frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Let's Get Physical

https://m4iler.cloud/posts/lets-get-physical/
54•MBCook•1h ago

Comments

illithid0•1h ago
From one red teamer to red teamer to another, glad your first assessment went so well and you had a great time. My first physical pentest made me want to never sit in front of a terminal again.

People, as we like to say, are not paid enough to care. At-will employment, company-sponsored healthcare, etc. have employees so focused on their own wellbeing that protecting "the company" is the last thing on their minds, and I can't really blame them. That lady who you barged in on may very well have just been used to micromanaging jerks doing it to her all the time, so she has to seem busy.

Physical security, in my experience, comes down to giving people something to protect which actually benefits them to protect. All the technical controls in the building can fail and one person with enough skin in the game can kill an intrusion attempt in seconds.

sillysaurusx•1h ago
I want to hear about your first assessment please! (Former pentester here. I never got to do a physical red team but always daydreamed about it.)
illithid0•46m ago
My first assessment was honestly as anticlimactic as OP's.

We had to break into a particular unit of a multi-tenant office building. The client wanted us to focus on social engineering, but if we were able to do that, to move on to testing if anyone would see it as suspicious if someone was messing with doors and stuff.

So my partner walked up to the reception desk with a toolbox and a clipboard, claiming to be there for an off-schedule inspection of the elevator fire suppression system. Signed the guestbook with no formal verification, walked into the office area, and sat down to plug his laptop into an ethernet drop.

Meanwhile, after he texted me to let me know he was in, I took the stairs up to a door that led into the back of the target unit and just had to use a traveler's hook to pull door latch open. No guard plates or anything in the way.

Then I walked around in my business casual outfit until I found what looked like an IT closet, waited for a time when no one was in the hall with me, and used an under-the-door tool to pop it open. All their network equipment was in there along with spare laptops and an unlocked IT admin machine on a desk.

:)

simlevesque•1h ago
I love pentesting stories. Great blog post, I was smiling while reading most of it.

It reminded me of Deviant Ollam's stories such has his elevator security talk w/ Howard Payne: https://www.youtube.com/watch?v=oHf1vD5_b5I

totallygeeky•56m ago
Pentesting seems like a hoot, love to see these stories!
jgilias•17m ago
Many moons ago I worked a job that involved physical on-premise installations of different equipment. That’s when I learned that for access all that’s needed is often a toolbox, an attitude that you belong there, and a friendly hi to the security guy if you stumble upon one. Not always (and then you actually being authorised helps), but often enough.
nathan_douglas•13m ago
Great stuff. I love that there's this kind of modern noir tone to the writing.

> I wanted to try and see if we could bypass the door entirely, and that’s where the canned air comes in. If you turn a can of compressed air upside down, it starts “boiling off cold gases.” These are not harmful in open spaces, and their temperature is well below freezing point even when gaseous. This can trigger a sensor that checks for temperature increases: First it sees a drop to -50C, thinks “Baby, it’s cold outside.” Then, the temperature starts rising again, and the sensor thinks “Oh, temperature going up?! Must be a human!” and opens the door. If this works, I will update my Mastodon. If it doesn’t, well I can still walk in after someone, so it’s a finding nonetheless.

I enjoyed it a lot.

crowfunder•12m ago
This post was so engaging to read, it felt like the best war-story you'd randomly hear in the break room. Gotta check out the rest of OP's posts.

Show HN: BurnShot v2.0 – Zero-Knowledge ephemeral sharing

https://www.burnshot.app/
1•axaysharma•35s ago•0 comments

The entrancing sea pulpits of central Europe

https://www.worldofinteriors.com/story/sea-pulpits-central-europe
1•speckx•1m ago•0 comments

Claude hit #1 on the iOS App Store in 14 countries

https://xcancel.com/RyD0ne/status/2029595911127724247
1•doener•2m ago•0 comments

EPO's new search tool for examiners now used in over 40 national patent offices

https://www.epo.org/en/news-events/news/epos-next-generation-search-tool-examiners-now-used-over-...
1•JeanKage•2m ago•0 comments

Andrew Ng's Building LLMs with Jax

https://learn.deeplearning.ai/courses/build-and-train-an-llm-with-jax/information
1•northlondoner•2m ago•0 comments

Show HN: GitHub-powered instant developer portfolios

https://remotedevelopers.com/lander
1•plsft•3m ago•0 comments

Sycophantic AI is changing the world of romance and dating

https://economist.com/culture/2026/03/05/who-wants-a-partner-to-toady-to-them-quite-a-lot-of-people
2•loughnane•3m ago•0 comments

Ask HN: Is Waymo Down?

1•philip1209•4m ago•0 comments

Two marsupials believed extinct for 6000 years found alive

https://www.newscientist.com/article/2518082-two-marsupials-believed-extinct-for-6000-years-found...
3•janandonly•4m ago•0 comments

Show HN: Expose The Culture – Anonymous company culture reviews

https://exposetheculture.com
1•david_fanxie•5m ago•0 comments

Show HN: XML, Markdown, or JSON: Which gives LLMs the most reliable boundaries?

https://systima.ai/blog/delimiter-hypothesis
1•systima•6m ago•1 comments

Activision put awkward pressure to make a game about Iran invading Israel

https://www.eurogamer.net/call-of-duty-co-founder-claims-activision-put-very-awkward-pressure-on-...
1•spaghetdefects•7m ago•0 comments

Ascend: Run Python Functions on Kubernetes

https://ocramz.github.io/posts/2026-03-05-ascend.html
1•todsacerdoti•9m ago•0 comments

BYD rolls out EV batteries with 5-minute 'flash charging.' But there's a catch

https://techcrunch.com/2026/03/05/byd-rolls-out-ev-batteries-with-5-minute-flash-charging-but-the...
1•jmercouris•13m ago•1 comments

Ask HN: Anyone using "Deep Agents" for production or operational tasks?

1•codecracker3001•14m ago•0 comments

ChatGPT for Excel and new financial data integrations

https://openai.com/index/chatgpt-for-excel
1•surprisetalk•16m ago•0 comments

'ATM jackpotting' leads FBI to issue warning. Here's what to know

https://www.usatoday.com/story/money/2026/02/27/atm-jackpotting-fbi-warning/88896796007/
2•rmason•17m ago•0 comments

Show HN: AgentShield – Real-time risk monitoring for AI agents

https://useagentshield.com/
1•jairooh•18m ago•0 comments

Parenting as a Solo Founder

http://www.benjaminoakes.com/2026/03/05/Parenting-as-a-Solo-Founder/
1•speckx•20m ago•0 comments

The Cost of Simple

https://www.metateam.ai/blog/how-efficiency-works
2•falsename•21m ago•0 comments

The AI Industry's Moment of Gloom, Doom, and Profit

https://www.motherjones.com/politics/2026/03/artificial-intelligence-quitters/
1•cdrnsf•23m ago•0 comments

FBI Nabs Contractor for Allegedly Stealing Crypto from Marshals

https://www.bloomberg.com/news/articles/2026-03-05/fbi-arrests-contractor-in-alleged-crypto-theft...
2•pilingual•24m ago•0 comments

Show HN: Docker pulls more than it needs to - and how we can fix it

https://dockerpull.com
3•a_t48•24m ago•1 comments

GrapheneOS: Microsoft Authenticator does not support secure Android OS

https://www.heise.de/en/news/GrapheneOS-Microsoft-Authenticator-does-not-support-secure-Android-O...
2•RachelF•25m ago•1 comments

Show HN: Stoneforge – Open-source orchestration for parallel AI coding agents

https://stoneforge.ai/blog/introducing-stoneforge/
1•adamjking3•26m ago•0 comments

ChatGPT vs. MOSQUITO Trolley Problem [YouTube] [video]

https://www.youtube.com/shorts/CJrOMs4L-lc
1•sydney6•27m ago•1 comments

Attempted Hack of Water Treatment Plant in 2021 [pdf]

https://vault.fbi.gov/attempted-hacking-of-oldsmar-water-treatment-plant-on-february-5-2021/attem...
1•sans_souse•27m ago•0 comments

Mac Studio 512GB RAM Option Disappears Amid Global DRAM Shortage

https://www.macrumors.com/2026/03/05/mac-studio-no-512gb-ram-upgrade/
5•ashivkum•28m ago•1 comments

Cluely Retracts June 2025 Revenue Statement

https://twitter.com/im_roy_lee/status/2029606868369236088
1•tech234a•29m ago•0 comments

Auto update and visualize your AI chat context

https://99helpers.com/tools/visual-contextual-chat
1•nickk81•31m ago•0 comments