mnemonic security podcast
Hosted by Robby Peralta from mnemonic, one of Europe’s leading cybersecurity companies, the show features conversations with researchers, founders, operators, and security leaders working across the cybersecurity landscape.
Each episode explores a specific topic within cybersecurity: from incident response, threat intelligence, AI, and geopolitics, to leadership, resilience, and the changing role of security leaders.
The podcast is tailored to cybersecurity practitioners and decision-makers who want grounded conversations about where cybersecurity is going, what organisations should prepare for, and what experienced people are seeing.
mnemonic security podcast
Black Teaming
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Many are familiar with cybersecurity penetration testing – ethical hacking to uncover digital weaknesses. But what about the real-world threats to your company's physical security? How confident are you in your locks, cameras, and physical security measures to protect your sensitive data or equipment?
In this episode, Robby speaks with Brian Harris, a leading expert in physical penetration testing as a part of Black Teaming. Black Teaming is a type of security assessment that simulates an attack on an organisation, including tactics such as physical intrusion and social engineering. Brian, Chief Instructor for the Covert Access Team, has conducted hundreds of these physical pen tests, helping organisations identify and fix vulnerabilities that could lead to corporate espionage and other threats.
They provide real-world examples, discuss the limitations of common security measures, and touch on methods for improvement. These methods can include gamifying security by incentivizing employees to take an active role in physical security, for instance by keeping an eye on suspicious activity in the office.
Physical Pen Testing and Security Auditing
SpeakerFrom our headquarters in Oslo, Norway, and on behalf of our host, Robby Peralta, welcome to the Mnemonic Security Podcast.
Robby PeraltaThe definition and focus on security tends to change over time. A hundred million years ago, we'd be worried about dinosaurs. In the late 90s, folks were worried about the Y2K bug. And nowadays we've got everything from phishing, software and hardware vulnerabilities, and the fact that your IT help desk might just get tricked into giving away access to the bad guys. Never a dull moment at least. Now I, and probably you too, have all the bells and whistles to protect myself online. That being said, I recently found out that my front door lock is one of the most common in Europe and only takes about 20 seconds for someone that knows what they're doing to open it. But don't get any ideas. It'll be changed by the time you hear this. My point is, I don't think we use enough time and effort on physical security. I'd be willing to bet that a majority of you listening to this work for an organization with the cybersecurity team, but if I ask you about physical security, ah, we just use one of those security companies, you know, with the uniforms and small electric bikes or whatever. So ask yourself, would it really be that hard to put a listening device in one of your secret rooms? When was the last time you checked for weird devices behind the corporate boardroom TV or under the industrial printer that we all have? As an employee, you probably already have a few ideas of how you could break into your own office. But if you can do it, why can't an attacker? What's really stopping them? And I know you don't have time to immerse yourself in the physical security world and start lockpicking or whatever, but as our next speaker would tell you, you can bring a lot of value to your organization, starting with a simple physical audit. But uh, what is that again? Brian Harris, welcome to the podcast.
Brian HarrisThank you. Glad to be here.
Robby PeraltaA lot of the cool people that I look up to and think are awesome, you've been an instructor for them.
Brian HarrisThere's been a lot of really awesome people who've uh done some of my training. So I'm really happy to have met a lot uh a lot of people that work with your company and and a lot of others.
Robby PeraltaWhat is their training about? Because I've heard people do you have like a lot of training, I guess, because there's a big spectrum there.
Brian HarrisYeah, yeah. So it's uh so the training that we do is everything from how to do you know covert methods of entry, covert access, that sort of thing. Um basically run a physical pen test. Um there's also physical auditing, elicit elicitation, and social engineering. There's counter-elicitation. So it's there's there's a lot of different types of things.
Robby PeraltaYou have a lot of hats somewhere.
Brian HarrisI do. I wear a lot of hats. Yep.
Robby PeraltaSo I was looking, I was doing some cyber stalking of you. Started off at the Center for High Insurance Computing, which sounds awesome. Everything from chips and drones to programming, which you've done a lot of. Uh, you've been a researcher at a university in Germany, a pen tester. How did you get to where you are today?
Brian HarrisYeah, so I I have a very winding path, as I'm sure most people do. Uh, I actually started off in like applied mathematics, and my professor basically told me if you have no aspirations of going on to a PhD, you're not gonna have a job in math. It's just not gonna happen, right? So I went on and got a computer science degree on top of math. And um, I happened to know a professor who got me a job at the Center for High Shirts Computing at the time, and I got to do some really fun um research with them. Among other things, they were trying to solve problems of how do you verify if a computer chip is supposed to be doing what it's what it claims it's doing out of the box at scale, right? Like if you get if you get a a million computer chips from China, Taiwan, wherever, how do you vet them and and verify that they're all every one of them is doing what they're supposed to be doing? Because they those chips go into places like, you know, well, really sensitive laptops and computers and other things. So anyway, that's a huge thing today still. Yes, it is. And it well, just about any amount of software security is going to be superseded by a hardware vulnerability. Yeah. Like you can have all the software security in the world, but if you've got a hardware vulnerability that's doing something especially intentionally bad, you're almost guaranteed not to find it. You have to go to the hardware level to figure it out. And so, yeah, that that's that's a really, really tricky question. It's really hard. Um yeah.
Robby PeraltaSo today you're you're Mr. Physical Pen Test expert. Yep.
Brian HarrisI get um I mean I've gotten to work with people who who they've broken into some exceptionally secure places um that you need some very high clearances to even to go to, let alone break into. It's one of those things that as a result, by training with some of the best people in the world who do this kind of stuff. You get to, you a lot of that rubs off, and then I've been doing this for like 15 years now, and so I think I know what I'm doing.
Robby PeraltaUm how many physical tests do you think you've done? Like 100, 200, 300, 400?
Brian HarrisThere's really several different kinds. There is there's auditing, which is I'm not trying to break into your building. I'm going to your facility, I'm walking through the entire thing, and I'm trying to point out all the stupid stuff that I would have taken advantage of if I was actually breaking it. And then there's a covert entry where you're, you know, you're you're a physical pen test, a black team, red team, whatever you want to call it, where you go in and you try to break in. Right. If you're asking about the ladder, uh probably maybe a few hundred somewhere in there over 15 years. Um if you're including things like auditing and then the miscellaneous, oh, hey, we found this weird, suspicious device on the back end of the corporate boardroom, and we don't know what it is. And and the police don't seem to understand what it is either. So can you come in and take a look at it? I've had some of those too. And um, I can say even last month, the last uh the month of May, I I was I don't think I have a single day off, including the weekends. I mean, it's just it's just constant. Wow, it's it's a lot of work.
Robby PeraltaWell, at least it's cool, right? You're having fun.
Brian HarrisThat's how it's it's it's a it's a great job. Um as long as you set it up correctly and you're not running a physical engagement alone, yeah, it's a great job. It's a lot of fun.
Robby PeraltaHow often does uh a threat actor actually break into uh a building? I haven't heard that much about it, but I could also assume that that when it if it is happening, that I'm never gonna hear about it because it's uh
Brian HarrisYeah, yeah, of course. So there's a lot of um there's a lot of misconceptions when it comes to what threat actors are. We have this idea of threat actors being state entities or guys in scheme masks breaking in in the middle of the night. You know. The the first thing you have to do is identify what your threat to your client is. If you're in downtown London at present, your big threat actor is not corporate espionage, your downtown or your uh your threat actor is more of people in ski masks breaking into your store and stealing everything you have, right? So if you're if your uh business is merchandise, you know, jewelry, watches, cell phones, that sort of thing, uh then your theft, petty theft, is I I always hate the word petty because it can destroy people's businesses and livelihoods. But it's it's that. It's it's basically theft. If you're talking major conglomerates, uh people who are selling um IP or you know, other things, then it's going to be corporate espionage, it's going to be insider threats, it's going to be um a combination of the both. Um but this kind of stuff happens all the time. But if then if you're dealing with critical infrastructure, like the Department of Energy in the United States, they argue that about one to 200 times per year somebody's attacking their critical infrastructure and power grid. Uh, this can be anything from taking try to take down transformers or substations or you know, digging up water lines or whatever. So it really just depends on what your threat is. There was one in it uh recently, an attack on uh a substation outside of Fort Bragg, North Carolina. So Fort Bragg, North Carolina is the largest military installation in North America. It's all like this U.S. Special Operations Command, the airborne, and a whole bunch of other stuff. Um, and some people were able to figure out how to shoot a substation in just the right place at distance and take the entire substation offline, uh, which took power out to the entire base until an emergency mobile substation was brought in to off to take over the load. There are not a lot of emergency mobile substations out there, they just don't exist. And that was a very perfect example of an asymmetrical attack where you don't take, you don't require much, a rifle, a bullet, and a little bit of knowledge. And those substations can take two to four years to to build up, put into place, and they're very expensive. So, I mean, this again, this this kind of stuff happens a lot. It's just you don't typically hear about it. Yeah, exactly. Whoa.
Robby PeraltaWhat is a typical like assignment for you these days then when it comes to uh a company in in our neck of the woods?
Brian HarrisPhysical auditing, which I I encourage all businesses to start off with auditing before pen testing. Uh pen testing is more of like let me say it this way a physical pen test is usually we have a robust security apparatus and we actually want to test it. We're doing our due diligence, right? That's the correct approach. Another one is the CISO wants a budget, right? Like the CISO needs a bigger budget to justify something and he wants to scare the hell out of the boardroom. Most companies have never even run a physical pen test. What I usually say is, you know, you will never find a self-respecting large organization today that would say, I don't know what a cyber-based pen test is, we've never done one, and I don't see the value of it because we have antivirus and firewalls. It's like nobody, nobody would say it. But but a lot of people say we don't know what a physical pen test is, we've never done one, and we don't see the value because we have alarms and cameras. And it's like, it's the same thing, it's the same principle, right? Um So I do a lot of auditing, which is you go in and you try to verify all the stupid stuff that they should be improving. You you basically help to point out everything they're doing wrong, and then help them to bring up their security to a certain competency level. Um and then about a third is is physical engagements, where I'm actually trying to go in and covertly break into buildings. And then I do a lot of training where I'll train people how to do this, I'll train people how to do you know everything from elicitation, counter-elicitation, covert entry, you know, whatever. Um so I'd say that those are mostly what I've been doing on any given day.
Robby PeraltaFun. Very fun. You said um, you know, the auditing aspect, what most people are doing wrong, just the top three.
Brian HarrisI would say the things that people mostly do wrong is that they don't understand what a threat is. So in Europe, uh, I just happen to have this on my desk, it's a little Euro cylinder lock. You see them all over Europe. What most people don't realize is is that these are these are a huge vulnerability. You walk up to the door, you see what type of brand it is, what type of keyway it is, you purchase the same thing, you so that the client's
Physical Security Misconceptions and Vulnerabilities
Brian Harriskey will fit, but it won't unlock it, right? And then you repin yours in such a way that every key that fits inside that keyway will unlock it. And you that's not hard to do. It takes you 10 minutes if you know what you're doing. You come up to the client's door, you break their lock from the outside. There's now no lock keeping the door closed, you open the door, you put your lock inside, you leave. As a result, the client's gonna come back and their key's still gonna work. But your key's gonna work. Unless you're really observant, you're not gonna notice the difference, right? And so one of the biggest flaws is that people don't understand that it's these there are vulnerabilities out there that you don't that you don't know are vulnerabilities. A lot of them is just uh locks, doors, latches, all that kind of stuff. Another one is cameras. So camera systems, you you look at it, you say, like, well, I have a camera, right? It's it's protecting me. But a lot of cameras, not all of them, but a lot of them, the way that it works is that it's not an it's not some poor soul sitting in front of a wall of monitors making sure that you know nobody's actively screwing with something. What it usually is, is that those are being hired off by a third-party security company, and in the event of an attack, a break in a theft, something, that they retroactively go back and they see who did it. And the entire business model is, well, an alarm is going to go off or somebody's gonna notice something was stolen or or whatever, and they're going to alert us immediately. But what you don't know is if I were if I were to ask you to take out your smartphone and start recording a video, how you know do you think that you would still be recording a video this time tomorrow? It's like, no, of course not. Like your phone would run out of storage space almost immediately, right? Like 1080p, 4K, you know, whatever. It's really bloated file size. As a result, your phone can't hold that much data. But then when you think about a third-party security company, in Denmark, G4S is a huge one. But uh but imagine how many video feeds they're getting at any given moment. It's huge. It's astronomical. And then when you think of how much data storage they need to hold all those surveillance cameras or that video feed, you start realizing if you look at the fine print of a lot of these companies, they're only gonna keep your footage for two, maybe five days, and then they're gonna wipe over it. So if something has happened, and you can co and this is one of the benefits of covert entry, if you can covertly get into a building and do something and you're not caught, you plant a device, you steal something, whatever, and it's not discovered for say two weeks, there's probably not gonna be any video evidence you were ever there. And as a result, it becomes incredibly difficult, if not impossible, to figure out who did it. So there's a like I said, there's a lot of misconceptions when it comes to security. And I'd say that these are kind of the big ones. Access control systems, of course, are a huge one. You know, that's always gonna be the case where, you know, callable badges, uh vulnerable readers, that sort of thing. Um but I would say that the big one is just most people do not know what they don't know. And when it comes to physical security, you we really do have this misconception of like cameras, alarms, fences, doors, locks, they they make us secure and nobody can get in. It's like, but that's not that's not reality, that's not how it works. So I would say that that honestly is the answer to that question.
Robby PeraltaWell, that's perfect. And now I want to make the rest of the episode about the things we don't know, right? And Yeah, sure. What's better, digital or a physical lock?
Brian HarrisSo it it it really depends. What most people think of with digital locks is they think, well, the background software is going to be secure, right? Which it may be. Maybe let's suppose for a minute that whatever you're running on the back on the digital side of things perfectly secure. Great. Okay, so you can't hack the Bluetooth or or whatever you know communications method you're using. But if the door itself is vulnerable, if you can do something like this, so latch slipping is a colonoil, right? So this is where the old school Hollywood credit card trick, where you slide a credit card into the door and you pop it open. In Europe, you don't have quite that same vulnerability because in Europe you have this um zigzag pattern in the door frame. And you did that for insulation purposes. It's not because people, you know, 100 years ago were like, man, this will this will prevent this attack. You did it for insulation purposes, but as a result, you can still go to companies like Multipick, which is a German company, that make basically makes like a little corkscrew device. And you can put it on the outside and you can twist a corkscrew and it'll screw through that little bend and get to that lash, and you can push the latch and open the door. So when you talk about that, when you ask that question, really, it's not just about the lock. It's really about everything. It's about the door, can you bypass it? So have you ever seen what's like called an underdoor tool? Yeah, I have seen that, yeah. Okay, yeah, great. So this is from the it's basically just a long uh uh piece of metal with a wire. Robot arm thing, yeah. Yeah, yeah, yeah. You slide it underneath the door, you grab the handle from the opposite side, you pull it, yeah. It's a cute trick. Cool, it's cool, it's cool. Yeah, yeah. But well, see the downside to digital doors is that a lot of times they are one-way secure. Meaning that in one direction we need a card, a badge, a phone, whatever, but in the other way you need nothing. Well, any door that has that setup is probably going to be vulnerable to an under-door attack. Because if I can just pull the handle from the other side, you know, open the door, right? So and you can get some serious sophisticated, you know, underdoor attacks where you can go through letter boxes, you know, if they if you've got one on the front door, you can go through all kinds of stuff. Uh, I've seen ones with like cameras on the end to go through and make sure you're grabbing what you're, you know. So there's some really sophisticated stuff out there. And it's not just about the lock. But with the lock, if you if you're talking about preventing something like drilling and snapping, then just buy an anti-drill, anti-snap lock. But then again, you have to ask the question like, what is your big threat? If your big threat is in a downtown major city, well, you're not maybe not concerned about somebody trying to covertly get in or maybe snapping a lock. Maybe you're worried about like break through the window, right? In which case you need, you know, shadow-proof windows and maybe bars and maybe a steel door. So it really just depends on what is your threat level. What are you, what are you actually trying to prevent against? The funny thing about those locks, by the way, is if you look at a Eurocylinder lock that is anti-drill, anti-snap, that will prevent it from being able to drill into the lock or snapped from the outside, it'll tell you right on the front. It'll literally, it'll have like, you know, Yale, you know, three-star, some weird symbol thing. And you just go look up that thing, right? You take a picture of it and you go look it up. And like you find it on Amazon, you find it wherever, you're like, oh, this is from the manufacturer. This says that I cannot drill this lock and I cannot snap this lock. So I'll just go around to your back door and see if you have that on every door. Right? Like that, I mean that's that's kind of the trick, right? You're it'll tell you right on the box, like if it's going to prevent you from doing this attack. So there's no such thing as a locked door for you. Of course there is. Of course there are locked doors. There are there are locks that I would never try to pick. There are locks that I would never even approach, but it's not just about the lock. So, for example, you can do things like impression a key, right? So if you've got a key that's you know ridiculous that you you could never like if the if you could never pick the lock, maybe you could impression the key. Maybe you could impression the lock. Maybe you can slit the latch. Maybe you can pop the hinges off the door. Maybe you can go under the door and grab a handle from the other side. Maybe you can social engineer your way into the building. Like there, there's always a way in. It's just a question of what do you have to do and how far do you have to go into it? Um and that's really at the end of the day, when you're doing a physical pen test, that's really what you're trying to do. You're trying to figure out if you were an attacker, what could you do? You know, what are the real methods for getting inside? And this is one of the reasons why this is the trade-off between auditing and covert entry. With covert entry or pen testing or black team or red team, whatever you call it, you usually have a very limited time, maybe a week, two, three weeks, very, very limited. And you're trying your best to not get caught. So you're the the types of attacks you're gonna run are very limited. You're not gonna try the really dumb stuff until the last, maybe the last things, right? So you don't get to try everything. You don't get to test everything. It's really kind of uh like when you're doing an internal network test, all you're doing is looking for domain admin, right? It's at the end of the day, that's really all you're doing. How many paths can I get to domain admin? Um, but with an audit, you're not doing any of that. You're just trying to find all the stuff that you could have taken advantage of. Maybe, you know, okay, employees are wearing their badges outside, this lock can be snapped, that door is vulnerable for the underdoor attack, this rec sensor is vulnerable. So it's it's tricky. It's really tricky to increase the security of something because it all comes back down to what are your threats? And that's one of the things that a lot of clients don't know. Or maybe they do know them, but they're they're unaware of it. A lot of them, I've been hired by a lot of major companies to play the insider threat. They basically say, okay, well, what if you, you know, we suppose that we are a company that has 500 employees in the office or in this area, and you have access to the building, what could you do? And it's like, well, if you give me a badge to the building and you have basically a flat physical security posture where every person, Bob from Bob the intern to the CEO, has access to everything. Well, you're screwed. Because if Bob the intern can go to the server room, the mainframe, you know, he can get to everything. Well, you have no real security at that point. And you know, this gets back to um for for legal reasons, I won't mention them in a podcast, but uh there's uh there's a certain organization that launched a very, very successful engagement on the U.S. government and was able to pilfer enough information from certain agencies to get what's referred to as tax exempt status. Um, this basically means that if you're a recognized religion in the United States, you don't pay taxes on anything, which is a very coveted thing to have, right? You know, that'd be great. Uh so basically what this organization did was they got members of their group to go get legitimate jobs at the FBI, the NSA, the CIA, the IRS, like all these organizations. And they started pilfering information back. And the secretary of, I believe, the FBI or maybe IRS who was investigating this group, that person's secretary was a member, was a plant. So every single time they would have a meeting concerning this, the office would be bugged. And it's one of those things that it's like, yes, if you are tenacious enough, patient enough, you're gonna get in, right? You just will. And so it really comes down to what is if you know the insider threats are a massive concern, security concern. And a lot of bigger players start to recognize it and they're like, all right, how do we prevent this? How do we fix it? If Ot the intern goes rogue or he gets bribed or he gets really disgruntled or whatever, how do we stop him from completely messing with us? And I I get hired to answer those questions and solve those kinds of things a lot. And it it's yeah, it's a very, very common thing.
Sophisticated Insider Threat Tactics
Robby PeraltaSpeaking of insiders, right? Uh scattered spot in the states where they're like, you know, calling employees and say, I'll give you $500 for access to this. Uh, do you actually do that? Do you actually like call people and say, hey man, I know you work here, I'll give you $5,000 to do this?
Brian HarrisThe way that this goes are two methods. One, you have somebody who works at the company or gets a job at the company, and they build rapport with somebody over time. And then you ask, oh, by the way, you know, I'm actually not a real employee here. I'm actually somebody who works for this other government or this other organization. We're gonna ransomware your company for $10 million. Now we've done this all over the world. We've never had a failure. We wipe the servers as soon as the device is planted, so there's no possibility that you can get screwed. Uh like Stuxnet, it's gonna sit there for 14 days and do nothing. So the camera networks are all deleted by the time this thing triggers. We're gonna ransomware for 10 million. We'll give you two. If you walk this into the server or whatever, tomorrow at midnight and plant this device in, then we'll give you two million dollars. And the question is is that one, you just created a pawn if he said he agrees to it, but how many of your employees would say no to two million dollars if you really have a lot of trust and a lot of rapport with somebody and then you tell them to go do this, right? It's hard. It's it's a really tricky thing. Now, the other way that this happens today is you use a lot of AI. You clone a person's voice, you clone a person's face. In Hong Kong, some poor soul just, you know, transferred five million dollars to the wrong place because he thought that the I think it was the accounting manager. Yeah. Yeah, yeah, yeah.
Speaker 1Yeah.
Brian HarrisAnd some of the some of the clever tricks that I've seen done with this are if I'm the attacker, what I do is I spin up a fake LinkedIn account and looks like I am like the head recruiter at Google or Apple or Microsoft or whatever. Right. And I I really polish this out to really look legitimate. And then I reach out to somebody who has access, somebody that I would want, you know, maybe a board member, maybe, you know, like a low-level board member. And I contact them and I say, you know, we've been watching you for a while. We have an open position at this really high, you know, position in Google or Microsoft or Apple. It's five times the salary that you're currently making. It's fully remote. It's all these bells and whistles that you want. Would you be interested in having a call with us? And it's like, well, yeah. So most people are going to be like, yeah, I'll have a call with you. Of course I'm going to have a call with you over this job, right? And then what you're really doing is you're actually cloning, you know, their face, their voice, you're, you're using the entire meeting. So if you look at AI facial models, a lot of times, if I do something like this, it's okay. But if I do something like this, you can start to see breaks in the face, in the modeling. And so a lot of times what you're doing is you're looking for extreme angles, you're trying to get lots of voice data to make a really convincing facial mesh. And then you can take that later and then go back and do what happened to the guy on call. Right. So it's I mean, so these are these are much more sophisticated ways of that are that we're seeing a lot more uh common of how do you steal people's data, how do you get them to do things they shouldn't, whether they know they're doing it or not. And that's the other aspect about insider threats. Maybe they're not actually a bad guy. Maybe they've tripped, right? Possible.
Robby PeraltaWe never hear that much about these insider threats, though, at least in my neck of the woods. I'm not sure it's maybe a little more in Denmark. I don't know.
Brian HarrisWell, it's you don't hear about it often because the company has no real reason to publish it.
Robby PeraltaYeah, of course not. It's not gonna help their stock price.
Brian HarrisYeah, exactly. Like the, I mean, they they will publish it if they've had a breach of data or if if it becomes public. But they're under no obligation to say, like, oh yeah, by the way, Bob, when we fired him last week, we caught him trying to put a bash bunny into the server, right? Like it's you know, nobody they're not gonna say bath. They're gonna tell you that this happened, unless they have to.
Robby PeraltaIt sounds like you don't necessarily need the coolest toys for a lot of the stuff that uh to get in. You don't need to bring out your best tool kit that often, I guess.
Brian HarrisIt depends on what the engagement is and depends on what your goals are. If you're working in like an OT environment, maybe the entire purpose is just to get to a specific spot, right? If you're dealing with industrial control centers, if you're dealing with uh power plants and other things, maybe you're literally just supposed to get to a place and take a picture of yourself there and then leave. Because you you like on a live production facility, you literally don't have access to touch any. If if the goal is to plant a listening device or uh a man-in-the-middle device or whatever, I think you're gonna bring that with you. It it really, really depends. You're gonna need now the funny thing is that when you think about it, you're gonna need your breaching tools. You're gonna need whether you're doing destructive entry or a covert entry or you know, RFID cloning or social engineering, whatever it is that you're doing, you're gonna have to bring all of that, maybe disguises, maybe anything. You have to breed all and you have to do it in such a way that it's not obvious. You can't bring like a hiking backpack full of gear, right? You gotta try and be that James Bond where all the gadgets are tiny and whatever, but they're usually not. Um this is where your team comes in, right? You don't want to this is one of the many reasons why you don't want to go alone. Because if you go alone, you have to bring everything, right? Well, because once you get inside, well, maybe I'm gonna need this, maybe I'm gonna need that. What happens if you get to the third floor and you realize you need a tool that you don't have? Right? So you like it can be really, really tricky. But what's that Robert Renford quote from the movie Spy Game where he says, you know, oftentimes all you need is a stick of gum, a pocket knife, and a smile? It's like, yeah, if you're if you're if you're a good social engineer, sure, absolutely.
Robby PeraltaBack to the cool tool things. Uh what are about around like card readers and yeah, how often do you have to use like uh radio devices that like do sync like frequency stuff.
Brian HarrisYeah, of course. So you you you have tons and tons of stuff. You have long-range Wi-Fi, you know, things that can get you out of Wi-Fi netcro from like a mile away. You have um I there's a there's a guy, a gentleman in the US names Travis Weather, he's got a company that's that's fantastic. Imagine a uh card reader uh that's spake, and you put it on a door that doesn't need a reader, and then you see if people will badge into it, and then you can just walk off, take the reader itself, and you know you've got the weekend data or wherever. Uh so those are fun. Um you could also use what's called the ESP keys. They're they're like the size of a postage stamp, and you can pull the card reader off and put one of these on the back end of the reader and steal the weekend data. Um, that that's also really cute. Uh, you can use signal analysis tools, you can use various Wi-Fi tools. But but the thing is, is like there's in a lot of these ways, you know, you often want to make your life easier. So, do you know what a bore scope is? No. A bore scope is what a plumber will use. It's it's basically a camera on a wire, right? And you've got this, you imagine you have a little device, it's about the size of a wallet, and it's got a camera, it's got a uh a screen on it that'll show you uh whatever the camera is looking at. The camera's this really long, maybe like two or three meter long wire. Well, if you plug into um if you go when you go home tonight and you get onto your access points, you know, your Wi-Fi, your phone, your laptop, whatever, at one point you had to type in a password, right? Well, most of the time, unless you're specifically set it up this way, if you plug in an Ethernet port directly to that Wi-Fi or to that uh access point, you don't have to authenticate in any way. You just plug your laptop with the Ethernet core directly into the access point, you're just on the network, right? So, yes, you could bring, you could bring a one-mile Wi-Fi extender and you could find a hide site, and you could try to break into, you know, crack the WPA2, you know, all that kind of crap. Or if you could just find an access point that's in a vulnerable spot and plug a device into it, you're just on the network and you have to do any of that. Um, similarly, with the board scope, which is really funny, is when you get a router for the first time, oftentimes it'll have like a little thing on there, a sticker that'll say, like, this is the access point, this is the admin password, this is this, this is that. Many, many times people don't take those off. And if you if the if the router is like really high up and you've got a little board scope, you can just run it up there while it's recording, see that sticker, and just walk off. So, I mean, yes, you can you can do a lot of you know, fun gadgets and all kinds of stuff. You can use flippers and i copies and proxmarks and wall range readers and all this kind of stuff, and that's great. Um, but in a lot of cases, you know, you're not you're definitely not going to need all of them. But it's really important to know how they work.
Robby PeraltaAnd these devices, I actually went on spy shop.no just to see like what kind of devices were there. All those devices are like super cheap, and anybody can go in there and buy it. That's just legal. People could do it.
Brian HarrisYeah, so it's always important to know what the laws are locally. Like some places you can't have Locktic, some places Canada for a while try to ban flippers or other RFID cloning devices. Like it's really important to know that.
Physical Security Vulnerabilities and Solutions
Brian HarrisUh, you asked about drones earlier. It's really important to know where you can use drones. Often, like, I can't go to downtown Copenhagen and just have a drone fly around an office building. Like, there's laws, right? I can't just jump on like a uh a radio and just use any frequency that I want. There's restrictions. So knowing the local loss is very, very important.
Robby PeraltaAll I know is that uh you always have the when you're get out of jail free cards, should be somebody on your own team first, at least.
Brian HarrisYeah, so it's yeah, there's there's definitely you want to downgrade the getting caught. You don't always just be like, okay, jigs up, I'm caught, right? Yeah. Um, and it's a fun job. It's a fun, fun thing. And sadly, it's wildly overlooked. Um Usually what I tell clients is this I say, look, you spend millions of dollars making sure that your cyber threat landscape is, while it's very, very broad, right? You've got websites, mobile apps, bank accounts, um, email servers, like all this broad cyber stuff, you spent millions of dollars making sure that the probability that you're gonna be catastrophically screwed is almost zero, right? Like that's what you do. You spend people's salary, you have socks, internal pen testers, you have all these people constantly trying to make sure that nothing bad's gonna happen to you. But it's like, but then when you say, but your physical security landscape is really narrow, maybe it's only one building. But if somebody who knows what they're doing attempts it, they're almost guaranteed to get in and catastrophically screw you, right? Yep. And again, it's funny because then you you tell that to like the board of directors or a C suite or something else, and they don't really have a response. They basically just say, well, yeah, but it's not likely to happen. It's like, well, then either is a rant somewhere, but you still spend millions of dollars making sure that doesn't happen. You've got backup plans and you test for it and with all these things. But when it comes to physical security, you're just like, well, yeah, fences and fences and camera, so we're good. That's it.
Robby PeraltaIt's kind of funny. Like over the past like 40 years, it went for all any money on security was like physical security, real security, or yeah, physical, I guess. And then now it's all digital and nobody cares about the physical anymore. But there's not very many of you.
Brian HarrisThe reason, in my opinion, why there's not many is because core companies and organizations have yet to see the ballot in book. Fortunately, for anybody in Europe, you have these several security standards that are coming up and going to be enacted in October. And uh there's a lot of organizations who basically are going to be mandated to start doing it. They don't have a chance. So you've got NIST2, CER, and Dora. And there are physical components to each one, but CER especially is basically just anybody in critical infrastructure or weirdly critical infrastructure adjacent, which nobody knows what that means. Um, and there's it there's a massive amount of companies, organizations, and things that all have to now comply. And so how do you handle that? And it's like like bang, that's one of the reasons why I've been ridiculously overworked lace.
Robby PeraltaUm well, thank you for taking time for this podcast. Absolutely. No, no, we can we can go as long as you want. Okay, cool. So I'm thinking of like anti-uh now I'm just being like full paranoid, right? You go into a hotel room. I'm going to a country next week that I'm kind of like, oh shit, I need to turn off my phone and my computer when I go through the airport, sort of place, right? And I'm just thinking, like, yeah, it would be cool. It'd be nice if I walked in that hotel room and had something like, am I good in this hotel room? Do you do that? Do you actually have tools that have those capabilities?
Brian HarrisSo the things in hotels that you would I would be most concerned about are going to be breaking into a hotel when I'm not there, cameras inside the hotel, and then just generally being on the Wi-Fi. Right? These would be the types of things that I'd be concerned about. One, if I'm in a hotel, I'm probably not, especially if I'm in a country or a place where I'm questioning things, I'm just going to be using data. Right. I'm not going to be using the hotel. I'm not gonna, I'm not gonna be using your Wi-Fi at all. Because treat it like a cafe, right? You would never want to go to a cafe and start blogging into your bank account and you know, doing all that kind of stuff. So one, and you've you basically eliminated that entire possibility. Um, now that doesn't account for like Bluetooth attacking and other things, but you know, I bet you can only do so much. Um the the cameras, the cameras are fairly easy to look through. Uh there are devices out there that'll detect uh cameras and such, but it's also fairly obvious. Once you kind of know what the types of cameras are that exist, you're probably not dealing with state entity level, you know, unless you're unless you're really important or really rich, you're not going to be dealing with, you know, the state of Russia is trying to get information on you, or the NSA is trying to get information on you, or whoever. If that's the case, you're screwed, right? They have ways of finding everything about you. Um but for the most part, most attackers are buying stuff off the shelf. They're buying things in Alibaba, on Amazon, on wherever. And as a result, you'll know what they look like. You'll know how to detect them. They'll be in, you know, very obvious places. Um, and then the last one is you know, your hotel room getting breached while you're not there. That's that's a big one, right? So, like if you go into a hotel room and you leave your passport, your wallet, your laptop, or whatever, one of the easiest ways to secure the hotel room that people don't think about is you can buy little cameras that are tiny that will just ping you through an SMS if any if any motion is detected. And you can even set them up to like basically blare out an alarm. So think about it. Like, imagine like somebody you know uses an underdoor tool or something, they pop into a hotel room and they take one step in and alarm starts going off. Chances are they're gonna run. Yeah. Right. Yeah. Um, because it's a hotel room, you're not, you're not likely to deal with like breached entry where somebody's got a sledgehammer or a mule kit to the door or something. You're probably using an underdoor tool or maybe a cloned or you know, badge or something like this, or trying to get up through the window if that's open. Um, but yeah, and and I mean, yeah, then you would know who did it. You've got the alarm set up. It doesn't take up much space, it's easy. Uh, if you're in the hotel room, that's a whole different topic, right? You can just um you can either tie off the door handle so another door attack wouldn't work, or you can you can set that up in a lot of different ways.
Robby PeraltaThe classic chair underneath the handle. I do that all the time.
Brian HarrisYeah, yeah. Any anything to anything to prevent the the mechanism from from running uh or from working. Um and another another instance is cleaning staff. Unfortunately, cleaning staffs can and will sometimes steal stuff. You know, they have access to everybody's room. So make sure when you're not there, always to put that little hanging thing that says, you know, do not disturb. I don't want you coming into my room. So yeah.
Robby PeraltaCool. Well, now I know I know I have at least one thing to buy. Um what do you see yourself doing that over the next two years? Like where where are we going from like a physical pen test direction?
Brian HarrisWell, I see, I mean, the physical security
Supply Chain Vulnerabilities and Employee Security
Brian Harrislandscape is likely to explode. By the way, for companies, I highly recommend this. If you are a major company, you don't want to hire somebody like me to come and just do a pen test on every one of your facilities, right? That's ridiculous. What you want to do is you want to hire me to come in and train your internal security staff to go do that because that's far more cost-effective for you. Um, you saw things, let me say it this way. You saw things like uh with the um NordSortuo bombing. You know, you you see, now that's an extreme case because that's almost guaranteed to be a state entity, but there are methods that you can disrupt entire supply chains for next to nothing. Going back to the Fort Bragg, North Carolina example, if you know what you're doing, you can take down a substation asymmetrically very easily. And it becomes very, very difficult to protect. If you look, if you Google Substation, right? So anybody of your listeners, Google Substation, and one of the so most of the things that's going to come up is you're going to see a whole bunch of transformers in the middle of nowhere guarded by a chain link fence. Yeah. And that and that is your security, right? Like you have a power plant which has all of this security, all of this, you know, resources. That power plant is pumping energy to a substation, a series of transformers, whatever, and they are then pumping that energy to a city or wherever. But at the substation, you have no security. It's a chain-link fence. And that's a massive security vulnerability. And I will say it this way: every aspect of your supply chain, whether it's food, power, water, anything, has those bottlenecks. They all have those types of choke points. And we are not doing enough to secure them. We're just not. And it it's it's gonna be one of those things that if sort of certain things are probably going to happen, and then you're going to retroactively say, okay, now we're going to start taking things seriously. But yeah, I don't know.
Robby PeraltaI mean, last question here. Since there's only five people in Norway doing this, like I guess is the the most the best approach, the most likely to succeed approach to help your digital security team to learn or teach them these things, or who who do you grab in your company?
Brian HarrisSo this is why I differentiate between black and red team. A red team, so you you can have red teams that are 100% cyber, right? We're gonna run a red team. Okay, yeah, fine. And we're gonna we're gonna attack you through the cyber, through the email server, through phishing, social engineering, phone, websites, the internal network, the Wi-Fi, all that, right? But it's all cyber. But then maybe, maybe, in the tender or in the project, it says, oh, and you can do 5%, 10% of a physical engagement. Well, we only have Bob, the web app guy, who's even interested in this, but he's seen a few YouTube videos, so and he's got a pick set of lock picks at a flipper. So send him to go break into the bank, right? And it's like they're not transferable skills in the same way that if I'm a pen tester, I don't know how to do incident response, right? They're not, they're not it's it's not a one-for-one thing. So what I recommend is first find people who are even interested in it. That might be your cyber people, usually is, but it could be anybody. I've had project managers and companies who are like, that's what I want to do, right? Like it's like, I want to break into buildings, I want to do this kind of stuff. It it's anybody who has an interest in it. Anybody can learn these skills, anybody can get good at it. So, you know, grab whoever it is you have. And the most important thing is have a team. Have a team of people who know what they're doing. Do not just have one guy who knows what they're doing, and he's just gonna take a whole bunch of people who are interested in it on a live engagement because somebody's gonna mess it up. And what the here's here's here's the really here's the reason why I say do an audit first to most companies. The vast majority of physical pen tests today, not all of them, but a lot of them, what happens is this you will sell a red team engagement. Um they will there will be a small physical component to it. And you will usually take somebody on your cyber team to go do that physical component, they'll do their best. Usually that is we try to tailgate into the building and maybe we use an underdoor tool or we try to pick a lock, and that's it. That's all we do. If it was successful, great. If it wasn't, fine. But either way, that's the only thing in the report. And as any c any consultant will tell you, if it's not in the report, the client assumes it's not an issue. So the client gets a report and they say, Well, we try to tailgate in and it didn't work. Okay, great. Then we don't need to do anything else, right? That's so we're we're totally secure on the physical side of things. And that's clearly not correct. So it's no more correct than if I took a cross-site scripting uh payload and I threw it at your login portal, and that was the only thing I did to test your website. Like I that would be ridiculous. But that's kind of what you're doing here. So you really want to test as much as you possibly can in the time that you have allotted. And usually that's where I say start with an audit, do that first, because the audit also gets your team practice. They get to practice what they're doing, they get to practice all the things. And hopefully by the time they've done a few audits, they can walk through a building go, they can literally just say, that's vulnerable, that's a dead zone, you know, and they can just start pointing out all the stupid stuff that they would they would have taken advantage of. And they can really increase their security. Then you can come back a few months later and say, okay, let's see if what you're doing now is actually working, right? You now your security is at a high level. Yeah. But before we go, I I will say this. Um I've been saying this for 10 years, I'm gonna keep saying it, but I will ask you this question. What do you think is the best, most cost-effective thing that a company could do to increase their security? I want to say two-factor, but I guess that's not the answer. Okay, it is employee interaction and awareness. And it's not the way you think of it, right? Um, so here's the two things that you have to do for this. One, every employee in writing give them uh a promise from the company that under no circumstance will they ever get in trouble if they stop somebody in a professional way and say, I don't know you, or you're not wearing a badge, or you seem suspicious to me, we have to go to security. Under no circumstance will they ever get in trouble for that. Because that's one thing. People are legitimately concerned, like it's not my job, I might get in trouble, I don't know who that person is, whatever. Second, you have to incentivize though. If I was in the pneumonic office and we were doing this live, and I said, Okay, by the way, I have hidden a piece of garbage somewhere in this building with my signature on it. And if you bring that back to me, you're gonna leave here with $500,000. You would stop this interview right now and go look for that, and the entire place would be cleaned. Like it would be spotless, right? Because you incentivize, you incentivize people with what they really want. Now, companies cannot afford to just give out, you know, hundreds of thousands of dollars to people, right? They just can't. So you have to give them something they can't, that the companies can afford and that they want, and it's usually time. So what do you do is you say, okay, so once a quarter or once a month, have somebody who's not supposed to, who's not an employee or not supposed to be here, walk through the building. And if you're the employee who stops them and professionally says, Hey, I don't know you, you get a week of paid vacation. Now, the reason why that's so effective is because it turns all your employees, because it first off, it turns it into a game. Second, it incentivize them with something they want. Paid vacation. Everybody wants that, right? And it it also means that every single employee is constantly looking. They think of it as a game, they're looking everywhere, saying, like, you know, who is this person? Maybe that's the guy. I can go stop them. And I know for a fact, having broken back into buildings after companies have implemented the strategy, if you break in during the day,
Physical Security Threats and Solutions
Brian Harrisevery 10 or 15 feet, somebody stops you with, like, I don't know who you are, you've got to come with me. Ha. Like it really makes your job a living half to try and break in during the daylight hours. And so it's it it really it costs the company next to nothing, right? You don't have to give them a full week of paid vacation. That's up to you. But I mean, it turns it into a game, it costs you next to nothing, and it also improves employee morale a lot. Yeah. Because now the employees are having fun with it. They think they can get a reward, which they can. Um, but yeah, I tell you, yeah, I tell employees to do that all the time. And you can extend that to like devices, you know. So if you're running a physical engagement, well, what are you doing? You're usually bugging the building, right? Like I'm gonna break into the corporate boardroom and I'm gonna put like an HDMI man in the middle behind the big TV, you know, to and you know, got a listening device in there and HDMI device. So stealing basically the presentation, right? Because, you know, that that's a huge threat. Uh things that are said in boardrooms and such are usually very sensitive information. So you can also extend that to like, hey, I'm also gonna plant little devices here and there around the building periodically. And if you find one, bring it to me, you know, hey, a couple days pay vacation. Because it also, you know, it's it's little things like that that cost you next to nothing that drastically increase your security. So I just hope that companies adopt that and start doing it.
Robby PeraltaWhen it comes to board room stuff, uh, I mean, it wouldn't be a completely stupid idea. Like, do you ever have you ever given advice to clients that, like, by the way, next board meeting, before you start the board meeting, have somebody go around with a little thing just to is that like uh ever a piece of advice you've given? Do you think that's over?
Brian HarrisSo yes, it yes, it is. So when you when you are assessing at the very first stage of your physical engagement, when you were talking to the client and you're trying to familiarize yourself with who they are and what their threats are, when it comes to like the board alone or sensitive information, maybe that's the the boardroom, maybe that's a client meeting room, maybe that's a research department, whatever. You can do things through physical uh access that you just can't through uh digital. So I'll give you an example, right? In the Western world, there's something called PCI compliance. Um, this is payment card industry compliance. Basically, it just says that, you know, organizations like banks, for instance, you have to have a network segmentation so that you can't go directly from the internet to the mainframe where all the PCI data is. Right. And that's just an example. There's more to it than that, but that's that's a component to it. So usually what that aspect of it is is that the the banks or somebody will hire a third-party consultant company, they'll come in, they'll say, Congratulations, you've changed nothing about your network topology from last year. I can't go from the internet to the mainframe, and therefore you pass your PCI compliance or at least the section of it good for you, Gold Star. But it's like, but somebody at that company or that bank has to be talking to the mainframe. Of course they do. Like there, there has to be some communication. So if I break into your bank and I figure out who's doing that, usually through something like a Citrix environment, and I bug their workstation, well, then I can get all the mainframe. And it's usually not very hard to figure that out. So when you go through that process, it's like, okay, so you passed PCI compliance as long as they only attack you through the internet, but you failed it if I include a physical component to the test. And that's an aspect that people don't seem to understand. So, like boardroom, uh boardroom hacking, right? So if I were to break into your boardroom and I were to put an HDMI man in the middle behind the big TV that every boardroom in the world has, and it has, I'm I'm recording audio and HDMI, I'm stealing every presentation you have. Well, okay, how hard would that be through the internet to break into that TV and steal that exact thing? It might literally be impossible. Or it may be something that you need to, you know, work for years to develop various zero-day exploits to get to that point. But with through physical access, it's trivial. I can go buy, you know, a hack five HDMI man of the middle and a small little audio uh uh recording device that'll send over on the cell line or something. And it's like, yeah, I can absolutely do that. So when you, if that's the threat level, yes, tell the boardroom, like, look, here's if I, if it were eight, here's where I would be planting devices. So here if it were me, this is where I would just check, right? You don't need a sweeping team to go through and and check, you know, every last outlet and every lamp and everything everything. But here are the places that I would check, right? And it's it it doesn't take much time. And yeah, I mean, it's it basically when you do, and this goes to any anybody who's running physical pen testing, when you do that, make sure in the report you tell them things like, this is like if I was doing this, this is where I would plant devices, this is where I would do this. So this is these are the things that you should check. These are the things that you should look for. Because keep in mind, loss of reputation can be just as damning to a company as loss of intellectual property. It just depends on what their business model is. Or where yeah, yeah, if I bug a room that's not the board room, but it's like a client meeting me, where clients are having confidential meetings with that company and they're divulging really sensitive information, and I start putting that on the internet, like that reputation is permanently damaged. And you you may completely lose business with them. That company may sue you, you know, for you know, for for leaking that information. And it's like, yeah, it's there are a lot of potential threats through physical access that people are not aware of or don't think about when it comes to the internet, because you wouldn't think about that through the internet, right? If you're asking, like, okay, what's a network? If I'm running an internal network pen test, you don't think about bugging the you know, the audio or the HDMI of a boardroom or a client meeting room or other things. That's just not something you would ever think of. But it is something that you should think of through physical, and there's lots of things like that.
Robby PeraltaDo you have a blog post or anything that you go through some of these like initial uh Yeah.
Brian HarrisUm if you go to my website, there's a at the very top, there's a thing that says blog and it'll take you to my sub stack and you can delete all kinds of stuff. Yeah. Um yeah.
Robby PeraltaWell, listeners, you will find that in the show notes. Mr. Harris, we went way over time. I appreciate every minute and every second I got out of you.
Brian HarrisThank you. It was great to be here.
Robby PeraltaThank you for your time, uh, Mr. Harris. We'll talk to you soon. Thank you. Ciao. Well, that's all for today, folks. Thank you for tuning in to the Mnemonic Security Podcast. If you have any concepts or ideas that you'd like us to discuss on future episodes, please feel free to hit me up on LinkedIn or to send us a mail to podcast @mnemonic.no. Thank you for listening, and we'll see you next time.