Devroom Glyph

Security

Software, Hardware or Radio. Break it or protect it.

Accepted Proposals

Welcome to the Security devroom.


Nine talks made it in this year. Azim and Ayushman will take apart a smart IP camera on stage, from the PCB to the binaries inside it. Gautham and Alwin from bi0s will pull an AES key out of a microcontroller using a ChipWhisperer. serv0id reverse engineered the “encrypted” QR code on the new PAN cards and wrote an open source reader for it. Nisarga is talking about the CBSE exam portal bugs that made the news in May, and what disclosing them to a government body was like. Hamdaan found a way around a security fix in Axios and got a CVE for it. Shreyas (Georgia Tech) has a paper on what age verification vendors actually collect in your browser. And for the people building defences: Saniya on adding script analysis to capa, Philippe Ombredanne on his plan to sort out the CVE mess, and Raunak on building sandboxes from plain Linux primitives.


Bring questions.


Join us at IndiaFOSS 2026 in Bengaluru, 26–27 September. Day 2, Hall 3  (Ground Floor). Here's the schedule:


TimeSession
10:00 AMWelcome to the Security Devroom
10:05 AMReverse Engineering the PAN QR Code
10:20 AMWhen NO_PROXY Lies: Finding an IPv4-Mapped IPv6 Patch Bypass in Axios
10:35 AMExtracting AES Keys from Embedded Devices Using Open Source Hardware
10:55 AMThe Art of Userspace Sandboxing on Linux
11:20 AMExtending Capa for Malicious Script Analysis
11:35 AMKeeping an Eye on your Eye: Disassembling and Reassembling Smart Camera Hardware to breach YOUR Security
12:05 PMHacking India's Largest Exam System
12:20 PMPapers, Please: A First Look at Age Verification on the Web
12:45 PMA plan to sort out this CVE mess


A few practical things


  1. Lightning talks are 10 minutes, regular talks are 20, plus 5 minutes for questions. Sessions run back to back, so if you are coming for one talk in particular, come a few minutes early.
  2. A few talks have hardware on the table (camera boards, a ChipWhisperer, flash programmers). Sit up front if you want to see it.
  3. Speakers will hang around after their talks. Go say hi.
  4. The code of conduct applies. Try the techniques on your own hardware, or on things you have permission to poke at.


What this room covers


Supply chain, hardware and firmware, offensive research, appsec, infra and cloud-native, crypto and privacy, OSINT, radio, and AI security. Basically anything security where the tooling is open.


Devroom Managers


This devroom is managed by:

  1. Hritik Vijay - Sr. Product Security Engineer at CRED. Co-maintainer and Google Summer of Code mentor for VulnerableCode - an open source SCA solution. Presented at OSSNA, IndiaFOSS 3.0, nullcon, Blackhat.
  2. Akshansh Jaiswal - Senior Security Engineer at Atlan and one of India’s leading bug bounty hunters. Organized and hosted multiple bug bounty meetups and live hacking events across India. Also a frequent speaker at global and regional conferences such as Black Hat, ThreatCon, and BSides.


Devroom Managers


Call For Proposals

Closed on 2026-06-28 11:59:00