security run · changelog

# Hack My Hermes — security run changelog

An honest, running log of how the walls change. Newest first.
Edit /etc/nixos/arena-changelog.md to add entries.

## 2026-09-11
- **Now with traceroute.** The path out is deliberately visible again — a TTL walk
  from inside a guest shows the real hops (host → wg → VPS → cloud), each named by
  the authored PTR breadcrumbs. The ICMP type-11 drops are gone.
- **Open internet for all players.** Every arena now reaches the open net for real,
  but only out the wg0 "hop of faith" — never a sibling, the host, or the tunnel
  endpoint. Every new connection is logged. Real DNS resolves for real; the decoy
  plane / honeypot / echo-room stay reachable by IP.
- **No real IP on any public surface.** /history now returns a locked opaque hash
  in place of the client IP and no longer leaks the routing token.
- **Splash:** community discord, subnet primer, the MSRC Hyper-V bounty this rehearses,
  a live status light, a canary-probe counter, a reroll button, and feedback.
- **Admin status console** at /admin (own token): set the red/yellow/green light
  players see on the splash.

## 2026-09-10
- Token scoreboard: durable grand-total "tokens burned" on the splash, plus a
  per-session snapshot written at teardown before the key is revoked.
- Traceroute mask (since reversed above); tmux scroll-trap fixed.

## 2026-09-09
- Subnet renumber (10.241.10-13 → 110-113) to escape the shared-netns route hijack.
- Dual-firewall discovery + guest-/24 honeypot (.224/27, ping-alive, canary-fed).
- Flag/keyhole plant fixed to target the guest (.2), not the host tap (.1).
- Service ports moved off the obvious ones: LiteLLM 4000→61697, front door 8080→58315.
- Real JFrog Artifactory OSS added as an in-box, on-claim target.
- Hermez persona + orientation (Spectre/side-channel = report-don't-exploit boundary).

## 2026-09-08
- Arena goes live: per-session budgeted LiteLLM virtual keys as the key boundary,
  the derived d0-d6 FIRESALE flag ladder (HMAC over a host-only salt), the 4R73MI5
  model alias, the canary (:9998) + gateway echo-room + 10.242 decoy plane.
- **Sudo made available as a target.** Arena players get a real sudo password to
  earn via the puzzle chain; fleet agents stay locked.

## 2026-09-03 / 04
- A container agent read the whole host /nix/store out of a shared mount → lockdown,
  then migration off systemd-nspawn onto KVM microVMs with a private per-guest root.

← back to the doors