Hack.lu 2026

Nicolas Seriot

Nicolas Seriot is a security engineer. His earlier work focused on iPhone privacy, the Twitter API, and JSON parsing. He now writes about unusual corners of computing, most notably PostScript programming. His articles appear in Paged Out! magazine, his code lives at github.com/nst, and he is reliably drawn to making everyday tools do things their designers never intended.


Session

10-21
11:45
30min
Unintended Computations
Nicolas Seriot

A printer language, a Jira rule, and Unicode transliteration are rarely treated as execution environments. Yet ordinary features can compose into something much more powerful than their intended role suggests.

This talk asks a simple question: what can this system compute?

We start with a network printer playing chess, then make the question systematic. A universal two-counter machine is assembled from ordinary text utilities, then rebuilt in Jira automation. Finally, universal computation emerges from Unicode transliteration rules.

Across these examples, the same pattern appears: state, conditional choice, and feedback. Together they can create an unexpected programmable substrate even when no individual component looks like an interpreter.

But computational power alone is not a vulnerability. The security questions come next: who can steer the computation, what operational bounds constrain it, what authority does it inherit, and what trust boundaries can it cross?

The result is a practical method for finding unexpected execution surfaces hidden inside ordinary systems and their composition.

topic: hack.lu
Europe