
Welcome to the Security devroom.
Nine talks made it in this year. Azim and Ayushman will take apart a smart IP camera on stage, from the PCB to the binaries inside it. Gautham and Alwin from bi0s will pull an AES key out of a microcontroller using a ChipWhisperer. serv0id reverse engineered the “encrypted” QR code on the new PAN cards and wrote an open source reader for it. Nisarga is talking about the CBSE exam portal bugs that made the news in May, and what disclosing them to a government body was like. Hamdaan found a way around a security fix in Axios and got a CVE for it. Shreyas (Georgia Tech) has a paper on what age verification vendors actually collect in your browser. And for the people building defences: Saniya on adding script analysis to capa, Philippe Ombredanne on his plan to sort out the CVE mess, and Raunak on building sandboxes from plain Linux primitives.
Bring questions.
Join us at IndiaFOSS 2026 in Bengaluru, 26–27 September. Day 2, Hall 3 (Ground Floor). Here's the schedule:
| Time | Session |
| 10:00 AM | Welcome to the Security Devroom |
| 10:05 AM | Reverse Engineering the PAN QR Code |
| 10:20 AM | When NO_PROXY Lies: Finding an IPv4-Mapped IPv6 Patch Bypass in Axios |
| 10:35 AM | Extracting AES Keys from Embedded Devices Using Open Source Hardware |
| 10:55 AM | The Art of Userspace Sandboxing on Linux |
| 11:20 AM | Extending Capa for Malicious Script Analysis |
| 11:35 AM | Keeping an Eye on your Eye: Disassembling and Reassembling Smart Camera Hardware to breach YOUR Security |
| 12:05 PM | Hacking India's Largest Exam System |
| 12:20 PM | Papers, Please: A First Look at Age Verification on the Web |
| 12:45 PM | A plan to sort out this CVE mess |
A few practical things
Supply chain, hardware and firmware, offensive research, appsec, infra and cloud-native, crypto and privacy, OSINT, radio, and AI security. Basically anything security where the tooling is open.
This devroom is managed by:
Devroom Managers