Join us at hack.lu 2026 — Info & Registration
Duration: 30 min
Type: Talk
Speakers: Nicolas Seriot
Abstract
A printer language, a Jira rule, and Unicode transliteration are rarely treated as execution environments. Yet ordinary features can compose into something much more powerful than their intended role suggests.
This talk asks a simple question: what can this system compute?
We start with a network printer playing chess, then make the question systematic. A universal two-counter machine is assembled from ordinary text utilities, then rebuilt in Jira automation. Finally, universal computation emerges from Unicode transliteration rules.
Across these examples, the same pattern appears: state, conditional choice, and feedback. Together they can create an unexpected programmable substrate even when no individual component looks like an interpreter.
But computational power alone is not a vulnerability. The security questions come next: who can steer the computation, what operational bounds constrain it, what authority does it inherit, and what trust boundaries can it cross?
The result is a practical method for finding unexpected execution surfaces hidden inside ordinary systems and their composition.
Description
Security reviews usually ask what a component is for. This talk asks what it can compute.
The distinction matters because programmability can emerge through composition. Individually mundane features may collectively provide state, branching, and feedback - enough to implement a recognizable computational model.
We begin with a deliberately playful example: a network printer running a chess engine in PostScript. The point is not the printer itself, but the abstraction failure: describing a system by its intended purpose can hide capabilities that are relevant to security.
We then apply a repeatable method to progressively less obvious substrates:
- POSIX text utilities: ordinary commands compose into a universal two-counter Minsky machine. No individual utility is remarkable; the computation appears in their composition.
- Jira automation: the same computational model reappears in a workflow engine. The substrate changes, but the underlying machine does not.
- Unicode transliteration: state, ordered rewrites, and repeated application are sufficient to express universal computation. What looks like declarative text transformation becomes a programmable execution surface.
The hunting method is simple:
- Find where the system can hold state.
- Find where behaviour depends on that state - choice.
- Find whether results can influence subsequent processing - feedback.
From there, map the available primitives onto a known computational model and determine how far the system can go.
Theoretical expressiveness is only the first step. Real systems impose quotas, size limits, iteration bounds, timeouts, permissions, and sometimes require repeated invocation. These operational constraints determine whether the theoretical machine is actually reachable.
Security significance requires another layer. An unexpected computer may be harmless. The important questions are whether an attacker can steer it, what authority it inherits, and whether it can act across a trust boundary.
Finding a hidden computer is interesting. Finding one an attacker can steer is more interesting. Finding one that acts with someone else’s authority is a security problem.
Attendees leave with a repeatable way to identify unexpected execution surfaces and evaluate when they become meaningful attack surface.
Target audience: security researchers, red teamers, pentesters, defenders, and anyone interested in what ordinary systems can be made to compute.