Foobar
google.com
google.com
Why do I find it irritating? Because it seems both elitist and adolescent, in a child-like "secret society" sort of way.
That pretty much sums up the people I have met that work in Google engineering. I have only met a few at conferences, but thanks for putting words to the initial feelings I got from them all.
On google search, you have the variable window.location.search = "?gfe_rd=cr&ei=XXXGyZiVNHoFcuF8Qe7wYHACw&gws_rd=ssl"
That string is appended to the url of the iframe: src="https://foobar.withgoogle.com/"+window.location.search
The code snippet will only load the URL with appended values if there are present in the parent URL: e.g. https://www.google.com/foobar/?some_query_string
If your Google searches are not linked with your Google account or if you search using different search engines, you're out of the game.
EDIT: Turns out you need a history of googling this stuff. My heavy Python phase in school was timed wrong it seems.
I'm not signed in to Google as a matter of course, and I block their ads, so I provide them very little value. As a result, I won't be able to use "foobar", whatever the hell it is.
Seems fair. Isn't really that irritating, is it? :-)
Has it occurred to any of you that we might do these things for sheer fun, because doing that is not only allowed but celebrated?
> 11 hours ago
Also, there are a lot of rabbits.
https://history.google.com/history
Also, it is possible that the url once you actually enter is different and that may be sufficient to get in.
Thanks!
Seems like you need to be "invited".
Why should any company be forbidden from utilizing assets their employees legally developed, especially when they want to use that asset in pursuit of a key objective ("hire more smart people")? Should a large newspaper be forbidden from advertising their openings in the printed newspaper itself just because other newspapers failed to acquire comparable audience?
On a personal level, I really don't like "we hire Python devs if you search on Google for python topics," but that's separate from saying there is a legal challenge here.
https://play.google.com/store/apps/details?id=com.paramount....
Note also that the application bounces you to /_ah/logout on deny. That is an admin URL within Google App Engine applications. I figure everything on "withgoogle.com" is hosted by GAE?
I checked waybackmachine for mirrors of older versions of the site, perhaps when it had more clues. Nothing. I did direct it to archive foobar.withgoogle.com though, since they did not yet have it cached.
When I arrived, not a single one of the 5 technical interviewers I dealt with used Python and seemed to think I was crazy to be interviewing with Python. Needless to say, I did not receive an offer.
That way, any hacker news people who would like to do so can.
Sure people could enable google search history and google random python stuff, but any privacy minded hackers will have that disabled permanently ( as I do ). I'd like to note that I actually googled python lambda's myself recently, attempting to ascertain whether "lambda:0" is really the shortest way to make an empty object in python...
The fact that google themselves hasn't commented on this hacker news thread itself is somewhat disappointing to me.
In what sense does "lambda:0" create an empty object? And how is it better than "object()"?
I believe this app/page is part of that push. Bunch of problems to complete.
"""But those buildings aren't ready for Google to occupy yet, and the first of the Sunnyvale buildings won't be completed until sometime in 2015."""
If you append /login to the url, you get another script:
Points to:
https://foobar.withgoogle.com/_ah/logout?continue=https://ww...
I've tried some ways to login to appengine etc but didn't work.
https://appengine.google.com/_ah/logout?continue=https://foo...
I've managed to get it to log me out of my google account. Not sure what's up.
<span class="term-red">Error(6): Login unavailable. Try again later.</span>
https://appengine.google.com/_ah/conflogin?continue=https://...
Throws a 500 error.
Same thing here... I'm guessing that Google figures anyone cynical enough not to trust Google implicitly is a less desirable potential hire.
You get a terminal, from the terminal you request coding challenges. They have a minimal IDE to code in. Choice of language is Java or python. Only tried one challenge. YMMV
The logins are being handled by an endpoint on AppEngine called 'ah'. Also this mysterious url: https://appengine.google.com/_ah/
Though there is definitely some semblance of it being a game, the iframe contains a reference to CSS file called rhgame.css.
There doesn't seem to be any avenue to log yourself in, by the looks of it they first send people to a registration URL of some description (probably a redirect from a specific set of search terms or something similar).
I am not really one for doing the kinds of puzzles where you just shoot in the dark for a while.. if there were actually clues/riddles hidden in the HTML/JS/CSS or similar then I would have alot more fun with it.
They are story problems. The first one is cycle detection for a singly-linked list. After solving that, you can request another (time remaining is reset). In the math category, its a subset sum problem: http://pastebin.com/SEZXhKHY
var g=document.getElementById("g");g.src="https://foobar.withgoogle.com/"+window.location.searchAll that bit of code is doing is ensuring the frame on the page gets passed the query string the outer page had.
E.g. https://www.google.com/foobar/?hello -> https://foobar.withgoogle.com/?hello
Stay away. They would just waste your time.
logoutUrl: 'https://foobar.withgoogle.com/_ah/logout?continue=https://ww...
It'd be amusing if it was a social experiment to see how many devs/wannabe devs frantically searched for Python topics after this foobar site was discovered. Like a contrast MRI to illuminate the people who wanted a job at Google.
https://foobar.withgoogle.com/staticfiles/css/rhgame.e6cf5ce...
.console {}
.prompt {}
.terminal {}
.cmd .cursor.blink { -webkit-animation: blink 1s infinite steps(1,start); animation: blink 1s infinite steps(1,start) }
But it seems I've already failed before even clicking on the Login link:
<div class="error">...</div>
[1] http://www.theverge.com/2014/10/7/6927605/welcome-to-endgame...
also found the rhgame reference in css...
edit: here https://news.ycombinator.com/item?id=8590018
https://foobar.withgoogle.com/staticfiles/js/landing.5252068... : !function(){ "use strict"; function a(){ var a=document.getElementById("login"); a.addEventListener("click",function(a){a.preventDefault(),window.launchPopup()},!1)} window.handleAuth=function(a){ a.logoutUrl ? window.location.href=a.redirectUrl : window.location.reload() }, window.launchPopup=function(){ window.open("/login/","AppLogin","resizable,scrollbars,status,width=600,height=400") }, a() } ();
This script handles the login. a object looks something like this : Object { message: "<span class="term-red">Error(6): Login unavailable. Try again later.</span>", logoutUrl: "https://foobar.withgoogle.com/_ah/logout?continue=…ps://foob..., redirectUrl: "/denied/", allow: false}allow: falselogoutUrl: "https://foobar.withgoogle.com/_ah/logout?continue=https://ww...: "<span class="term-red">Error(6): Login unavailable. Try again later.</span>" redirectUrl: "/denied/" }
handleAuth() function will either take you tohttps://foobar.withgoogle.com/denied/ or just reload the page.
Google is just getting a tonne of analytics data.
I imagine that when you login with the right user account a different redirectUrl would get passed back.
I see no way of finding that out what that URL is though, short of someone who has access to the puzzle posting it.
<p class="profile-name"></p> <form novalidate method="post" action="https://accounts.google.com/ServiceLoginAuth" id="gaia_loginform"> <input name="GALX" type="hidden" value="5tczTdlnWNs"> <input name="continue" type="hidden" value="https://appengine.google.com/_ah/conflogin?continue=https://... <input name="service" type="hidden" value="ah">
'questions'
'terminal', 'console'
'editor', 'ace_editor'
'count_down_timer', 'prompter' and 'resizer'
and the media rules for mobile, laptops, desktops
Perhaps if one can avoid preventDefault the object login may has some href to the real login. Just guessing.
Which opens https://foobar.withgoogle.com/login
There, an object a:
a = {
message: '<span class="term-red">Error(6): Login unavailable. Try again later.</span>',
logoutUrl: 'https://foobar.withgoogle.com/_ah/logout?continue=https://www.google.com/accounts/Logout%3Fcontinue%3Dhttps://appengine.google.com/_ah/logout%253Fcontinue%253Dhttps://foobar.withgoogle.com/denied/%26service%3Dah',
redirectUrl: '/denied/',
allow: false
}
Is passed to the original window's handleAuth function:window.handleAuth=function(a){ a.logoutUrl?window.location.href=a.redirectUrl:window.location.reload()}
It seems that the allow property of the object passed is never checked :(
window.handleAuth=function(a){ a.allow = true; a.logoutUrl?window.location.href=a.redirectUrl:window.location.reload()}
and then click the button.
But it won't help for the reasons explained above.
anyway, it doesn't look relevant to me.
/staticfiles/svg/error.33ab1eb5.svg -> 33ab1eb5 hexadecimal is 866852533, which seems to be a prime number.
I believe the probability is very low if unintended. Also other file names, can be factored more or less to 1 big prime number and few small primes.
e6cf5ce7 67a53a45 5252068f
sh-4.3$ md5sum error.33ab1eb5.svg
33ab1eb5129ee5085793166d2f691dae error.33ab1eb5.svg
I believe the point of appending them to the name is a kind of versioning: one'd want to be able to change these files and cause everyone to drop their cached version. This way when one changes a file, the filename changes too (most likely), so the cached old version will not be used.It looks like they're using Django. You can configure it to add the md5 of static files to each name. [1]
[1] https://docs.djangoproject.com/en/1.7/ref/contrib/staticfile...
But, isn't Google the same company that we're always reading about, the one shaping up to be one of the most evil entities humanity has ever seen? After all, they pretend to protect net neutrality until it's their turn to play ball. They pretend to be pro-freedom, anti-big-brother (maybe you should read a bit about what Julian Assange has to say about Larry Page and Google in general, in case you missed all that), and anything else that will help them gain traction in the minds of the public, especially the techy youth.
They always just want to help, don't they. They're so thoughtful... Now, Google wants to put tiny electronics in our blood... what's next?
My point is, why would anyone want to support such a company? I suppose humanity had supported many bad things. Maybe my convictions don't match up well with the rest of the US anymore.
quite an assertion.