Tom Chothia

Teaching & supervision

Students

Security is learned by doing, so most of what I teach is built around attacking something real in a sandbox and writing up what broke.

Project ideas for 2026

I only take challenging, research-focused projects. Current suggestions:

  • Security of online payments and payment APIs
  • Developing security test methods for EMV bank cards
  • Long-range radio interception of EMV bank cards
  • Analysis of the Microsoft Authenticator app
  • A deep dive into Windows OS security
  • Windows kernel security, game cheats and anti-cheat systems
  • A game that teaches ROP attacks, in the spirit of Human Resource Machine
  • Educational cyber security games in Unreal Engine
  • Genuinely good man-in-the-middle network software
  • The security of industrial control systems
  • Which rail safety incidents are actually IT-related?

Courses and summer schools

Modules I currently teach

  • Security of Real-World Systems (06 30231), 20 credits, third year undergraduate, semester 1. Finding and fixing real vulnerabilities: weak cryptography, buffer overflows, protocol flaws and common web vulnerabilities, using reverse engineering and network analysis tools.
  • Forensics, Malware and Penetration Testing (06 34233), 20 credits, masters, semester 2. Identifying vulnerabilities across software and hardware, analysing compromised systems, and writing the findings up as formal reports.

Material for both lives on Canvas and is not public.

A Finite Number of Monkeys

I co-founded and named Birmingham’s student hacking club, which is also why there is a monkey on the front page of this site.

afnom.github.io