342 karma · joined July 18, 2012
The UK isn't some pauper state where everyone's living on the breadline, we just take a different approach to the USA.
[edit] replaced GDP with PPP for better clarity/relevance.
Yes, farmers pump animals full of chemicals and this should be documented and, if you are concerned about this, it's a good thing that there are organic food certs out there. However, whole industries fuelled by bullshit have sprung up off the back of this very common fallacy. There are people out there who don't take scientifically-proven medicine because it's "not natural" and lean towards quackery like homeopathy, and this is what I'm opposed to.
To reiterate, IMO organic or free-range farm produce is a good thing and I'm sure most people would agree with that. That's not what I was talking about so don't get rude with people based on a misinterpretation of the subject, it's unnecessarily disruptive.
The bit about RSA aiding the NSA is spot-on though, if dual EC DRBG is in fact backdoored.
In terms of education, the real thing is more interesting - check out places like hackthissite.org or smashthestack.org for some real life (ish) hacking in a contained environment. Hold your breath though as the smell of teen angst may overpower you on some of these sites.
one UI thing that came up for me - going through the university pages, it wasn't totally clear that the green buttons were actually a "next" button. After I read the software page, I saw the green button said "what if I need help?", thought it was a help button and decided that since I couldn't find a next button, I was free to start playing. Confusion set in when the homepage sent me back to the tutorial.
[edit] in terms of a fix, a simple » or other arrow-icon might fix this
also a few little suggestions that I hope you'll like (as I like this type of game, a lot!):
- Maybe represent the user's balance purely in BTC? the idea of paying hackers in bank transfers seems a little insecure for a security game :)
- You might run into race conditions when editing logs, depending on how it's implemented on the backend - maybe just a checkbox next to each line to quickly delete lines relevant to you? this might ruin some of the fun possibilities re. dropping other people's IPs into logs though.
http://en.wikipedia.org/wiki/Little_Eichmanns
This ties into the concept of the "Banality of evil" which plays out pretty much exactly as you described.
I'd rather have ample documentation on how to harden my PHP application than no documentation on how to harden my Node application. Security through obscurity is no security at all. Plus, many of the mitigation strategies are simply rules like "don't use mysql_query" or "use htmlentities with ENT_QUOTES and UTF-8 to escape your output", both of which can be built into a framework. See: laravel.
[edit] downvoting is much easier than formulating a response, isn't it?
[edit]
to clarify, the reason I made this comment is to note a case where this strategy has been used in history, as mentioned by the parent post. Not to compare Obama/Bush to Hitler.