Hacker News new | past | comments | ask | show | jobs | submit login
Defcon Badge Walkthrough (potatohatsecurity.tumblr.com)
120 points by aaronsnoswell on Aug 18, 2014 | hide | past | favorite | 23 comments



If I ever considered a transition into cryptography, this story just blew that idea up for me, forever.

I can't imagine trying to solve this! You'd have to love puzzles with an insatiable appetite to endure this.

Good job, team.


The sorts of crypto I've dealt with in more traditional contexts (Attacking a web application, etc), are very different from the skillset required for 1o57's badge challenge.

They're both a ton of fun, and an aptitude for one probably hints at an aptitude for the other, but I wouldn't discount yourself entirely, just because one writeup scared you off :)


The DEFCON badge challenges are definitely above and beyond what most people are expected to be able to do. It's also less about cryptography and more about general puzzle solving and recognition, though good crypto knowledge is just a necessity.

In other words, some of the world's best cryptographers would probably not be able to get past the first or second parts, let alone complete the challenge.


This kind of thing would make DefCon challenging for me, I'd get into the puzzles and not attend any of the talks as I tried to figure them out!


Like a lot of people, I find that while the talks are interesting, there are enough other things going on that are even more fun, so the talks definitely take a lower priority. I'd need 10+ instances of myself to have paid full attention to everything I liked at DC22.


I never bother with going to the talks while at DEF CON. Everything gets posted online afterwards, and there's enough going on outside of the talks, that I've never been able to justify actually attending them.


Taking the following line from the Cryptex we can decode our message.

BBVB4RCVARLU

This is whats called an OTP or One Time Pad encryption. http://rumkin.com/tools/cipher/otp.php

OTP cannot be decrypted unless you discern the unique pad.

They lost me here, how did this get figured out?


I also completed the badge challenge (Though a few hours after this team), and as far as I know, there was no hint as to which line of the cryptex was the OTP. We just knew, from the 'YQESMJDOJOTM' comment on the one page, that the cryptex was involved, so we tried every line as a key until we got something.

1o57 tends to design most of his puzzles around similar ideas, so you just start to get a feel for how he works after a while.


Are the ideas similar enough that some of the steps could be automated?


Yes. I'm working on a pet project called F0UND that's meant to automate as much of the badge challenge as possible. There will still be a lot of human effort involved, but I think a lot of the information gathering and cross-referencing can be automated.

Next year the black badge will be mine, whatever it takes.


The winning team did a writeup on the event and how one of the sections they used automation to solve. I think it was a Vigenère cipher.


See the end of step 4e --

From a picture on the Cryptex: http://imgur.com/a/OE26v#15


Loved reading this. Some incredible reasoning, even being shown the answer there are multiple stages I can't follow the reasoning that allowed them to progress. Kudos, respect, and jealousy!


Great Walkthrough. How long did it take to get through the challenge?


The contest starts when you get your badge Thursday morning (8:00 AM - 3:00 PM depending on the line), and the team that won this year finished at about 6:00 AM on Saturday.


I love the use of Google's Latin-English dictionary. Which amazingly also includes the word microwave.


The absurdity of Google Translate's Latin-English output was discussed in a related item: https://news.ycombinator.com/item?id=8191462

...and I agree that for this to be used in the puzzle, is extremely clever if not somewhat fragile (it doesn't work anymore.)


That was kinda insane! Now I have to wonder just how many bits of random stuff get handed out to Defcon attendees that might or might not be part of some sort of puzzle like this.


I can't believe someone solved this. Champion effort.


This made my head spin. Fun ride! I'm always in awe of crypto guys. Truly, their mind works in a different way!


I loved this article.

Unfortunately I now have a burning urge to rejoin TBW ARG which I thought I had escaped from :(


Very impressive.


Holy shit.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: