Security Fest 2018 Challenge Badge
USB HID and serial puzzle badge
A simple Security Fest 2018 challenge badge with USB-A, two buttons, four DIP switches, red/green LEDs, HID text output, serial puzzle flow, and an open SecBadge hardware repository.
Country dossier
Worldwide badge coverage for Sweden, grouped into seeded badges, event editions, add-ons, operational issues, resources, and evidence sources.
Seeded artifacts
USB HID and serial puzzle badge
A simple Security Fest 2018 challenge badge with USB-A, two buttons, four DIP switches, red/green LEDs, HID text output, serial puzzle flow, and an open SecBadge hardware repository.
Blinky Gothenburg tram badge
A conservative first-pass record for Security Fest's 2022 tram-inspired badge, remembered in later badge writeups as a fun blinky object inspired by Gothenburg trams with a Rickroll reference.
UV-printed cyberpunk skyline CTF badge
A full-colour UV-printed Security Fest badge inspired by Gothenburg's skyline with a cyberpunk treatment, backside-mounted components, Micro-USB CTF interface, cryptography puzzles, and soldering-village LED personalization.
Music-and-airship CTF building badge
A Security Fest 2024 badge shaped around Gothenburg's Feskekôrka fish-market landmark, with piano/touch-key gameplay, an airship story CTF, LEDs, USB-C serial interaction, and documented attendee/speaker/crew variants.
NFC-updatable passive four-color e-paper developer-conference badge
Flutter & Friends' organizer-published conference-app source added a Friends Badge editor on August 30, 2025: users could select an image, preview it with dithering, and write it to the conference badge through NFC. The companion `friends_badge` package explicitly describes control of the Flutter & Friends e-paper conference badge, and its implemented target profile is a passive four-color e-paper device. The source-backed record establishes a real event-linked electronic artifact at the completed Stockholm conference, but does not establish that every attendee received one, that it served as admission, or what final physical units contained.
Source-backed RP2040 LED-matrix conference badge
Security Fest 2026's public firmware repository identifies this as the official conference badge: a small, hackable RP2040 device with a 9×9 LED matrix, six buttons, USB surface, and public firmware. The official event site confirms the completed May 28-29 Gothenburg conference, while a contemporaneous attendee report credits Carl Vargklint's badge work. Allocation and delivery are not documented.
Events
The Swedish Security Fest edition with a simple but public challenge badge built around USB HID, serial output, DIP-switch paths, and an open SecBadge hardware repository.
The Swedish Security Fest edition with a publicly remembered tram-inspired badge that blinked lights and included a Rickroll reference.
The Swedish Security Fest edition with a UV-printed Gothenburg Skyline CTF badge, soldering-village LED personalization, and serial cryptography challenges.
The Swedish Security Fest edition with the Feskekôrka Piano Badge, a music-and-airship CTF badge documented through Hackster and Hackerware build notes.
The August 31-September 2, 2025 Stockholm Flutter and Dart developer conference at Kulturhuset Stadsteatern. Its organizer-published conference-app source encodes the event schedule and, on August 30, added a Friends Badge extra that lets users select and dither an image before writing it to an e-ink conference badge through NFC. The source confirms an event-linked electronic artifact and mobile workflow, but not ticket eligibility, attendee-wide allocation, credential use, final physical configuration, or media rights.
The completed May 28-29, 2026 Security Fest edition in Gothenburg. Its public firmware repository calls the associated artifact an official, small hackable conference badge and documents an RP2040, LED matrix, buttons, USB surface, and public source tree; allocation, final production revision, and image rights remain unproven.
Lifecycle
Hackerware documents sticking a mini speaker on the backside and soldering its leads at LS1 to play the piano.
The same retrospective source preserves the badge's Rickroll reference as part of its social memory.
The companion package documents image transfer to the badge through NFC using a Type 4/NfcA tag workflow. This identifies the update surface without exposing a claim about any active radio or every event unit.
The later writeup remembers the 2022 badge as a fun blinky badge inspired by Gothenburg trams.
The writeup documents multiple clue texts triggered by toggling DIP switches and pressing a badge button, turning a small hardware input surface into the puzzle selector.
The badge CTF is framed as an airship journey with touch-key and serial navigation, games, riddles, and harder crypto, reverse-engineering, and memory-corruption challenges.
The badge CTF uses a serial monitor at 9600 baud; sending three stars enters CTF mode and solving eight cryptography puzzles unlocks eight building lights.
The badge presents itself as both HID and serial; HID button output gives onboarding and clues, while listening on the serial interface reveals the path into the PGP/key-recovery challenge.
The public README documents a 9×9 IS31FL3731 charlieplexed LED matrix and four front LEDs as the badge's visible interaction surface.
The repository's public Arduino/C++ source describes display states, animations, games, and personalization for the badge without establishing a final production firmware image for every unit.
Hackerware documents replacing C1 and C2 with 22 pF capacitors, then adding SMD LEDs and resistors at D9-D13 and R8-R12 to play the CTF and unlock airship lights.
Security Fest hosted a soldering village so attendees could solder their own LEDs in chosen colours and personalize the badge.
The package crops, resizes, and dithers an image before sending raw, uncompressed, column-major bitmap data to the documented badge target.
The package's implemented BadgeSpecification profile is a passive 240×416, 3.7-inch black/white/yellow/red target. It is the documented software target, not a full bill of materials or physical-production record.
The README documents USB CDC, controller/HID-capable USB behavior, an SAO port, and marked GPIO. It does not identify a supported add-on ecosystem, compatibility list, or final per-unit wiring revision.
The dated conference-app commit adds Android NFC declarations and iOS NFC reader configuration alongside the Friends Badge feature. This is source evidence for app integration, not a guarantee of device compatibility or successful writes for every participant.
The organizer-published app exposes a Friends Badge extra where a user can select an image, preview it, and invoke the badge write action. The source records a public customization interface, not a particular attendee's installed build or completed update.
Operational history
The record does not claim Bluetooth, BLE, a battery, or active-radio behavior for the actual conference badge merely because the reusable package documents additional protocol families.
The catalogue records a factual event-linked electronic badge and companion workflow without upgrading it to an all-attendee entitlement, admission credential, or distribution ledger.
The entry keeps open-source companion software separate from physical-badge firmware, event deployment, trademark/media rights, and any implied image-reuse permission.
The record captures the real operational work behind the polished attendee artifact and preserves a useful production failure mode for future badge teams.
The record can document a real event artifact without converting the public source trail into unsupported issuance or credential claims.
The compendium records this as a practical attendee caveat rather than an unresolved defect: the badge was intentionally open and modifiable, but not frictionless.
Hardware detail remains source-bounded, and the catalogue does not claim that every shipped board matched the repository's documented configuration.
Source code can be linked as evidence, but no repository media or event imagery is copied into the public catalogue and the badge remains image-free.
This is a useful lifecycle record: the badge was partly a shipped object and partly an on-site hardware workshop artifact.
The entry describes only the source-backed interface and target profile rather than reconstructing unsupported electronics or treating generic documentation as a final physical specification.
The Sweden record remains source-backed and image-free rather than copying source-page media, documentation screenshots, event photos, social media, placeholders, or generated approximations.
The Sweden record remains source-backed and image-free rather than copying source-page media, documentation screenshots, event photos, social media, placeholders, or generated approximations.
The Sweden record remains source-backed and image-free rather than copying source-page media, documentation screenshots, event photos, social media, placeholders, or generated approximations.
The Sweden record remains source-backed and image-free rather than copying source-page media, documentation screenshots, event photos, social media, placeholders, or generated approximations.
The Sweden record remains source-backed and image-free rather than copying source-page media, documentation screenshots, event photos, social media, placeholders, or generated approximations.
The source-backed facts remain useful while the catalogue withholds imagery until licensed original photos are curated.
The badge intentionally blurs software play with hands-on hardware rework; the compendium tracks that as a lifecycle/challenge caveat.
The catalogue records their existence at a high level but does not publish operational configurations or represent them as tested, unrestricted, or universally fitted features.
The dossier keeps the 2022 badge discoverable while avoiding chip-level, firmware, app, production, or author claims until primary sources are recovered.
The record remains source-backed for facts, while the catalogue withholds imagery until a licensed original photo is curated.