
Niklas Klee and Felix Thümmler held a workshop at this year’s TINCON 26 in Berlin on the topic of ‘Web security from the perspective of (ethical) hackers’. Both sessions were fully booked well in advance. In addition, Tim Philipp Schäfers and Felix Thümmler took part in an open Q&A session with the audience on Wednesday 20 May. A brilliant experience!
What is TINCON?
TINCON (Youth Network Conference) is a gathering focused on young people’s digital culture. It is aimed particularly at young people aged between 13 and 25.
It was launched in Berlin in 2016 and has since been held regularly in the capital as well as in other cities such as Hamburg and Düsseldorf. The programme features talks, workshops, discussions and activities centred on topics such as the internet, coding, politics, media, sustainability and digital society.
What makes it special is that the content is created by young people for young people. TINCON sees itself as a mix of festival, conference and community platform, with a focus on learning, experimentation and networking. Entry is free for young people. TINCON 26 took place alongside re:publica at STATION Berlin in Kreuzberg.
About the workshop
Under the title ‘Web Security from the Perspective of (Ethical) Hackers’, Niklas and Felix took the participants on a journey into the world of ethical hacking. They showed how security vulnerabilities arise in websites and how hackers could exploit them in practice. Classic attack scenarios were not only explained in theory but also vividly demonstrated in Live-Hacking demos:
- IDOR (Insecure Direct Object Reference): How attackers can access third-party data through manipulated requests, demonstrated live using a specially prepared example online shop.
- Cross-Site Scripting (XSS):How attackers can inject malicious code into websites and what consequences this can have for users.
- Session Hijacking: How sessions can be hijacked and why secure cookie configurations are so important.
The workshop was deliberately designed to be hands-on. In secure, specially prepared training environments, participants were able to get hands-on and try out their first steps in Penetration Testing. The aim was to develop an understanding of how hackers think and which methods can be used to protect oneself effectively.
Another key focus was on the ethical dimension of hacking. Niklas and Felix made it clear why it is important to report security vulnerabilities responsibly (‘Responsible Disclosure’) and what role security experts play in our digitalised society.
The Q&A session on Wednesday
On Wednesday, 20 May 2026, Tim Philipp Schäfers and Felix Thümmler took part in an open Q&A session with the audience. The session was not a traditional panel discussion, but a lively and honest conversation with young people who were keen to probe deeper.
Tim Philipp Schäfers and Felix Thümmler
Among other things, the following topics were discussed:
- Hacker ethics: Where does the line lie between legal security testing and a criminal offence? And what responsibility do security experts have towards society?
- AI and job losses in cybersecurity: Is artificial intelligence replacing traditional security roles, or is it creating new opportunities for the next generation?
The discussion did not yield any simple answers, and that is precisely why it was so valuable.
Our conclusion
TINCON 26 demonstrated just how much potential young people have when given a real platform. We were inspired by the participants’ energy, openness and curiosity. Here, no one speaks down to others; instead, we think and learn together. We’d love to come back!

