Psychic Paper: Making eink access badges accessible for anyone

Joshua Herman

DEF CON 32 Creator Stage · Day 1 · Creator Stage

Overview

In the DEF CON 32 talk "Psychic Paper: Making eink access badges accessible for anyone," Joshua Herman, also known as Zitterbewegung, unveiled a novel approach to physical red teaming and social engineering utilizing e-ink and e-paper displays. The presentation detailed how these low-power, non-emissive screens could be leveraged to create dynamic, reprogrammable identification badges, effectively mimicking legitimate access credentials in real-time. This technique represents a significant evolution beyond traditional static, printed badge counterfeits, offering a more adaptable and believable method for gaining unauthorized physical access.

Watch on YouTube

Visual summary for Psychic Paper: Making eink access badges accessible for anyone by Joshua Herman
Visual summary for Psychic Paper: Making eink access badges accessible for anyone by Joshua Herman

Key moments

  1. 0:00 Introduction to Psychic Paper and e-ink badge faking
  2. 2:00 Real-time badge cloning for physical red teaming and social engineering
  3. 2:18 Sourcing and features of common 3-color e-ink displays
  4. 3:05 E-ink technology: electro-mechanical, non-emissive, low power
  5. 4:00 Understanding e-ink's true three colors and image longevity
  6. 4:52 Anticipation for the upcoming five-color e-ink prototype

Psychic Paper: Making eink access badges accessible for anyone

Speakers: Joshua Herman

Conference: DEF CON 32

YouTube: https://www.youtube.com/watch?v=ssLu8xHMwSk

Overview

In the DEF CON 32 talk "Psychic Paper: Making eink access badges accessible for anyone," Joshua Herman, also known as Zitterbewegung, unveiled a novel approach to physical red teaming and social engineering utilizing e-ink and e-paper displays. The presentation detailed how these low-power, non-emissive screens could be leveraged to create dynamic, reprogrammable identification badges, effectively mimicking legitimate access credentials in real-time. This technique represents a significant evolution beyond traditional static, printed badge counterfeits, offering a more adaptable and believable method for gaining unauthorized physical access.

Herman's work highlights critical security vulnerabilities in readily available commercial e-ink systems, which often lack robust authentication or secure programming mechanisms. By demonstrating the potential to combine these dynamic visual fakes with established RFID cloning techniques, the talk underscores a potent threat to organizational physical security. The "Psychic Paper" concept aims to make sophisticated badge replication more accessible for ethical hacking engagements, prompting organizations to re-evaluate their physical security protocols in an era where digital displays can convincingly masquerade as static printed matter.

The core motivation behind this research is to expose the ease with which sophisticated physical social engineering attacks can be executed using off-the-shelf components, especially when paired with an understanding of existing access control system weaknesses. Herman’s project serves as a crucial wake-up call for security professionals, urging them to consider the implications of dynamic display technology on badge authenticity verification and overall facility access control.

Background

▶ Watch: Introduction to Psychic Paper and e-ink badge faking (0:00)

Physical security has long been a critical, yet often overlooked, component of an organization's overall defense posture. Social engineering, in particular, remains a highly effective vector for bypassing physical controls, with forged identification badges being a classic tool in the red teamer's arsenal. Historically, replicating employee ID badges involved obtaining high-resolution photographs, editing them, and then printing them out. While effective to a degree, this method produces static fakes that, once printed, cannot be easily altered or updated in response to changing circumstances or specific target profiles.

The advent of e-ink and e-paper display technologies introduces a new paradigm for physical social engineering. Unlike traditional light-emissive displays such as OLED or LCD, which constantly require power to emit light and maintain an image, e-ink and e-paper are non-light-emissive and electro-mechanical devices. This fundamental difference is crucial: once an image is "programmed" onto an e-ink display, the microscopic charged particles (or pigments) within its capsules are physically moved into position and remain there indefinitely without requiring further power. As highlighted by the speaker, a device could retain an image for over 12 years with no degradation, making it ideal for persistent, realistic fakes.

This property makes e-ink displays exceptionally power-efficient and allows them to mimic the appearance of printed paper, which is a key advantage for counterfeiting badges. The term "e-ink" is a trademarked technology (E Ink™), while "e-paper" is a more general term for similar display technologies. Both types leverage the same core principle of electro-mechanical pigment movement. While current commercially available e-ink displays are typically limited to a few colors—commonly "white-ish," black, and red—their non-emissive quality and image persistence make them highly suitable for creating convincing, dynamic visual fakes that blend seamlessly with a real-world environment, unlike the glowing screens of a smartphone or tablet.

Key Findings

▶ Watch: Sourcing and features of common 3-color e-ink displays (2:18)

Joshua Herman's research uncovered several significant findings regarding the application of e-ink displays for physical access badge replication and the broader implications for security. The primary discovery is the remarkable feasibility and effectiveness of using readily available, inexpensive three-color e-ink displays (white-ish, black, red) to create dynamic, reprogrammable fake identification badges. These devices, easily sourced from platforms like Amazon and Alibaba, offer a level of adaptability previously unattainable with static printed fakes.

A critical finding is the inherent lack of security in these commercial e-ink display systems. Herman notes that these devices are "reprogrammable" but often have a "weird way that you have to program them," implying a non-standardized or easily circumvented programming interface that lacks robust authentication or encryption. This ease of reprogramming, combined with their widespread availability, makes them an accessible tool for red teamers.

Furthermore, the talk highlights the strategic advantage of real-time image replacement. While existing methods might involve printing high-resolution images, the e-ink approach allows for instantaneous alteration of badge details (e.g., photo, name, department, access level) without needing to print new physical copies. This real-time adaptability is invaluable in dynamic social engineering scenarios, where quick changes might be necessary based on intelligence gathered during an operation. Herman also introduced the concept and design prototype of a five-color e-ink display, suggesting a future where even more realistic and harder-to-detect badge fakes could be produced, overcoming the current color limitations of three-color systems. Finally, the research implicitly underscores the potent combination of visual e-ink fakes with established RFID cloning techniques, enabling the creation of fully functional, dynamic physical access credentials.

Technical Deep Dive

▶ Watch: E-ink technology: electro-mechanical, non-emissive, low power (3:05)

The technical foundation of "Psychic Paper" lies in the unique properties of e-ink and e-paper displays, which fundamentally differ from conventional screen technologies. Unlike light-emissive displays like OLED or LCD that generate their own light, e-ink is a non-light-emissive technology. Its principle is electro-mechanical: microscopic capsules containing charged white and black (and sometimes colored) pigment particles are suspended in a clear fluid. When an electric field is applied, these particles move to the surface of the display, forming the desired image. Once the particles are in position, the electric field is removed, and the image remains stable without requiring continuous power. This characteristic allows e-ink displays to consume power only when the image is being changed, making them incredibly energy-efficient and capable of holding an image for extended periods—reportedly over a decade without degradation.

Commercially available e-ink displays, often found on platforms like Amazon and Alibaba, typically offer a three-color palette: white-ish, black, and red. Herman emphasizes that this is not an RGB (Red, Green, Blue) system, but rather a direct manipulation of physical pigments. The distinction between "white-ish" and true white is also crucial; devices like a Kindle reveal that the background white of an e-ink screen is often slightly off-white compared to, for instance, the true white of the device's plastic housing. This subtle color difference, along with the absence of light emission, can be a tell-tale sign for trained observers, although it is often overlooked in casual inspection. The speaker notes that these readily available units are generally more durable than the research prototype developed.

The "weird way" these displays are programmed hints at a lack of standardized, secure interfaces. While the specific protocols or methods are not detailed in the transcript, this typically implies either simple serial communication, direct memory access, or proprietary, easily reverse-engineered interfaces that do not incorporate cryptographic authentication or secure boot mechanisms. This ease of reprogramming is a critical vulnerability that allows an attacker to load arbitrary images onto the display without significant hurdles.

The concept of a five-color e-ink prototype represents a significant technical advancement for this application. By expanding the color palette beyond white-ish, black, and red, such a prototype could produce significantly more accurate and convincing badge replicas. Many modern access badges incorporate complex color gradients, company logos with specific brand colors, and intricate designs that are difficult to faithfully reproduce with only three colors. A five-color system would enable a much higher fidelity replica, making visual detection even more challenging for security personnel. The housing of the device is also mentioned as an important consideration for the prototype, suggesting that integrating the e-ink display seamlessly into a badge form factor, complete with a realistic bezel and texture, is part of the development challenge. The lower resolution of e-ink compared to high-quality printed badges is acknowledged, but the advantage of real-time dynamism often outweighs this limitation in practical social engineering scenarios.

Demo / Proof of Concept

▶ Watch: Understanding e-ink's true three colors and image longevity (4:00)

While the talk did not feature a live, in-person demonstration of the "Psychic Paper" system in action, Joshua Herman's presentation effectively served as a conceptual proof of concept by detailing the availability and capabilities of the underlying technology. He referenced existing two-color e-ink display demos found on Amazon, illustrating how these devices can display simple images. The core proof of concept revolves around the ability to load and display a convincing facsimile of an identification badge onto these easily sourced three-color e-ink displays.

The speaker’s own research prototype for a five-color e-ink display further extends this concept, demonstrating the feasibility of creating even more sophisticated and visually accurate badge replicas. The essence of the demonstration is the strategic advantage of real-time reprogrammability: an attacker could, for instance, capture an image of a legitimate badge, quickly edit it to change details (like a photo or name), and then push that updated image to the e-ink display on demand. This dynamic capability, when combined with RFID cloning techniques, effectively creates a fully functional, adaptable access credential that can be changed to suit different targets or scenarios in real-time. The "Psychic Paper" concept, therefore, serves as a powerful demonstration of how off-the-shelf and custom e-ink technologies can be weaponized for advanced physical social engineering.

Defensive Implications

▶ Watch: Anticipation for the upcoming five-color e-ink prototype (4:52)

The "Psychic Paper" concept presents a tangible threat to physical security, demanding a proactive and multi-layered defensive strategy from organizations. Relying solely on visual inspection of identification badges is increasingly insufficient when dynamic, reprogrammable e-ink fakes can mimic legitimate credentials with growing fidelity.

  1. Enhanced Security Awareness Training: Security personnel and employees responsible for verifying access must be trained to identify subtle cues that distinguish real badges from e-ink fakes. This includes recognizing the "white-ish" hue of e-ink backgrounds versus true white, the non-emissive nature (lack of self-illumination), and potential discrepancies in the device housing or thickness compared to standard laminated badges. Training should focus on looking through the badge rather than just at it.
  2. Multi-Factor Physical Authentication: Organizations should move beyond single-factor authentication (e.g., just an RFID swipe or visual check). Implementing multi-factor access control, such as combining RFID with a PIN, biometric scan, or a challenge-response visual verification (e.g., asking about a specific, complex anti-counterfeiting feature on the badge), significantly raises the bar for an attacker.
  3. Advanced Badge Design: Re-evaluating and redesigning physical access badges to incorporate features difficult or impossible to replicate on current e-ink displays is crucial. This includes:
  • Holographic overlays: Intricate, multi-dimensional holograms are challenging to replicate digitally.
  • Microprinting: Tiny text or patterns that require magnification to read are difficult to render clearly on lower-resolution e-ink screens.
  • UV features: Elements visible only under ultraviolet light are not reproducible on e-ink.
  • Complex color gradients and metallic inks: These are difficult to accurately reproduce with the limited palette of three- or even five-color e-ink displays.
  • Dynamic security features: Exploring badges with integrated, real-time changing elements (e.g., a rotating QR code or timestamp) could make static or even dynamic e-ink fakes easily detectable.
  1. Audit and Secure RFID Systems: Given that e-ink fakes can be combined with RFID cloning, organizations must audit their existing Mifid (or other RFID) access control systems. This includes ensuring proper encryption, mutual authentication between card and reader, and regularly updating card technologies to counter known vulnerabilities. Implementing reader-side detection of cloned cards or unusual access patterns is also vital.
  2. Physical Security Red Teaming: Proactively engage red teams to test current physical security measures using techniques like "Psychic Paper." This provides realistic insights into vulnerabilities and allows organizations to refine their defenses before real-world attacks occur. The "weird way" of programming commercial e-ink devices highlights the need for organizations to understand the supply chain and security of all components used in their access control ecosystem, including seemingly innocuous display technologies.

Key Takeaways

  • Dynamic Badge Forgery: Commercially available three-color e-ink displays (white-ish, black, red) can be easily sourced and reprogrammed to create dynamic, convincing fake identification badges for physical social engineering.
  • Real-Time Adaptability: E-ink's ability to be reprogrammed in real-time offers a significant advantage over static printed fakes, allowing attackers to quickly change badge details based on situational requirements.
  • Lack of Security in E-ink Devices: Existing commercial e-ink systems exhibit a notable lack of security, featuring easily accessible and programmable interfaces without robust authentication, making them vulnerable to malicious use.
  • Future of Five-Color Displays: A research prototype for a five-color e-ink display promises even higher fidelity badge replicas, further complicating visual authentication and increasing the threat.
  • Combined Threat with RFID: When paired with established RFID cloning techniques, e-ink displays enable the creation of comprehensive, dynamic physical access credentials that bypass both visual and electronic checks.
  • Urgent Need for Enhanced Physical Security: Organizations must adopt multi-factor authentication for physical access, redesign badges with anti-counterfeiting features, and provide advanced security awareness training to counter this evolving threat.

About the Speaker(s)

Joshua Herman, known by his handle Zitterbewegung, is an experienced professional with 11 years in the software industry. His work on "Psychic Paper" is a personal hobby project, explicitly not related to his employer, a point he emphasizes due to the advanced nature of his research. He is a frequent and active member of the DEF CON Discord community, demonstrating his deep engagement with the cybersecurity community.

All talks from DEF CON 32 Creator Stage