
DEF CON 33 - How NOT to Perform Covert Entry Assessments - Brent White, Tim Roberts
Source: YouTube · DEFCONConference · published Oct 10, 2025 · 55:54
Physical security penetration testing requires professionalism, practical experience, and understanding that you're helping clients rather than showing off [0:02-0:11, 2:48-3:02]. The presentation focuses on common vulnerabilities and realistic approaches rather than Hollywood-style theatrics 1:48-2:14.
Key Takeaways:
• Hollywood portrayals of physical security breaches are unrealistic and give bad ideas to newcomers 1:48-2:05
• The goal is to help clients identify weaknesses, not to demonstrate "cool spy" tactics 3:23-3:28
• Simple approaches often work better than complex methods - like piggybacking instead of badge cloning 23:02-23:06
• Social engineering effectiveness varies by region, with Southern and Midwestern people generally more helpful 14:56-14:59
• High-tech tools rarely save a bad plan - proper planning and social skills are more important 22:35-22:44
Professional physical security testing requires understanding the human element, proper planning, and focusing on practical vulnerabilities rather than flashy techniques 37:02-37:06.
Sources:
- 0:02-0:11 Introduction about professionalism and experience
- 1:48-2:05 Hollywood myth versus reality
- 3:23-3:28 Reminder that you're there to help clients
- 14:56-14:59 Regional differences in social engineering
- 23:02-23:06 Simple approaches often more effective
- 22:35-22:44 Planning over high-tech tools
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Penetration Testing. Commonly maps to: Security Assessment and Testing, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
As you can see from our slides, we take things very uh serious. We're extremely professional. Uh and we we do we do try our best, but we also like to have a lot of fun with this. We've been doing this for 12 plus years or so, and so after a while, you just kind of, you know, put our personalities and things into it. So, you will see a lot of things like this. However, uh we we promise we have some some good content, things that come from a lot of years of experience to share with you uh to hopefully save you some headaches. >> All right. So, welcome to how not to do physical security penetration tests. I am Tim Roberts >> and I'm Brent White. So, um some of the ground rules rules that we'll kind of go over. This is a lot. You don't have to read all of this. It's on our website wehackpeople…