π₯ Roast My Pick Β· SIH26159
SecureMailScope: AI-Assisted Cryptographic Security Posture Assessment for Secure Email Communications
National Technical Research Organisation (NTRO)
Good pick. Genuinely. Now sit down, because the judges are going to try anyway β and this is what they will try.
Strong pick. One of the cleanest NTRO problems β you generate your own data, the core is reliable deterministic protocol analysis, and the demo constructs itself, so build the assessment solidly and be honest that the AI is for prioritisation rather than the core verdict. Roughly 70β160 teams are expected to go here.
The receipts
Every red flag on this statement, in full. These are the four places it bites.
Exhibit A
Much of this is rule-based protocol analysis, so be honest that the AI adds value in prioritisation and anomaly detection rather than doing the core assessment, or the ML framing looks bolted on
It gets worse
Once TLS is fully established the traffic is encrypted, so a passive tool sees the handshake and certificate but not the content, which bounds what you can assess
Still reading?
Modern email increasingly uses TLS 1.3 which resists downgrade, so ensure your test data includes the weak legacy configurations the tool is meant to catch
And the finisher
Certificate validation has many edge cases, and getting chain validation subtly wrong produces false findings
The damage report
Every score this statement earned, and what each one actually costs you.
Feasibility
4/5Actually buildable, which on this slate is rarer than it sounds. Do not squander it on scope.
The description explicitly says participants generate their own PCAP data with any mail server and client, which removes the data barrier entirely, and TLS handshake parsing and certificate validation are well-supported in existing libraries, so the whole framework is buildable.
Innovation scope
3/5Mildly interesting. The novelty will not carry the room; the build has to.
Much of this is deterministic protocol analysis dictated by TLS standards, so the AI adds value mainly in anomaly detection and risk prioritisation rather than in the core assessment, which is rule-based by nature.
Clarity
5/5The ask is unambiguous, which quietly removes your favourite excuse.
The description names the protocols, the specific weaknesses to detect, the reconstruction and validation steps, the intended users and how to generate the data, making the requirement exceptionally complete.
Acceptance potential
4/5Strong footing before you have written a line. Try not to waste it.
A strong pick β you generate your own data so there is no sourcing risk, the specification is complete, the core protocol analysis is deterministic and reliable rather than dependent on shaky model accuracy, and it addresses a genuine gap since existing tools decode traffic but do not assess crypto posture.
Effort
HeavyHeavy. Somebody on this team is not sleeping in week three. Pick who, on purpose.
Session reconstruction from PCAP, TLS negotiation analysis, certificate validation, weakness detection and the risk-prioritisation layer are focused, well-bounded pieces on data you generate yourself.
Demo-ability
EasyEasy to demo β and so is everyone else's. Working is the floor here, not the achievement.
A good session and a downgraded session side by side, with the weak one flagged and ranked, is a clean, concrete demonstration you can construct exactly to show the tool's value.
The demo they will have already seen
Somewhere around 70β160 teams are heading here, and the description is doing the choosing for most of them. They will read the same brief, reach the same architecture, and build a version of the same demo you are planning. Being correct is the floor. If your five minutes could be swapped with the team before you and nobody in the room would notice, you have not picked badly β you have built predictably, which costs exactly the same and hurts more.
What survives
The ground worth standing on when the questions start.
- You generate your own PCAP data with any mail server, so there is zero data-sourcing risk and you can craft exactly the weak configurations you want to demonstrate
- The core analysis is deterministic protocol inspection, so most of your verdict is reliable ground truth rather than model output
- The good-session-versus-downgraded-session demo is clean, concrete and directly proves the tool's value
Nothing here is fatal. It is just the list of places this statement pushes back, and you now get to push there first.
The framing is a joke. The findings are not β they are the same analysis on the statement page, and every line above is attached to a score or a fact in the record. It is one opinion with its reasoning attached, so argue with it before you trust it.