Security
Software, Hardware or Radio. Break it or protect it.
Welcome to the Security devroom.
Nine talks made it in this year. Azim and Ayushman will take apart a smart IP camera on stage, from the PCB to the binaries inside it. Gautham and Alwin from bi0s will pull an AES key out of a microcontroller using a ChipWhisperer. serv0id reverse engineered the “encrypted” QR code on the new PAN cards and wrote an open source reader for it. Nisarga is talking about the CBSE exam portal bugs that made the news in May, and what disclosing them to a government body was like. Hamdaan found a way around a security fix in Axios and got a CVE for it. Shreyas (Georgia Tech) has a paper on what age verification vendors actually collect in your browser. And for the people building defences: Saniya on adding script analysis to capa, Philippe Ombredanne on his plan to sort out the CVE mess, and Raunak on building sandboxes from plain Linux primitives.
Bring questions.
Join us at IndiaFOSS 2026 in Bengaluru, 26–27 September. Day 2, Hall 3 (Ground Floor). Here's the schedule:
| Time | Session |
| 10:00 AM | Welcome to the Security Devroom |
| 10:05 AM | Reverse Engineering the PAN QR Code |
| 10:20 AM | When NO_PROXY Lies: Finding an IPv4-Mapped IPv6 Patch Bypass in Axios |
| 10:35 AM | Extracting AES Keys from Embedded Devices Using Open Source Hardware |
| 10:55 AM | The Art of Userspace Sandboxing on Linux |
| 11:20 AM | Extending Capa for Malicious Script Analysis |
| 11:35 AM | Keeping an Eye on your Eye: Disassembling and Reassembling Smart Camera Hardware to breach YOUR Security |
| 12:05 PM | Hacking India's Largest Exam System |
| 12:20 PM | Papers, Please: A First Look at Age Verification on the Web |
| 12:45 PM | A plan to sort out this CVE mess |
A few practical things
- Lightning talks are 10 minutes, regular talks are 20, plus 5 minutes for questions. Sessions run back to back, so if you are coming for one talk in particular, come a few minutes early.
- A few talks have hardware on the table (camera boards, a ChipWhisperer, flash programmers). Sit up front if you want to see it.
- Speakers will hang around after their talks. Go say hi.
- The code of conduct applies. Try the techniques on your own hardware, or on things you have permission to poke at.
What this room covers
Supply chain, hardware and firmware, offensive research, appsec, infra and cloud-native, crypto and privacy, OSINT, radio, and AI security. Basically anything security where the tooling is open.
Devroom Managers
This devroom is managed by:
- Hritik Vijay - Sr. Product Security Engineer at CRED. Co-maintainer and Google Summer of Code mentor for VulnerableCode - an open source SCA solution. Presented at OSSNA, IndiaFOSS 3.0, nullcon, Blackhat.
- Akshansh Jaiswal - Senior Security Engineer at Atlan and one of India’s leading bug bounty hunters. Organized and hosted multiple bug bounty meetups and live hacking events across India. Also a frequent speaker at global and regional conferences such as Black Hat, ThreatCon, and BSides.