Access Control Done Right the First Time
Tim Clevenger
DEF CON 32 Creator Stage · Day 1 · Creator Stage
Overview
In "Access Control Done Right the First Time," Tim Clevenger delivers a crucial talk that deviates from the typical DEF CON focus on bypasses, instead spotlighting the foundational importance of robust access control system installation. Clevenger, a network cybersecurity engineer with a background in physical security system certification, argues that many modern access control systems, particularly in large facilities, suffer from critical vulnerabilities and reliability issues stemming from poor initial deployment. This often results from a "low bid situation" where vendors prioritize minimal viable products over long-term maintainability, reliability, and security.

Key moments
- 0:00 Introduction and speaker background
- 0:40 Talk focus: installation tips for large facilities
- 1:25 Choosing a system: Mercury Security and its benefits
- 2:00 Basic four-door layout and risks of 'dumb' controllers
- 3:45 Wiring considerations: RS 485 limitations over distance
- 4:20 Voltage drop issues and poorly placed remote power supplies
- 5:45 Installation challenges: wall types and wiring security
- 6:10 Warehouse scenario: managing long-distance wiring for doors
Access Control Done Right the First Time
Speakers: Tim Clevenger
Conference: DEF CON 32
YouTube: https://www.youtube.com/watch?v=WscuQr5X1kc
Overview
In "Access Control Done Right the First Time," Tim Clevenger delivers a crucial talk that deviates from the typical DEF CON focus on bypasses, instead spotlighting the foundational importance of robust access control system installation. Clevenger, a network cybersecurity engineer with a background in physical security system certification, argues that many modern access control systems, particularly in large facilities, suffer from critical vulnerabilities and reliability issues stemming from poor initial deployment. This often results from a "low bid situation" where vendors prioritize minimal viable products over long-term maintainability, reliability, and security.
The presentation serves as a practical guide for organizations, project managers, and security professionals to specify, design, and implement physical access control systems with foresight and resilience. Clevenger’s insights are particularly valuable given his experience driving around Southern California, observing and working on a wide array of systems, revealing common pitfalls and best practices that often go overlooked. The talk aims to empower stakeholders to move beyond reactive security measures by ensuring that access control is built correctly from the ground up, preventing future headaches and potential breaches.
This article delves into Clevenger's recommendations, covering everything from system layout and wiring to power considerations, fire safety, and maintenance. It underscores the profound impact of diligent planning and quality installation on the overall security posture and operational efficiency of an organization, making a compelling case for investing in "Access Control Done Right the First Time" rather than patching vulnerabilities later.
Background
▶ Watch: Introduction and speaker background (0:00)
The genesis of this talk lies in a pervasive problem within the physical security industry: the prevalence of poorly installed access control systems. Tim Clevenger, drawing on his extensive experience as a certified installer for major systems like Lenel and S2, observed a consistent pattern of installations driven by cost-cutting, often resulting in systems that were neither secure, reliable, nor easily maintainable. This "low bid situation" frequently leads to the deployment of a "minimal viable product" that, while functional on the surface, harbors significant hidden weaknesses and operational challenges.
The core issue stems from a lack of comprehensive planning and an underappreciation for the intricate details involved in physical security infrastructure. Many talks at conferences like DEF CON focus on exploiting existing vulnerabilities or bypassing systems. Clevenger's unique contribution is to address the root cause of many of these vulnerabilities: the installation phase itself. By providing practical tips and tricks, he aims to elevate the standard of access control deployment, particularly for large facilities where the complexity and potential impact of failure are significantly higher.
A key player in the access control hardware market, as highlighted by Clevenger, is Mercury Security. Many larger vendors, including those Clevenger previously worked with, utilize Mercury Security equipment. These controllers offer several advantages: local storage and independent processing, meaning decisions about access rights are made at the panel level, not solely reliant on a central server. This design prevents scenarios where a network outage (like a DNS failure, as Clevenger quipped, referencing Facebook's past outages) could lock out an entire building. Furthermore, Mercury panels offer multiple vendor support and are reflashable. This allows organizations to switch between front-end software providers like Lenel, Genetec, or Honeywell without needing to replace all their existing hardware, significantly reducing the cost and complexity of vendor transitions. This flexibility, however, does not negate the need for proper installation practices, which remain critical regardless of the chosen hardware or software.
Key Findings
▶ Watch: Choosing a system: Mercury Security and its benefits (1:25)
Tim Clevenger's talk illuminates several critical findings regarding the proper installation and maintenance of access control systems, emphasizing that foresight and attention to detail are paramount.
Firstly, upfront planning and specification are non-negotiable. Clevenger stresses the importance of an RFP (Request for Proposal) that explicitly details requirements beyond just basic functionality. This includes considerations for system layout, power needs (especially for high-amperage locks), future expansion or division of space, and environmental factors. Failing to plan for these elements often leads to costly retrofits, such as poorly placed remote power supplies installed in inaccessible locations without proper consideration for environment or maintenance.
Secondly, the talk highlights the inherent limitations and necessary compromises in communication protocols. While Ethernet is standard for connecting the main access panel to the server, RS-485 is frequently used between the main panel and individual door controllers. Clevenger notes that RS-485, an older four-wire protocol, is theoretically good for 4,000 feet but is significantly more sensitive to interference and less reliable over long distances than modern alternatives. Despite its drawbacks, it often becomes a practical necessity in sprawling environments like warehouses, where running multiple Ethernet drops or fiber optic cables would be prohibitively expensive or complex.
Thirdly, voltage drop is identified as a silent killer of lock reliability. High-amperage locking mechanisms, such as magnetic locks or motorized crash bars, require substantial power. If these locks are a long distance from the power source, voltage drop can cause them to malfunction, either failing to unlock or, in the case of magnetic locks, becoming too weak to secure the door effectively. This often goes unnoticed until post-installation testing, leading to last-minute, suboptimal solutions.
Fourthly, fire safety and life safety are presented as paramount. Clevenger differentiates between fail-safe (door unlocks on power/system failure) and fail-secure (door remains locked on power/system failure) mechanisms. He unequivocally states that life safety should always take precedence over asset protection, urging that if a fail-secure door is chosen, there must be an unambiguous way for occupants to exit during emergencies like fires or power outages. Compliance with local fire codes and the Authority Having Jurisdiction (AHJ) is critical, as is integrating the access control system with the building's fire alarm system via a relay to ensure doors unlock during an alarm. The inclusion of a Knox box with a tamper switch for emergency services access is also strongly recommended.
Finally, the talk champions the use of composite access control cable and diligent power supply and battery management. Composite cable, with its integrated shielded conductors, spare wires, and thick outer jacket, is designed specifically for access control, offering superior durability and reliability compared to ad-hoc wiring. For power, Clevenger emphasizes specifying power supplies with charging capabilities and integrating AC fail and battery fail outputs into the monitoring system. Crucially, he advocates for regular battery replacement (every 3-5 years, depending on environmental conditions) and writing the installation date on batteries to facilitate maintenance. These measures ensure continuous operation during power outages and provide early warnings of potential failures.
Technical Deep Dive
▶ Watch: Wiring considerations: RS 485 limitations over distance (3:45)
The technical core of "Access Control Done Right the First Time" focuses on the intricate components and interconnections of a robust physical access control system, detailing how proper design and installation directly impact security and reliability.
At the heart of a typical system is the access panel, often referred to as the "brains of the operation." This main panel, frequently a Mercury Security board, is responsible for making all access decisions based on card numbers and assigned rights. It connects to a central server or computer running the access control software, typically via Ethernet. This Ethernet connection ensures high-speed, reliable communication over shorter distances within a network infrastructure.
Beneath the main access panel, in a typical enclosure, are additional door controller boards. These are often described as "dumber" controllers because they lack independent decision-making capabilities. Instead, they communicate with the main access panel, relaying card reader inputs and receiving unlock commands. The communication between the main panel and these subordinate door controllers usually occurs over RS-485. This is an older, four-wire serial communication protocol known for its ability to transmit data over relatively long distances—theoretically up to 4,000 feet. However, Clevenger highlights its significant drawbacks: RS-485 is highly susceptible to electromagnetic interference (EMI), requiring careful shielding (often with a foil shield within the cable) and proper termination at the end of a string of devices to prevent signal reflection. Its sensitivity makes it less reliable than Ethernet over long distances, often necessitating compromises in system layout, such as utilizing it in less harsh environments like interior warehouse walls where physical access for troubleshooting is easier.
System layout considerations are critical for optimizing both communication and power delivery. For instance, in a large warehouse with many dock doors, RS-485 might be the only practical solution for spanning hundreds of feet without expensive Ethernet or fiber runs. In a multi-tenant Class A office space, a centralized panel near elevators might fan out to multiple doors. However, Clevenger advises anticipating future needs, such as splitting a floor into smaller suites, by strategically placing panels and utilizing shorter RS-485 runs within localized enclosures to simplify future modifications.
Power delivery is another major technical concern. Access control systems typically operate on AC or DC 12 volts or 24 volts, or a combination thereof. The crucial issue here is voltage drop, especially for high-amperage locking devices like magnetic locks or motorized crash bars. These devices demand significant current, and if the wire run from the power supply to the lock is too long or the gauge too small, the voltage at the lock can drop below its operational threshold. This can result in the lock failing to engage properly (e.g., a magnetic lock becoming too weak to hold the door) or failing to release when commanded. The common, poor solution, as Clevenger points out, is the ad-hoc installation of cheap, unmonitored remote power supplies in hard-to-reach locations like soffits, leading to future maintenance nightmares. Proper planning dictates identifying these long runs beforehand and specifying appropriate power supplies with adequate amperage and closer proximity.
To mitigate wiring issues, Clevenger strongly advocates for composite access control cable. Unlike bundling separate wires, composite cable integrates all necessary conductors—card reader communications (properly shielded), spare conductors, and power wires—within a single, thick, robust outer jacket. This design not only protects against physical damage during installation (e.g., pulling through drop ceilings) but also ensures proper shielding and reduces the likelihood of signal interference. Its distinct appearance (e.g., "thick yellow cable") also makes it less prone to accidental cutting by other trades.
Enclosures housing the panels, power supplies, and batteries are fundamental to physical security. They come in various sizes and can accommodate single or multiple panels, sometimes chained together. Clevenger emphasizes specifying enclosures with tamper switches to detect unauthorized access and key locks. Crucially, he advises changing the default locks, as many enclosures share common keys, presenting a significant vulnerability. For outdoor applications, weatherproof enclosures are essential.
Finally, battery backup and power supply monitoring are critical for system resilience. Power supplies must include a charging circuit for the sealed lead-acid (SLA) batteries that provide backup power during AC failures. Clevenger stresses the importance of regularly replacing these batteries, typically every three to five years, depending on the ambient temperature (e.g., five years in an air-conditioned server room, three years in a hot garage). A practical tip is to write the installation date on the batteries. Even more critical is connecting the AC fail and battery fail outputs from the power supply back to the main access panel. This allows the system to generate alerts when AC power is lost or when batteries are no longer holding a charge, enabling proactive maintenance before a complete system failure. Without these outputs, a dying battery or tripped breaker can go unnoticed until a power outage leaves the facility entirely exposed.
Demo / Proof of Concept
▶ Watch: Voltage drop issues and poorly placed remote power supplies (4:20)
This talk, "Access Control Done Right the First Time," focused squarely on preventative measures, best practices, and robust installation methodologies for physical access control systems, rather than demonstrating a specific exploit or a proof-of-concept bypass. Tim Clevenger's objective was to equip attendees with the knowledge to build secure and reliable systems from the outset, thereby preempting the very vulnerabilities that often become targets for demonstration.
While there wasn't a live technical demonstration of an exploit, Clevenger did offer a tangible output: an RFP (Request for Proposal) template based on the principles discussed in his talk. This RFP, made available via a QR code, serves as a practical tool for organizations to specify comprehensive and secure access control installations, effectively acting as a "proof of concept" for better procurement and implementation practices. This resource empowers attendees to immediately apply the talk's teachings in real-world scenarios, ensuring that future access control projects adhere to higher standards of security, reliability, and maintainability.
Defensive Implications
▶ Watch: Warehouse scenario: managing long-distance wiring for doors (6:10)
The defensive implications of Tim Clevenger's talk are profound, shifting the focus from reactive vulnerability patching to proactive, secure-by-design physical access control. For defenders, the core message is that security must be engineered into the system from the very first step of planning and installation, rather than being an afterthought.
- Prioritize Comprehensive Planning and RFPs: Defenders should advocate for and contribute to detailed Request for Proposals (RFPs) that go beyond basic functionality. These RFPs must explicitly specify requirements for system architecture, wiring types (e.g., composite access control cable), power supply resilience (e.g., charger-equipped power supplies with AC fail and battery fail outputs), environmental considerations for hardware placement, and future scalability. This ensures that security and reliability are non-negotiable criteria, not just optional add-ons.
- Scrutinize Vendor Bids Beyond Cost: The "low bid situation" is a direct threat to security. Defenders must educate procurement teams and project managers on the long-term costs and risks associated with cheap, poorly installed systems. Emphasize the value of quality components, experienced installers, and comprehensive service agreements over minimal upfront expenditure.
- Ensure Life Safety Compliance: This is paramount. Defenders must verify that all locking mechanisms are configured to prioritize life safety, especially in emergency scenarios. This means understanding the difference between fail-safe and fail-secure and ensuring that emergency exits are never compromised. Strict adherence to local fire codes and liaison with the Authority Having Jurisdiction (AHJ), along with proper integration with the building's fire alarm system, are critical. The inclusion of a Knox box with a tamper switch is a simple yet effective defensive measure for emergency responder access.
- Harden Physical Infrastructure: Physical security of the access control components themselves is often overlooked. This includes:
- Placing enclosures in physically secure, climate-controlled locations.
- Ensuring enclosures have tamper switches and changing default key locks to prevent easy access.
- Protecting wiring runs, especially in public areas, by using conduit to prevent tampering or accidental damage.
- Specifying weatherproof enclosures for outdoor installations.
- Implement Robust Power Management and Monitoring: Power outages are a common threat. Defenders need to ensure that power supplies are correctly specified for voltage and amperage to prevent voltage drop issues, particularly for high-draw locks. Crucially, systems must have reliable battery backup with active monitoring (via AC fail and battery fail outputs) to provide early warning of power issues. Regular, scheduled battery replacement (every 3-5 years) is a non-negotiable maintenance task.
- Understand Communication Protocol Limitations: While RS-485 may be necessary for long runs, defenders should be aware of its susceptibility to interference. Where possible, shorter runs and more robust communication methods should be preferred. For long runs, ensure proper shielding and termination are implemented.
- Demand Comprehensive Documentation and Training: Post-installation, defenders need accurate documentation of all system components, wiring diagrams, power supply locations (especially remote ones), and maintenance schedules. Training for facility staff on basic troubleshooting and emergency procedures is also vital.
By adopting these defensive strategies, organizations can build a more resilient and secure physical access control infrastructure, significantly reducing their attack surface and enhancing overall security posture.
Key Takeaways
- Proactive Planning is Paramount: Security, reliability, and maintainability of access control systems are determined at the planning and installation phases, not retroactively. Comprehensive RFPs that specify detailed requirements are crucial.
- Prioritize Life Safety: Always ensure that in the event of power failure, system crash, or fire alarm, occupants can safely exit the building. Fail-safe mechanisms and integration with the fire alarm system are non-negotiable for emergency egress.
- Invest in Quality Wiring and Power: Use composite access control cable for durability and signal integrity. Specify power supplies with charging capabilities and monitor AC fail and battery fail outputs to ensure continuous operation and prompt alerts for power issues.
- Mitigate Voltage Drop: Carefully plan for high-amperage locks (e.g., magnetic locks) over long distances to prevent voltage drop, which can compromise lock functionality. Avoid ad-hoc, unmonitored remote power supplies.
- Secure Physical Components: Enclosures for access panels and power supplies must be physically secure with tamper switches and changed key locks. Protect wiring runs, especially in public areas, with conduit.
- Regular Maintenance is Critical: Batteries for backup power must be replaced every 3-5 years, depending on environmental conditions. Document installation dates on batteries and establish a routine maintenance schedule.
About the Speaker(s)
Tim Clevenger is a seasoned professional with a diverse background spanning both digital and physical security domains. By day, he operates as a network cybersecurity engineer, bringing a deep understanding of network infrastructure and cyber threats to his work. By night, Clevenger indulges his passion as a low voltage hardware junkie and a vintage computing enthusiast, showcasing a hands-on technical curiosity that extends beyond his professional responsibilities. In a previous role, he was certified with Lenel and S2 access and video systems, giving him practical, on-the-ground experience installing, troubleshooting, and observing a wide array of physical security systems across Southern California. He is an active participant in the security community, particularly on the Physical Security Village Discord, where he can be found under the handle NSFW.