Bypass 101
Bill Graydon
DEF CON 32 Creator Stage · Day 1 · Creator Stage
Overview
In "Bypass 101," Bill Graydon from the Physical Security Village delivered a critical message for internal employees navigating the often-overlooked realm of physical security within their organizations. The talk diverges from the typical narrative of highly sophisticated, "elite hacks" and instead focuses on prevalent, low-skill vulnerabilities that frequently undermine robust security postures. Graydon emphasizes that many physical security failures stem not from advanced attack techniques, but from fundamental misconfigurations, design flaws, or simple oversights that any observant individual can identify and exploit.

Key moments
- 0:00 Welcome and the core theme: systems not working
- 2:00 Demonstrating 'stupid shit' bypasses: accessibility button, reach-around
- 4:00 Explaining latch targeted bypass with simple tools
- 5:00 Lock picking: ethical considerations for internal employees
- 6:00 Lishis tools: game-changer for easy lock picking
- 7:30 Lishis tool's ability to decode keys from a lock
Bypass 101
Speakers: Bill Graydon
Conference: DEF CON 32
YouTube: https://www.youtube.com/watch?v=qY0Yb8_R3a0
Overview
In "Bypass 101," Bill Graydon from the Physical Security Village delivered a critical message for internal employees navigating the often-overlooked realm of physical security within their organizations. The talk diverges from the typical narrative of highly sophisticated, "elite hacks" and instead focuses on prevalent, low-skill vulnerabilities that frequently undermine robust security postures. Graydon emphasizes that many physical security failures stem not from advanced attack techniques, but from fundamental misconfigurations, design flaws, or simple oversights that any observant individual can identify and exploit.
The core premise of the presentation is to empower non-security professionals—employees whose primary job function is not auditing physical security—to effectively recognize, document, and report critical physical security flaws to their employers. Graydon argues that the most impactful vulnerabilities to report are often the "stupid shit" that requires no specialized skill to exploit. These are the issues that resonate most with management, as they highlight easily understandable and reproducible failures, thereby increasing the likelihood of corrective action.
This talk is particularly relevant in an era where cybersecurity often overshadows physical security, leaving organizations vulnerable to basic bypass techniques. By shifting the focus from complex lock picking to accessible entry methods and system misconfigurations, Graydon provides a practical framework for improving an organization's overall security posture from the inside out, leveraging the collective vigilance of its workforce.
Background
▶ Watch: Welcome and the core theme: systems not working (0:00)
The talk addresses a common dilemma faced by many employees: noticing glaring physical security weaknesses at their workplace but lacking the knowledge or confidence to report them effectively. Graydon highlights that the Physical Security Village at DEF CON is a hub for teaching both sophisticated and basic bypass techniques, but the "Bypass 101" talk specifically caters to the internal employee perspective. It contrasts the popular perception of physical security attacks—often involving intricate lock picking or covert entry—with the more prosaic reality of common vulnerabilities.
Graydon posits that hackers and security professionals often "get physical security wrong" by overemphasizing highly skilled, low-probability attack vectors. While covert entry, aiming to leave no trace, is a valid concern, the more common and often more effective threat model in the real world is forcible entry or the exploitation of simple, low-skill bypasses. This distinction is crucial because the defenses against these different threat models vary significantly. Forcible entry, for instance, is countered not by impenetrable doors (which don't exist), but by robust detection and response mechanisms.
The talk builds on the understanding that many physical security systems, much like the unreliable Wi-Fi that plagued Graydon's initial presentation, simply "don't work the way they're supposed to in the first place." This fundamental malfunction, rather than an attacker's elite skill, is the root cause of many security breaches. The speaker's goal is to equip attendees with the knowledge to identify these systemic failures and communicate their criticality in a way that prompts organizational change, emphasizing that simplicity and reproducibility are key to gaining management's attention.
Key Findings
▶ Watch: Explaining latch targeted bypass with simple tools (4:00)
Graydon's presentation revealed several critical and often overlooked physical security vulnerabilities, emphasizing that many are not the result of advanced attack techniques but rather fundamental flaws or misconfigurations:
- Accessibility Button Misconfiguration: A surprisingly common flaw where an external accessibility button is incorrectly wired or programmed to unlock a secure door, essentially functioning as a "free pass" button from the outside.
- Simple Latch Targeted Bypass: Many self-latching doors can be easily opened with a basic tool (like a bent wire) by retracting the latch. This vulnerability is often present when the dead latch, designed to prevent such bypasses, fails to engage correctly within the strike plate.
- Vulnerable Lock Hardware (Lishi Tools): The widespread use of easily pickable locks, particularly unbranded or cloned Schlage C keyways, which are trivial to open and even decode with specialized tools like Lishi picks. This makes generating working keys for these locks incredibly simple, even for those with minimal skill.
- Neglect of Forcible Entry Threat Model: Organizations often focus too heavily on preventing covert entry while underestimating or failing to detect forcible entry. No physical barrier is truly "invulnerable," and with sufficient time, force, and motivation, any door can be breached. The true defense lies in detection and response.
- Access Control System Misconfigurations Leading to Disablement: Access control systems are frequently misconfigured, leading to false alarms. When false alarms become too frequent, facilities managers often disable the alarm system altogether, eliminating any detection capability and rendering the system useless against bypass or forcible entry.
- "Reach-Around" and Other Physical Anomalies: Simple physical gaps or design flaws that allow an attacker to bypass a locked gate or door by reaching through or around it to manipulate an internal locking mechanism.
These findings collectively underscore the talk's central theme: the most critical physical security issues are often the most basic and require the least amount of skill to exploit, making them highly relevant from a threat modeling perspective.
Technical Deep Dive
▶ Watch: Lock picking: ethical considerations for internal employees (5:00)
The "Bypass 101" talk delves into specific technical weaknesses in common physical security implementations, highlighting how simple flaws can lead to significant vulnerabilities.
One of the most common "stupid shit" vulnerabilities Graydon discusses is the accessibility button bypass. This occurs due to a fundamental misconfiguration in the wiring or programming software of an access control system. Instead of the accessibility button on the secure side of a door triggering an internal release, it's incorrectly linked to the external side, effectively acting as an unlock button for anyone outside. This is a logical flaw in system design or implementation rather than a physical vulnerability, allowing immediate access without any tools or force.
Another critical bypass technique demonstrated is the latch targeted bypass. Self-closing doors are designed to latch and lock automatically. The primary component involved is the latch bolt, which protrudes from the door edge and engages with the strike plate on the frame. To prevent simple shimming or "credit carding," a dead latch mechanism is incorporated. This is a secondary, smaller pin usually located adjacent to the main latch bolt. When the door is closed and the main latch engages the strike plate, the dead latch is depressed, preventing the main latch from being pushed back into the door (retracted) from the outside. However, as Graydon explains, if the dead latch is either misaligned, damaged, or the strike plate hole is too large, the dead latch may not fully engage or drop into the hole. In such scenarios, a simple tool—even a piece of bent wire or plastic—can be inserted between the door and frame to physically retract the main latch bolt, allowing the door to be pulled open. This highlights a failure in the intended interlocking mechanism of the latch assembly.
The talk also provides a significant technical deep dive into lock vulnerabilities, specifically focusing on Lishi tools and the Schlage C keyway. The Schlage C keyway is a widely used profile due to its commonality and historical prevalence. Lishi tools are specialized lock-picking and decoding instruments designed for specific keyways. For the Schlage C keyway, Lishi tools make picking "trivial" for two main reasons:
- Ease of Manipulation: The tools are designed to precisely interact with the internal pins of the lock, allowing for rapid manipulation and setting of individual pins.
- Decoding Capability: After successfully picking the lock, Lishi tools allow the user to "read off the numbers" corresponding to the bitting of the key. This means an attacker can not only open the lock but also determine the exact key code and cut a duplicate key, effectively granting permanent access.
Graydon distinguishes between genuine Schlage locks and their Chinese clones. While genuine Schlage locks with the C keyway are "well-made" with "security pins" and "tight tolerances" (making them still pickable with Lishi tools but requiring "at least a little bit of skill"), the clones (often unbranded) lack these security features. Clones are "very easy just raking" and become "trivial, no skill required whatsoever" with Lishi tools. The visual cue for a vulnerable lock is the distinct "Z shape at the bottom" of the keyway. This detail is crucial for identifying high-risk assets protected by easily compromised locks.
Finally, Graydon touches upon forcible entry and the Halligan tool. This tool, primarily used by firefighters, is a multi-purpose entry device with a claw, a blade, and a spike, designed for leverage, prying, and striking. While firefighters use it with "full science" developed over 80 years for rapid entry into burning buildings, criminals also employ similar methods, albeit with less speed and more noise. The technical implication here is that no door or lock is inherently invulnerable to sufficient force, skill, time, money, and motivation. The defense is not in creating an impenetrable barrier, but in implementing robust detection mechanisms (e.g., contact sensors, glass break detectors, shock sensors) and having an effective response plan to mitigate the time an attacker has to breach the barrier.
Demo / Proof of Concept
▶ Watch: Lishis tools: game-changer for easy lock picking (6:00)
While the talk didn't feature a live, on-stage exploit of a complex system, Bill Graydon effectively conveyed the "proof of concept" for several critical vulnerabilities through illustrative videos and direct references to practical demonstrations available at the Physical Security Village.
The most prominent demonstrations of "stupid shit" were presented through short videos:
- Accessibility Button Bypass: A video showed a locked door that, when an external accessibility button was pressed, immediately popped open. This visually confirmed the common misconfiguration where the button, intended for internal egress or accessibility, was incorrectly wired to provide external access. This served as a clear, reproducible proof of concept for a critical logical flaw.
- "Reach Around" Bypass: Another video demonstrated a physical bypass where an individual reached around a seemingly secure cage or barrier to manipulate an internal latch or bar, gaining entry. This highlighted how simple physical design oversights or gaps can negate the security of a lock or gate, proving that physical presence and simple dexterity can bypass inadequate barriers.
Graydon also explicitly referenced the Physical Security Village as a hands-on demonstration area where attendees could "try it for yourself." This included:
- Latch Targeted Bypass: Attendees could experiment with tools to retract door latches, specifically understanding how the dead latch mechanism works and how its failure or circumvention leads to a vulnerability. This provides a direct, tactile understanding of the technical details discussed.
- Lishi Tools: While not explicitly demonstrated in the talk, the detailed discussion of Lishi tools for picking and decoding Schlage C keyways serves as a conceptual proof of concept. The audience was encouraged to look up these tools and understand their capabilities, especially concerning the ease with which they can compromise specific lock types, even allowing for key generation.
The overarching theme of these "demos" was not about showcasing advanced attacker prowess, but rather demonstrating how easily common physical security systems can fail or be bypassed due to design flaws, misconfigurations, or the use of inadequate hardware. The emphasis was on the low skill required and the high impact of these easily reproducible vulnerabilities.
Defensive Implications
▶ Watch: Lishis tool's ability to decode keys from a lock (7:30)
The insights from "Bypass 101" offer crucial guidance for organizations and internal employees seeking to bolster physical security. The core defensive strategy revolves around identifying and remediating "stupid shit" vulnerabilities, prioritizing robust detection and response, and fostering better communication between security teams and facilities management.
- Prioritize Low-Skill, High-Impact Vulnerabilities: Defenders should shift their focus from highly sophisticated, low-probability attacks to the common, low-skill bypasses Graydon highlights. These include misconfigured accessibility buttons, easily defeated latches, and physical "reach-around" opportunities. These issues are often simple to fix and present a disproportionately high risk because "any idiot can look at and see this is something that might work and they can try it."
- Audit Access Control Systems for Intended Functionality: Regularly test access control systems to ensure they "function as intended." This means verifying that they:
- Allow entry to correct cards and deny entry to wrong cards reliably.
- Allow egress without false alarming. Miscalibrated request-to-exit (REX) sensors or contact sensor timings can lead to frequent false alarms.
- Address False Alarms Proactively: False alarms are a critical threat to effective detection. When systems "false alarm too much," facilities managers often "just turn off the damn alarm." This effectively eliminates all detection capability. Defenders must work with facilities to properly tune systems, fix underlying issues, and reduce false alarm rates to ensure alarms remain active and credible.
- Upgrade Vulnerable Lock Hardware: Organizations must assess their lock infrastructure, particularly focusing on doors protecting critical assets, PII, or inventory. Any lock utilizing an unbranded or cloned Schlage C keyway (identifiable by the "Z shape at the bottom" of the keyway) should be considered highly vulnerable, especially to Lishi tools. While genuine Schlage C locks offer better tolerances, switching to higher-security locks for which Lishi tools do not exist or are less effective is ideal. At a minimum, ensure genuine Schlage hardware is used over clones.
- Implement Robust Detection and Response for Forcible Entry: Acknowledge that "no door is invulnerable" to forcible entry. The primary defense against this threat is not an impenetrable barrier, but effective detection and response. This includes:
- Deploying appropriate sensors (e.g., door contacts, glass break, shock sensors) to detect attempted breaches.
- Ensuring that alarms are actively monitored and responded to promptly by security personnel or law enforcement.
- Minimizing the "time" an attacker has to breach a barrier through rapid response.
- Empower and Guide Internal Employees: Organizations should encourage employees to report physical security flaws and provide clear channels for doing so. Employees should be advised to:
- Make note of all findings but bring up only the most critical to underscore importance.
- Focus on getting systems working as intended before worrying about advanced bypasses.
- Connect with internal facilities teams to foster collaboration.
- Avoid being a pedant about low-probability, low-impact findings; instead, prioritize issues based on skill required and potential impact.
By focusing on these practical and often overlooked defensive strategies, organizations can significantly enhance their physical security posture against the most common and easily exploitable threats.
Key Takeaways
- Prioritize "Stupid Shit" Vulnerabilities: The most critical physical security flaws are often simple misconfigurations or design oversights that require minimal skill to exploit, making them high-impact and easy to demonstrate to management.
- Audit for Basic Functionality: Regularly verify that physical access control systems (doors, alarms) function as intended, allowing correct access/egress and reliably detecting unauthorized attempts without excessive false alarms.
- Address False Alarms Immediately: Frequent false alarms lead to security systems being disabled, completely negating their defensive purpose. Proper tuning and maintenance are crucial to maintain detection capabilities.
- Upgrade Vulnerable Lock Hardware: Locks with unbranded or cloned Schlage C keyways are highly susceptible to Lishi tools, allowing trivial picking and key decoding. Prioritize replacing these with higher-security alternatives for critical assets.
- Focus on Detection and Response for Forcible Entry: No physical barrier is impenetrable. The primary defense against forcible entry is not an unbreachable door, but rather robust detection mechanisms and a rapid, effective response plan.
- Empower Internal Employees: Non-security personnel are vital eyes and ears. Encourage them to report critical, low-skill physical security flaws, emphasizing clear documentation and prioritization to facilitate action by facilities teams.
About the Speaker(s)
Bill Graydon is a prominent figure within the physical security community, specifically known for his involvement with the Physical Security Village at DEF CON. His expertise lies in identifying and understanding various physical security bypass techniques, from simple misconfigurations to lock vulnerabilities. Graydon is passionate about raising awareness regarding practical physical security threats and empowering individuals, particularly internal employees, to recognize and address these issues within their own environments. His talks often emphasize the importance of realistic threat modeling and the often-overlooked impact of basic, low-skill bypasses compared to more complex, "elite" hacking methods.