Access Control Done Right the First Time
Tim Clevenger (Network Cyber Security Engineer)
DEF CON 33 · Day 1 · Main Stage
Overview
In this insightful DEF CON talk, Tim Clevenger, a Network Cyber Security Engineer with a unique background in physical access control system installation and maintenance, dissects the common pitfalls and critical vulnerabilities inherent in many commercially deployed access control solutions. Titled "Access Control Done Right the First Time," Clevenger's presentation serves as a practical guide for security professionals, facility managers, and anyone involved in the design, implementation, or upkeep of these essential physical security infrastructures. The core message is clear: the industry's pervasive "low bid, minimal viable product" approach often leads to systems that are unreliable, difficult to maintain, and fundamentally insecure, despite appearing to function on the surface.

Key moments
- 0:00 Introduction and common access control system pitfalls
- 1:00 Why Mercury Security boards are a good choice
- 2:00 Distinguishing access panels from door controllers
- 3:00 Key factors for access control equipment placement
- 4:15 Understanding and avoiding RS485 daisy chain problems
- 5:55 Common mistakes and importance of proper wiring
- 6:50 Introducing composite access control cable for reliability
Access Control Done Right the First Time
Speakers: Tim Clevenger, Network Cyber Security Engineer
Conference: DEF CON
YouTube: https://www.youtube.com/watch?v=6OFZjlym4r0
Overview
In this insightful DEF CON talk, Tim Clevenger, a Network Cyber Security Engineer with a unique background in physical access control system installation and maintenance, dissects the common pitfalls and critical vulnerabilities inherent in many commercially deployed access control solutions. Titled "Access Control Done Right the First Time," Clevenger's presentation serves as a practical guide for security professionals, facility managers, and anyone involved in the design, implementation, or upkeep of these essential physical security infrastructures. The core message is clear: the industry's pervasive "low bid, minimal viable product" approach often leads to systems that are unreliable, difficult to maintain, and fundamentally insecure, despite appearing to function on the surface.
Clevenger draws extensively from his hands-on experience, exposing how cost-cutting measures and a lack of understanding regarding long-term security implications result in widespread deficiencies, from inadequate wiring and outdated communication protocols to easily exploitable badge technologies. He advocates for a proactive, informed approach, urging audiences to challenge vendor defaults and demand robust, maintainable, and secure designs. The talk offers actionable advice and specific technical recommendations to ensure that access control systems not only open doors but do so securely and reliably for years to come.
The relevance of this talk is paramount in an era where physical security is increasingly intertwined with cybersecurity. A compromised access control system can lead to unauthorized entry, theft of intellectual property, or even endanger personnel. Clevenger's deep dive into the practicalities of installation and common weaknesses provides a crucial roadmap for organizations looking to fortify their physical perimeters effectively and avoid the costly consequences of a poorly implemented system.
Background
▶ Watch: Introduction and common access control system pitfalls (0:00)
The landscape of physical access control systems is often shaped by economic pressures, where the lowest bid frequently dictates the chosen solution. This prevalent "minimal viable product" mentality, as highlighted by Clevenger, results in systems that "work" in the most basic sense—they open and close doors—but lack the resilience, maintainability, and security features necessary for robust protection. Many vendors, driven by competitive pricing, install systems that cut corners on everything from component quality to installation best practices.
Clevenger's background as a CIS admin for an alarm company and later as an installer and troubleshooter for access control systems provides him with a unique perspective, having witnessed these issues firsthand in countless deployments. He emphasizes that while a system might function initially, its long-term security and reliability are often severely compromised by these initial design and installation choices. This problem is exacerbated by a lack of awareness among end-users and project managers regarding the technical nuances and potential vulnerabilities.
At the heart of many modern access control systems, Clevenger points to Mercury Security as a dominant equipment manufacturer. Many other companies rebrand and sell Mercury's boards, which are noted for their local storage and onboard processing capabilities. This architecture is crucial because the access panels make decisions independently, ensuring doors can still operate if network connectivity to the central server is lost, unlike some other vendors. A significant advantage of Mercury boards is their reflashable firmware, allowing organizations to switch software vendors (e.g., from Lenel to Genetec or Honeywell) without needing to replace all their physical hardware, offering considerable long-term flexibility and cost savings.
The fundamental components of a typical access control system include access panels and door controllers. Access panels are the "brains," typically connected to the network via Ethernet, storing the cardholder database, and making most access decisions. They often incorporate a two-door controller. Door controllers, on the other hand, are "dumber" and cheaper, lacking local storage of the cardholder database. If they lose connection to the access panel, they revert to a highly insecure state, either allowing everyone, denying everyone, or granting access based on an outdated, static facility code, regardless of a cardholder's current authorization status. This architectural distinction underscores the critical importance of reliable communication and power to all components.
Initial planning for equipment placement is also a frequently overlooked aspect. Considerations such as environmental factors (heat, humidity, dust, corrosive elements like saltwater), reliable power availability (hardwired, dedicated circuit), physical security of the enclosure (locked closet, tamper switches), and future accessibility (avoiding drywalling over equipment) are paramount. Neglecting these can lead to premature hardware failure, system instability, and costly, difficult repairs, as exemplified by a board failing in a saltwater pool filtration room due to corrosion.
Key Findings
▶ Watch: Distinguishing access panels from door controllers (2:00)
Clevenger's talk highlights several critical findings that underscore the pervasive vulnerabilities and operational inefficiencies in contemporary access control deployments:
- Outdated and Insecure Protocols: The continued reliance on archaic communication protocols like RS485 for panel-to-controller communication and especially Wiegand for reader-to-panel communication is a major security flaw. Wiegand, dating back to 1975, is trivial to intercept and spoof, allowing attackers to clone badges or replay access signals with minimal effort, often from outside the building using off-the-shelf tools.
- Poor Wiring Practices: A significant percentage of installations suffer from substandard wiring, including the use of thin-gauge, unshielded, spliced, or entirely unsuitable cables (e.g., Ethernet cable for power/data). This leads to voltage drops, electromagnetic interference (EMI), unreliable communication, and frequent system crashes, particularly with card readers.
- Lack of Physical Tamper Protection: Most installations omit crucial tamper switches on equipment enclosures, card readers, and even Knox boxes. This means that an attacker can physically open a panel, pull a reader off the wall, or access a Knox box key without the system generating any alert, providing ample opportunity for compromise.
- Absence of Supervision Resistors: The talk identifies the "sheer laziness" of installers who neglect to include supervision resistors on door contacts. These inexpensive components are vital for distinguishing between a door being truly open/closed, a wire being cut, or a wire being shorted, significantly enhancing fault detection and preventing bypasses.
- Vulnerable Badge Technologies: Widely used badge types such as 125 kHz Prox and older iClass cards are easily cloned using cheap readers available online. This vulnerability is compounded by the common use of default or easily guessable facility codes, which attackers can leverage to generate valid badge credentials.
- Underutilization of Modern Security Features: Despite the existence of more secure protocols like Open Supervised Device Protocol (OSDP) (introduced in 2015), which offers encryption and secure reader enrollment, Clevenger notes that 84% of installers either "never or seldom" use it. This indicates a widespread failure to adopt modern security standards.
- Inadequate Power Management and Documentation: Remote power supplies for power-hungry locks are often installed in hidden, inaccessible locations, using cheap components, and frequently lacking backup batteries or tamper switches. This leads to single points of failure, undocumented system components, and doors failing during power outages.
- Neglect of Life Safety Connections: While fire codes often mandate connections between access control systems and building fire alarms to automatically unlock doors during emergencies, these critical relays are sometimes overlooked, risking lives in a high-rise scenario.
These findings collectively paint a picture of an industry where foundational security and reliability principles are routinely sacrificed for expediency and cost, leaving organizations exposed to significant physical security risks.
Technical Deep Dive
▶ Watch: Key factors for access control equipment placement (3:00)
The technical core of Clevenger's presentation revolves around the intricate details of access control system components, communication protocols, and installation methodologies. Understanding these elements is crucial for building robust and secure systems.
Communication Protocols: RS485 and Wiegand
At the heart of many access control systems lies RS485, a serial communication protocol dating back to the 1980s. It's typically used for communication between the main access panel and downstream door controllers. RS485 utilizes a two-wire or four-wire cable, requires proper shielding (drained at one end), and termination resistors at the end of a string to prevent signal reflections. While theoretically capable of distances up to 4,000 feet, Clevenger highlights a critical architectural flaw in common implementations: daisy-chaining. If a single wire in a daisy-chained run is cut, or if a single door controller fails, or if there's electromagnetic interference (EMI) along the line, the entire string of up to 31 door controllers can become inoperable. This creates a single point of failure that is incredibly difficult to troubleshoot across thousands of feet of wiring.
Even more concerning is the widespread use of the Wiegand protocol for communication between card readers and door controllers/access panels. Originating in 1975, Wiegand is an unencrypted, unidirectional protocol that is "trivial to capture." An attacker can simply pull a card reader off the wall, attach a small device to the exposed wires, and capture badge data, often transmitting it wirelessly via Wi-Fi from outside the property. This vulnerability allows for easy badge cloning and replay attacks.
The modern alternative is the Open Supervised Device Protocol (OSDP), introduced in 2015. OSDP leverages RS485 but adds crucial security enhancements: encryption for data transmission and secure reader enrollment. This process ensures that readers and panels communicate over a trusted, encrypted channel, significantly mitigating eavesdropping and replay attacks. However, Clevenger laments that 84% of installers still "never or seldom" use OSDP, sticking to the outdated Wiegand, thereby leaving a gaping security hole. While OSDP also supports daisy-chaining readers, it is generally advised against due to potential reliability issues, except in very specific, controlled circumstances.
Wiring Quality and Best Practices
Poor wiring is a ubiquitous problem. Clevenger frequently encounters installations using inappropriate wire gauges (e.g., 18 gauge for long power runs to locks), spliced cables, unshielded wires (leading to reader crashes from EMI), or entirely unsuitable cables like Ethernet wire. These issues lead to voltage drops, communication failures, and system instability.
The solution is composite access control cable, specifically designed for these applications. This cable bundle contains all necessary conductors (power, data, auxiliary) within a single, thick exterior jacket. Crucially, sensitive data lines are properly shielded, and the cable is available with auxiliary and spare conductors for future expansion (e.g., push buttons). Its distinct appearance immediately signals appropriate quality to technicians.
Power Management and Locking Hardware
Power delivery is another critical area. Power-hungry locks, such as magnetic locks (mag-locks) and motorized crash bars, require substantial current. If a wire run is too long or the gauge too thin, a voltage drop occurs. For magnetic locks, this means the lock might appear engaged and even rattle, but can be forced open with enough pulling pressure. To counteract this, Clevenger suggests using remote power supplies closer to the lock or running 24V instead of 12V over the same wire to effectively double the power delivery. However, remote power supplies are often installed in hidden, inaccessible locations (e.g., above a conference room ceiling), using cheap components, and lacking essential backup batteries or tamper switches, turning them into single points of failure. Solenoid-based locks, if constantly activated during business hours, can also overheat and fail prematurely.
Logical Layout and Clustering
Clevenger strongly advocates for a clustered equipment layout wherever possible. This involves housing access panels and their associated door controllers in a single, large enclosure, with short RS485 runs to the door controllers. This centralizes troubleshooting, minimizes cable length, and improves reliability. For a typical office floor, a central cluster or two clusters for segmented halves of a building (e.g., for subleasing) is ideal.
Exceptions exist, such as warehouses with long linear runs of dock doors or remote gates. In these scenarios, a single, long RS485 run for door controllers or a gate reader might be more practical than attempting to extend Ethernet with fiber media converters over vast distances, provided the wiring is exposed, well-protected, and free from EMI.
Physical Security Components
Beyond communication, the physical integrity of the system relies on several components:
- Tamper Switches: These inexpensive switches, typically installed on enclosure covers, card readers, and Knox boxes (which hold emergency keys for fire departments), detect if the device has been opened or removed. Their absence means an attacker can compromise a component without triggering an alert.
- AC Fail and Battery Fail Contacts: These monitoring points, often present on power supplies, detect if main AC power is lost or if backup batteries are failing. Connecting these to the access control system ensures immediate alerts, preventing unexpected door failures during outages.
- Supervision Resistors: These small, inexpensive resistors (around $1.50) are installed in-line, as close as possible to door contacts (sensors that detect if a door is open or closed). Instead of simply signaling "open" or "shorted," they change the resistance level, allowing the system to differentiate between four states: door open, door closed, wire cut, or wire shorted. This significantly enhances fault detection and makes simple wire manipulation much harder to conceal.
- Motion Sensors (Request to Exit - REX): Used to legitimately open a door from the inside, these sensors (infrared, microwave, or both) require careful aiming and range adjustment to prevent bypasses (e.g., spraying under the door) or false trips.
Badge Security
Badge security is a critical weakness. 125 kHz Prox cards are the cheapest and "trivial to break." They use a 26-bit format with a facility code (256 options) and a badge ID. Common facility codes like "1" and "132" are widely used, making them easy targets. Older iClass cards are also "pretty well broken." More secure options include Desfire V2 and above and HID COS, though Clevenger notes "asterisks" indicating potential workarounds.
The recommended solution is custom badges, such as HID Corporate 1000. These are CO compatible (more secure, but not explicitly defined in the talk), use a 48-bit format offering 8 million badge numbers, and provide a dedicated facility code that can only be ordered by specific authorized personnel from a preferred vendor. When implementing such a system, it's crucial to disable older, less secure badge formats to prevent their continued use.
Demo / Proof of Concept
▶ Watch: Common mistakes and importance of proper wiring (5:55)
While Tim Clevenger’s presentation was rich with practical advice and visual examples, it did not feature a live, hands-on demonstration of system vulnerabilities or a proof-of-concept exploit during the talk itself. The speaker did, however, refer to having "pictures of a couple boards here" and "another good time for a picture" to illustrate various components and installation scenarios. Furthermore, Clevenger explicitly encouraged attendees to visit the physical security village at DEF CON, stating, "I haven't gone into any bypasses, but there's lots of that stuff. So come to the physical security village. We've got all kinds of demos set up there for you to to take a look at." This indicates that while the talk focused on theoretical and practical guidance, the opportunity for experiencing live demonstrations of bypasses and vulnerabilities was available elsewhere at the conference.
Defensive Implications
▶ Watch: Introducing composite access control cable for reliability (6:50)
Clevenger's talk provides a comprehensive blueprint for bolstering physical access control systems against common threats and operational failures. Defenders should adopt a proactive, security-first mindset, moving away from reactive fixes and minimal viable products.
- Prioritize Planning and Vendor Selection:
- Comprehensive RFPs: Develop detailed Requests for Proposals (RFPs) that explicitly outline security requirements, preferred technologies, and installation standards. Clevenger offers an RFP template on his GitHub, encouraging customization.
- Challenge Defaults: Never accept vendor default configurations or components. Insist on adherence to the RFP and best practices.
- Equipment Choice: Opt for systems built on flexible, robust hardware like Mercury Security boards, which offer local processing and reflashable firmware, allowing for future vendor changes.
- Modernize Protocols and Components:
- Embrace OSDP: Mandate the use of Open Supervised Device Protocol (OSDP) for all card reader communications. Ensure readers are properly enrolled and configured for encrypted communication, moving away from the highly vulnerable Wiegand protocol.
- Secure Badges: Implement custom, high-security badge formats such as HID Corporate 1000 (48-bit) with dedicated facility codes. Crucially, disable support for older, easily clonable formats (e.g., 125 kHz Prox, older iClass) in the system to prevent their use.
- Supervision Resistors: Insist on the installation of supervision resistors on all door contacts. This inexpensive addition significantly enhances the system's ability to detect wire cuts, shorts, and tampering, providing better visibility into door status.
- Implement Robust Physical Installation Practices:
- Strategic Placement: Carefully plan equipment placement to avoid harsh environments (e.g., saltwater, extreme heat), ensure dedicated, hardwired power with circuit breakers, and guarantee physical security (locked enclosures, tamper switches). Plan for future accessibility to prevent costly ceiling demolition for maintenance.
- Quality Wiring: Specify and verify the use of composite access control cable for all runs. This ensures proper wire gauge, shielding, and overall reliability, mitigating issues like voltage drop and EMI.
- Clustered Layouts: Design systems with clustered equipment wherever feasible, centralizing access panels and door controllers for shorter RS485 runs, easier troubleshooting, and reduced points of failure. Document any necessary linear runs (e.g., warehouses, gates) carefully.
- Tamper Protection: Install tamper switches on every access control enclosure, remote power supply, card reader, and Knox box. These alerts are critical for immediate detection of physical compromise.
- Monitor Power: Connect AC fail and battery fail contacts from all power supplies to the access control system for immediate alerts on power disruptions or battery failures.
- Optimize Locking Hardware and Sensors:
- Appropriate Locks: Select locking hardware suitable for the door's security requirements and usage frequency. Be mindful of power-hungry locks like magnetic locks; ensure adequate power delivery (e.g., 24V for long runs) to prevent voltage drops that compromise security.
- Remote Power Supply Best Practices: If remote power supplies are necessary, ensure they are documented, easily accessible, housed in secure enclosures with tamper switches, and equipped with backup batteries.
- Sensor Configuration: Properly aim and configure motion sensors (REX) to prevent bypasses and false trips.
- Maintain and Monitor Diligently:
- System Alerts: Configure the access control system to generate actionable alerts (e.g., email notifications) for all critical events, including tamper alarms, power failures, and unauthorized access attempts.
- Camera Integration: Link the access control system with the CCTV system to automatically pull up camera views associated with specific doors when an event occurs, enabling rapid visual verification.
- Comprehensive Documentation: Maintain thorough documentation of all system components, including panel locations, door controller assignments, remote power supply locations, battery types, and wiring diagrams.
- Regular Maintenance: Routinely test card readers and other components. Implement a schedule for battery replacement (typically every 3-5 years, or 3 years in hot environments, 5 years in air-conditioned spaces).
By implementing these defensive strategies, organizations can transform their access control systems from potential liabilities into robust pillars of their overall security posture.
Key Takeaways
- Don't Accept Defaults; Plan Proactively: Vendors often provide minimal viable products. Organizations must demand robust systems through detailed RFPs, challenging default configurations, and actively participating in design and installation decisions.
- Modernize Communication Protocols: Abandon the easily exploitable Wiegand protocol for card reader communication. Insist on Open Supervised Device Protocol (OSDP) with encryption and secure reader enrollment to prevent eavesdropping and cloning.
- Prioritize Physical Integrity: Implement tamper switches on all enclosures, readers, and Knox boxes. Use composite access control cable for reliable, shielded wiring, and install supervision resistors on door contacts for enhanced fault detection.
- Secure Badge Technologies: Migrate away from easily cloned 125 kHz Prox and older iClass badges. Adopt custom, high-security badge formats like HID Corporate 1000 and disable support for less secure formats in the system.
- Emphasize Life Safety and Monitoring: Configure all doors to fail safe in emergencies, integrate with fire alarm systems, and ensure Knox boxes have tamper detection. Connect AC fail and battery fail contacts for proactive power monitoring.
- Document and Maintain: Thoroughly document all system components, including hidden remote power supplies. Implement regular maintenance schedules, particularly for battery replacement (every 3-5 years), and configure actionable alerts linked with camera systems for efficient incident response.
About the Speaker(s)
Tim Clevenger is a Network Cyber Security Engineer who brings a unique and invaluable perspective to physical security systems. Before transitioning into network cybersecurity, Clevenger worked as a CIS admin for an alarm company. In this previous role, he gained extensive hands-on experience in the field, not only in the "dark server room" but also driving a truck to install, troubleshoot, and maintain a wide array of access control systems. This practical background, having worked on systems installed by both his company and competitors, has provided him with deep insights into the common flaws, vulnerabilities, and best practices that are often overlooked in the industry. His talk reflects this dual expertise, bridging the gap between theoretical security principles and the realities of physical security deployment.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
Competent practitioner talk with real-world grounding in physical access control — Clevenger clearly knows the install side of this domain and the content is technically honest. Nothing here is novel to anyone who's done physical pen testing or attended previous DEF CON phys-sec tracks, but it's well-organized and the advice is sound.
Heather Calloway (CISO) — SOLID
Clevenger knows his subject cold — this is practitioner-grade content on physical access control that most organizations genuinely need. But it operates almost entirely at the installer and facilities level, and never climbs to where security leaders or board advisors actually sit.