
DEF CON 32 -Your Smartcard is Dumb A Brief History of Hacking Access Control Systems - Chad Shortman
Source: YouTube · DEFCONConference · published Oct 16, 2024 · 53:23
The video explores vulnerabilities of building access control systems and smart cards, showing how easily commercial systems can be compromised 0:14. Various attacks are demonstrated, from simple relay bypasses to sophisticated smart card cloning 3:31.
Key Takeaways:
• Many access systems use basic relay technology vulnerable to simple tools like magnets or vape smoke 4:54-5:29
• Most commercial smart cards use symmetric keys, meaning compromising one compromises all 20:37-20:49
• HID's master key was extracted in 2010, making millions of systems vulnerable to cloning 21:03-21:49
Despite known vulnerabilities, many organizations still use insecure systems, highlighting the security knowledge-implementation gap 26:06-26:43.
Sources:
- 0:14 Introduction to building access control systems
- 4:54-5:29 Relay bypass demonstrations
- 20:37-20:49 Symmetric key vulnerabilities
- 21:03-21:49 HID master key extraction
- 26:06-26:43 Security implementation gap
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
all right let's kick this thing off so I found out today this was not an hacker tracker so everybody in here must read the old ink version of the schedule so thank you for reading the old paper version and showing up today we're going to learn how to break into buildings plain and clear why do I like breaking into buildings I've actually never broken into a building for context but when you can do a computer exploit and it touches the real world that has always been the ultimate for me so I've played CTF for a long time done a lot of binary exploitation but seeing a pound sign pop up on your screen versus seeing a door unlock is a very different adrenaline hit so let's go back through the history and see all the different ways you can break into buildings with laptops so first we'll go ove…