
Category
Security Kultur
Topic
Hacking & Democracy
Audience
The public & schools
Reading time
approx. 7 minutes
At the end of August, we spent two days travelling with Mint Secure across two federal states: on 26 August at the theatre in the Hanseatic city of Wismar and on 27 August at the Salt Works Museum in Halle (Saale). The occasion was the Democracy Days, held under the motto ‘My vote counts! Experience, shape and celebrate democracy!’ – an event designed by pupils for pupils and organised jointly by the Chair of Social Ethics at the University of Bonn, the Federal Pupils’ Conference and the GermanDream educational initiative.
The timing was no coincidence. In Mecklenburg-Western Pomerania, a new state parliament will be elected on 20 September 2026; in Saxony-Anhalt, the election had already taken place on 6 September. Many of the young people in the audience on those two days will be voting for the first time – or are about to do so. We found the idea of organising an event during this very timeframe – one that doesn’t merely explain democracy but makes it a tangible experience – compelling even before we gave our commitment. And even more so after those two days.


Our workshop: What ‘hacking’ actually means
Felix and Tim from our team ran the workshop ‘Learn to Hack! But for the Good Guys’ at both locations – each session was for a group of Year 10 and Year 11 pupils, lasted around 90 minutes, and featured far more live demonstrations than a slide presentation.
We began with a question to which there are a surprising number of answers: what exactly is hacking? The image most people have in mind comes from films and the news – hoodies, dark rooms, crime. Yet the essence of the term is quite different. A ‘hack’ is, first and foremost, a technical trick. Hacking is the creative, inventive use of technology: an extension of functionality, a solution to a problem, or simply a goal achieved in an unconventional way. The fact that, alongside malicious motives, there is also such a thing as ethical hacking – and that this is a profession in its own right – was new to some members of the group.
Hacking is the creative, inventive use of technology: expanding functionality, solving a problem, or simply achieving a goal by unconventional means.
Bevor es technisch wurde, haben wir über die Hackerethik gesprochen, wie sie beispielsweise der Chaos Computer Club formuliert hat. Ein paar der Punkte haben dabei die Schüler:innen besonders interessiert:
- Der Zugang zu Computern und allem, was einem zeigen kann, wie diese Welt funktioniert, sollte unbegrenzt und vollständig sein.
- Öffentliche Daten nützen, private Daten schützen.
- Misstraue Autoritäten – fördere Dezentralisierung.
- Beurteile einen Hacker nach dem, was er tut, und nicht nach Aussehen, Alter, Herkunft, Geschlecht oder gesellschaftlicher Stellung.
- Mülle nicht in den Daten anderer Leute.
Und wir haben deutlich gemacht, was rechtlich gilt: Alles, was wir zeigen, ist für Lern- und Lehrzwecke gegen eigene Systeme gedacht. Unbefugte Nutzung kann eine Straftat sein (wie wir selbst schon öfter gemerkt haben). Aus großer Macht folgt große Verantwortung – abgedroschen, aber in diesem Kontext einfach richtig.

From theory to the hack lab
Next, we turned our attention to the technical side. First, we set up a web application – client, front-end, back-end, database – as a shared model that we could refer back to time and again later on. Then came the question: how does one actually attack a website? Gather information, launch an attack. Our own, deliberately vulnerable online shop in the Hack-Lab served as a testing ground, which the groups were initially allowed to explore for themselves. The ideas that emerged from the audience on both days were remarkably good.
In terms of content, we then worked our way through the classics:
- Account Hacking
Username Enumeration – also das Herausfinden gültiger Benutzernamen, weil eine Anwendung zu gesprächig antwortet. Und Bruteforcing beziehungsweise Wörterbuchangriffe auf Passwörter, live vorgeführt mit Hydra. Die anschließende Übersicht dazu, wie lange das Durchprobieren eines Passworts je nach Länge und Zeichenvorrat dauert, vermittelt in einer Minute mehr über gute Passwörter als jedes Merkblatt – und macht die Diskussion über Passwortmanager zu etwas anderem als einer Belehrung. - IDOR (Insecure Direct Object Reference)
Der “Angriff” besteht darin, eine Zahl in der URL hochzuzählen – und dass man dann plötzlich die Bestellung einer fremden Person sieht. Kein Spezialwissen, kein Werkzeug, nur genaues Hinschauen. Hier kam “Mülle nicht in den Daten anderer Leute” dann zum Einsatz. - Cross-Site-Scripting (XSS) Erst harmlos: eigenes HTML in eine Seite einbetten, dann ein Bild. Danach der Schritt weiter – was Cookies sind, wozu Sessions dienen, und was passiert, wenn jemand einen Session-Cookie stiehlt. Die Live-Demo, in der wir eine Payload in einen Artikel injizieren und anschließend einen fremden Account übernehmen, ist erfahrungsgemäß der Moment, an dem aus einem abstrakten Sicherheitsthema etwas sehr Greifbares wird.
To round off, here’s a glimpse of what we didn’t have time to cover in 90 minutes: SQL injection, SSRF, broken access control, CSRF, clickjacking and Path Traversal – plus tips on where you can practise these techniques legally on your own. A few young people stayed behind afterwards and wanted to know how one actually ends up working in this field. For us, conversations like these are the real reward of a workshop, and we’re grateful to be able to pass on our knowledge in this setting.
Warum Demokratie und IT-Sicherheit zusammengehören

Ein Tag mit vielen Stimmen
As much as we are attached to our own format, the best thing about both days was actually the surrounding activities. Each day began with a plenary session featuring three short talks. What was remarkable about this was the format: no lectures on democracy, but personal stories. How does one even come to get involved in the first place? When did you first realise that your own voice makes a difference – and what do you do with the feeling that it isn’t making a difference right now? The speakers shared their experiences of student council work, educational initiatives and climate activism – told honestly and at just the right pace for an audience of 15- and 16-year-olds. The effect was palpable: democracy was presented not as an institution, but as something that people do.
The workshop programme was also remarkably wide-ranging, and it was striking to see just how different the approaches to the same topic can be. Some of the sessions took an artistic approach: rap and graffiti as a way of giving expression to a stance, or movement and bodywork as a starting point for exploring when one dares to become visible. Others took a discursive approach: a dialogue on values, in which young people sorted through and weighed up their own core beliefs; a workshop exploring what actually shapes one’s own identity; and a session on dealing with fake news, which provided practical training in verifying and evaluating sources. Still others focused on play and a change of perspective – board games as a model for negotiation processes, or a session in which young people were asked to design ‘screenshots from the future’, thereby posing the question of what sort of society they actually want to live in. In addition, there was a workshop on taking action itself: how do I turn an opinion into concrete action? And for the accompanying teachers, there was a dedicated programme on teaching democracy in the classroom.
We found the common thread running through all the workshops to be compelling: nowhere was the aim to teach the young people the ‘right’ opinion, but rather to equip them with tools – artistic, rhetorical and technical – with which they can find and express their own views. Our hacking workshop fitted in better with this approach than we’d have thought beforehand.
In the afternoon, the ‘Debate Box’ session took place: pupils discussed deliberately polarising questions in pairs, each time with limited time and different discussion partners. The format is not about being right, but about being able to justify a position and remain in dialogue despite disagreement – a skill that is difficult to teach in theory and which was simply practised here. The event concluded with a joint concert. The organisers’ overarching programme – listening, reflecting, experiencing, celebrating – truly came to fruition over the two days.
Ein Tag mit vielen Stimmen
What has stayed with us most of all is the atmosphere. Open, respectful, curious – without the heaviness that such topics often bring. The young people came with genuine questions; the organising team prepared both days very well and still managed to run things in a relaxed manner; and amongst the speakers, the tone was collegial and engaging. During the breaks and at lunch, conversations arose that we’d like to continue – with people from the fields of political education, academia and cultural work, who work on completely different topics to us but share the same question in mind: how do you really reach young people?
We love to network. If you work at a school, for an organisation or in an educational setting and would like to offer a hacking workshop, a talk or a Live-Hacking session – please get in touch. And if you’ve come across any of the other events at the Democracy Days: the team there are doing a brilliant job that deserves much more recognition.
A big thank you goes to the Democracy Day team, the University of Bonn, the Federal Pupils’ Conference and GermanDream for the invitation and for organising the event – and to the pupils in Wismar and Halle, who really put us on the spot with their questions. We’d love to come back.

How Mint Secure makes a contribution
🔬
security research
We identify previously unknown vulnerabilities and report them responsibly before they cause any damage.
🎤
Talks & Live-Hacking
We make cyber attacks visible and explain them in a way that is easy to understand, from school classrooms to specialist conferences.
🛡️
Penetration Testing
We test systems from an attacker’s perspective so that vulnerabilities can be addressed whilst there is still time.
🤝
Awareness & Consulting
We empower organisations and individuals to identify digital risks for themselves.
Are you planning an event? We organise Live-Hacking sessions, talks and workshops for schools, businesses and conferences. Get in touch.
Don’t just take the system at its word; check for yourself. This approach protects both computers and democracy in equal measure.
Mint Secure GmbH
