Bishop Fox named “Leader” in 2024 GigaOm Radar for Attack Surface Management. Read the Report ›

Dan Petro & David Vargas to Present at Black Hat USA 2023

August 9-10, 2023
Mandalay Bay Convention Center, Las Vegas, Nevada
Black Hat USA 2023 white logo on dark background.

Join Bishop Fox's Dan Petro, Senior Security Engineer, and David Vargas, Senior Security Consultant, as they present their session, "Badge of Shame: Breaking into Secure Facilities with OSDP" at the 26th Annual Black Hat USA in Las Vegas. The two-day main conference will feature more than 100 selected briefings, dozens of open-source tool demos, a robust business hall, networking and social events, and much more.

"Badge of Shame: Breaking into Secure Facilities with OSDP"

Breaking into secure facilities used to be possible by inserting a listening device (such as an ESPKey) behind an RFID card reader and sniffing the unencrypted Wiegand badge numbers over the wire as they go to the backend controller. The physical security industry has taken notice and there's a new sheriff in town: the encrypted protocol OSDP which is starting to be rolled into production. Surely encryption will solve our problems and prevent MitM attacks, right? ... Right?

In this presentation, we'll demonstrate over a dozen vulnerabilities, concerning problems, and general "WTF"s in the OSDP protocol that let it be subverted, coerced, and totally bypassed. This ranges from deeply in-the-weeds, clever cryptographic attacks to boneheaded mistakes that undermine the whole thing. We will also demonstrate a practical pentesting tool that can be inserted behind an RFID badge reader to exploit these vulnerabilities.

Get your orange vest and carry a ladder, because we're going onsite!

For more details, visit

Dan Petro Headshot

About the speaker, Dan Petro

Senior Security Engineer

As a senior security engineer for the Bishop Fox Capability Development team, Dan builds hacker tools, focusing on attack surface discovery. Dan has extensive experience with application penetration testing (static and dynamic), product security reviews, network penetration testing (external and internal), and cryptographic analysis. He has presented at several Black Hats and DEF CONs on topics such as hacking smart safes, hijacking Google Chromecasts, and weaponizing AI. Dan holds both a Bachelor of Science and a Master of Science in Computer Science from Arizona State University.

More by Dan

David Vargas

About the speaker, David Vargas

Senior Security Consultant I

David Vargas is a Senior Security Consultant I on Bishop Fox's Red Team, with extensive experience in social engineering and physical penetration testing. David is an active security researcher with multiple CVEs in publicly accessible web applications.

More by David

Ready to get started? We can help.

Contact Us

This site uses cookies to provide you with a great user experience. By continuing to use our website, you consent to the use of cookies. To find out more about the cookies we use, please see our Privacy Policy.