Daniel Raines, a luminary in the realm of electronic security, shares his extensive journey through the intricate landscape of physical security and digital access. With three decades of experience, he has transitioned from hands-on installation of access control systems to software development, addressing vulnerabilities and enhancing security measures. Our discourse delves into the convergence of physical and digital security, exploring the nuances of vulnerability disclosure and the industry’s response to emerging threats. Raines elucidates the complexities of hard-coded encryption keys and the imperative for robust security practices, particularly as the industry shifts towards mobile credentials and biometric solutions. This episode serves as a profound exploration of security’s evolving nature, emphasizing the significance of adapting to technological advancements and fostering a culture of continuous learning and improvement.
Daniel Raines’ extensive career within the electronic security industry, spanning over three decades, serves as a testament to the evolving landscape of physical security and digital access. Initially immersed in the practical aspects of the field, Raines dedicated the first fifteen years to the installation of physical access control systems, including surveillance cameras and biometric solutions. However, he subsequently transitioned into software development, focusing on creating robust systems for access control and security research. This shift was catalyzed by his encounters with software vulnerabilities, which sparked a deep dive into ethical hacking and vulnerability disclosure. Raines’ narrative illustrates not only his personal journey but also the critical intersection of physical and digital security, emphasizing the need for improved practices in vulnerability reporting and response within the industry.
The discussion between Raines and the host, Joe Carson, delves into the intricacies of vulnerability disclosure in the realm of access control systems. Raines categorizes companies’ responses to vulnerability reports into three distinct groups: those that are receptive and proactive, those that provide minimal feedback, and those that are entirely unresponsive. This classification underscores the varying maturity levels within the industry regarding security practices. Furthermore, Raines highlights the pressing issue of hard-coded credentials and encryption keys, which present significant security risks if not adequately addressed. The conversation also touches on the ongoing evolution towards mobile credentials and biometric systems, reflecting a broader trend towards enhancing security while minimizing user friction. Raines’ insights serve as a clarion call for greater accountability and proactive measures in safeguarding both physical and digital access points. In a landscape increasingly characterized by the convergence of physical security and digital access, Daniel Raines’ experiences and insights illuminate the paramount importance of vigilance and innovation in the electronic security industry. His journey from hands-on installation to software development exemplifies the dynamic nature of the field, where technological advancements continually reshape the strategies employed to secure environments. Raines articulates the necessity of adopting best practices in addressing vulnerabilities, particularly emphasizing the detrimental effects of hard-coded keys and unsecured systems. As the conversation progresses, it becomes evident that the industry is at a pivotal juncture, with a notable shift towards mobile credentials and cloud-based solutions. This transition not only enhances operational efficiency but also raises questions about data privacy and security in the cloud. Raines’ reflections serve as a vital reminder of the ongoing challenges and opportunities within the realm of electronic security, urging both practitioners and organizations to remain proactive in adapting to the evolving landscape.
Takeaways:
- Daniel Raines has accumulated approximately three decades of experience in the electronic security industry, transitioning from hands-on installations to software development.
- The conversation highlights the critical intersection of physical security and digital access control, illustrating how these domains converge in today’s security landscape.
- Raines emphasizes the importance of ethical vulnerability disclosure practices within the electronic security industry, advocating for responsible reporting of security flaws.
- As technology evolves, there is a notable shift from traditional physical access methods to more advanced mobile credentials and biometric solutions, enhancing security measures.
- The discussion reveals that hard-coded encryption keys and default passwords remain prevalent vulnerabilities, underscoring the need for improved security practices in software design.
- Raines advocates for a proactive learning approach, encouraging individuals interested in security to engage practically with hardware and software to deepen their understanding.
Transcript
Hi, everyone.
Speaker A:Welcome back to another episode of the Security By Default podcast.
Speaker A:I’m the host of the show, Joe Carson.
Speaker A:It’s a pleasure to be here and one of my favorite times of the week is to get to chat to amazing, great people who really make the world a safer place.
Speaker A:And today is going to be exciting episode.
Speaker A:I have got a guest today.
Speaker A:It’s first time on the show.
Speaker A:Daniel.
Speaker A:Daniel, do you want to give the audience a bit of a background about yourself, your origin story, how you got into the industry?
Speaker A:Did you choose this path or was this path kind of, you know, taken for you and you kind of fell into it?
Speaker A:So if you want to give.
Speaker A:Tell us a little bit about yourself and your story.
Speaker B:Okay.
Speaker B:Yeah.
Speaker B:So my name is Daniel Raines.
Speaker B:I’ve been in the electronic security industry as a whole for approximately 30 years.
Speaker B:For the first 15, I was actively on the tools, installing physical access control arms, cameras, et cetera.
Speaker B:And then for the last 15 or so, I’ve been writing software development for the same industry, but around construction for access control, biometrics.
Speaker B:Basically, I started looking at the security research side of things because I was finding there was like bugs in some of, like the local SDKs and APIs.
Speaker B:And I was like, I can’t continue or I can’t get it to do what I want it to do the way it should function.
Speaker B:So obviously you reach out initially to the companies and go, there’s a bug here.
Speaker B:This doesn’t work.
Speaker B:I do this, it crashes the server or whatever the case may be.
Speaker B:And then obviously, then it takes them time, sometimes months and months to obviously implement fixes.
Speaker B:And I’m like, well, let’s just take a deep dive and just see where the problem lies and see if I can fix the problem myself temporarily until I roll out an official fix.
Speaker B:And then whilst I’m there, I’m like, hold up, what, what’s this doing?
Speaker B:Why is this here?
Speaker B:I found these encryption keys that hold up, these are, these are hard coded and et cetera, et cetera.
Speaker B:And then it got to a point probably about 18 months ago where I sort of decided to sort of.
Speaker B:I’m not this on the head now.
Speaker B:I’ve sort of had enough of it and I’ve just, I’ll put a post up on LinkedIn just saying like, time for changes to sort of just move on and just go back to the.
Speaker B:Just, just doing software development.
Speaker B:And then there was a group of people, which I’m now part of a group on Signal that reached out to me and said, do you want to join our group?
Speaker B:And I was like.
Speaker B:So I was like, okay, yeah, I can do.
Speaker B:I mean, I’m not sure how much I’ll contribute because I’m sort of decided to just go back to software dev.
Speaker B:And then that just opened a can of worms.
Speaker B:And I’ve just been looking even more at different various products since then.
Speaker B:Yeah, there’s a, a good and a bad influence all at the same time.
Speaker B:So, yeah, so it was for a necessity to begin with because there was sort of problems, small bugs.
Speaker B:And then I just fell down a rabbit hole looking at stuff and thinking, this ain’t right, hold up, I can do this, I shouldn’t be able to do that.
Speaker B:And then I just started reporting stuff and some were open, some not so much, some threatened to sue me.
Speaker B:And it’s just been a roller coaster since then really.
Speaker A:So question on that.
Speaker A:You know, that’s something, you know, we obviously on the, in the software side, we’ve got the vulnerability disclosure programs.
Speaker A:You know, that gives some level of way of notify on vulnerabilities and bugs and so forth.
Speaker A:More on the access control, which does tend to be that it’s a convergence.
Speaker A:It’s.
Speaker A:It’s almost that kind of bridge between the physical world and the digital kind of, you know, you got the physical machines for accessing whether RFID readers, nfcs and so forth, or even the physical cards.
Speaker A:How is that industry specifically, how has it been for vulnerability disclosure?
Speaker A:Is it still catching up?
Speaker A:Made lots of events as well.
Speaker A:Where would you see in the access card kind of world how they’ve been responsive to the type of work that we would typically do?
Speaker A:You know, finding vulnerabilities in software and hardware.
Speaker B:I mean, as per.
Speaker B:I did another podcast a little while ago and as per, the same sort of question arose from that and I sort of defined it as sort of three separate categories.
Speaker B:One where companies were open and have been open initially from day one, they accept the report, they give you feedback and updates, and then they determine themselves the severity of what they deem as a fix.
Speaker B:And then when they’re going to fix it, and they keep you in the loop.
Speaker B:And then you’ve got like the middle ground, the gray area, so to speak, where you will submit something, they’ll say, you know, thanks for submitting that, and then you just won’t hear anything back.
Speaker B:And then you check for future versions and nothing’s been fixed and it’s exactly the same as it was.
Speaker B:And then the last one is like you just don’t hear Anything you submit stuff, you follow up and you just get no response whatsoever.
Speaker B:And then you just, after 90 days you just send that email, send up, I’m going to talk about this now.
Speaker B:And in the hope they’re going to do something.
Speaker B:And some do and some don’t.
Speaker B:So it’s.
Speaker B:Yeah, it’s, it’s very sort of up and down really.
Speaker B:Some take it on board, some just say thanks and some just don’t do anything.
Speaker B:So very mixed bag.
Speaker A:Yeah.
Speaker A:So sometimes even, you know, in some countries we do are fortunate, you know, where it’s the national security agencies who tend to maybe also contact them and kind of force them, you know, to doing something.
Speaker A:Especially if their devices and technologies being used in government agencies, they tend to take a much more, let’s say, you know, persuasive approach we might find it, but they tend to be the ones that’s like, well we’re using it, we’ve got it deployed.
Speaker A:So sometimes you get a little bit more force.
Speaker A:But it sounds like it’s very much similar to other industries as well, is.
Speaker A:I think those categories, you know, are very aligned.
Speaker A:It just comes to the maturity sometimes or the acceptance to change and to fixing things.
Speaker A:And what, what, what do you kind of enjoy the most?
Speaker A:Do you like still the physical side of things?
Speaker A:You know, the access cards or.
Speaker A:You said you were kind of more moving into the software side.
Speaker A:What was, what was kind of, do you still kind of enjoy the kind of more hardware side?
Speaker A:Because for me it was a hobby that started for me probably about a little bit over 10 years ago and I bought so much tools to help me with that side that it became a bit of an expensive hobby.
Speaker A:But where’s, where’s your passion lies?
Speaker A:Is it in the software side more these days or is it you still enjoy the hardware piece?
Speaker B:Yeah, I mean, so predominantly all of the work that I do, software development and the hacking stuff, is all around physical access control.
Speaker B:That’s where my passion lies and that’s the whole spectrum.
Speaker B:So that’s the software that you would either install, you’re communicating, you know, in the cloud, the physical controllers, the readers.
Speaker B:So I do a lot of stuff as well with biometrics for like face recognition, fingerprint stuff.
Speaker B:But it was more sort of fingerprint pre Covid and then Covid came and then everyone, it just sort of switched and now sort of predominantly in the area that I’m working with, it’s full face recognition.
Speaker B:So.
Speaker B:Yeah, so anything and everything associated with physical access control, whether that be the software, the Hardware, hacking, cloning, physical credentials.
Speaker B:I’ve actually written software and firmware.
Speaker B:There was actually a project called Paxton and Reader that was for capturing and decoding, logging stuff for Paxton Net2 switch to that sort of thing.
Speaker B:And that all sort of arose from the group that I joined.
Speaker B:I spoke about when I sort of just said I’m out sort of thing and then they sort of dragged me back in.
Speaker A:It’s great to have that, you know, you know, the need for, you know, it gives you some motivation as well in those situations.
Speaker A:It is good to feel kind of like, you know, your skills is adding value and needed and contributing.
Speaker B:So yeah, I mean, we aim, or at least me, you know, and the industry as a whole to do stuff responsibly and ethically.
Speaker B:But yeah, when you, you sort of join a group and then they were said, oh, we’re trying to do this, and then you think, oh, maybe I could help in some way, some part to do that.
Speaker B:And then you end up writing firmware for it first a lot in ESP module and.
Speaker B:And then, yeah, I mean, it wasn’t 100% sold in me.
Speaker B:There was contributions from the group as well and said we could add bits and we can do that.
Speaker B:And they supplied some source code like firmware and that got integrated and merged.
Speaker B:So, yeah, so very much sort of a group effort to.
Speaker B:To get the device where it needed to be so they can do their job, like sort of black team engagements.
Speaker B:So, yeah, and you know, and they’ve told me stories, obviously I can’t speak about them, but they’ve said we’ve managed to break into ABC because of the device.
Speaker B:So.
Speaker B:Yeah, definitely.
Speaker B:And obviously they did it ethically, responsibly.
Speaker B:It was part of an official engagement.
Speaker B:So.
Speaker B:But yeah, to, to create something and then have it used on an engagement is sort of just awesome.
Speaker B:It’s fantastic.
Speaker B:So, yeah, it might go far.
Speaker A:So what type of skill sets do you need?
Speaker A:What would you say?
Speaker A:The skills in your area that are valuable to be able to kind of, you know, contribute in this area.
Speaker A:What types of skills or knowledge is essential, really?
Speaker B:I mean, for me it’s just.
Speaker B:It’s all about just being able to read, write and reverse software, you know, regardless.
Speaker B:Obviously there’s loads of different languages involved.
Speaker B:A lot of the physical access control, like desktop software that you can install on prem predominantly is written like C Net.
Speaker B:So that makes my life so much easier.
Speaker B:Obviously there are tools for like opsification and some use good tools and some use mediocre tools and.
Speaker B:Yeah, but then I’ve also got my own tool set stuff.
Speaker B:I’ve either that’s free or I’ve purchased or I’ve written myself to sort of aid in the ossification and running through the binaries, et cetera.
Speaker B:And really it’s just that determination, it’s the, it’s the drive.
Speaker B:It’s like not giving up.
Speaker B:Even when you’ve tried and you try and you fail and then you just put it on the shelf and I’ll come back to that, and then you come back to that and then you get that light bulb moment.
Speaker B:Oh, damn, I can just do this and that’s it, I’m in sort of thing.
Speaker B:So yeah, it’s just being interested really.
Speaker B:I mean, you know, anyone can learn how to do stuff if you’re interested in learning how to do it really.
Speaker A:And what’s, what’s your go to application for doing reverse engineering?
Speaker A:Is it something like Ghidra or using IDA Pro or what’s, what’s your.
Speaker B:Yeah, so a mixed bag like IDA and Ghidra, um, got DNSPY Peak, netspy.
Speaker B:Net Reflector.
Speaker B:I’ve got some, some stuff I’ve come across is like VB6.
Speaker B:I’ve got some tooling to sort of reverse engineer all that stuff.
Speaker B:So yes, it, it really is sort of a mixed bag.
Speaker B:Even like the, a lot of installers, like Phys, like software installers, we use our MSI packages and then you’ve got like MSI extracts to sort of look into that, look at custom actions, see if there’s sort of embedded stuff in that.
Speaker B:As part of the installation I found a load of passwords hard coded in there when it first gets set up and then you can just extract that and go.
Speaker B:Right now I’ve got, I’ve got the sa, it’s hard coded, voila.
Speaker B:And it’s open.
Speaker B:TCP IP is enabled over the network.
Speaker B:I can just now connect to it.
Speaker B:Execute command shell.
Speaker B:I’ve now got my code execution.
Speaker B:Away we go.
Speaker A:So things will trigger some old memories for me because I used to be on the team of the Wise Package Studio for the installers.
Speaker A:That was a team that I had.
Speaker A:So it brings back a lot of memories for the installers and being able to understand about how they’re packaged and made executable.
Speaker A:So one question I’ve got for you as well is around what’s the most common types in the spaces?
Speaker A:From the vulnerability side of things, what’s the most common things you see is it weaknesses in the encryption are the keys are Just hard coded.
Speaker A:What’s the most common areas that you experience?
Speaker B:Yeah, I mean it’s just that it’s hard coded encryption keys.
Speaker B:We are literally hard coded into the binary.
Speaker B:I have seen a shift in some companies since you sort of point that out to them and go, you should to do this.
Speaker B:Because once I’ve got them, I’ve got them and that’s it, it’s game over.
Speaker B:At least create a random unique key for every install, every time you install the software.
Speaker B:So that means I need physical access or I need to gain remote access to the machine to extract the keys, in which case I’ve already got physical access to the machine anyway.
Speaker B:So.
Speaker B:But yeah, predominantly a lot of it is hard coded encryption keys and once you’ve got them, you’ve got them and that’s it, it’s game over at that point.
Speaker B:And Also hard coded SA passwords like sip, MySQL like Microsoft SQL Server and it’s just enabled like TCP IP is just on and it’s accessible and browsable over the network by default, even when sometimes it doesn’t need to be because the desktop software client is talking to its own custom server and not necessarily directly to SQL Server.
Speaker B:So just turn that off, just disable it and just run it localhost if you’ve got your own server anyway.
Speaker B:So yeah, hard coded stuff, SA passwords, encryption credentials and all that stuff is, is like the holy grail basically.
Speaker A:Okay, and what’s some of the best practices?
Speaker A:Are you also seeing a shift in technology as well as you mentioned, you know, used to be fingerprint readers and physical cards and it’s moving to more biometric, you know, facial recognition side and of course that was to get it more touchless based.
Speaker A:And we’ve also seen here, even in the Estonian national ID they moved to things like nfc, near field communication more or mobile based, let’s say authentication.
Speaker A:Are you seeing a shift in technology and moving away from the older kind of old, let’s say, let’s say the old 125khz cards which had very basic functionality to much more modern technology?
Speaker B:Yeah, I mean when I first started obviously like many, many years ago, it was just basic cars, 125 kilohertz.
Speaker B:And then yeah, then you obviously you’ve got lots of different car technologies and different levels of protection.
Speaker B:Then you’ve got obviously the NFC side of things, but you do have a lot of backwards compatibility.
Speaker B:So the reader itself, although it can support best file for example, it can also just read the uid and you can use that as the credential.
Speaker B:Okay, then, cool.
Speaker B:So I just, you know, just clone the card and use the UID and boom, you’re in.
Speaker B:And then there was a lot of push for fingerprint readers, at least in my experience in the field that I was working in.
Speaker B:So a lot of people were like, oh, we can use fingerprint readers, it’s more secure, et cetera.
Speaker B:I mean, the ones that I’ve tested aren’t.
Speaker B:We’ve managed to spoof them just with wax impressions like pva, Covid.
Speaker B:I did some stuff with Matt Lewis on fingerprint and Face Rec, like spoofing all of these readers that I had in my collection over the years.
Speaker B:And I think we pretty much spoofed all of them apart from one manufacturer.
Speaker B:And then, then obviously Covid come along and then it was like, okay, we don’t touch fingerproof readers anymore.
Speaker B:We now use face recognition.
Speaker B:And then the industry sort of got to realize actually this is, it’s better because it’s quicker.
Speaker B:As soon as I walk up to the door or turnstile, even sort of get right to it, it’s already detected me, the turnstile, the doors open, I just walked straight in.
Speaker B:And obviously now we’ve sort of got a push for mobile credentials, especially sort of, you know, in the advertisement of Apple and in the wallet and all that sort of things.
Speaker B:So, yeah, I mean it’s, the paradigm is shifting, but then I think it always does.
Speaker B:There’s always something new that will come along.
Speaker B:You know, it’s just the nature of the beast, so to speak.
Speaker A:Absolutely.
Speaker A:I think it’s.
Speaker A:You made a good point as well that backwards compatibility, you know, not everyone can shift immediately and we always have to have some way of dealing with the older technology.
Speaker A:And I see that sometimes as many of the failures, you know, the ones that gets exposed.
Speaker A:Exposed is because of the backwards compatibility or the need to support legacy means that your, your, your level of basically security is as low as those, you know, those technologies provide as well.
Speaker A:So when, when, when you’re doing assessments.
Speaker A:So what’s a typical tool?
Speaker A:What’s, what’s the tool tool set that you have?
Speaker A:Do you use Proxmarks or what’s, what’s your go to set of tools?
Speaker B:Yeah, so obviously I’ve got the, the Proc Spark Iceman firmware.
Speaker B:So I use that.
Speaker B:I don’t do tons of stuff with sort of the cars themselves.
Speaker B:I’m all that to the group that I’m in because they’re the ones that’s for the Black team engagement.
Speaker B:So I don’t, I don’t physically break in anywhere.
Speaker B:I’m doing this sort of part time, spare time as a hobby because so really sort of tooling is, it’s just basically is.
Speaker B:I try to look at it from a perspective like, is it, is there a problem that needs to be solved in respect of any tooling that might be missing, whatever that may be.
Speaker B:And then if I can and I’ve got the time, then I’ll try and create something for that.
Speaker B:I’m actually working on another project with firmware for sort of the Wigan side of things, like a hid R90 reader.
Speaker B:And I’ve got a whole list that was provided to me of all like 60 different sort of encodings for all the different types of CAR technologies.
Speaker B:I’m writing firmware that will not only log that data, but then try and do all the decoding based on how many bits it was, et cetera, et cetera.
Speaker B:And this is for me, it’s just for fun.
Speaker B:Yeah, Got my full time job and obviously I know there’s tools out there that will already do some of what I’m doing or if not all of it, but I’ll be.
Speaker B:So I’ll do it for myself because I, you know, put my own spin on it.
Speaker B:And it’s also, for me, it’s education, it’s learning.
Speaker B:It’s like, you know, keeping your finger sort of in that pie, so to speak, to keep yourself sort of sharp.
Speaker B:And how do you do this?
Speaker B:Now there is a lot of stuff that I come across and go, oh crap, how do I do this?
Speaker B:How do I figure this out?
Speaker B:And then you sort of just, you know, you fall down this rabbit hole and then six months later you’ve figured it all out and you’ve got this product, software, piece of hardware, firmware, whatever the case may be, and you’re like, oh yeah, that’s cool, that’s another check mark.
Speaker B:And then you’ve got that code to refer back to later should you need to use it for anything else.
Speaker B:Yeah, for very, it’s very much for fun and for learning for me.
Speaker B:So.
Speaker A:Absolutely.
Speaker A:Same same for me in this, in this area.
Speaker A:Because I mean, my specialty focuses on identities and credentials and you know, a lot of the software side of things, infrastructure and cloud.
Speaker A:And it was actually the, the physical access side of things.
Speaker A:I think I did years ago helping with an assessment for a ship management company.
Speaker A:And you know, we got into the physical side of things then and that’s where I really got the Interest and I end up going down this path as well where it’s become a very, very long passion hobby with the Proxmarks and everything else has came with it.
Speaker A:And I end up even just sitting here.
Speaker A:I’ve got a whole package sitting of cards that is to be delivered to Iceman.
Speaker A:Yeah, I don’t know if you’re like me is that when you go to traveling or hotels or you go anywhere you end up with a collection of lots and lots of actually.
Speaker B:Yeah, absolutely.
Speaker B:Yeah, I’ve got my fair share of collection of cars that I’ve collected over the years for various meetings that I’ve been to and hotels.
Speaker B:So yeah, I definitely collect it all.
Speaker A:I do get the kind of, you know, the needs.
Speaker A:I was like check it as well.
Speaker B:Yeah, absolutely, absolutely.
Speaker B:Yeah, scan it on your phone initially maybe just for a quick check and then stick it in, you know, on Proxmark and just find out what it is and, and then revert to the group that I’m in and go guys, what’s this?
Speaker B:I haven’t come across this or how did you decode this?
Speaker B:And they go, oh, you can do this.
Speaker B:Oh sweet.
Speaker B:So again, it’s all about earning.
Speaker B:I’m under no illusion that, you know, I know everything because I most definitely know that I don’t.
Speaker B:And it’s all about for me.
Speaker B:Yeah, reaching out and just asking questions and trying to contribute in any way that I can that would help the industry.
Speaker A:Absolutely.
Speaker A:It’s the same same for me.
Speaker A:I mean I have knowledge in it, I like to kind of explore and play around with it.
Speaker A:But my preference is kind of connect with the experts, yourself and Iceman and others in the field and that really help fill the gaps for me.
Speaker A:So you know, because it’s not nerdy that I don’t do it every single day.
Speaker A:I probably, you know, spend maybe a weekend a month or so forth and kind of pull it out and play around with it.
Speaker B:Yeah.
Speaker A:Even, even the point where when I, when I bricked things, I bricked my tool so many times I had to pull out things like the bus pirate in order to kind of rewrite the firmware and then was it to kind of do the chips and try to get it to work, which has been a good skill.
Speaker A:But Iceman’s helped me many times out of, out of a hole when I’ve got into it self inflicted of incompatible versions sometimes.
Speaker A:So what, what’s, what’s, what do you see, you know, what’s next in the industry?
Speaker A:Where do you see some of the kind of the future going, what’s some of the best practices organizations doing in order to really make sure that this is something, you know, that becomes protected much more in the future?
Speaker A:Where do you see the trends?
Speaker B:I think for me for the minute, what I’m looking at is definitely a massive push for stop using plastic cards and move to mobile credentials.
Speaker B:That’s what I’m seeing all over LinkedIn with various sort of manufacturers and installers and even end users saying yeah, how they’ve benefited from disregarding the plastic altogether.
Speaker B:So there’s no, there’s no vulnerability in cloning a physical car because they just don’t exist anymore, you know, on certain sites and they’re using mobile credentials.
Speaker B:But then that piques my interest.
Speaker B:I’m like, oh, mobile credentials.
Speaker B:How is there any way to sort of interact and do something you shouldn’t be able to do with those?
Speaker B:And so yeah, I think it’s, it’s very much sort of cat and mouse really.
Speaker B:But me, you know, you try to be ethical and responsible and if you find something, you report it.
Speaker B:What they do with it is up to the manufacturer.
Speaker B:But that’s the sort of shift I’m seeing.
Speaker B:There’s still a lot of biometrics.
Speaker B:People are using biometrics a lot, especially in construction, a lot of phase readers.
Speaker B:But predominantly the shift I’m sort of seeing is, you know, dropping plastic, moving to mobile credentials and a lot a big push as well for like removing on premises software and just having it all in the cloud.
Speaker B:I don’t necessarily always agree with that.
Speaker B:I think there should be options for companies that don’t want it in the cloud for sort of privacy and all the rest of it.
Speaker B:But again it’s down to the installers and the end users to decide what route they want to take personally.
Speaker A:Absolutely.
Speaker A:Sometimes there’s a regulatory enforcement to have something continually within country or within location and that can cause challenges.
Speaker B:Yeah.
Speaker B:But I do see some countries there is, they’re using face rec but there’s like, I can’t remember what country it was but you’re not allowed to store or retain the template information on the physical device or the server.
Speaker B:So they introduce like template on mobile or template on card, present card or mobile template gets transferred, then it does the match and disregards it.
Speaker B:Yeah, it just, it just depends really who your target audience is and I suppose what country you’re targeting as well.
Speaker A:Absolutely end up just becoming a mathematical fingerprint off the actual facial recognition or the, the image itself, which makes it much more Secure and a method of when you’re transferring, transmitting it as well.
Speaker A:But I do, I like the move to mobile credentials anyway because from an enablement and provisioning it’s a much more simpler method.
Speaker A:With the physical cards you have to, you know, transport them and get them in people’s hands and then you’re exposing the readers to the external facing side where moving to mobile credentials it can be proximity based credentials where it could be even Bluetooth initiated, initiated where the reader can be on the inside.
Speaker A:So it can be done through wireless as well.
Speaker A:And I completely agree.
Speaker A:I’ve seen you know, a lot of countries shifting to the digital wallet kind of standards or it means then it can you know, just be basically an, an attribute within the wallet itself and much easier, much easier to provision.
Speaker A:I think the challenge has always been when you get into the mobile side of things it’s much more difficult to migrate.
Speaker A:Migration has always been a challenge.
Speaker A:How do you know new devices, how do you move it securely to a new device and so forth or, or if you have multiple devices, how do you make sure that you’re not, you know, getting it cloned accidentally with someone else?
Speaker B:So I’ve also seen a shift as well in readerless access control.
Speaker B:Well, yeah, there is no physical reader.
Speaker B:It’s you’re just using your phone and basically like an NFC plaque or, and, or QR code and then your phone is then authenticating you and then sending data to a server which then clicks the relay energizers and lets you through and opens the door.
Speaker B:So yeah, there is a company that is releasing something.
Speaker B:I’m not sure if I’m allowed to say anything about it yet so I won’t.
Speaker B:That’s releasing something of literally next month I believe.
Speaker B:And there’s actually another company called Door Deck that does the exact same thing and they just pop plaque on the door and yeah, you present your phone and away you go.
Speaker A:Yeah, I do see this.
Speaker A:You know the great thing is it’s going to merge with lots of different things like things like digital visas and so forth.
Speaker A:You know, you know when you go into countries you can already have the templates already set up beforehand.
Speaker A:So you’re going through immigrations and visas or you know, airport travel and stuff like that.
Speaker A:We need to cross borders.
Speaker A:Then this can also be combined with your access control too.
Speaker B:Yeah, definitely, definitely.
Speaker A:So what’s, what’s some of the ways, I mean, so this is a, you know, you said it’s a hobby passion area for you.
Speaker A:You enjoy, you know, you’re doing it for a long time and you have access to, to a group.
Speaker A:How do you stay up to date?
Speaker A:What’s in this area?
Speaker A:You know, it’s, it’s always changing.
Speaker A:There’s always new hardware, new technology, lots of kind of movement and what resources do you.
Speaker A:Do you know, how, how do you stay up to date?
Speaker A:How do you continue to learn?
Speaker A:Do you, do you do courses?
Speaker A:Do you go to conferences?
Speaker A:Do you, you have a mentor?
Speaker A:Do you.
Speaker A:Where’s your kind of source of knowledge?
Speaker B:Yeah, so I don’t really have a mentor, but I’ve got the group and obviously they’re a great bunch of guys, very, very knowledgeable.
Speaker B:The group I’m in, I don’t know why I’m in it, because I do this for fun and they do it all day, every day.
Speaker B:So.
Speaker B:But they invited me.
Speaker B:Sort of stuck with me now.
Speaker B:But yeah, so of any questions I’ve got regarding hacking stuff, like for all different aspects of it, then yeah, I can just sort of throw them a question and they can point either they know the answer or they can point me in the right direction.
Speaker B:And then I watch a lot of sort of YouTube stuff that’s dedicated around hacking and software and cloning, all that side of things, to sort of, you know, keep up to date.
Speaker B:I do read certain bits and pieces, some publications and white papers, et cetera.
Speaker B:It just depends whether I’m interested in that area that done.
Speaker B:And I’m now starting like doing sort of more podcasts and that’s the hope.
Speaker B:Do more sort of get the word out there about who I am and who, who the host is and what we do as an industry.
Speaker B:Yeah.
Speaker B:So.
Speaker B:And really as well, it’s just if you, if you just sort of reverse engineer software, then you can see what they’re doing and how they’re doing it and what technologies they’re using and how they’re implementing it and whether what they’ve done is good in the middle or bad.
Speaker B:And then you can sort of learn from that as well.
Speaker B:So, yeah, I do find a lot of learning just by simply reversing, softening.
Speaker B:And you get that moment, you think, oh, I didn’t think of that, that’s a good idea, or no, don’t do that, that’s bad.
Speaker A:So, yeah, absolutely.
Speaker A:nd up doing a course on Atari:Speaker A:So I did Atari course to write games in assembly language.
Speaker A:So when I was getting the reference engineering side, I would be a better understanding about what I was looking at, which actually helped.
Speaker A:It helped a lot.
Speaker B:Yeah, yeah.
Speaker A:Is there any bit of a, you know, for any of the audience who’s listening in and you know, decide, oh, this is an interesting area.
Speaker A:What would can a.
Speaker A:What would be the starting point?
Speaker A:Where would you recommend them to go to to get started?
Speaker B:What would be the best place to what learn.
Speaker A:To learn about access controls, to learn about, let’s say, you know, the devices and this technology.
Speaker A:What’s.
Speaker A:What would be the best place to get started?
Speaker A:What do you kind of.
Speaker A:Where would you direct them to?
Speaker B:That’s.
Speaker B:That’s a really good question.
Speaker B:Yeah, I don’t really have a good answer for it to be fair.
Speaker B:I mean, yeah, there’s.
Speaker B:Because there’s so many manufacturers doing so many different things really are.
Speaker B:It really is a minefield because like you said, it’s compatibility and what reader should you choose and what access control or platform?
Speaker B:I mean as a, as a youngster that’s trying to get into the industry then like skills for security and you got the, the security event that happens every year in the NEC in Birmingham.
Speaker B:Maybe that’s a good starting point.
Speaker B:Obviously apprentices, trainees, that sort of stuff to get into it.
Speaker B:If you want to hack stuff, you just got to start hacking stuff.
Speaker B:You gotta learn.
Speaker B:That’s the thing.
Speaker B:It’s just dive in.
Speaker B:You know, we can all just sit there for six weeks watching videos, but really hands on, let’s get some example code.
Speaker B:Let’s just try to figure out now let’s start writing something.
Speaker B:It doesn’t matter if it works or not.
Speaker B:At least you know, that’s for me the best way to learn is by doing so.
Speaker B:Yeah, you could even buy some cheap physical hardware stuff off ebay and just up way with it, you know, whether you’re hacking it or just figuring out how to use it, just wire it up and you know, if you get something cheap and you break it, it doesn’t matter.
Speaker B:You, you know, just play with it.
Speaker A:Yeah, I think I.
Speaker A:Even when I remember starting and working, you know, getting my kids involved in it, it was the Arduino and getting the NFC kind of card reader extension to Arduino and kind of.
Speaker A:And then you’re creating your own.
Speaker A:You’re actually, you know, implementing it and doing the code and then you start understanding how it works.
Speaker A:I think even before that.
Speaker A:You’re absolutely right.
Speaker A:I think going to conference and, and you’ll find conferences out there, whether it be, you know, likes of B sides and other types of, you know, local events.
Speaker A:They might have a, you know, access control village that will kind of show you also how everything works and give you some training and knowledge.
Speaker A:I think I remember going back to the really early times, was even just getting my kids kind of into lock picking.
Speaker B:Okay.
Speaker B:Yeah.
Speaker A:Understanding about, you know, the simple locks and since starting there.
Speaker A:Funny story was when my son was coming to my office all the time and, and he wanted to play PlayStation.
Speaker A:I was like, no, you can’t.
Speaker A:You have to do something educational.
Speaker A:I was like, what have I got lying around here?
Speaker A:I was like, oh, there’s a couple of lock picks.
Speaker A:You put the controller in a box, put the lock on it, it open it, you can play PlayStation.
Speaker B:Yeah.
Speaker A:He was like sitting there and then he got really good at it.
Speaker A:And then one of the funny things, when I was going to DEFCON last year, he was like, do you want me to bring anything back, like a T shirt, hat or something?
Speaker A:He’s like, no, I want a professional lock set.
Speaker B:That’s it.
Speaker A:Yeah, okay.
Speaker A:But absolutely.
Speaker A:I think, you know, going, going to a conference and an event and, and, you know, seeing if there’s a village or, or, or a session or something.
Speaker A:There is definitely a great way to, to one is meet the community, is meet people behind a lot of it.
Speaker A:Absolutely.
Speaker A:For the audience, if they do want to connect with you or reach out, what’s, what’s the best place that they can connect with you, probably LinkedIn will.
Speaker B:Be the best place because that’s, anything that I’m doing publicly will be published.
Speaker B:There’s various bits and pieces on there and yeah.
Speaker B:So for anything physical access, whether that be development or hacking or whatever, then.
Speaker B:Yeah, LinkedIn is the best place.
Speaker A:I’ll make sure even in the show notes we can, we can add the link so people can easily find it.
Speaker A:Absolutely.
Speaker A:Daniel, it’s been fantastic having you on.
Speaker A:So it’s a topic that, for me, it’s, it’s, you know, it’s a hobby, a passion of mine, so.
Speaker A:Absolutely.
Speaker A:It’s a pleasure having you on.
Speaker A:Really excited to, kind of to keep in contact with you.
Speaker A:And whenever anything comes up, we can definitely share ideas and knowledge.
Speaker A:And for the audience, many thanks for listening in to this episode.
Speaker A:It’s an area which is exciting because it’s that kind of crossover between the physical and the digital world.
Speaker A:It’s where, you know, physical meets digital.
Speaker A:And having that knowledge about access is essential and critical in today’s world.
Speaker A:So hopefully this episode has been educational and giving you some enlightenment and also maybe give you an idea of maybe other paths or other ways and careers that you can go down and learn something new.
Speaker A:Daniel, many thanks for being on.
Speaker A:It’s a pleasure having you.
Speaker A:For the audience, tune in every two weeks for an episode of the Security By Default podcast.
Speaker A:I’m the host of the show, Joe Carson.
Speaker A:To everyone out there, stay safe, take care, until the next time.
Speaker A:Thank you.
Speaker B:Thank you, Joe.
Speaker A:Thanks.
