On the quality of recent boxes...

While I generally agree overall with the sentiment expressed by the creator of this thread, I have spent some time ruminating about the CTF-y boxes I’ve encountered on the HTB platform. Attempting to find a silver lining to my “try harder” and “just enumerate more bro lol” struggles, I have come to the conclusion that the CTF-y boxes (for better or worse) what they produce in frustration and rage they also produce a corresponding amount of required social interaction on the platform - think forum posting and trading clues on various boxes in the current mix. So it is important to consider the social aspects of CTF boxes and what they provide to the HTB platform.

One sentiment brought out by this discussion that I think is worth it to consider moving forward is that CTF style challenges can be very off-putting to both beginners trying to learn basic techniques to build confidence and seasoned veterans trying to practice their skills so as to not get rusty. Currently, there is no way of telling how a box will be without reading its forum thread. For example, imagine a rating system for boxes that had 4 categories (beginner / intermediate / advanced / expert) - there should be no CTF-y elements in the beginner category, and only VERY sparingly introduced at the intermediate level. Advanced level boxes are where a hacker can be expected to have the base knowledge / google research / social skills required to solve the CTF and know to approach the problem from different angles until the correct answer is identified - along with “earning” the satisfaction of solving it. Expert level is fair game for anything goes IMO - but extreme examples like getting user requires being forced to “guess” reconstruct a one-time pad encryption key for an encrypted archive stegoed into an image of a donkey will be policed by the HTB community (as evidenced by this thread) and the creator will suffer the consequences accordingly.

That being said, I do think an easy-to-use binary choice system like (CTF | REAL) with a percentage total of votes should be implemented alongside the thumbs up | thumbs down after rooting a box. But along with that - I think the ability to vote on the box should be delayed by a day or two after completion so you have time to reflect on your experience and what you learned before providing feedback.

edit : tl;dr there is a balance between Realism and CTF and it must be maintained - have HTB management implement a rating system and reevaluate the state of affairs after an appropriate amount of time.