. [49:59.710 --> 50:00.910] This is what it looks like from the hand scanner. [50:02.490 --> 50:03.390] Cast your own hand. [50:03.890 --> 50:04.990] Come on, you can buy kits on the web. [50:06.450 --> 50:07.170] Retina scan. [50:07.330 --> 50:09.490] Nobody has ever falsified a retina publicly. [50:09.730 --> 50:11.330] Some CIA guys probably have. [50:11.510 --> 50:12.430] But it's really invasive. [50:12.570 --> 50:15.970] You've got to get your eye really close to the scanner and take off your glasses and everybody hates to do it. [50:16.710 --> 50:20.430] Iris scanner is the simpler, less intrusive way. [50:20.750 --> 50:21.710] Camera takes a picture. [50:22.150 --> 50:23.210] Really low error rate. [50:23.350 --> 50:25.890] Really, really, really, really low error rate, in fact. [50:25.890 --> 50:32.370] The problem is your average magazine cover, like if President Bush has enough resolution to fool the iris scanner. [50:32.590 --> 50:37.230] So you go up to the nuclear bunker with your cover of Time magazine and be like, sure, I am President Bush. [50:37.490 --> 50:39.030] Give me all the nuclear launch codes, please. [50:39.910 --> 50:42.850] You can also print on contact lenses, custom contacts, anybody. [50:43.610 --> 50:44.490] Signature recognition. [50:45.050 --> 50:46.570] It's easy to forge your signature. [50:46.790 --> 50:49.770] And I've been told to stop, which is great because I'm done. [50:53.560 --> 50:54.380] Further reading. [51:02.430 --> 51:04.410] Any questions before they kick me out? [51:11.120 --> 51:11.720] Thank you. [51:14.640 --> 51:16.180] Well, as long as one person learned. [51:17.280 --> 51:21.580] I think, if I remember right, public subscription actually has one very crucial problem. [51:22.060 --> 51:22.400] Mm-hmm. [51:22.660 --> 51:23.360] Like, there's a... [51:23.360 --> 51:26.320] Your Mac thinks those random addresses have shares that maybe you want to use. [51:26.520 --> 51:26.860] Pardon? [51:27.020 --> 51:28.720] Your Mac thinks those random addresses have shares that maybe you want to use.