* Episode 0: https://www.youtube.com/watch?v=przDcQe6n5o
* Challenge 1: https://hackerchess-web.h4ck.ctfcompetition.com/
* Challenge 2: https://aurora-web.h4ck.ctfcompetition.com/
* Episode 1: Coming soon
* Episode 0: https://www.youtube.com/watch?v=przDcQe6n5o
* Challenge 1: https://hackerchess-web.h4ck.ctfcompetition.com/
* Challenge 2: https://aurora-web.h4ck.ctfcompetition.com/
* Episode 1: Coming soon
I was actually doing something, was a bit curious, spent 30 seconds on it and thought "well this looks like a waste of time" and then scrolled through to see the comments and now I'm bouncing and going back to what I was doing.
The people better than me wouldn't have even done that.
The best and the brightest are busy doing stuff. Why would they even come in contact with stuff like this?
There are often cash prizes, comped travel, and companies are eager to give a lot of these people interviews. I'm fairly confident the US government is happy to shower this type of thing with money as well.
This is like ACM programming competitions. A significant number of the teams on ctftime.org represent colleges world wide.
CTF's come with points and scores and ranks. Why do people play recreational sports? Why do people do escape rooms or puzzle hunts or any of that other stuff?
As far as methods used to solve CTF problems, the practical knowledge gained from solving many CTF problems is directly applicable to future jobs in a way that other methods (like the majority of college homework) are not. If you do CTF's, you will definitely have to write programs that interact with file formats and you will definitely have to write programs that interface with webservers, and you are very likely to get into the esoteric edge cases of various languages that will result in a fairly deep understanding of how languages work past a few reserved words and a couple data structures. There are even problems that will draw you into learning about signal processing or how punch cards used to work.
There are many students who are doing higher level work than "pros" - the best and brightest are often bored out of their minds sitting in high school, undergrad, and graduate classes.
Don't discount the younger generation just because they don't have as much experience.
Like CTF (what this seems to be basically) and similar hacking competitions? Competitive programming?
There's a lot of clever people that really do not care for competitive recreation. You can be a serious scholar without also being an enthusiastic puzzlemaster
So CTF is just another form of cohort filtering masquerading as competence selection; a modern version of going for beers and golfing with a candidate and then wondering why you have a bunch of beer drinking golfers working for you
And that's why it's not there.
Just about any filter, even the most arbitrary one will work some of the time.
To go back to the previous analogy, plenty of competent people like beer and golfing and plenty don't. It's about trying to recognize what's culturally myopic and extricating those signals.
The parent comment said: "The best engineers and people I know with PhDs in computer security who can't reveal their employer really don't give a toss about games."
As a person who is a member of the very group you are speaking about, I find this statement to be completely non-factual.
Do CTFs identify the very best security minds? No. They are fun hobbies. But you didn't say that CTFs aren't useful for finding the very best hires. Instead you said that the very best hires do not enjoy CTFs at all. This is just straight up wrong. Both in academic and industrial circles.
Saying I personally know smart people who don't play games doesn't mean I'm claiming all people who play games are stupid.
This is extremely basic logic stuff here. Do you need me to draw you some pictures? I can do that
This is a set intersection. There's something called Venn diagrams that can help you here.
Any recruitment of a feature by a proxy can do at best the intersection of the proxy and the feature set.
That's the small overlapping slice of the diagram.
You can argue how big that intersection is but recruitment by feature, directly, is a better strategy unless the feature matches the proxy in which case it's equivalent.
So just go direct and skip the proxy.
There's a tendency to hire by games of arguable relevance these days as opposed to direct observations of work. The optimizing towards the game is fundamentally dysfunctional for team building and eventually product development.
It's not coincidental that valley tech has become more manipulation, extraction and distraction services than substantive products as a lagging indicator of this trend. (Of course there's macroeconomic forces as well. I mean, obviously, no shit)
I really can't put any more time into this
Their website has cyber security challenges and, apparently, if you complete all 12 levels you'll get a interview.
Honestly, it's pretty neat. If you hated resume bullshit, then that's a great option.
Or a knock on the door in the middle of the night and an attempted online trolling campaign, maybe with a free side of attempted fake-rumor-based reputation assassination irl too.
Anyway, what game should I pick up instead?
is the goal to hack the chess game or the admin panel? I never know how to do these things
Analyzing and listing out ways to interact with the site will show you your surface area, although sometimes the interaction is so opaque you might have to check the "robots.txt" or other well known files.
The start button, the difficulty level, making a move, and the admin panel all offer ways to test different inputs to see if you can get unexpected output.
What inputs do they accept? What headers do they have? What encodings do they use? Are there any input checks done client side rather than server side?
Then it becomes a matter of thinking about what happens with these inputs/outputs. Did it ask for a file name? What if I feed it a file it doesn't expect. Might this input be used for a database query, how could I abuse that? Could my input or the output be marshaled? Could my input be passed to an exec somewhere? Can I find artifacts that tell me what programming languages/servers/libraries are being used? How can I probe for these things?
The people who do these for fun several times a month will often make writeups that offer hints of techniques to solve problems when the competition is done.
These are some related sites:
See: http://wbec-ridderkerk.nl/html/UCIProtocol.html , https://github.com/official-stockfish/Stockfish/issues/3720
That said I don't think a strong chess engine alone would be enough to pass this puzzle.
A 500 is almost always a good sign when it comes to hacking. Hacking is the art of finding the difference between intended behavior and actual behavior. That is pretty much the definition of a 500.
I tried brute forcing the login admin panel but no luck yet.
What username should I use? I tried all the basic ones and cant get it to display anything besides "Invalid Login!".
What do you imagine the code that takes the logins eventually does? It seems likely that the username and password will end up in a query against a database to see if the user is valid and (theoretically) if the hash of the password matches the stored value.
What kind of input could you try to see if that behavior is done securely?
This is a good site to start learning about security: https://owasp.org/www-project-top-ten/
Injection will be the most immediately relevant.
I can't help but wonder how effective something like this actually is. I'm trying to not be overly negative, even though I have nothing nice to say about the company. I just find it really hard to believe that anyone would be sincerely excited to work at a place like Google.
I mean, I'm sure the pay and benefits are good for the moment, but it just seems like an unethical move, you know? Drug dealers make tons of money, but it doesn't really entice smart or ethical people to the profession in large numbers. Is wrapping it in some shallow webpage supposed to push people over the edge for some queer reason?
Similarly, there are lots of reasons why improving the security of google is a good thing _even if_ you think google itself is evil.
Especially when you consider the fact that a lot of stuff that Google security researchers do directly affects and influences (for the better, I'd say) the current industry too. See: Project Zero team, etc.
Disclaimer: I work at Google. Opinions are my own, etc etc
Yeah, and a lot of stuff that Google security researchers do directly affects and influences (for the worse, I'd say) the current (and future) users.
Disclaimer: I work on security there.
Assuming the ethical premise as given, you are really glossing over the difference in potential consequences between doing something unethical and something illegal. Specifically the part where the latter can leave you locked up for life.
Whether by ignorance, stupidity, or mere indifference I draw little distinction between ethics and legality. This isn't to say that there isn't a different, but rather that I mush both together because of the three points mentioned.
Generally speaking, just because something is legal should not make it right, in the same way that something being illegal, merely by the fact of it being written and codified, does not make it wrong. To put a point on it: I think that some of the actions that Google has taken should have and still should result in prison sentences. As far as I am aware, they have not. That being the case, I certainly would not classify a drug dealer who is not currently in prison being free of wrongdoing.
> but it just seems like an unethical move
Whether you can empathize with it or not you must realize that of course people are sincerely excited to work at Google?
As for the ethics, at Google security you may be in a position to have some of the largest impact on the most people's personal security. You can say "oh but Google sells ads based on that data" - OK, and you might have a serious problem with that, but the person who's making sure that malicious 3rd parties can't read the GMail accounts of journalists probably doesn't see that as a deal breaker.
A lot of people also don't have the luxury to make these choices based on a purely ethical basis. If you're sending money back to your family back home is it a straightforward ethical question of "well Google sells ads, so my family has to starve" ?
But the friendly 3rd party has no issue reading the GMail accounts of journalists. Remember the "Doctor" incident some months ago ?
and the point is that it's cold comfort getting protected from MITM when the person protecting you openly acts as a MITM
And to the journalists out there who are hypothetically using gmail to communicate with confidential sources: please stop.
Not always.
> And to the journalists out there who are hypothetically using gmail to communicate with confidential sources: please stop.
Uh, no.
Really? What circumstances lead from someone going from Googler to unemployable?
> Uh, no
Uh... because it's the best option available?
I didn't say unemployable. But maybe other jobs aren't paying as well or you don't have time to shop around.
> Uh... because it's the best option available?
It's a pretty good oen
Sure, but there's a lot of distance between "I would have to take a pay cut" or "interviewing is time-consuming"(?) and "I have to do this or my family will starve to death". If that seems like a high bar to pass, that's the one that you set.
I'm not necessarily criticising people's choice to work for Google. I'm definitely not saying that every Googler should quit immediately. What I am saying is that there are people out there legitimately doing jobs because the only other option is their family going hungry. Silicon Valley software engineers are not in that category.
> It's a pretty good oen
But if we're talking about journalists' ability to protect the information and identity of their confidential sources (again, a bar that you set), of all the options available, Gmail is not a pretty good one. And if you are dealing with information whose security can affect people's lives and livelihoods, then "pretty good" isn't the sort of standard you should be working towards anyway.
> But if we're talking about journalists' ability to protect the information and identity of their confidential sources (again, a bar that you set), of all the options available, Gmail is not a pretty good one.
I disagree. Gmail is an incredibly secure mail service and is a fine way to perform some communications - in particular, while something like Signal may be ideal, Gmail can have a much better UX around initial contact.
Even if it weren't, it really doesn't matter, journalists do use it and they are targeted. But again, journalists are just an example, there are hundreds of millions of people using gmail - protecting them is something one could very easily consider to be ethical.
I'm not disputing that people are supporting their families. I'm not disputing that finding another job is a PITA. The grey area that I am trying to demonstrate is that every single Googler has more career options than "continue working for Google" or "let my family starve to death"
> Gmail can have a much better UX around initial contact
I have no idea what this means. An email is an email, no?
> there are hundreds of millions of people using gmail
No argument there. And I'm not saying that securing their inboxes isn't worthy work. My original comment was directed to the hypothetical journalists who use Gmail for professional communication - it had nothing to do with the hundreds of millions of other users. They should be using E2E encrypted communications with confidential sources and encouraging their sources to do the same. That's just part of being a responsible professional in that line of work.
Literally just the very post before by you:
> What I am saying is that there are people out there legitimately doing jobs because the only other option is their family going hungry. Silicon Valley software engineers are not in that category.
This is incoherent.
Whatever point you're trying to make is not coming across and doesn't seem important. The initial point I made was that "is anyone excited to work for Google?" is a hilariously naive point of view both in terms of the obvious fact that they often are, and also in terms of a basic ethical framework. I gave examples. Nitpicking them isn't important because there are a million other examples.
I'm sorry you're having trouble following this. I agree that the original "nobody could be excited about working for Google" is a weird and most likely wrong assertion. But answering it by inventing a sub-class of Google workers whose only options are a) keep working for Google or b) let their family STARVE TO DEATH is not very helpful.
My original comment: I suspect that if you work at Google you have plenty of other career options before reaching the point where your family has to starve. really said it all. You have every right to be contrary, but it's more interesting if you stick to the topic and don't introduce fanciful edge cases.
Yes, there are Googlers who are supporting their families. No, that is not their only option.
Maybe there are journalists using Gmail for what should be confidential communication. No, they should not be doing that.
Call that nitpicking if you like, that's fine. They seem like simple, fundamental points to me. This thing that you've done a couple of times in this thread of refusing to see a very simple point and then complaining that it isn't "coming across" doesn't really do much to progress the discussion.
I can understand why some people wouldn't want to work at Google. I cannot understand how somebody couldn't understand how anybody would want to work at Google.
Maybe I'm a consequentialist and you're more of a deontologist? I see a big distinction between "I lost my money, my home and eventually my life" and "I feel my privacy has been infringed on at a conceptual level in the pursuit of ad sales". Do you think there are Google products out there that are actually harmful and ruining people's lives in a concrete way? I would love to hear about how, if yes.
The other interpretation is you have a much higher estimation of drug dealers than I do. No dramas with people dealing pot or pills, I'm talking meth and heroin.