Intro to Physical Security Bypass

Karen Ng, Matthew Cancilla

DEF CON 33 · Day 1 · Main Stage

Overview

In "Intro to Physical Security Bypass," Karen Ng and Matthew Cancilla deliver a rapid-fire exploration of common physical security vulnerabilities, demonstrating how many seemingly secure entry points can be easily compromised without resorting to complex lockpicking techniques. The talk emphasizes that while lockpicking often captures the imagination, a vast array of faster, more consistent, and simpler bypass methods exist, leveraging design flaws, improper installation, and human error. This presentation serves as a crucial wake-up call for anyone responsible for securing physical spaces, from residential properties to high-security corporate environments.

Watch on YouTube

Visual summary for Intro to Physical Security Bypass by Karen Ng, Matthew Cancilla
Visual summary for Intro to Physical Security Bypass by Karen Ng, Matthew Cancilla

Key moments

  1. 0:00 Introduction to physical security bypass and its importance
  2. 2:00 Humorous examples of poor physical security design
  3. 2:55 Basic door latches and the 'carding' bypass technique
  4. 3:30 Understanding dead latches and how they prevent carding
  5. 5:00 Tools and methods to deactuate dead latches
  6. 5:45 Live demonstration of the 'pulling' method to bypass
  7. 6:30 Explanation of the 'shoving' bypass technique

Intro to Physical Security Bypass

Speakers: Karen Ng, Matthew Cancilla

Conference: DEF CON

YouTube: https://www.youtube.com/watch?v=tTAISQqmfWQ

Overview

In "Intro to Physical Security Bypass," Karen Ng and Matthew Cancilla deliver a rapid-fire exploration of common physical security vulnerabilities, demonstrating how many seemingly secure entry points can be easily compromised without resorting to complex lockpicking techniques. The talk emphasizes that while lockpicking often captures the imagination, a vast array of faster, more consistent, and simpler bypass methods exist, leveraging design flaws, improper installation, and human error. This presentation serves as a crucial wake-up call for anyone responsible for securing physical spaces, from residential properties to high-security corporate environments.

The speakers systematically dissect various locking mechanisms and access control systems, illustrating how everyday objects or easily obtainable tools can grant unauthorized access. Their core message is clear: robust physical security extends far beyond the lock itself, encompassing proper installation, architectural design, and a pervasive security-minded culture among occupants and staff. By highlighting these often-overlooked vulnerabilities, Ng and Cancilla empower both red teamers seeking to identify weaknesses and blue teamers aiming to implement effective remediations.

The importance of this talk cannot be overstated in an era where cyber and physical security are increasingly intertwined. As organizations invest heavily in digital defenses, a single physical breach can render those efforts moot, allowing attackers direct access to sensitive data or critical infrastructure. This session provides practical, actionable insights into strengthening the often-neglected physical perimeter, underscoring that even the most secure encrypted servers are vulnerable if an adversary can simply "take it home."

Background

▶ Watch: Introduction to physical security bypass and its importance (0:00)

The perception of physical hacking is often heavily influenced by popular media, which frequently portrays dramatic scenes of expert lockpickers meticulously manipulating pins. This cinematic bias leads many to believe that physical security breaches are rare, difficult, and require specialized, high-skill adversaries. Karen Ng and Matthew Cancilla challenge this notion directly, asserting that lockpicking is often a "later resort" for skilled red teamers, chosen only when quicker and more reliable bypass methods fail.

The fundamental problem, as articulated by the speakers, stems from a pervasive lack of security-mindedness in the design and installation of physical spaces. Architects and builders frequently prioritize aesthetics, convenience, and cost over robust security, leaving critical vulnerabilities in their wake. A prime example given is a locked Assa Abloy door – a hard lock to pick – rendered irrelevant by an accessible mail slot through which an attacker can reach the handle and let themselves in. This illustrates the talk's central premise: focusing solely on the lock’s pick-resistance while ignoring the broader context of the door, frame, and surrounding environment is a critical oversight.

Physical security, much like cybersecurity, is described as a constant cat-and-mouse game between red and blue teams. As red teams uncover vulnerabilities, blue teams develop remediations and patches, only for red teams to find new exploits for those patches. This ongoing cycle necessitates continuous vigilance and a proactive approach to identifying and mitigating emerging threats. The talk aims to equip attendees with the mindset and knowledge to participate effectively in this cycle, moving beyond superficial security measures to address the root causes of vulnerabilities: design flaws, improper installation, and human complacency. The speakers emphasize that some bypass methods can take as little as "three seconds," highlighting the urgency of addressing these often-simple weaknesses.

Key Findings

▶ Watch: Basic door latches and the 'carding' bypass technique (2:55)

The presentation reveals several critical findings regarding common physical security bypasses and their underlying causes:

  • Bypass Over Lockpicking: Many physical access methods are significantly faster and more reliable than traditional lockpicking, often taking mere seconds to minutes.
  • Installation Flaws are Paramount: A recurring theme is that improper installation of doors, frames, strike plates, and security devices creates the most prevalent and easily exploitable vulnerabilities.
  • Convenience vs. Security Trade-offs: Features designed for convenience (e.g., easy exit mechanisms, automatic door openers, key boxes for Airbnb) frequently introduce significant security risks that are often overlooked.
  • Default Settings and Lack of Maintenance: The failure to change default codes on combination locks and entrophones, or to maintain locks and door systems, leaves wide-open entry points.
  • "Going Around" is Effective: Attackers often find creative, non-direct ways to circumvent security, such as climbing fences, exploiting unextended walls above false ceilings, or using exterior maintenance access points.
  • Human Error and Social Engineering: Human factors, including propping doors open, leaving keys exposed, or simply lacking security awareness, remain one of the most significant vectors for physical breaches.
  • Cheap Locks are Inadequate: Standard, inexpensive padlocks are easily defeated by simple shims, demonstrating that basic security hardware often lacks real-world resilience.

Technical Deep Dive

▶ Watch: Understanding dead latches and how they prevent carding (3:30)

The talk provides a comprehensive technical deep dive into numerous physical security bypass methods, detailing the mechanisms, tools, and vulnerabilities.

Door Latches and Carding

The most basic form of door lock, the door latch, is highly vulnerable. The classic carding technique, often depicted in movies, involves inserting a flat, flexible material (like a credit card or latch slip tool) between the door and the frame to push the latch bolt back. The primary defense against this is a dead latch, a small semicircle or triangle on the latch bolt that prevents it from being pushed in when the door is properly closed and the dead latch is actuated by the strike plate. However, Ng and Cancilla demonstrate that improper installation often renders dead latches ineffective. If the door frame, strike plate, or door itself is not flush, or if the strike plate is loose, gaps can be created. Attackers can use latch slips or traveler's hooks to bypass even dead latches by either "pulling" the latch towards them (if the latch is angled inwards) or "shoving" it away (if angled outwards), often deactivating the dead latch in the process.

Handle-Targeted Bypass

When dead latches are properly actuated, attackers shift to targeting the handle. For lever handles, an under-the-door bypass tool (a wire with a hook and string) is inserted under the door, maneuvered to hook onto the handle from the secure side, and then pulled down via the string. This mimics a legitimate exit from the inside, unlocking the door. For older doorknobs, a similar wire-and-string tool, often with tape for extra friction, is shaped to wrap around the knob from the side. By tensioning the string back and forth, the knob can be slowly rotated until it opens. These methods exploit the convenience of internal egress.

Crash Bars and Push Bars

Crash bars (or panic bars) are long bars on exit doors that, when pushed, retract the latch. Push bars are similar but typically lie flatter against the door. For crash bars, a wire tool with a hook (similar to the under-the-door tool) is inserted through a gap (often at the bottom or side) and hooked onto the bar. Pulling the string attached to the wire then depresses the crash bar, opening the door. For push bars, particularly on double doors with a central gap, a double door tool (a stiff J-shaped metal tool) can be inserted to push the bar in. Alternatively, string can be fed through a gap, looped around the push bar, and then pulled from both sides to retract the latch. The talk also humorously notes the "pulling really hard" method for doors with loose or weak latch mechanisms, which can often be yanked open.

Deadbolts and J-tools

Deadbolts, common in residential settings, are key-actuated locks with a solid bolt. Many modern deadbolts include a thumb turn mechanism on the inside for easy egress. The J-tool (also called a thumb turn bypass tool) is designed to exploit this. It's a thicker, wired tool with a clawed end. If a sufficient gap exists between the door and the frame (typically a couple of millimeters), the J-tool can be inserted, its end manipulated to grip the thumb turn, and then rotated to retract the deadbolt. This bypass highlights the vulnerability of internal thumb turns when external access to the mechanism is possible.

Padlock Shims

Standard, inexpensive padlocks are highly susceptible to padlock shims. These thin pieces of metal (often DIYed from soda cans) are inserted into the shackle opening next to the locking pins. By manipulating the shims, the internal pins that hold the shackle in place are deactivated, allowing the shackle to be lifted and the lock opened. This bypass is quick and requires minimal skill, exposing the weakness of many off-the-shelf padlocks. Manufacturers have responded by adding ball bearing designs to make shimming more difficult, but many older or cheaper locks remain vulnerable.

Button-Push Combination Locks

These locks, like Simplex models, are used in various settings, including key boxes for Airbnbs or business access. A significant vulnerability is the failure to change default factory codes. For Simplex locks, the default is often "2 and 4 pressed simultaneously, then 3." The speakers claim a "good 30%" of installations retain this default. Additionally, key boxes containing key fobs or credentials are often not shielded. Attackers can use ProxMark devices or Flipper Zero tools to duplicate the fob credential by simply placing the device against the plastic box, without needing to know the combination. Exposed combinations (e.g., written on signs near the door) are also a glaring vulnerability.

Entrophones

Entrophones (intercom systems common in apartment or office buildings) also suffer from default settings and hardware vulnerabilities. Many major brands use default master codes that are readily available online, allowing unauthorized access or system manipulation. Older systems frequently use "key-to-like" master keys, meaning a single key can open all entrophones of a specific brand and model. Attackers can acquire these keys online for "pennies." Once the panel is opened, the internal circuitry is exposed. Many entrophones even have a map of the board inside. By identifying the access relay port and using any piece of conductive material (e.g., cables), an attacker can "jump the circuit," simulating a legitimate buzz-in and unlocking the door. This method is highly non-intrusive and takes mere seconds.

Accessibility Features: Wheelchair Buttons and REX Sensors

Wheelchair buttons designed for accessibility can become security flaws if improperly installed. If a button on the unsecure side of a door can be pushed to unlock it, it provides direct bypass. Request to Exit (REX) sensors (often using passive infrared or PIR) are designed to detect movement from the secure side to allow egress without triggering alarms. However, these can be tricked. By inserting the tube of canned air through a door gap and flipping the can upside down, the extremely cold spray creates a rapid temperature differential that fools the PIR sensor into thinking someone is exiting, thereby unlocking the door. More advanced dual-technology REX sensors incorporate both PIR and radar to detect actual movement, making this bypass harder, but they are significantly more expensive.

"Going Around" and Environmental/Human Factors

Beyond direct lock manipulation, attackers often find indirect routes:

  • Fences: Improperly installed fences (e.g., barbed wire on the inside) or those compromised by overgrown trees provide easy climbing access.
  • Ladders: A caged ladder meant to secure rooftop access is useless if the back of the ladder is open.
  • Exterior Access: Unsecured exterior vents, maintenance holes, or walls that don't extend past false ceilings allow direct entry into buildings.
  • False Ceilings: If a secured area's wall does not extend to the true ceiling (only to the false ceiling), an attacker can climb above the false ceiling from an unsecured area and drop into the secured space.
  • Human Error: Propped-open doors, clutter preventing doors from closing, staff forgetting to lock up, or general complacency are major vulnerabilities.
  • Social Engineering: Convincing staff to grant access or leave doors open.
  • Exposed Credentials: Keys or credentials left on desks can be photographed and duplicated.
  • Environmental Factors: Warped door frames (due to humidity), air pressure differences, or simply broken/missing locks can compromise security. The speakers highlight an absurd but real scenario where a door had no lock, but because the handle didn't open it, staff assumed it was secure, unaware a screwdriver in the empty lock hole could open it.

Demo / Proof of Concept

▶ Watch: Live demonstration of the 'pulling' method to bypass (5:45)

The talk is replete with practical demonstrations, often featuring Karen Ng herself, illustrating the bypass methods in real-time. These videos are crucial for understanding the ease and speed with which these vulnerabilities can be exploited.

  • Door Latches: Karen demonstrates "pulling" and "shoving" techniques using a traveler's hook, showing how quickly a door can be opened once the dead latch is bypassed.
  • Handle-Targeted: A clear split-screen video shows the under-the-door bypass tool being inserted, maneuvered onto a lever handle, and then pulled to open the door from the secure side. Another video shows the more intricate process of using a string-and-wire tool to rotate a doorknob.
  • Crash Bars/Push Bars: A video shows a hooked wire tool being inserted under a crash bar door, hooking the bar, and then being pulled to open it. Another video, sourced from "fire response," demonstrates a double door tool quickly pushing in a push bar on an external double door.
  • Deadbolts: A video clearly illustrates the J-tool being inserted into a door gap, engaging the thumb turn, and then rotating to retract the deadbolt.
  • Hinge Removal: Karen demonstrates removing a hinge pin using a screwdriver and vice grips, then gently shuffling the door to separate it from the frame, gaining access.
  • Accessibility Features: A live demonstration shows Karen pushing a wheelchair button on the unsecure side of a door, causing it to automatically unlock and open. For REX sensors, a video depicts the classic canned air trick: inserting the can's tube through a door gap, flipping it upside down to release cold air, which triggers the PIR sensor and unlocks the door.
  • "Going Around": Videos show a coworker easily jumping over a backward-installed fence with barbed wire, using the open back of a caged ladder for rooftop access, and a coworker climbing above a false ceiling from an unsecured area to drop into a key-fob-secured office.

These visual proofs underscore the talk's central argument that many physical security measures are often superficial or easily circumvented when design flaws, installation errors, or simple physics are exploited.

Defensive Implications

▶ Watch: Explanation of the 'shoving' bypass technique (6:30)

The speakers provide concrete remediations for each vulnerability, emphasizing a multi-layered approach to physical security:

  • Door Latches:
  • Proper Installation: Ensure doors, frames, and strike plates are perfectly flush. Test that the dead latch is fully actuated when the door is closed.
  • Latch Plates: Install metal latch plates over the gap between the door and frame to prevent tools from accessing the latch bolt directly.
  • Handle-Targeted & Wire-Based Bypasses (Crash Bars, Doorknobs):
  • Door Gaps: Eliminate gaps under and around doors through proper sizing, fitted bevel door thresholds, and rubber/brush seals.
  • Lever Handle Design: Choose lever handles with minimal curve or an angled edge to make it harder for tools to hook onto. Avoid highly curved handles.
  • Eliminate Windows: Remove windows in doors, especially near the lock, as visual access significantly aids bypass attempts.
  • Deadbolts:
  • Double-Sided Deadbolts: Replace thumb-turn deadbolts with double-sided deadbolts that require a key from both sides. However, acknowledge the trade-off with fire code and convenience, as staff might leave them unlocked.
  • Proper Installation: Ensure no gaps exist around the door that would allow tool insertion.
  • Hinge Removal:
  • Non-Removable Pin Hinges: Use hinges with set screws that prevent pin removal when the door is closed.
  • Stud Hinges: Install stud hinges which have jut-outs that fit into corresponding holes, preventing the door from being removed even if the pin is taken out. Retrofit plates can mimic this.
  • Padlocks:
  • Ball-Bearing Designs: Opt for padlocks with ball-bearing mechanisms that resist shimming. Avoid cheap, standard padlocks.
  • Button-Push Combination Locks & Entrophones:
  • Change Default Codes: Immediately change all default factory codes on combination locks and entrophones.
  • Shield Fobs: If using key boxes for fobs, ensure the box is RFID-shielded to prevent cloning.
  • Avoid Exposed Combinations: Never display combinations publicly.
  • Replace "Key-to-Like" Systems: Upgrade older entrophones that use common master keys.
  • Physical Barriers: Add bars or cages over entrophones to prevent easy access to internal circuitry.
  • Accessibility Features (Wheelchair Buttons, REX Sensors):
  • Proper Installation: Ensure wheelchair buttons only activate from the secure side or are physically inaccessible from the unsecure side.
  • Dual-Technology REX Sensors: Invest in dual-technology REX sensors (PIR + radar) to prevent bypass with canned air.
  • Alternative Exit Methods: In high-security areas, consider push buttons (properly installed) or tap-in/tap-out credential systems for exit, balancing security with staff convenience.
  • General Security Posture:
  • Comprehensive Design: Do not rely solely on one security layer (e.g., elevators for floor access). Implement additional physical security on all doors and vulnerable points within a secured area.
  • Close and Lock Doors: Enforce a strict policy of closing and locking all doors, including employee entrances and utility access.
  • Clear Entryways: Keep door areas clear of clutter or debris that could prevent proper closure.
  • Staff Training & Security Culture: Educate staff on physical security best practices. Promote a security-minded culture where employees understand and adhere to protocols, such as not propping doors open or leaving credentials exposed.
  • Alarms and Sensors: Deploy comprehensive alarm systems and sensors to detect unauthorized entry.
  • Rapid Response: Ensure security personnel or law enforcement have a fast response time (e.g., significantly less than the time it takes an attacker to breach and exfiltrate).
  • Regular Maintenance: Regularly inspect and maintain all locks, doors, and frames to address issues like warped wood or broken mechanisms.
  • Have a Lock: As a fundamental and often overlooked point, ensure every door has a functional lock.

Key Takeaways

  • Bypass is Often Easier and Faster Than Lockpicking: Contrary to popular belief, many physical security vulnerabilities can be exploited in seconds or minutes using simple tools, making lockpicking a last resort.
  • Improper Installation and Design Flaws are Critical Weaknesses: The most common and easily exploitable vulnerabilities stem from doors, frames, and security hardware not being installed correctly or designed with security in mind.
  • Convenience Often Comes at a Security Cost: Features designed for user convenience (e.g., quick exits, easy access for guests) frequently introduce significant security risks that must be carefully balanced.
  • Human Error and Lack of Awareness are Major Attack Vectors: Complacency, failure to change default codes, propping doors open, or exposing credentials make staff and occupants the weakest link in physical security.
  • A Multi-Layered, Holistic Approach is Essential: Effective physical security requires more than just good locks; it demands proper installation, robust architectural design, vigilant monitoring (alarms, cameras, fast response), and a strong, pervasive security culture among all occupants.
  • Simple, Cheap Tools Can Defeat Common Locks: Basic items like bent wires, credit cards, or even soda cans can be fashioned into effective bypass tools, highlighting the inadequacy of many off-the-shelf security solutions.

About the Speaker(s)

Karen Ng and Matthew Cancilla are experienced practitioners in the field of physical security, particularly from a red teaming perspective. Their presentation at DEF CON demonstrates their deep understanding of various bypass techniques and their ability to clearly articulate complex security concepts to a broad audience. Both are actively involved in the physical security community, likely contributing to security villages and workshops, where they provide hands-on demonstrations and education. Their insights are grounded in practical experience, making their advice on both vulnerabilities and remediations highly relevant and actionable for security professionals and enthusiasts alike.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Competent, well-organized intro to physical bypass techniques with solid demo coverage — but this is a DEF CON 101 talk, not a research contribution. The content is well-executed for its lane, but veterans in the room already know the J-tool, the canned air REX trick, and shimming padlocks. It earns its slot as an accessible on-ramp, not as a conversation-advancer.

Heather Calloway (CISO) — WEAK

Solid DEF CON primer on physical bypass techniques with genuinely useful remediation guidance, but it stays firmly in red team demonstration mode and never reaches the institutional or governance level where physical security decisions actually get made. Competent execution for its audience; limited value for mine.

→ Top-rated talks at DEF CON 33

All talks from DEF CON 33