DEF CON 33 - Intro to Physical Security Bypass - Karen Ng, Matthew Cancilla

DEF CON 33 - Intro to Physical Security Bypass - Karen Ng, Matthew Cancilla

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 57:05

Penetration Testing
No ratings yet Log in to rate
Transcript Available
Description

This video presentation demonstrates various physical security bypass techniques and their remediations, focusing on how attackers exploit vulnerabilities in locks and access systems 0:00. The presenters explain that bypass methods are often faster and more reliable than traditional lockpicking 0:49.

Key Takeaways:
• Physical security vulnerabilities often stem from poor installation rather than weak locks, with examples like doors with mail slots allowing easy bypass 1:07
• Door latch bypasses include "carding" techniques that exploit improperly installed dead latches 3:24
• Handle-targeted bypasses use tools inserted under doors to operate levers from the secure side 8:25
• Many systems remain vulnerable due to unchanged default codes and master keys 29:51
• Proper remediation involves correct installation, eliminating gaps, and replacing vulnerable hardware 7:22

The presentation emphasizes that physical security requires constant evaluation, similar to cybersecurity, as attackers continually develop new bypass methods 2:33.

Sources:

  • 0:00 Introduction to physical security bypass concepts
  • 0:49 Explanation of why bypass methods are preferred over lockpicking
  • 1:07 Example of mail slot vulnerability
  • 3:24 Carding techniques demonstration
  • 7:22 Proper installation as remediat

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Penetration Testing. Commonly maps to: Security Assessment and Testing, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

All right. Hello everybody and welcome to Intro to Physical Security. Uh my name is Karen >> and I'm Matt. >> And today in the next 45ish minutes to 50 minutes, we're going to be going kind of through a flurry of different uh physical security bypasses and then the remediations for each. So before we get started, you guys might be wondering what is bypass? A lot of the times when people are thinking about physical hacking, they're thinking about like the cool showy stuff they see in the movies, right? So lockpicking especially is something that like looks very visually interesting. They use in a lot of those movies, but it takes a lot of time. And there's a lot of other methods that allow people access into physical locked out locations that are usually faster, more consistent, and usually…