All events

VIScon Workshop: Hunting for bugs in the e-ID

VIScon

Event start time 10.10.2026 14:00

Event end time 10.10.2026 17:00

Add to calendar: ics Google

This event is only available for VIScon Symposium or Hackathon participants, as well as Helpers! Please sign up for one of these events first!

In this workshop, students will get an introduction on the technical foundations of the Swiss e-ID and will learn how to set up their own infrastructure to issue a custom credential, the VISCon-ID, and verify it. After that, they will go on to configure a pentesting setup for their ecosystem, where they will learn how all components interact with each other at every step of the credential issuance and presentation processes.

Since early 2025 the Federal Office of Information Technology, Systems and Telecommunication (BIT/OFIT/UFIT) has been developing an electronic ID to serve as the digital counterpart of physical documents (passports, driving licenses, national ID cards, ...). To guarantee the security of the ecosystem, the BIT implemented several security measures such as a bug bounty program and regular internal and external reviews.

After this workshop, students will be able to set up their own e-ID infrastructure using the open-sourced swiyu components, and will be able to start hunting for bugs. Because the e-ID shares many similarities and standards with related initiatives, their newly gained experience will also allow them to perform bug hunting on other systems based on OID4VC/OID4VP as is the case with EU's eIDAS.

Students do not require any specific knowledge before coming to the workshop. At the end of the course, the instructor will share a Packer script to automatically create a VM with an Issuer, a Verifier and VSCode already configured.

Additional slots might become available later on. Please use the waiting list!

The VSETH General Privacy Policy applies to this event.

Details and Prerequisites

Workshops may require items VIScon cannot provide (e.g., a Laptop) which you have to bring with you or to set up something (e.g., install software) that would otherwise take up a significant chunk of the workshop. You may also need knowledge in certain fields (e.g., how to program in a specific language). All of this information can be found in the following paragraphs, so you can decide whether you want/can participate in this workshop, or not.

What you have to bring to the workshop:
  • A Laptop
  • (Optional) A physical Android device for testing (no root required)
What you have to do before the workshop:
  • Students are encouraged to bring a VM with Debian 13 and all the dependencies (git, adb maven, openjdk-21-jdk, Visual Studio Code and Android Studio) installed
  • Android Studio with an emulated device already created. If the student has a physical Android device for testing (no root required), they can also use it.
Knowledge requirements(/recommendations) for this workshop:
  • Familiar with the linux command-line (cd, clone + compile dependencies, etc.)
  • Basic Java knowledge to understand the code structure is a plus

FAQ

Why can't I sign up for this workshop?

If you signed up for the main event after the early access deadline (8:00pm, 17th of September), you can sign up from the 20st of September. But don't worry, we will send you a reminder when the sign up opens. Early access is our way to thank early supporters!

The fine print

  • By participating you agree that pictures and videos can be taken of you that could be used for VIS-Purposes (VISIONEN, Instagram, etc)

  • By participating, you agree to adhere by the VIS Code of Conduct

  • Every participant is responsible for their own insurance

  • All statements are made without guarantee

  • In general, there are no refunds

Event organisers

Main event organiser Kaushik Vempati

Co-organisers