[HN Gopher] Let's Get Physical
       ___________________________________________________________________
        
       Let's Get Physical
        
       Author : MBCook
       Score  : 81 points
       Date   : 2026-03-05 19:21 UTC (3 hours ago)
        
 (HTM) web link (m4iler.cloud)
 (TXT) w3m dump (m4iler.cloud)
        
       | illithid0 wrote:
       | From one red teamer to red teamer to another, glad your first
       | assessment went so well and you had a great time. My first
       | physical pentest made me want to never sit in front of a terminal
       | again.
       | 
       | People, as we like to say, are not paid enough to care. At-will
       | employment, company-sponsored healthcare, etc. have employees so
       | focused on their own wellbeing that protecting "the company" is
       | the last thing on their minds, and I can't really blame them.
       | That lady who you barged in on may very well have just been used
       | to micromanaging jerks doing it to her all the time, so she has
       | to seem busy.
       | 
       | Physical security, in my experience, comes down to giving people
       | something to protect which actually benefits them to protect. All
       | the technical controls in the building can fail and one person
       | with enough skin in the game can kill an intrusion attempt in
       | seconds.
        
         | sillysaurusx wrote:
         | I want to hear about your first assessment please! (Former
         | pentester here. I never got to do a physical red team but
         | always daydreamed about it.)
        
           | illithid0 wrote:
           | My first assessment was honestly as anticlimactic as OP's.
           | 
           | We had to break into a particular unit of a multi-tenant
           | office building. The client wanted us to focus on social
           | engineering, but if we were able to do that, to move on to
           | testing if anyone would see it as suspicious if someone was
           | messing with doors and stuff.
           | 
           | So my partner walked up to the reception desk with a toolbox
           | and a clipboard, claiming to be there for an off-schedule
           | inspection of the elevator fire suppression system. Signed
           | the guestbook with no formal verification, walked into the
           | office area, and sat down to plug his laptop into an ethernet
           | drop.
           | 
           | Meanwhile, after he texted me to let me know he was in, I
           | took the stairs up to a door that led into the back of the
           | target unit and just had to use a traveler's hook to pull
           | door latch open. No guard plates or anything in the way.
           | 
           | Then I walked around in my business casual outfit until I
           | found what looked like an IT closet, waited for a time when
           | no one was in the hall with me, and used an under-the-door
           | tool to pop it open. All their network equipment was in there
           | along with spare laptops and an unlocked IT admin machine on
           | a desk.
           | 
           | :)
        
       | simlevesque wrote:
       | I love pentesting stories. Great blog post, I was smiling while
       | reading most of it.
       | 
       | It reminded me of Deviant Ollam's stories such has his elevator
       | security talk w/ Howard Payne:
       | https://www.youtube.com/watch?v=oHf1vD5_b5I
        
       | totallygeeky wrote:
       | Pentesting seems like a hoot, love to see these stories!
        
       | jgilias wrote:
       | Many moons ago I worked a job that involved physical on-premise
       | installations of different equipment. That's when I learned that
       | for access all that's needed is often a toolbox, an attitude that
       | you belong there, and a friendly hi to the security guy if you
       | stumble upon one. Not always (and then you actually being
       | authorised helps), but often enough.
        
       | nathan_douglas wrote:
       | Great stuff. I love that there's this kind of modern noir tone to
       | the writing.
       | 
       | > I wanted to try and see if we could bypass the door entirely,
       | and that's where the canned air comes in. If you turn a can of
       | compressed air upside down, it starts "boiling off cold gases."
       | These are not harmful in open spaces, and their temperature is
       | well below freezing point even when gaseous. This can trigger a
       | sensor that checks for temperature increases: First it sees a
       | drop to -50C, thinks "Baby, it's cold outside." Then, the
       | temperature starts rising again, and the sensor thinks "Oh,
       | temperature going up?! Must be a human!" and opens the door. If
       | this works, I will update my Mastodon. If it doesn't, well I can
       | still walk in after someone, so it's a finding nonetheless.
       | 
       | I enjoyed it a lot.
        
       | crowfunder wrote:
       | This post was so engaging to read, it felt like the best war-
       | story you'd randomly hear in the break room. Gotta check out the
       | rest of OP's posts.
        
       | wobblyasp wrote:
       | Y c a. E b c c ky
        
       | Animats wrote:
       | Only the military, and some banks, really take physical security
       | seriously.
       | 
       | Someone tried to crash through the main gate at the Camp
       | Pendleton Marine Corps Base two years ago. It did not end well
       | for them.[1]
       | 
       | Attempt to crash the gate at CIA HQ last year. Drunk driver
       | shot.[2]
       | 
       | Attempt to crash the gate at NSA HQ a few years ago. Two drugged-
       | out "men dressed in women's clothing". Hit barrier, tried to turn
       | around and escape, blocked by guard vehicle. One killed, one
       | injured, one guard injured.[3]
       | 
       | [1] https://www.youtube.com/watch?v=RPQPKnNj8wM
       | 
       | [2] https://www.nytimes.com/2025/05/22/us/shooting-cia-
       | headquart...
       | 
       | [3] https://www.youtube.com/watch?v=K49x05eOowo
        
         | i_think_so wrote:
         | There was a story, I think back in the '60s or '70s, about some
         | cantankerous old 1-star general who used to personally conduct
         | unscheduled inspections. One day he requisitioned a deuce-and-
         | a-half (one of those Army trucks with two axles in the back and
         | a green canvas covering for the bed, like you've seen in the
         | movies) and just crashes it right through the front gate at
         | some base.
         | 
         | The private who was manning the guard post at the gate came
         | running along behind, probably worried that somebody had been
         | hurt in the crash. The general hops out of the cab and unloads
         | on the poor kid with both barrels of choice insults about the
         | private's parentage, IQ, social standing and hygiene, finishing
         | it off with "and why the hell didn't you shoot me?!"
         | 
         | According to legend, that was what the private was punished for
         | -- dereliction of duty, failing to shoot the threat to base
         | security.
         | 
         | (Obviously, this story is most likely complete BS.)
        
       | surround wrote:
       | Reminds me of "Story of a failed pentest"
       | 
       | https://web.archive.org/web/20181118010006/https://threader....
       | 
       | https://news.ycombinator.com/item?id=18475438
        
       | i_think_so wrote:
       | Anybody else feel a strong urge to copyedit that post?
       | 
       | I make as many typos as the next dog, but really. Don't kids
       | today have the Internets to proofread their datas?
        
         | rfw300 wrote:
         | I did, and yet I also felt more relaxed reading it than I am
         | reading most blog entries posted on here. I didn't feel like I
         | had to guard against my time being wasted by vacuous LLM
         | fiction.
        
       ___________________________________________________________________
       (page generated 2026-03-05 23:00 UTC)