Dev Lahrani
I am a security researcher and undergraduate engineer at VIT Pune. My primary technical focus is on offensive application security, applied cryptographic protocol design, and threat intelligence.
Field Notes serves as my public vulnerability research log. Every entry documents the exact methodology, findings, technical root-causes, and defensive lessons from live security assessments.
Technical Domains & Tooling
Featured — Veli Chat
Veli Chat — E2EE, serverless, ephemeral terminal chat over Tor
v0.4.2 ↻ stars… MIT
Two-party, end-to-end encrypted, serverless terminal chat that leaves nothing on disk. Every session generates an ephemeral X3DH bundle + Tor v3 onion, exchanges a single invite code out-of-band, completes a Double Ratchet handshake, then speaks XChaCha20-Poly1305 over padded 6-bucket frames. Keys, ratchet state and history live in RAM only and are wiped on /quit.
npx veilchat — or — npm i -g veilchat && veil
gen X3DH bundle + onion → share one invite code OOB → dial .onion via Tor → X3DH → Double Ratchet → chat → /quit wipes all state. Verify with /whois safety numbers (4×4 grid) aloud.
Resume & Contact
Seeking Security Internships for 2026 in Application Security, Penetration Testing, or Cryptography.