Hacker News new | ask | show | jobs
by xg15 25 days ago
This is amazing!

Currently you can "cheat" by simply denying all requests as quickly as possible. This will give you the "security-conscious engineer" badge and a perfect score in terms of how many requests were processed. (You will get the "overblock" notification, but it's somewhat tucked away at the bottom and the screen still looks as if you won)

I also tried to play as the hustle4lyfe move fast and break things engineer and simply approved as many requests as quickly as possible - turns out, the "malicious command" popups actually slow you down. Mean!

2 comments

Good catch, this has now been nerfed and this approach has gotten its own title
Actually, the only secure default is to deny everything...how do you know that innocent command is actually innocent?
A strange game. The only winning move is not to play.
It’s the security mantra: the safest code is the one you never release. Code that never runs is the most secure code
A computer is only secure if it remains powered off and airgapped.
Turn off your computer and make sure it powers down

Drop it in a 43-foot hole in the ground

Bury it completely, rocks and boulders should be fine

Joshua
Would you like to play a game?
Top 18%! I denied everything, unless I could see at a glance that it was safe (like Git diff)
Glad I could help. I love the new title :D
Just like real life! deny it from doing anything and you're safe :)