How to Fake a Badge like a Pro: Counterfeiting Event Credentials

Russell Phillips

DEF CON 33 · Day 2 · Main Stage

Overview

The event credentialing industry has operated on a foundation of security through obscurity for decades. Badges, wristbands, lanyards, and stickers guard entry to everything from music festivals to pr

Watch on YouTube · Slides

Visual summary for How to Fake a Badge like a Pro: Counterfeiting Event Credentials by Russell Phillips
Visual summary for How to Fake a Badge like a Pro: Counterfeiting Event Credentials by Russell Phillips

Key moments

  1. 2:13 Introduction: 11 practical tips for counterfeiting event credentials
  2. 6:44 Scope: this talk is about physical forgery, not cryptographic attacks
  3. 11:14 Tip: exploit volunteer fatigue to slip through credential checks
  4. 15:49 Physical craft: using inconspicuous materials for realistic badge duplication
  5. 20:15 Case study 1: live show-and-tell of first forged credential
  6. 24:44 Aging technique: matching wear patterns of legitimate credentials
  7. 29:19 Extreme case: NASA badge signing practices and their security implications
  8. 33:43 Defensive analysis: how event staff actually verify credentials at speed

How to Fake a Badge like a Pro: Counterfeiting Event Credentials

Speakers: Russell Phillips

Conference: DEF CON 33

YouTube: https://www.youtube.com/watch?v=Wq09JxymiFQ

Slides: https://media.defcon.org/DEF%20CON%2033/DEF%20CON%2033%20presentations/Russell%20Phillips%20-%20How%20to%20Fake%20a%20Badge%20like%20a%20Pro%2011%20Tips%20to%20Counterfeiting%20Event%20Credentials.pdf

Overview

The event credentialing industry has operated on a foundation of security through obscurity for decades. Badges, wristbands, lanyards, and stickers guard entry to everything from music festivals to professional conferences — yet most of these credentials rely on the assumption that an attacker cannot learn enough about them in the brief window they are in use to successfully counterfeit them. Russell Phillips, who works in security for South by Southwest, dismantles that assumption with surgical precision in this DEF CON 33 talk, presenting eleven actionable tips for counterfeiting event credentials while teaching attendees to think like both attackers and defenders in the physical access control space.

This is not a talk about breaking cryptographic RFID chips or hacking backend ticketing databases. It is a deliberate, practical walkthrough of the human and material elements of credential security — the parts that most event organizers never think to harden because they assume no one will ever bother. Phillips argues that the security-through-obscurity model fails precisely because a determined and technically literate attacker can close the knowledge gap in a matter of hours.

Background

▶ Watch: Introduction: 11 practical tips for counterfeiting event credentials (2:13)

The Event Credentialing Threat Model

Large-scale events like music festivals, trade shows, and conferences are high-value targets for credential fraud. The motivations are straightforward: paid entry can cost hundreds or even thousands of dollars, and the actual verification process at the door is often shallow. Event organizers invest in credentials that look sophisticated at a glance — holograms, multi-layer composites, UV-reactive inks — but the verification staff checking those credentials at the gate may be underpaid, undertrained, and operating under time pressure.

Phillips frames the problem from the organizer's perspective as well. Access control is not just about revenue protection. Events need to know how many people are inside for fire safety, ensure that restricted areas like backstage zones and press pools are properly gated, and maintain legal compliance with occupancy limits. This creates a real security problem on both sides, and understanding the attacker's perspective is essential for building better defenses.

The talk draws a clear distinction between credential types. Some credentials rely entirely on visual inspection — their security model depends on the checker noticing that a badge looks wrong. Others incorporate referential checks, comparing a barcode or name against a database, and defeating those requires attacking the database itself rather than the credential. Still others use cryptographic elements like RFID or NFC chips to enforce hard authentication. Phillips focuses his eleven tips on the visual and material layers — the ones that are most universally deployed and most universally underestimated.

Key Findings

▶ Watch: Tip: exploit volunteer fatigue to slip through credential checks (11:14)

Phillips identifies several structural weaknesses in how event credentials are designed and checked:

  1. Verification is shallow. In practice, credential checkers at most events are looking for the general silhouette of the correct credential and lanyard, not examining fine details. Security elements embedded in the credential that go unverified at the access point provide zero actual security.
  1. Credentials are time-bounded. The attacker has limited time to study and replicate a credential, but so does the event. By the time a counterfeit is good enough to use, the event may be half over. Organizers take comfort in this temporal advantage, but Phillips argues it is a weaker defense than it appears.
  1. The composite nature of credentials is systematically underexploited by attackers. The combination of badge plus lanyard constitutes the full credential. A badge without the correct lanyard immediately draws suspicion. Sophisticated counterfeiters should treat the entire credential package as the unit of replication.
  1. Counter-surveillance is a genuine force multiplier. Being caught conducting reconnaissance — taking photos, asking too many questions, hovering near access points — adds an attacker's face to a "be on the lookout" list that can invalidate even a perfect counterfeit.

Technical Deep Dive

▶ Watch: Case study 1: live show-and-tell of first forged credential (20:15)

The Eleven Tips

Tip 1: Social Engineering — Look the Part

The most important element of credential fraud is not the credential itself — it is the attacker's demeanor. Matching attitude and body language to a plausible role (rushed executive, tired volunteer, catering vendor) dramatically reduces scrutiny. A convincing human presentation can make a mediocre credential good enough; poor presentation can cause a perfect credential to fail.

Tip 2: Retouch and Recreate

Photographic or scanned reproductions of credentials carry the artifacts of their capture — glare, color shifting, resolution degradation. Attackers who simply print a cropped photo will produce an inferior result. The correct approach is to load the source image into image editing software and clean it up: blacks should be true black, text should be crisp, edges should be sharp. This step separates amateur counterfeits from convincing ones.

Tip 3: The Touch Test

Credential checkers handle large volumes of badges rapidly, and tactile inconsistency is a significant detection signal. A badge that is slightly thicker than its genuine counterpart, or that has a different surface texture, will feel wrong even when it looks right. Matching the substrate — whether that means laminated card stock, soft PVC wristband material, or Tyvek — is essential. If the correct material cannot be sourced, the credential will fail against experienced checkers even if it passes visual inspection.

Tip 4: Context Awareness — What Do You Actually Need?

Before investing effort in counterfeiting a credential, Phillips advises evaluating whether a credential is even necessary to achieve the goal. Classic physical social engineering vectors — claiming to be with a vendor, representing a band, delivering equipment — may provide access with no credential at all. Someone carrying a speaker through a back entrance will often get waved through on premise alone. The credential is a fallback, not the primary tool.

Tip 5: Accessorize

Event attendees typically carry more than just their badge. They have parking passes, event pamphlets, receipt printouts, branded merchandise. Adding these supporting artifacts to the presentation creates a holistic picture of legitimacy. A pamphlet retrieved from a trash bin near the entrance is essentially free corroborating evidence. Strategic placement of these accessories can also cover weak points on the credential itself — a spot where the counterfeit is not convincing can sometimes be obscured by an overlapping pamphlet or lanyard clip.

Tip 6: Anti-Counterfeiting Layer Awareness

Phillips provides a taxonomy of anti-counterfeiting technologies that event credentials commonly employ:

  • Material-based controls: Special substrates (Tyvek, security paper), thread weaving, tamper-evident layers
  • Visual security elements: Fine-line security printing, microtext, color-shift inks
  • Optical elements: UV fluorescent ink, lenticular graphics, holographic overlays
  • Composite elements: Multi-layer constructions where badge plus lanyard together form the authenticated credential
  • Referential elements: QR codes, barcodes, or RFID chips that are checked against a backend database
  • Cryptographic elements: NFC/RFID with signed payloads

The key insight is that for a given event, only a subset of these elements will actually be checked at the access point. Identifying which elements receive scrutiny and which are ornamental is the core intelligence task.

Tip 7: Counter-Surveillance Hygiene

Reconnaissance is necessary to produce a good counterfeit, but it must be conducted without triggering alerts. Modern events use CCTV systems and may have dedicated security staff watching for suspicious behavior near entry points. Photography near access points, repeated approaches without entry, and extended dwell time in front of checking areas are all behavioral indicators. Phillips recommends distributing reconnaissance over multiple days and across multiple individuals if possible, and blending into the environment by behaving as though legitimately present.

Tips 8–11 extend the framework into refinements: sourcing correct lanyard hardware, understanding how access zones with different credential types are managed, timing entry to coincide with high-traffic periods when checker attention is most diluted, and understanding that multi-day events typically have credential roll-overs that create additional windows.

Demo / PoC

▶ Watch: Aging technique: matching wear patterns of legitimate credentials (24:44)

Phillips brought physical credential samples to the talk and walked the audience through live analysis of genuine event credentials. Attendees were shown how to identify which security elements on a real badge would realistically be examined during entry, versus which elements existed purely for visual deterrence. The demonstration underscored his central argument: the gap between a "good" counterfeit and a "perfect" one is often irrelevant, because checkers are not equipped to detect details that fall within the gap.

The session included a hands-on examination phase where attendees could physically handle sample credentials and discuss their construction — a format that aligned with the DEF CON ethos of learning by doing.

Defensive Implications

▶ Watch: Defensive analysis: how event staff actually verify credentials at speed (33:43)

For event security professionals, the talk is a prescriptive list of what to fix:

Train checkers on what to check. If your credential includes a UV element, provide UV lights at entry points and train staff to use them. Security elements that are never verified provide no security.

Randomize credential elements per event day. Credentials that are identical across all days of a multi-day event give attackers a longer window to study and replicate them. Introducing daily variation — color, hologram design, a printed date — reduces the effective counterfeiting window.

Use composite credentials intentionally. The badge-plus-lanyard composite is an underutilized security feature. Event organizers should design lanyard hardware that is difficult to source (custom clasps, unusual weaves) and brief staff to notice mismatch.

Layer referential checks. Adding a database check for even a percentage of entrants changes the threat model significantly. Selective random scanning creates uncertainty for counterfeiters who cannot guarantee their badge will avoid the scanner.

Conduct red team exercises. Hiring people to attempt entry with counterfeit credentials before the event is the only reliable way to discover where the real weaknesses are. Security by obscurity is not a substitute for tested security.

Key Takeaways

  • Event credentials rely heavily on obscurity and the time-bounded nature of their use. These are weaker foundations than they appear.
  • The composite nature of badge-plus-lanyard is the highest-leverage underutilized security control in event credentialing.
  • Social engineering and behavioral elements outperform technical counterfeiting in most real-world access scenarios.
  • Counter-surveillance awareness is as important as credential quality — a perfect credential carried by a flagged person provides no benefit.
  • For defenders, the actionable path is verification training, daily credential variation, composite design, and red team exercises.

About the Speaker

Russell Phillips works in security and operations for South by Southwest (SXSW), the Austin-based cultural festival and conference that annually hosts tens of thousands of credentialed attendees across music, film, and interactive programming tracks. His work involves designing and implementing physical access control systems at scale — an environment where credential integrity is operationally critical and threat actors range from opportunistic scalpers to sophisticated social engineers. His DEF CON 33 talk reflects years of practical experience observing both the failures of real credentials and the ingenuity of real counterfeiters.

Reviews

Dr. Zero (Offensive Security Researcher) — WEAK

Practical walkthrough of event credential counterfeiting from an SXSW security professional. Good operational tradecraft, useful for physical security practitioners, but light on technical depth, not novel research, and doesn't belong in DEF CON's main content lineup.

Heather Calloway (CISO) — WEAK

A practitioner from SXSW walks through eleven tips for counterfeiting event credentials, framing the exercise as a red team methodology lesson for event security professionals. Competent for its audience. The security implications do not extend beyond the event access control domain.

→ Top-rated talks at DEF CON 33

All talks from DEF CON 33