Bypass 102
Terry Luan, Karen Ng
DEF CON 32 Creator Stage · Day 1 · Creator Stage
Overview
In "Bypass 102," Terry Luan and Karen Ng delve into the crucial, yet often overlooked, realm of physical security vulnerabilities and their remediation. This talk serves as a practical follow-up to "Bypass 101," focusing on common bypass methods that exploit physical door hardware and surrounding structures to gain unauthorized access. The speakers highlight how easily these vulnerabilities can be leveraged by individuals with minimal know-how, underscoring the critical need for a proactive and security-conscious approach to physical infrastructure.

Key moments
- 0:00 Introduction to Bypass 102 and physical security
- 0:52 Defining physical security bypass methods and their use
- 1:57 Understanding latch targeted bypasses like carding
- 4:00 In-depth explanation of dead latches and their purpose
- 4:40 Analyzing common latch security retrofits and their flaws
- 5:30 Visual demonstration of the dead latch mechanism
- 6:15 Introduction to handle targeted bypass methods
- 6:30 Remediations for handle bypasses and general door security
Bypass 102
Speakers: Terry Luan, Karen Ng
Conference: DEF CON 32
YouTube: https://www.youtube.com/watch?v=GJgTkxL5txw
Overview
In "Bypass 102," Terry Luan and Karen Ng delve into the crucial, yet often overlooked, realm of physical security vulnerabilities and their remediation. This talk serves as a practical follow-up to "Bypass 101," focusing on common bypass methods that exploit physical door hardware and surrounding structures to gain unauthorized access. The speakers highlight how easily these vulnerabilities can be leveraged by individuals with minimal know-how, underscoring the critical need for a proactive and security-conscious approach to physical infrastructure.
The core message of the presentation revolves around the ongoing "cat-and-mouse" game that characterizes both physical and cybersecurity. As new vulnerabilities are discovered, patches and retrofits are developed, only for new bypasses to emerge. Luan and Ng systematically break down various bypass techniques targeting latches, handles, hinges, and even advanced access control systems like Request to Exit (REX) sensors and elevators, offering practical, albeit sometimes inconvenient, remediation strategies. The talk emphasizes that a truly secure facility requires more than just locks; it demands proper installation, thoughtful design, and a robust security culture.
This discussion is particularly relevant for security professionals, facility managers, and anyone responsible for physical asset protection. It exposes the common pitfalls of inadequate installation practices and superficial retrofits, providing actionable intelligence to harden physical defenses against prevalent bypass techniques. By understanding how adversaries exploit physical weaknesses, organizations can move beyond basic security measures to implement more resilient, layered protection strategies.
Background
▶ Watch: Introduction to Bypass 102 and physical security (0:00)
The concept of "bypass" in physical security, as defined by the speakers, involves "ignoring the lock completely and finding an alternative way to get that door open or avoid using the door altogether." This approach contrasts with traditional lock picking, instead focusing on exploiting the door hardware or its surrounding environment. "Bypass 102" presumes attendees have a foundational understanding from "Bypass 101," which would have introduced the basic bypass methods themselves. The current talk, therefore, shifts focus from how to bypass to how to prevent bypasses.
The pervasive nature of these vulnerabilities stems largely from a fundamental disconnect in the installation process. As Karen Ng points out, many installers of doors and associated hardware "don't care about the security, they don't know what these features do." Their primary focus is on functionality and aesthetics, often neglecting the inherent security mechanisms designed into the hardware. This oversight leads to widespread misconfigurations and improper installations, creating easily exploitable gaps that malicious actors or red teams can leverage. The speakers draw a direct parallel to cybersecurity, where the discovery of vulnerabilities, subsequent patching, and the emergence of new bypasses form an endless cycle.
Physical hacking, often employing these simple bypass methods, is a common tactic in red team engagements and real-world unauthorized access scenarios. The accessibility of these techniques, requiring "a little bit of know-how" that can be quickly acquired, makes them a significant threat. The talk highlights that understanding the attacker's perspective—how they identify and exploit weaknesses—is crucial for effective defense. This background sets the stage for a detailed exploration of specific bypass targets and their corresponding, often challenging, remediation efforts.
Key Findings
▶ Watch: Understanding latch targeted bypasses like carding (1:57)
The talk reveals several critical insights into the state of physical security and its vulnerabilities:
- Widespread Installation Deficiencies: A primary finding is that many common physical security features, such as dead latches, are rendered ineffective due to improper installation. Installers often lack a security mindset, leading to doors and hardware that do not function as intended to prevent bypasses.
- Superficial Retrofits Create False Security: Organizations frequently implement retrofits (e.g., metal plates over latches, door sweeps) as quick fixes. However, these are often superficial and can themselves be easily bypassed using simple tools like piano wire or by exploiting other existing gaps. Red teamers specifically look for these retrofits as indicators of underlying, exploitable vulnerabilities.
- The Security-Convenience Trade-off is Constant: Many effective remediation strategies, such as double-sided deadbolts or tap-in/tap-out access control systems, significantly enhance security but come at the cost of convenience. This trade-off requires careful consideration based on the security requirements of a given facility or area.
- Layered Security is Essential: No single security measure is foolproof. Effective physical security requires a multi-layered approach, combining robust hardware, proper installation, detection systems (alarms, sensors, cameras), and a strong security culture among employees.
- Social Engineering Remains a Top Threat: Despite technical hardware fixes, human elements like tailgating and other social engineering tactics remain "the easiest way to get into a secure space." Fostering employee awareness and vigilance is paramount.
- Elevator Security is Often Misplaced: Relying solely on elevator floor lockouts for security is a critical mistake. These systems are often bypassable, and true security for restricted floors should involve additional physical barriers after exiting the elevator.
These findings collectively emphasize that physical security is a complex discipline demanding a holistic approach that integrates technical solutions with human factors and continuous vigilance.
Technical Deep Dive
▶ Watch: Analyzing common latch security retrofits and their flaws (4:40)
The core of "Bypass 102" lies in its detailed examination of specific physical security components and the methods used to bypass them, along with their respective remediations.
Latch-Targeted Bypasses (Carding, Latch Slipping/Shoving)
One of the most fundamental bypass methods targets the door's latch. This technique, often referred to as carding or latch slipping/shoving, involves manipulating the latch mechanism to retract it, thereby opening the door without using the handle or lock.
- Vulnerability: The primary defense against these techniques is the dead latch. This small, half-moon-shaped plunger, located adjacent to the main latch bolt, is designed to prevent the latch from being pushed in when the door is closed and the dead latch is actuated by the strike plate. However, the speakers stress that the dead latch is frequently rendered ineffective due to improper installation. If the strike plate is not correctly aligned, or if the door frame warps, the dead latch may not fully actuate when the door is closed. This leaves the main latch vulnerable to simple manipulation.
- Remediation: The most effective remediation is ensuring proper installation. The door must fit the frame correctly, and the strike plate must be installed precisely so that the dead latch is consistently actuated when the door is closed.
- Retrofits and Their Bypass: A common retrofit observed in facilities is the installation of a metal plate or latch cover over the latch area. While seemingly robust, these covers are often a red flag for red teamers, indicating an underlying issue with the dead latch. These covers can frequently be bypassed using a piano wire, which can be inserted behind the cover and used to manipulate the latch.
Handle-Targeted Bypasses
These bypasses mimic someone exiting from the secure side, typically by manipulating the internal handle or push bar from the exterior.
- Under-the-Door Tools (J-tools): These tools are designed to reach under a door and actuate the handle or push bar on the inside.
- Vulnerability: Gaps underneath or around the door, or adjacent windows, provide sufficient space for such tools. Lever handles can sometimes be easier to manipulate than traditional doorknobs.
- Remediation:
- Properly sized doors that fit snugly within the door frame, minimizing gaps.
- Door sweeps or gap reducers, often intended for weatherproofing, can also make it more difficult to insert tools.
- Covering or eliminating windows adjacent to the door.
- For deadbolts, a standard deadbolt with a thumb turn on the inside is vulnerable to J-tools. The solution is a double-sided deadbolt, which requires a key on both sides, eliminating the thumb turn and preventing external manipulation. This, however, introduces a significant inconvenience and potential safety hazard in emergency exits.
- For push bars (crash bars), the primary vulnerability is having holes or gaps in the door that allow an attacker to reach around and depress the bar.
- Remediation: Using push bars with integrated dead latches and ensuring no gaps in the door. Bar guards (retrofits) can be installed to cover the push bar, making it harder to manipulate, though not impossible.
Removing Hinges
Doors secured by hinges on the exterior of a room or facility are susceptible to hinge removal.
- Vulnerability: Standard hinges have pins that can be easily removed, allowing the door to be lifted off its frame once the pins are out.
- Remediation:
- Set screw hinges: These hinges have a small set screw that locks the hinge pin in place, preventing its removal even if the door is open.
- Stud hinges: These hinges feature studs on one leaf that interlock with holes on the other leaf when the door is closed. Even if the hinge pin is removed, the door cannot be pulled off the frame because of these interlocking studs.
Request to Exit (REX) Sensors
REX sensors are used in access control systems to allow free egress from a secured area. They detect a person's presence and momentarily unlock the door.
- Vulnerability: Most REX sensors rely on Passive Infrared (PIR) technology, which detects body heat and motion. These can be tricked by various means, such as directing a heat source or a motion simulator at the sensor, making it "think there's someone on the inside."
- Advanced Sensors: Some higher-security sensors combine PIR with radar to more accurately detect human presence and minimize false positives or bypass attempts. The speakers mentioned a defunct company, Interlogics, that made such a sensor, noting that current alternatives are often "many thousands of dollars."
- Remediation:
- For more secure areas, REX buttons are preferred over sensors. These buttons should be placed "away from doors so people can't use any sort of wire to push it from the outside."
- The most secure method for egress, though least convenient, is a tap-in/tap-out system, where users must present credentials both upon entry and exit. This eliminates the REX sensor vulnerability entirely but trades convenience for security.
Elevator Bypass
Elevators, especially in modern buildings, often incorporate security features like floor lockouts.
- Vulnerability: Relying on elevator floor lockouts as the primary security measure for restricted areas is a significant flaw. Many default elevator locks can be changed, and the systems themselves can be vulnerable to bypasses. The speakers explicitly warn against tampering with fire recall key switches, which are critical safety devices.
- Remediation: The best approach is to avoid relying on elevator floor lockouts for security. Instead, implement additional locked doors and physical barriers after people exit the elevator on restricted floors. This creates a layered defense that doesn't depend on the inherent security of the elevator system itself.
Demo / Proof of Concept
▶ Watch: Visual demonstration of the dead latch mechanism (5:30)
The "Bypass 102" talk, unfortunately, experienced significant technical difficulties, which impacted the live demonstration of several key concepts. The speakers had prepared videos to illustrate the mechanisms of various bypasses and their remediations, but these largely failed to load during the presentation.
One notable instance where a visual aid did manage to appear was a brief video demonstrating the function of a dead latch. This video visually explained how the dead latch, when properly actuated, prevents the main latch from being pushed in, thereby stopping latch slipping or carding attempts. This short segment, though limited, successfully clarified the mechanical principle discussed.
The speakers also mentioned having a video from a red team engagement that showed an individual bypassing a push bar by reaching around a gap in the door. Due to the ongoing technical issues, this video could not be shown on the main screen, but the speakers offered to share it privately on a phone after the talk, highlighting the real-world applicability of the discussed vulnerabilities.
Despite these technical setbacks, the speakers' detailed descriptions and offers to provide offline demonstrations underscored the practical nature of the bypass methods and the importance of understanding how they work. While the live demos were curtailed, the emphasis remained on the tangible impact of these vulnerabilities in physical security scenarios.
Defensive Implications
▶ Watch: Remediations for handle bypasses and general door security (6:30)
The insights from "Bypass 102" provide crucial guidance for bolstering physical security defenses. Defenders must adopt a holistic and proactive approach, moving beyond superficial fixes to address root causes.
- Conduct Comprehensive Physical Security Audits: Organizations should perform detailed audits of all access points, focusing specifically on the common vulnerabilities highlighted:
- Dead Latches: Verify that all dead latches are properly installed and consistently actuate when doors are closed, preventing latch slipping and carding. Inspect for door warping or strike plate misalignment.
- Door Gaps and Handles: Assess doors for excessive gaps underneath or around the frame that could allow under-the-door tools or J-tools. Evaluate the type of lever handles and push bars for susceptibility to external manipulation.
- Hinges: Identify any exterior-facing doors with standard hinges and prioritize replacement or retrofit with set screw hinges or stud hinges to prevent door removal.
- Request to Exit (REX) Sensors: Examine REX sensor types and their placement. Consider upgrading to PIR/radar combination sensors in high-security areas or replacing them with securely placed REX buttons or tap-in/tap-out systems.
- Elevator Security: Review reliance on elevator floor lockouts. Implement secondary, physical barriers beyond the elevator on restricted floors.
- Prioritize Proper Installation and Maintenance: The most significant defensive implication is the need for meticulous installation and ongoing maintenance. Facility managers and security personnel must:
- Train Installers: Ensure that all contractors and in-house personnel involved in door and hardware installation understand the security implications of their work, emphasizing the correct functioning of features like dead latches.
- Regular Inspections: Implement a schedule for regular inspections of all door hardware to identify wear and tear, misalignment, or damage that could create new vulnerabilities.
- Avoid Superficial Retrofits: Be critical of quick-fix retrofits. While a latch cover or basic door sweep might seem to address a vulnerability, they often introduce a false sense of security and can be easily bypassed. Invest in robust, long-term solutions that address the underlying weakness.
- Implement Layered Security: A single point of failure can compromise an entire system. Defenders should deploy a layered security strategy:
- Physical Barriers: Robust doors, frames, and hardware, properly installed.
- Detection Systems: Integrate alarms, sensors, and cameras at all potential bypass points. These systems, while bypassable themselves, are crucial for deterrence, early detection, and forensic analysis.
- Response Plan: Develop and regularly test a rapid response plan, integrating timing analysis with detection systems to ensure security personnel can intercept an intruder before significant harm occurs.
- Foster a Strong Security Culture: Human factors are often the weakest link. Organizations must educate employees on physical security best practices:
- Tailgating Awareness: Train staff to recognize and challenge tailgating attempts.
- Suspicious Activity Reporting: Encourage employees to report unrecognized individuals or suspicious activities.
- Security Mindset: Instill a general security mindset, where employees understand their role in maintaining physical security.
By adopting these defensive strategies, organizations can significantly reduce their exposure to common physical bypass techniques and build a more resilient security posture.
Key Takeaways
- Physical security is an ongoing "cat-and-mouse" game, constantly evolving with new bypasses and remediations, mirroring the challenges in cybersecurity.
- Many prevalent physical vulnerabilities stem from improper installation and a lack of security-conscious design, rather than inherent flaws in the hardware itself.
- Superficial retrofits often create a false sense of security and can be easily bypassed (e.g., piano wire bypassing latch covers), making them a red flag for attackers.
- Defenders must understand the trade-off between security and convenience, especially when implementing robust solutions like double-sided deadbolts or tap-in/tap-out systems.
- A comprehensive physical security strategy requires a layered approach, combining properly installed robust hardware, effective detection systems (alarms, sensors, cameras), and a strong, vigilant security culture among employees.
- Red teamers actively seek out common bypass opportunities like misactuated dead latches, accessible REX sensors, and standard hinges, underscoring the importance of addressing these known weaknesses.
About the Speaker(s)
Terry Luan and Karen Ng are security practitioners with expertise in physical security and bypass techniques. While specific titles and companies were not detailed in the transcript, their deep understanding of physical vulnerabilities and remediation strategies is evident. They are involved in the security community, particularly through conference villages, where they teach practical physical security "know-how." Karen Ng also mentioned providing services related to "timing analysis" in combination with security systems, indicating a focus on comprehensive security response planning. Their joint presentation at DEF CON 32 highlights their commitment to educating the community on critical, often overlooked, aspects of physical security.