Doors, Cameras, & Mantraps Oh my!

The Magician

DEF CON 32 Creator Stage · Day 1 · Creator Stage

Overview

This talk, "Doors, Cameras, & Mantraps Oh my!", delivered by The Magician at DEF CON 32, delves into the often-overlooked yet critical domain of physical security. Far from a mere lock-picking demonstration, the presentation serves as a practical guide for understanding, assessing, and mitigating physical vulnerabilities in corporate and institutional environments. The Magician, a former physical security assessor for Gold Sky Cyber security and a member of the Open Organization of Lock Pickers (OOLP), brings a unique perspective rooted in hands-on experience of "breaking into buildings" with the express purpose of educating clients.

Watch on YouTube

Visual summary for Doors, Cameras, & Mantraps Oh my! by The Magician
Visual summary for Doors, Cameras, & Mantraps Oh my! by The Magician

Key moments

  1. 0:00 Introduction: The Magician's physical security assessment experience
  2. 2:00 Talk overview and client education philosophy
  3. 2:29 Analyzing common physical security vulnerabilities: doors and windows
  4. 4:00 Passive security controls: fencing and bollards
  5. 4:50 Man traps: underutilized and effective security control
  6. 6:00 Cameras and a warning against Wi-Fi cameras
  7. 6:37 How to learn physical security and get started
  8. 7:25 Closing remarks and contact information

Doors, Cameras, & Mantraps Oh my!

Speakers: The Magician

Conference: DEF CON 32

YouTube: https://www.youtube.com/watch?v=J7GFF-GVOpA

Overview

This talk, "Doors, Cameras, & Mantraps Oh my!", delivered by The Magician at DEF CON 32, delves into the often-overlooked yet critical domain of physical security. Far from a mere lock-picking demonstration, the presentation serves as a practical guide for understanding, assessing, and mitigating physical vulnerabilities in corporate and institutional environments. The Magician, a former physical security assessor for Gold Sky Cyber security and a member of the Open Organization of Lock Pickers (OOLP), brings a unique perspective rooted in hands-on experience of "breaking into buildings" with the express purpose of educating clients.

The core of the talk revolves around the practical business aspects of physical security, emphasizing effective client communication, vulnerability demonstration, and fostering a higher mitigation rate by involving stakeholders directly in the assessment process. It addresses fundamental physical controls like doors, windows, fencing, bollards, mantraps, and cameras, highlighting common weaknesses and straightforward exploitation methods. This presentation is crucial for security professionals, facility managers, and business leaders seeking to understand the tangible risks posed by physical security gaps and how to approach these challenges without resorting to fear, uncertainty, and doubt (FUD) tactics.

Background

▶ Watch: Introduction: The Magician's physical security assessment experience (0:00)

The realm of cybersecurity often focuses intensely on digital threats, network vulnerabilities, and software exploits, sometimes leading to the neglect of a foundational layer of defense: physical security. Yet, as countless incidents have shown, a robust digital perimeter can be utterly circumvented by an adversary gaining unauthorized physical access to facilities, equipment, or personnel. This talk underscores the persistent relevance of physical security in an increasingly interconnected world, drawing attention to the reality that even the most sophisticated cyber defenses can be rendered ineffective if a malicious actor can simply walk into a server room or plug in a rogue device.

Historically, physical security has encompassed a broad range of measures, from traditional locks and guards to more advanced access control systems and surveillance. However, the effectiveness of these controls is frequently undermined by poor implementation, lack of maintenance, or insufficient understanding of how they can be bypassed. The speaker's experience as a physical security assessor highlights a common disconnect: organizations often invest in security measures without fully comprehending their true vulnerabilities or the practical implications of a physical breach. Prior work in this field has often involved theoretical assessments or penetration tests that, while identifying weaknesses, sometimes failed to translate into effective mitigation strategies due to a lack of direct engagement and understanding from the client's side. The Magician's approach, which involves actively demonstrating exploits to clients, seeks to bridge this gap, ensuring that the "show and tell" method leads to a significantly higher rate of remediation compared to traditional audit reports alone. This client-centric, educational methodology forms the bedrock of the talk's practical advice.

Key Findings

▶ Watch: Analyzing common physical security vulnerabilities: doors and windows (2:29)

The Magician’s talk distills years of practical experience into several key findings regarding physical security assessments and client engagement:

  1. Direct Client Involvement Boosts Mitigation: The most significant finding is that bringing clients along during the physical penetration test, allowing them to witness and even attempt exploits themselves, dramatically increases the mitigation rate. This hands-on, experiential learning fosters a deeper understanding of vulnerabilities than any report or presentation alone. The speaker explicitly states, "Bringing the client with me gave them the option to try it themselves and often the mitigation rate was much higher." This underscores the power of practical demonstration over abstract reporting.
  1. Overlooked Common Vulnerabilities: Many fundamental physical security controls are frequently overlooked or poorly implemented, creating easily exploitable weaknesses. The talk highlights:
  • Exposed Hinges on Perimeter Doors: A simple mechanical vulnerability allowing for easy door removal or manipulation.
  • Latch and Strike Plate Manipulation: The ability to use tools to slide between the latch and strike plate to open a door without a key.
  • Door Handle Manipulation: Reaching under or over doors to manipulate interior handles or crash bars, particularly on double doors or server room exits.
  • Insecure Windows: Windows are often neglected, offering similar manipulation avenues to doors or providing easy observation points for shoulder surfing or intelligence gathering (e.g., operating hours, PC OS, browser types).
  1. Passive Controls are Essential but Not Sufficient: Controls like fencing and bollards establish clear perimeters and prevent vehicle-based attacks, respectively. While crucial for deterrence and defining access expectations, they are "passive," meaning they don't require active human monitoring. They form a foundational layer but must be complemented by active measures.
  1. Underutilized High-Security Controls: Mantraps, despite their proven effectiveness in secure facilities like banks, are "completely underutilized." These multi-door, multi-authentication antechambers offer a robust layer of access control, significantly complicating unauthorized entry, although they can impact the flow of personnel.
  1. Camera Implementation Often Suboptimal: While ubiquitous, cameras are frequently used only for post-incident forensics rather than active monitoring. The speaker also strongly advises against Wi-Fi cameras in many environments, suggesting inherent security weaknesses or reliability issues, though not elaborating on the specific "soapbox rant" during the talk.
  1. Education Without FUD: The talk advocates for educating clients about risks without resorting to fear, uncertainty, and doubt (FUD). By demonstrating vulnerabilities directly and explaining the "how," clients gain empowerment and understanding, leading to more proactive and effective security improvements.

Technical Deep Dive

▶ Watch: Man traps: underutilized and effective security control (4:50)

The technical deep dive into physical security, as presented by The Magician, focuses on the practical mechanics of bypassing common controls and the underlying principles that make these exploits possible. The talk emphasizes that many physical vulnerabilities stem from fundamental design flaws, improper installation, or a lack of understanding regarding their operational security.

Doors: The First Line of Defense

Doors are typically the primary point of entry and, consequently, the first target for physical penetration testers. The talk identifies several common weaknesses:

  • Exposed Hinges: On many exterior doors, the hinge pins are accessible from the outside. If these pins can be removed, the door can often be lifted off its frame or swung open from the hinge side, bypassing the lock entirely. This is a classic mechanical exploit that highlights the importance of hinge design and installation (e.g., using non-removable pins or hinges secured from the inside).
  • Latch and Strike Plate Manipulation: The latch bolt mechanism, which holds the door closed, can often be defeated. By inserting a thin, flexible tool (e.g., a shim, a credit card, or a specialized latch-tool) between the door frame and the door itself, an attacker can push the angled latch bolt back into the door, allowing it to open without turning the handle or using a key. This exploit is particularly effective against spring-loaded latches that lack a deadlatch mechanism (a secondary plunger that prevents the latch from being pushed back when the door is closed).
  • Door Handle Manipulation: For doors that cannot be shimmied, tools can sometimes be slid under or over the door to engage the interior handle. This is particularly relevant for doors with lever handles or panic bars.
  • Crash Bars (Panic Bars): Commonly found on emergency exits and server room doors, these horizontal bars are designed for quick egress. An attacker might manipulate these from the outside by using a tool to depress the bar or engage the internal mechanism, especially on double doors where a gap might exist or the bar extends close to the door's edge. This bypasses the external locking mechanism entirely.

Windows: Overlooked Entry Points and Intelligence Sources

Windows, often seen as less secure than doors, present distinct vulnerabilities:

  • Mechanical Manipulation: Similar to doors, insecure windows can be opened or manipulated if their locking mechanisms are weak, improperly secured, or accessible from the outside. This could involve forcing latches, removing panes, or exploiting faulty frames.
  • Intelligence Gathering (Shoulder Surfing): Beyond direct entry, windows provide a low-complexity, high-yield avenue for reconnaissance. An attacker can observe operating hours, identify specific employee routines, discern the types of PC operating systems in use, or even identify browser types and other sensitive information simply by looking through a window. This passive form of information gathering is a precursor to more complex social engineering or cyber attacks.

Fencing and Bollards: Passive Physical Deterrents

These controls are foundational for establishing a perimeter but operate on different principles:

  • Fencing: Defines a clear boundary and creates an expectation of limited access. It's a passive security measure because it doesn't require active monitoring to perform its primary function. While a determined attacker can scale or cut a fence, its main technical contribution is deterrence and the creation of a time-consuming obstacle, making daytime breaches particularly difficult without attracting attention.
  • Bollards: Reinforced obstacles, typically made of steel or concrete, designed to prevent vehicle ramming attacks. These are critical for protecting building entrances, storefronts, and critical infrastructure from vehicular assault, acting as a passive yet highly effective barrier against high-impact physical breaches.

Mantraps: The Pinnacle of Access Control

Mantraps represent a sophisticated, multi-layered approach to access control:

  • Sequential Authentication: A mantrap is a small room with two interlocking doors. To gain access, an individual must typically authenticate at the first door (e.g., with an RFID badge), enter the small room, and then authenticate again at the second door (e.g., with a biometric security control like a fingerprint reader). Only when the first door is closed and secured can the second door be opened, and vice-versa. This prevents tailgating and ensures that only one person can enter at a time, or that a person can be held within the trap if a security alert is triggered.
  • Physical Segregation: The technical strength of a mantrap lies in its ability to physically isolate an individual between two secure zones, providing an opportunity for security personnel to intervene or verify identity during the transition. The challenge lies in managing people flow and ensuring strict adherence to procedures.

Cameras: Surveillance and Forensics

Cameras are ubiquitous but their technical deployment and utilization vary:

  • Recording vs. Active Monitoring: Many small to mid-sized businesses simply record video for forensic purposes or post-incident review. More robust security postures involve active monitoring in a Security Operating Center (SOC), providing real-time threat detection and response capabilities.
  • Wi-Fi Cameras: The speaker firmly believes Wi-Fi cameras are a "poor choice in many environments." While the specific technical rationale wasn't detailed, common issues include:
  • Wireless Interference and Reliability: Susceptibility to signal jamming or environmental interference, leading to dropped frames or outages.
  • Network Security Risks: Potential for unauthorized access to the camera feed or compromise of the camera device itself, which could serve as an entry point into the internal network.
  • Bandwidth Consumption: High-resolution video streaming over Wi-Fi can strain network resources.
  • Power Dependency: Most still require a power cable, negating some of the perceived flexibility of wireless. Hardwired (Ethernet) cameras often offer greater reliability, security, and power-over-Ethernet (PoE) capabilities.

In summary, the technical deep dive emphasizes that effective physical security hinges on understanding not just what controls are in place, but how they function, where their weaknesses lie, and how they can be exploited. This knowledge is crucial for designing and implementing truly resilient physical defenses.

Demo / Proof of Concept

▶ Watch: Cameras and a warning against Wi-Fi cameras (6:00)

While The Magician did not conduct a live, on-stage hacking demonstration, the talk's entire premise is built upon a highly effective, client-centric "show and tell" methodology that functions as a robust Proof of Concept (PoC). The speaker's core service as a physical security assessor involved bringing clients directly into the assessment process and demonstrating vulnerabilities in real-time within their own facilities.

This "demo" worked as follows: The Magician would physically attempt to bypass security controls – such as manipulating door latches, exploiting exposed hinges, or gaining access through insecure windows – with the client observing. Crucially, after demonstrating the exploit, the client would then be given the opportunity to try it themselves. This hands-on experience served as an immediate and undeniable proof of concept. For example, if a door could be opened with a simple shim, the client would be handed the tool and guided through the process, allowing them to personally experience the ease of the breach.

The impact of this approach was profound. As The Magician states, "Bringing the client with me gave them the option to try it themselves and often the mitigation rate was much higher." This direct, experiential learning transcends theoretical reports, transforming abstract risks into tangible realities. It fostered a deeper understanding of the "how" and "why" behind physical exploits, making the vulnerabilities undeniable and the need for remediation urgent and clear. This methodology effectively combined an on-site demonstration with an educational workshop, empowering clients to understand their security posture from an attacker's perspective and leading to more effective and sustained defensive actions.

Defensive Implications

▶ Watch: Closing remarks and contact information (7:25)

The insights shared by The Magician offer crucial defensive implications for organizations looking to bolster their physical security posture. The core message is that effective defense begins with understanding the attacker's perspective and engaging stakeholders through education, not just reports.

  1. Conduct Hands-On Physical Security Assessments: Organizations should move beyond theoretical audits and engage in practical, hands-on physical penetration testing. Ideally, this should involve key stakeholders (e.g., facility managers, IT security leads, executive sponsors) directly witnessing or even participating in the simulated breaches. This direct exposure significantly increases understanding and buy-in for mitigation efforts.
  1. Scrutinize Common Entry Points:
  • Doors: Regularly inspect all perimeter doors for exposed hinges. If hinges are on the outside, consider installing non-removable hinge pins or security studs/pins that interlock the door and frame when closed, preventing removal even if pins are compromised. Ensure all exterior doors have deadbolt mechanisms or deadlatches to prevent simple shimming attacks. Review the security of crash bars and panic hardware, ensuring they cannot be easily manipulated from the exterior, especially on double doors.
  • Windows: Windows are often overlooked. Implement policies for securing windows at all times, especially after hours. Conduct regular checks for faulty locks or easily bypassed mechanisms. Consider window films for privacy to prevent shoulder surfing and visual reconnaissance.
  1. Implement Layered Security with Passive Controls: While passive, controls like fencing and bollards are fundamental. Ensure perimeters are clearly defined and consistently maintained. Strategically place bollards to protect vulnerable building facades and high-traffic areas from vehicle-borne threats. These measures deter opportunistic attackers and slow down determined ones, buying critical time.
  1. Leverage Mantraps for High-Security Zones: For areas requiring stringent access control (e.g., server rooms, data centers, financial vaults), mantraps should be seriously considered. While they require careful planning for people flow and adherence to procedures, their ability to enforce sequential, multi-factor authentication and prevent tailgating makes them an invaluable control. Integrate them with existing access control systems (e.g., RFID, biometrics) and ensure robust security procedures are in place for their operation.
  1. Re-evaluate Camera Systems:
  • Active Monitoring: Move beyond mere recording. If budget allows, implement active monitoring of security cameras, ideally in a dedicated Security Operating Center (SOC). This enables real-time threat detection and rapid response.
  • Avoid Wi-Fi Cameras: As highlighted by the speaker, Wi-Fi cameras are often a poor choice. Prioritize hardwired (Ethernet) cameras for reliability, enhanced security (less susceptible to jamming or network compromise), and often Power over Ethernet (PoE) capabilities, simplifying installation and power management. Ensure all camera systems, regardless of type, are on segregated networks and regularly patched.
  1. Educate Internal Staff: Train employees on physical security best practices, including challenging unknown individuals, reporting suspicious activity, and understanding the importance of secure access control. Foster a culture where physical security is everyone's responsibility, not just the security team's. This includes awareness of shoulder surfing risks and the importance of securing workstations.
  1. Focus on "Show and Tell" for Internal Buy-in: When presenting physical security risks to management or other departments, adopt the "show and tell" approach. Use real-world examples, photos, or even small-scale demonstrations to illustrate vulnerabilities. Frame security improvements not as an expense, but as a direct mitigation of demonstrated risk, fostering understanding and collaboration rather than fear.

By implementing these defensive strategies, organizations can build a more resilient physical security posture, recognizing that the physical realm remains a critical battleground in the broader landscape of enterprise security.

Key Takeaways

  • Direct Engagement is Key: Involving clients directly in physical penetration tests and allowing them to experience vulnerabilities firsthand significantly boosts understanding and mitigation rates.
  • Common Physical Controls are Often Overlooked: Basic elements like doors (exposed hinges, latch manipulation) and windows (easy access, visual reconnaissance) present widespread and easily exploitable weaknesses.
  • Layered Security is Essential: Combine passive deterrents (fencing, bollards) with active controls (access systems, monitoring) to create robust physical defenses.
  • Mantraps are Underutilized but Highly Effective: For high-security zones, mantraps provide superior access control by enforcing sequential, multi-factor authentication and preventing tailgating.
  • Camera Deployment Matters: Prioritize hardwired cameras over Wi-Fi for reliability and security, and shift towards active monitoring rather than solely relying on post-incident forensics.
  • Educate Without Fear: Present physical security risks and solutions in an empowering, educational manner, focusing on practical demonstrations rather than FUD tactics, to foster genuine buy-in and proactive remediation.

About the Speaker(s)

The speaker, known as The Magician, is a seasoned expert in physical security with a background as a physical security assessor for Gold Sky Cyber security. In this role, The Magician traveled across the United States, specializing in "breaking into buildings" with the unique approach of bringing clients along to observe and participate in the exploits. This hands-on, educational methodology was central to achieving higher mitigation rates for identified vulnerabilities. Beyond professional work, physical security remains a significant hobby for The Magician. The speaker is also an active member of the Open Organization of Lock Pickers (OOLP), a prominent group within the lock-picking community, and encourages conference attendees to visit the Lock Pick Village at DEF CON to learn more. The Magician is based in the Orlando hacker community and is eager to share stories and insights regarding physical security and building penetration.

All talks from DEF CON 32 Creator Stage