security run · changelog
# Hack My Hermes — security run changelog
An honest, running log of how the walls change. Newest first.
Edit /etc/nixos/arena-changelog.md to add entries.
## 2026-09-11
- **Now with traceroute.** The path out is deliberately visible again — a TTL walk
from inside a guest shows the real hops (host → wg → VPS → cloud), each named by
the authored PTR breadcrumbs. The ICMP type-11 drops are gone.
- **Open internet for all players.** Every arena now reaches the open net for real,
but only out the wg0 "hop of faith" — never a sibling, the host, or the tunnel
endpoint. Every new connection is logged. Real DNS resolves for real; the decoy
plane / honeypot / echo-room stay reachable by IP.
- **No real IP on any public surface.** /history now returns a locked opaque hash
in place of the client IP and no longer leaks the routing token.
- **Splash:** community discord, subnet primer, the MSRC Hyper-V bounty this rehearses,
a live status light, a canary-probe counter, a reroll button, and feedback.
- **Admin status console** at /admin (own token): set the red/yellow/green light
players see on the splash.
## 2026-09-10
- Token scoreboard: durable grand-total "tokens burned" on the splash, plus a
per-session snapshot written at teardown before the key is revoked.
- Traceroute mask (since reversed above); tmux scroll-trap fixed.
## 2026-09-09
- Subnet renumber (10.241.10-13 → 110-113) to escape the shared-netns route hijack.
- Dual-firewall discovery + guest-/24 honeypot (.224/27, ping-alive, canary-fed).
- Flag/keyhole plant fixed to target the guest (.2), not the host tap (.1).
- Service ports moved off the obvious ones: LiteLLM 4000→61697, front door 8080→58315.
- Real JFrog Artifactory OSS added as an in-box, on-claim target.
- Hermez persona + orientation (Spectre/side-channel = report-don't-exploit boundary).
## 2026-09-08
- Arena goes live: per-session budgeted LiteLLM virtual keys as the key boundary,
the derived d0-d6 FIRESALE flag ladder (HMAC over a host-only salt), the 4R73MI5
model alias, the canary (:9998) + gateway echo-room + 10.242 decoy plane.
- **Sudo made available as a target.** Arena players get a real sudo password to
earn via the puzzle chain; fleet agents stay locked.
## 2026-09-03 / 04
- A container agent read the whole host /nix/store out of a shared mount → lockdown,
then migration off systemd-nspawn onto KVM microVMs with a private per-guest root.
← back to the doors