back
214 comments
In my office complex, we have a bunch of security guards who _check_ badges of people who enter the building (My building houses about 8-9 companies). If you don't have a badge then the guard calls the office you claim to be part of to ensure you have access, and then issues a temp badge.

A couple months ago, I forgot my badge at home, but didn't want to go through the hassle of getting a temp badge, so I flashed my driver's license at the guard (which is roughly the same size as my ID badge) and he simply waved me through.

I told my colleagues this, and since then we have a silly game where we try to get in using ridiculous cards. Most recently, we have people who have flashed blood donation cards (a card that acknowledges that you donated blood on so and so date), a credit card and a folded bookmark and successfully gotten into the complex.

While this is a running joke, really goes to show how lax manual security can be (Especially because once you are on my floor, you can easily tailgate your way into my office).

TL;DR Most of our security systems work on implicit trust more than anything else.

I used to be a security guard after I left the army (no skills in civvi street to get a better job).

Couple of things come to mind reading this. One that security guard is probably getting paid a pittance to do that job and you get what you pay for. Two the guard recognises you and your colleagues, knows you work there and doesn't really care that you're playing silly games because on their wage it's not worth the hassle pulling you up for you to get all high and mighty about the inconvenience of a lowly security guard daring to question you. Three that single guard, whilst ostensibly there for "security" is really just there for show, there's no way a single lowly paid guard can possibly provide security for a building housing 8 or 9 companies even with the best intentions.

My experience as a guard was that the employees of the companies within the building treated me with contemptuous distain until something happened at which point it was righteous anger.

I wonder if the security guards probably notice but are more interested in avoiding confrontation. I'd hate harassing someone who probably won't cause any trouble, and having to potentially get into an argument, where they'll likely belittle my position and make me feel like a shitty person for doing my job.

I was a bank teller during college, and would be occasionally berated by people when I'd ask to check their ID when they were withdrawing money. I always asked if they'd prefer I let anyone trying to take money out of their account do so w/o checking photo ID. One guy swore he was going to get me fired for not letting him take money out of his account because he forgot his wallet at his desk.

Devils advocate, they might simply know your face.

I worked in a 5000 person building for a year, left, and went back a year later for a christmas party. The shared reception still remembered who I was without being told and were able to guess who I was visiting.

Nice- the old psychic paper trick.

I made a little experiment like that myself when I was studying for my Masters. In the town where I live there is a bus card system that uses scratch cards. You get a card with dates (1-31), months and four years (say 2012 to 2016) and you're responsible yourself for scratching off the seven days, month and year when you intend to use the card. So, if you want to use the card starting next Monday, you'd scratch off dates 23 to 29, October and 2017. Then you show it to the bus driver when you board the bus. The understanding is that if you scratch off the wrong days, you can't use the card.

Obviously, mistakes can and do happen. A couple of times I noticed I had scratched off the wrong days or month, or even year. Once I scratched off eight days. One of those mistakes (can't remember which) was noticed by a driver, but most seemed oblivious to the fact my card was irregular, at least (if not totally invalid).

So I decided to make my little experiment: I kept buying and scratching (correctly) a new card each week, but I also kept on me the previous week's card and showed this one to the driver. Then I marked a tick on the card for each time I was waved through without a batting of an eylid. I got about a dozen cards like that, each with a week's worth of ticks or so. I got caught exactly once (at which point I just said "oops, mistake" and took out the right card).

Outcome: we have refuted the null hypothesis that people see what they're looking at.

Ah, reminds me of simpler times...

When my friends and I all first turned 21 we would swap around our drivers licenses amongst ourselves before entering a bar and showing them to the bouncer. We didn't all look alike, and we have a variety of weights, hair colors, and skin colors. We'd always get in without a problem then all high five each other and give the licenses back to the proper owner. I'm not sure when exactly we stopped doing it but it was amusing for us for a while to "fool" bouncers.

There was a guy on Pawn Stars who was trying to sell Slash's drivers license. He claimed Slash gave it to his ex girlfriend in return for flashing him her breast. He also claimed to use it as ID to drink from 18-21, apparently being successful despite it not being his ID.

Why would you have someone manually looking at badges? That’s what HID readers are for. I have occasionally seen a security guard in addition to a badge reader to make sure that your face matches the badge photo as you pass through a turnstile, but it doesn’t matter what’s on your badge - the “source of truth” photo is loaded from the database onto the guard’s screen.
I once went to a building I had been in before years earlier, but had installed proxycard activated turnstiles. I told the receptionist I didn't have a card but I knew the building well and she walked me to the ID card office where they made me one on the spot with no verification other than to see if I had a driver's license. The card they made me was good for 5 years and got me right through the turnstiles.
The problem of security guards being too relaxed is a consequence of people being too easily inconvinienced. People don't want to wait while security verifies them, and the security doesn't want to waste time verifying people as they don't have enough incentive and receive pushback if they inconvinience anybody. The solution would be to give incentive to both sides of the interaction; guards should give positive feedback and e.g. a popsicle to the person being verified if the interaction takes too long and the guard should receive a monetary reward when finding false ID:s (there should be a way to limit the abuse of the proposed system). Just my 2 cents, feedback and ideas appriciated.
Thank god the TSA is not so lax! All that money going into high-tech state of the art security equipment and advanced training really does the difference.

Wink, Wink ....

The most secure building I've ever been was one of the Giro buildings in Budapest. All visitors must show id and it is checked by professional guards, doesn't matter who you are are. They will call whoever you claim to be visiting and verify. Next you get your visitors badge. You can't get anywhere with it but the given office. Where corridors cross, you have man traps and your badge will only open the one direction you are allowed to go. This was a converted building so they added sliding glass doors to the existing doors and guess what, you need a badge to open any of those. To enter from the elevator to a corridor again you have a man trap. Tailgate that. Visitor's bathroom is outside of the secure area.
This was quite some years ago, I wonder how much has changed: As an employee of a private company, I was asked to do some work at one of the major data facilities of the Danish state. The place was - and still is - a huge, sprawling mass of concrete, steel and glass, and was internally partitioned into four concentric zones of supposedly escalating security, all fancy with locked doors and card readers. I was expected to present myself at the front desk in the reception area, but somehow, with my equipment on a trolley, and sort of looking for directions, I slipped in behind someone back at a delivery bay. And then just followed signs and color codes and various people through various doorways. In no time at all my trolley and I were at our destination: The holiest of holies, the central tape archive room (yes, it's that many years ago). Got to work for probably about half an hour, not another soul in sight, but in the end was interrupted by the chief of security himself, bursting in with the grimmest of looks and the strangest of colors on his face. Now, this fellow knew me, so no alarm sounded, but I was urgently desired to shut the fuck up and follow him out to reception, where I was registered, issued my proper guest card and authorization, and solemnly escorted back to the archive vault, deepest security, zone four.
When I read Kevin Mitnick's Ghost in the Wires, what impressed me was how he'd combine social engineering with technical hacks. For example even if people did call their boss or Kevin's alleged employer (the utility company, a partner company, whatever), he would have set up their phone system to send the call to himself. I'm sure that social engineering alone gets you a long way, and I'm sure that Kevin was good at it, but when your electronic communications aren't trustworthy you can really do a number on people! How are you even supposed to defend against that?
Social engineering is easier as a woman than a man, at least that is what I believe.

I know companies that perform social engineering tests like this and they try to use their female colleagues for voice-based attacks as much as possible.

I wonder how much different the whole thing is just because pen-testers get paid to do this by the same company, from somebody actually trying to do this for real.

Getting caught for pen-testers means something completely different, I wonder how that affects tactics.

A very good lesson for the company, via a red-faced Mary. She'll share the lessons from this experience widely I'm sure. Excellent that she wasn't fired.

Not to say that this is anything less than completely believable, but I wonder why Mary's boss didn't check up on the cover story? I get that Sophie was able to hack the usual social proof with Mary with her pregnancy sob-story, but wouldn't her boss have asked who sent her?

The most fun I've had using social engineering was to get access to a database that the pukes in the home office had locked up. Our boss' boss wanted access to the raw data, but they wouldn't give it to us. My colleague and I tag teamed them to figure out which server it was on and the names of the files, then he was able to break into it. The boss was very pleased to be able to provide the data as real-time on his boss' dashboard. Christmas bonuses all around.
Good article about physical security and a intro to social engineering.

As an aside I think the easiest way to get into buildings which are associated with a technology company like this would be to apply for a job there. At worst you will be there for an hour. At best it would be eight hours. Also, there is a lot of downtime in between interview(s) or even just plain waiting on someone. You can get "lost" and if you get caught you could say "where is the bathroom".

My goodness, how does someone get into a job like this in the first place? Start breaking into secure facilities until somebody notices you and gives you a job?
I find that casually yawning while walking by security guards has a great effect. It communicates comfort and at the same time increases the cost of interrupting your yawn. Having a card that looks like the badge they're looking for casually in your hand helps also.

For getting into expensive clubs, I used a technique similar to this article. I say that I want to check out the club for a birthday party, then the red carpet gets rolled out.

Another way is to say that you left your credit card in there by the bartender an hour ago, and if they can call someone... or you can just go and get it yourself. And you are flying out or something. Never did this one though :)

Did she bother changing her voice on the phone vs. when she met Mary in person? For familiar voices, it's often pretty easy to know who's speaking even when they change their pitch or accent, but maybe it was practical to assume that Mary wouldn't be able to notice a voice she'd only heard once on the phone. Obviously this isn't a key part of the exploit since she could've always gotten someone else to do the phone conversation, just wondering how careful she needs to be with those sorts of details to avoid something going wrong.
A de-cluttered version:

https://outline.com/saPHcb

This story reads like a social engineering attempt itself.

As in, fully made up, never happened.

I realize the person is a pentest consultant. And before that they were a journalist. As the story says, "trust but verify"? Which in this case I guess it doesn't make enough difference to verify and the events "could" have happened which is enough for the story. It just feels made up to me though.

Sorry, but this story didn't convince me. It was too straight forward and too much focused on professional sounding keywords and representing stuff as serious security risk that actually isn't.

What I can agree with is that in most companies you probably get in without having files/id cards checked and that this may become a problem to that company at some point.

"Third, if it seems too good to be true, it probably is."

This story was mostly or all fictional.

It often seems like the biggest con that physical pen testers pull on their clients is convincing them to hire them in the first place. What's the threat, exactly?

Let's say you do something like BeyondCorp. Gaining "network access" doesn't mean anything any more, because you can "gain" "network access" from anywhere in the world since it's all on the internet. Physical access shouldn't be the perimeter, identity should be.

Is that a tall bar? Sure, but it's basically the bar. Instead of wasting money on fancy pen-tests, put that money into the IT budget to get identity management up to that point.

Next, is the risk really that someone will gamble a physical snoop into a secure compound, where the possible negative outcomes are police custody and prison time, for a score of a few thousand dollars, as Sophie mentions in the article? Sure, that's a risk, hobos would cruise in and swipe a laptop off someones desk to sell it on ebay for booze money. Do you need to pay a pentesting shop $80k to know that? No. And, the risk is basically the same as if an employee takes home a laptop and their car is broken into. The fix is the same too: encrypt everything at rest.

These are all basic lessons that you can learn by downloading a CISSP study guide.

However, I think that there will always be failure points because what you want to defend against this is a culture of security, and it's difficult to instill that even when you work in an environment that is rightfully charged with maintaining high security. It's boring and generates friction. If someone shows up for an important meeting at a high security building and they forgot their ID, the guards will not accept any amount of "do you know who I am" because they know that when their supervisor is called in, they'll be backed up. Everyone else knows this too, on some level, so there's much more of a culture of "why didn't X happen?" "oh, there was a paperwork SNAFU somewhere and security stopped us at the front door" "lol! typical! we'll try again next week." That just wouldn't fly in the private sector: because the risk doesn't weigh anywhere near as much as the reward for just cutting the corner and doing it without the I's dotted and T's crossed.

So, sure. You can fast-talk your way past the rent-a-cop at the front desk of the offices of an aluminum siding manufacturing plant and swipe some coffee cups and staplers out of the supply closet, and you'll always be able to do this...

I see the entrance security as a deterant rather than a foolproof security system.
Maybe it's just me, but I find the presentation here quite distracting.
every human can be a psychopath with the right incentive / motivation
So... Is this the job she's most proud of AND most ashamed of? I'm not sure if that was elucidated, or just implicitly evident there...
Well, you can buy Fedex, UPS, DHL, or AT&T employee shirts right off eBay still in the packaging in basically any size you might need.
I'm an engineer at my company but when people come to visit I always give them an ocular patdown. It has never failed me.
So how do you deal with strangers who walk behind you when you enter the building with your security card?
Hit pulled up the back button on that page and it had a dozen copies of the article in the back buffer.
Oooh, try SwitchNAP in Las Vegas!
the gifs are annoying, imo.
PLEASE let this godforsaken phase of gifs after every other paragraph come to an end already. It makes yet another fascinating article basically unreadable.
The original version of this story was posted by Jek Hyde on twitter:

https://twitter.com/HydeNS33k/status/920323236176556037

Her exact story with the same gifs was posted on the 17th.

Update: Thanks internet peeps for letting me know this is the same person.

Great story. Those animated gif's, every paragraph, were killing me.
Story copy-pasted without the gifs:

Hello! My name is Sophie and I break into buildings. I get paid to think like a criminal.

Organizations hire me to evaluate their security, which I do by seeing if I can bypass it. During tests I get to do some lockpicking, climb over walls or hop barbed wire fences. I get to go dumpster diving and play with all sorts of cool gadgets that Q would be proud of.

But usually, I use what is called social engineering to convince the employees to let me in. Sometimes I use email or phone calls to pretend to be someone I am not. Most often I get to approach people in-person and give them the confidence to let me in.

My frequently asked questions include: What break-in are you most proud of? What have you done for a test that you were the most ashamed of?

What follows is the answer to both of these questions.

A few months ago, a client had hired me to test two of their facilities. A manufacturing plant, plus data center and office building nearby.

First step: open source intelligence, or OSINT. I look at maps, satellite images, study what I can of their delivery and supply schedules, and so on.

The manufacturing facility looked like a prison. No windows, heavy iron gates, no landscaping. Generally a monstrosity of architecture.

This facility had armed guards, badge readers, biometric security controls and turnstiles at every entrance.

I remember thinking, "It's got to be hell to work in there. I wonder if I can use that…"

One thing was for sure… The chances of tailgating (following behind an employee with valid credentials) into this building were next to non-existent.

I was going to have to get down and dirty with my social engineering.

First stop: LinkedIn. Your LinkedIn is my best friend. The more information you have on your LinkedIn, the more options I have.

I have several fake LinkedIn profiles that you are probably connected to.

I scour profiles of employees who work at these facilities, and cross-reference them to other social media sites. And I find a lovely young woman who I'm going to call Mary.

Mary was a brand-new hire working as an assistant at the manufacturing facility. Mary had a public Facebook account too.

On Mary's public Facebook account, she documented all of her family's adventures.

Side note: Now I know where Mary went to high school, her mother's maiden name, the names of her pets, etc.

Answers to those "security questions" you use to reset your passwords are very easy to find if you aren't careful with that information.

Not to mention that now I know where Mary works, where her kids go to school, where they vacation…I could go on. Scary stuff.

This is not an advanced investigation. I'm not a private investigator and I don't have the resources of the NSA. But I can do a lot of damage with simple methods.

Most notably to me, there were photos Mary posted of her time volunteering with a certain maternity support center.

Her passion for children and caring new moms was very plain. So of course, I took advantage of it.

For this assessment I played two roles. For the first, I spoofed my phone number to make it look like it was coming from the company's headquarters.

I called the front desk of the manufacturing facility and was transferred to Mary. "Hi Mary!" I said, "My name is Barbara."

"I am a project coordinator with facilities management. We are renovating a few of our facilities. We are sending an interior designer out to you tomorrow so she can put together proposals to update your space!"

Mary replied, "Well that's great! But why the short notice?" I could feel her getting suspicious, so I pulled out my trump card…

Sigh "Well Mary… You really should have heard from me sooner. I've just been so overloaded at work…I feel like I can't catch up, and to top it off the baby is due in 6 weeks. If my boss finds out I messed this up he's going to flip."

I was really getting into this, voice shaking. (Yes, I know, I'm a terrible human being.)

She cut me off, "Oh hunny, hunny it's ok. We will work this out! Tell me about the baby! Is it your first? Boy or girl?!"

Our Mary was committed at this point. Not because she is stupid, but because she is a good person. She wanted to help me.

We talked babies and birth plans for a while (never pick a pretext you can't speak about at length.)

Mary took down the name of the "designer" who was coming by the next day and we said our goodbyes. Mary could have saved her company a lot of heartache by simply verifying that I was who I claimed to be. (Just to be clear here, I would never give out Mary's real identity. I'm not totally heartless. This could have happened to anyone. She has not been fired.)

I showed up the next day as "Claire" with a fictional architecture firm that I had made business cards and a website for. My alter-ego Barb had done most of the leg work for me. When I arrived, Mary and her boss were waiting for me with smiles. I shook hands all around and handed them the business card I printed out the night before. I was given a visitor badge and the red carpet was rolled out.

I gained rapport with the staff there by asking them to tell me what they wanted in an office space. They were so excited. I might have claimed to be on the team that put together the Google offices…(Yes, I am HORRIBLE. This is my inner demon child.)

"You want a standing desk? New chairs over here?! Ergonomic keyboards for everyone! Let's look at swatches!"

We became best buds. I was given complete and unaccompanied access to the facility where I stayed for several hours.

I gained network access and stole several thousands of dollars in physical primitives by picking my way through cheap locks (credit to Deviant Ollam for the rad lockpicking animations.)

This client had been pretty confident that I wouldn't get into either facility, much less be able to hit both in a short time span. So the timeline was left to my discretion, but it was assumed that I would need to fly to the area twice.

I didn't see the need in burdening them with two round-trip expenses.

I went back to Mary's office and said, "Well I think I have what I need from here. How do I get to the office center?"

She looked at her watch and said, "It's almost lunch time. I'll take you there!" A whole group of us piled into the parking lot, and they took me to a nearby taco shop. That's right. My Marks took me to get tacos… I love my job.

After lunch they drove me to the offices and a few of them came in with me to show me around.

I took FOREVER looking around this office space, and eventually they said their goodbyes because they had to go back to work. They had a strict policy of escorting visitors. But I had been seen walking around with trusted insiders so no one questioned me.

I was free to take my time. I made myself at home. My main objective at this site was to weasel my way into private corner offices.

When I accomplished my goals, I tracked down my point of contact's office. This is the man who hired me in the first place. This is the best part of every job.

Steve was there, hard at work when I disturbed his groove by knocking on the door. He glanced up, "Hi there, can I help you?"

I smiled. "Hi Steve! I'm Sophie from Sincerely Security. It's nice to meet you in-person!"

I will never forget the look on his face… Pure gold. "Who?.... Wait, what? How? How did you get in here?!"

We stayed in his office and talked for a long time. I went over exactly the steps that could have prevented my success. First of all, the desire to help others is human and natural. We don't want to discourage that.

Second, I'm sure they did have some sort of policy that required visitors to check in showing government issued identification, but they weren't following it.

We also need to post by every computer, phone and door: "TRUST, BUT VERIFY."

An employee who does their homework can ruin my day.

Third, if it seems too good to be true, it probably is.

Is your company going to hire the team who designed Google's offices? Magic 8 ball says no.

Lastly, the team who took me to the second location should have found someone else to escort me through the building.

I've been doing this job for a couple years now, and almost every job is a variant of this story. Very rarely do I go through an entire assessment without some sort of social engineering.

There are ways to protect yourself and your company from attacks like this. I think it starts by sharing stories like these, and educating and empowering each other to be vigilant.

The reaction gifs were a bit too distracting for me to finish the article.
Not to add to the complaints but can somebody extract the text and post it vanilla elsewhere without the gifs? Seems like a very interesting article otherwise.
Hmmm, to me it sounds far too good/easy to be true.
I think the term "Social Engineering" is making this seem so fun and technical, if we started using the words "fraud" or "identity theft", or "impersonation", maybe companies and lawmakers can give it the legal and enforcement attention this issue desperately needs.

Not a judgement of the article or Sophie, more just terminology which makes it difficult for non-technical people to understand the gravity of these attacks