The Spicy Security Spectrum

▶ Watch (6:11)

AI lip reading was a tier-one capability years ago, usable only by nation states. Now it costs $0.90 and a $20 optical lens on an iPhone. That demo showed 85% accuracy from a block away. Shawn’s point: TTPs slide down the spectrum over time. A red team’s job is to stay ahead of that slide. Physical security teams rarely think about these vectors. Cyber teams do, but don’t apply them to the physical space.

10 Steps to Get Physical Testing Off the Ground

▶ Watch (9:40)

Start with a threat model. Understand who would attack you and why. Use their language when you propose the test. Get a letter of authorization from someone who actually has the authority. Practice your tactics before the field. Execute the operation and know when to stop — sometimes you escalate until caught. The single most important step: an immediate debrief within one hour. Talk to everyone you social-engineered. Ask what would have stopped you. That root cause analysis is gold.

Four Tactics That Get You Into Most Buildings

▶ Watch (21:47)

Underdoor tool, canned air, latch attacks, and ESP key. Canned air works on passive infrared sensors — a cloud of cold air triggers motion. The ESP key reads clear-text badge data from wires with vampire clamps and replays it from a phone. Shawn rarely uses lockpicks in the field; these tools are faster and less suspicious. A Verizon shirt walked a team into a police station’s server room. A ladder stole a safe with a crypto key worth over a billion dollars.

Mitigation Strategies: Turning Exploits Into Upgrades

▶ Watch (33:27)

For underdoor tools, a $125 door shroud blocks the wire. For canned air, move the sensor or use active infrared that tracks motion direction. For ESP keys, move readers behind glass or add a tamper switch. Badge cloning is harder to fix — two-factor adds friction but works. Shawn’s advice: train facilities staff to do a $25 door audit every quarter. “Help hack the solution, not just create the problem.”

Red Team Superpowers

▶ Watch (41:41)

Red teams can demonstrate instead of just report. One video of an end-to-end break-in beats ten audit reports. Shawn uses “fictional intel” — a story that combines real threat logs with a fictional physical attack. Gamify security awareness: walk around acting suspicious, reward employees who catch you. Never plant actual bugs in people’s homes. Send a proof-of-concept instead. The goal: make everyone look good so they want more testing.

Q&A

Can a magnet defeat magnetic door latches? Yes, on some hardware — you probably need a better latch. ▶ 51:02

Does adding a PIN to badge swipes help? It makes cloning significantly harder, but attackers can still shoulder-surf the PIN or use adversary-in-the-middle attacks on external readers. ▶ 52:21

Do you recommend cyber hygiene like hiding political donations? Yes, when the scope is broad. One deep dive on an employee shows how publicly available data — campaign donations, home addresses — feeds physical targeting. ▶ 53:46

How do you defeat door motion sensors that trigger on cold air? Move the sensor down the hall, minimize door gaps, or use a hand warmer thrown through the gap. ▶ 54:56

Notable Quotes

For every 5 minutes of action there’s 5 hours of reporting. Shawn · ▶ 49:53

Discovering the vulnerability is easy. Figuring out why it exists is hard, but that is the most important thing to actually get it fixed. Shawn · ▶ 47:08

We are essentially doing a bunch of criminal acts, and the only reason it’s okay is because someone asked us to and gave us a letter that said it is. Shawn · ▶ 43:48

Testing is fun. Seeing things improve is rewarding. Shawn · ▶ 49:26

Key Takeaways

  • AI lip reading and commodity cameras have made surveillance cheap and accurate.
  • An immediate debrief with social-engineered targets yields the best root cause data.
  • Cheap mitigations like door shrouds and training facilities staff beat expensive hardware upgrades.

About the Speaker(s)

Shawn helps companies match and defend against the adversary’s tactics — no firearms required. As an adversary for hire, Shawn leads physical red teams that test Fortune 100s, government agencies, and critical infrastructure. He started the largest physical red team in Silicone Valley and teaches security risk management and red teaming to cybersecurity graduate students. From fake badges to forged businesses, kidnapping executives to smuggling weapons, he runs ops that find the gaps in physical security before the bad guys do.