If your infosec training / CTF lab is buggy and slow, instructions have typos, and usability is crap because you haven’t like, set VM resolutions right, you are actively people away from this industry right when we should be hooking them. If you think I’m subtweeting you, I am.
-
-
Prikaži ovu nit
-
Even after years I sometimes have to go recertify on something. And sometimes despite all my command line and security knowledge I get stymied by systems crashing and losing my work, 3 second typing latency into VMs, CTF questions that spell commands wrong unintentionally.
Prikaži ovu nit -
If I’m pissed off waiting on busted lab VMs to reboot, even though I can shortcut flags because I know answers and can get around the command line with cat and grep to do things faster, and I know you misspelled a question, how does a young person dipping their toes in feel?
Prikaži ovu nit -
Let’s set a few basic ground rules for labs / open CTFs? Feel free to add... - Ensure there is a clear support mechanism if key machines or networking break - Ensure the environment can work okay under load - Ensure instructions and flags involving command are spelled right
Prikaži ovu nit -
- Ensure output is within expected bounds every time an specified input is received - Ensure the system doesn’t unexpectedly drop competitor or student process under normal conditions - Ensure there is some way for students to take breaks without fearing losing their progress.
Prikaži ovu nit -
I am going to stop because I’m pretty irate right now, but please... Labs and CTFs are where most whitehats pop their first box. They get shell for the first time and everything changes. They see how powerful nmap or powershell can be. Let’s not screw up those defining moments.
Prikaži ovu nit -
I never would have thought so many people would fight me about not making bad educational cyber ranges and training labs. That’s Twitter for ya

Prikaži ovu nit -
Sorry I went on a tear yesterday. I had to do a CTF for a supposedly solid certification in my very precious little free time, and I lost an hour and forty minutes troubleshooting VM networking and spontaneous latency and resets. It was disheartening.
Prikaži ovu nit
Kraj razgovora
Novi razgovor -
-
-
it's not the same thing but we've been bitching for years about the quality of the CCIE Lab environment - you pay 1600 for non-tabbed Putty to run 30 devices, and for a long time, one monitor - and the crappiest Logitech keyboard known to exist (I bought one for practice)
-
And CCIE is probably the most kind example of this because you are supposed to be incredibly competent and random things are supposed to break haphazardly. Yet still!
- Još 1 odgovor
Novi razgovor -
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.