TL;DR
- Online suppliers have made it easier and cheaper to copy the physical signs of trust used by organisations, including lanyards, identification badges, branded clothing, and personal protective equipment.
- Social engineers can combine publicly available logos, photographs, custom printing, and ordinary clothing to create a convincing pretext for gaining physical access.
- We have used fake badges, uniforms, hard hats, key fobs, and corporate materials during physical security engagements. No single item gets you through the door, but together they can make you look as though you belong.
- Anti-counterfeit features can make convincing copies more difficult and expensive, but appearance should never be treated as proof of identity.
- A genuine “trust, but verify” culture requires staff to challenge unfamiliar people and consistently follow access procedures, even when someone looks the part.
The Problem
In this online world it’s been easier than ever to order what you need, when you need and to the exact specifications you want… mostly.
The clothing world, alongside many other sectors, is plagued by fakes to the cost of billions, and these figures have increased year upon year for quite a while.
Now what if the clothing you are worried about is not your own wardrobe but your corporate “clothing”. Your eyebrows have shot up, I can tell, but the things I am talking about are aspects such as lanyards, ID badges, personal protection clothing, corporate event attire, security team branding and, while not clothing, even postal branding and letterheads are applicable here.
We often watermark and protect our online IP where it impacts trade or prices, and technological steps are taken to prevent copying or editing, but we rarely consider the concept of living off the land as it applies to OSINT, online suppliers, and very short delivery timeframes.
The vector
The vector here is physical access. The attack itself is not new, but its components have become much easier to copy and order online.
Lanyards, identification badges, and branded clothing act as visual tokens of trust. They help staff distinguish employees from visitors, but they can also make an intruder appear legitimate. Convincing copies can often be ordered in small quantities using little more than photographs and logos found online.
Personal protective equipment can be particularly easy to imitate. Many organisations use similar suppliers, colours, and layouts, sometimes leaving the corporate logo as the only meaningful difference. An iron-on transfer may be enough to make generic equipment look convincing.
There is an old adage in social engineering that says, “If it looks like a duck and quacks like a duck, then it’s probably a duck.” This can have other names, such as “the grey man” or even “affiliative herd behaviours”, but all highlight that wearing the correct attire and the right dress code and clothing associated with the job or role will often make you less conspicuous. The more details that align to expected norms, the less an alert is likely to be triggered. A wolf in sheep’s clothing, if you will.
These are all items we have used or faked on engagements to facilitate entry to a site:
- Fake lanyards
- Fake ID badges
- Fake (branding) PPE
- Fake polo shirts
- Fake (branding) hard hats
- Fake key fobs
- Fake letterhead or fake business cards
- Fake (branding) rucksack
No single item guarantees physical access, but several consistent details can make a pretext far more convincing. A credible badge, the expected clothing, and a plausible reason for being there may be enough to avoid scrutiny, particularly where “trust, but verify” is encouraged in principle but not consistently practised.
Click. Customise. Break in.
Online vendors allow for the upload of logos copied from the internet, printed on standard colour swatches and with “common” design options. Some personalisation can be made with items such as extendable ID badge fobs. Every personalisation comes at an increased unit cost, however, and some of them make them too expensive to consider for the opportunistic attacker. Also, not only do we have access to online vendors, but printing and iron-on technology have come a long way, and it’s relatively simple to take a single colour logo and turn it into an iron-on transfer for under a fiver. We can do the same with full colour logos and sticker prints.
Ask yourself, “Could you spot a fake item of designer clothing if asked?” You might say yes if you are an avid fan or know specifically about how that firm prevents fakes. Here’s some ideas to help:
The mitigations and preventions
- Think about the cost of entry for an attacker.
Living off the land, or in this case living off the internet, relies on cheap and easy findings that can be combined to form something more sinister. Watch for postings online of access control related clothing or PPE that infers a direct trust element between you and the public, such as a security uniform for public event handling. Don’t make it easy or cheap to make clones or copies.
- Use of colours which are clearly and strictly defined such as Pantones can make it much harder for a clone to be made as they raise prices and are colours that cannot be easily colour matched.
- Use of full colour printing or high-quality imagery makes it harder to make an easy copy, and the attacker might even need access to a real item for an extended period to enable a good fake.
- Use of materials that can have a clear “look and feel”. And by ‘feel’ I do mean literally, the item should use materials that are not of the cheapest and lowest cost derivation where clones can be made for a pound or two.
- Create logos or designs that are specific to access control systems. These could be a distinct colour palette or a unique design or variation of the corporate logo that is not publicly available online.
- Use ID badges that have holograms if you can – these can only be mimicked through very high spend or stickers, but these can be “felt” to be wrong by running a finger across the card.
- Use fonts that have telltale signs in certain letters that can help identify a fake. Serifs or lack of serifs, for example, and by the changing of a single character this can be a hidden means of anti-fraud prevention that only security teams should know. Attackers may miss the finer details if they feel the font is close enough.
- Use of reputable vendors who are contracted to take account of your intellectual property and prevent arbitrary copies from being made or sold to untrusted third parties.
- Consider name badges or unique IDs sewn into labels (QR codes) in clothing which is imperative to trust, such as a uniform that infers membership of a trusted infrastructure provider. This can be used to track clothing kept by leavers sold on public sites and forums.
- Protect internal stores of printed materials. Those letterheads and pre-paid envelopes make it easy to commit a targeted fraud. In finance sectors this can be of greater impact, but it can be used in bank transfer frauds.
- Train staff or key teams to recognise good from bad
All the prevention in the world won’t help if no one recognises real from a fake and blindly accepts a cheap knock off or a poor facsimile.
Conclusion
Living off the land can be extrapolated to living off the internet using a browser and some key online retailers to create “good enough” fakes that allow for intruders and possible petty thieves. Staff need to be aware of fakes and be trained or given advice on how to spot good from bad. Security is everyone’s responsibility, but we often overlook the mundane or inconspicuous items that can easily be used to help verify individuals. There are some simple steps to make it harder and more expensive for opportunistic attackers or dumpster divers.