frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Frontier AI has broken the open CTF format

https://kabir.au/blog/the-ctf-scene-is-dead
47•frays•1h ago

Comments

walletdrainer•25m ago
>I started playing CTFs in 2021

>and the old game is not coming back

For many people the CTF scene was already dead in 2021 because it had turned into something unrecognisable.

In reality it’s just different.

lukan•20m ago
Well, I had to google what CTF means (capture the flag, a hacking competition), so surely cannot judge here, but the text indicates that with AI some things are very different today:

"That makes open CTFs pay-to-win. The more tokens you can throw at a competition, the faster you can burn down the board. Specialised cybersecurity models like alias1 by Alias Robotics are becoming less relevant compared to general frontier LLMs. The competition is turning into "who can afford to run enough agents, with enough context, for long enough.""

mock-possum•7m ago
Isn’t that the bitter lesson in a nutshell? “Specialised cybersecurity models … are becoming less relevant compared to general frontier LLMs.”
Grimburger•1m ago
>Learning about eternal September in May 2026

Hits different doesn't it

deafpolygon•23m ago
Unrelated, but does anyone find this site incredibly hard to read?
walletdrainer•22m ago
Bizarre font and poor contrast, yep.

The text itself being exceedingly long for no obvious reason doesn’t help.

lukan•17m ago
Poor contrast? White on black?

And if you think it was too long, what part would you have shortened? I never knew about the scene and found it interesting to read this personal take on it.

tromp•19m ago
https://en.wikipedia.org/wiki/Capture_the_flag_(cybersecurit...

still has no mention of AI, but that will likely change as they increasingly dominate competition.

vasco•19m ago
My first ever was Stripe CTF in 2012 I think, I still wear the shirt I got (now super fainted) from passing some challenges. I was a student in portugal and remember receiving the shirt for it and thinking, maybe those Americans aren't any better than me and I can compete at the same level.

I never got super into security but it gave me the confidence to play in the same field and lose the stupid aura I had that somehow "rich americans" would be better than me at everything because they had better universities or because of Hollywood or something.

Sad that another cool thing is lost to AI but I guess kids will learn in other ways.

chvid•19m ago
What is CTF? And why is the cyber security world filled with silly gaming references?
throwa356262•12m ago
https://en.wikipedia.org/wiki/Capture_the_flag_(cybersecurit...

Its a war game reference I guess?

mort96•7m ago
Capture The Flag is a cybersecurity game where the organizers set up a bunch of intentionally vulnerable computer systems with a "flag" on them, a string that's "supposed to be" secret but is accessible through exploiting the vulnerabilities. This may be a line in /etc/password, a string in memory, a field in a database, whatever. The goal of the game is to hack into the computer systems, find ("capture") the flag, then copy/paste it into the organiser's scoreboard website to prove that you solved that particular challenge.

It's pretty fun. Or at least it was, back when you had some sense that your competitors were competing on an even playing field and just beat you because they were better than you.

I wouldn't say the name is a "gaming reference", it's just a descriptive name for a game.

monarx•17m ago
used to see some really good CTF videos show up on youtube and now nothing like that shows up on the feed
susam•16m ago
I have normally found any sort of timed technical competition intimidating. Even so, about 6 or 7 years ago, after being persuaded by a colleague, I participated in a few CTFs. I am glad I did, back when this type of thing still meant something. I have kept a screenshot from one of the CTFs that I am quite fond of: https://susam.net/files/blog/ctf-2019.png
hmmmmmmmmmmmmmm•7m ago
Isn't this like saying "Chess is dead" because we have chess engines? Why not just ban the usage of LLMs?
eecc•7m ago
“solve”, why not solution? Like “spend” and not expenditure, why use the verb as a noun and not care about grammar?
iainmerrick•1m ago
They’re shorter.

Why so pedantic?

kevinsimper•4m ago
You could make it offline and with provided laptops only, just like with the competitive CS2 scene.
rurban•3m ago
I don't do CTF's but took part at the security workshop for fun ~2 years with my Android phone only. I was first with the first simple challenge, but then couldnt continue because my phone was just too limited. But I watched what the others did. And a young Indian guy did everything with ChatGPT then. I found it silly, but amusing, because he actually got second. There was no Codex nor Claude then. Nowadays it must be dead for real, because I would solve everything with my agents, as I do in the real world.
Grimburger•3m ago
Very impressed that OP has gone from starting university in 2021 to becoming a Senior Security Engineer.

It's an incredibly exciting time in security research in my humble old man opinion. Think it's a shame if others can't see that.

himata4113•2m ago
I was writing an obfuscator recently, I just had the model deobfuscate and optimize the code back to original and I kept improving the obfuscator until it couldn't. The funny thing is that after all this I also ended up with a really strong deobfuscator and optimizer which is probably more capable than most commercial tools.

The solution is just to make CTFs harder, but when do CTFs become too hard? Maybe the problem is that 'hard' CTFs are fundementally too 'simple' where it's just a logic chain and an exhaustive bruteforce towards a solution since there really are limited ways to express a solution in plain sight.

Or maybe human creativity has been exhausted and we're not so limitless as we thought. Only time will tell.

amingilani•2m ago
I don’t think CTFs are dead, they’ll just evolve. The difficulty level will need to be increased or the rules locked down. Just like sports and racing persist despite the existence of performance enhancing drugs and rocket technology.

I just did a CTF where I was in the top 10. It was the first CTF I completed and I used AI because the rules permitted it. That said, I couldn’t solve all challenges.

But yes, it was significantly easier now than I last attempted one. Even manually solving with AI assisted assembly interpretation was much easier.

Six Million Selections Later: How the DMA Is Giving People Browser Choice

https://blog.mozilla.org/netpolicy/2026/05/11/six-million-selections-later-how-the-dma-is-giving-...
1•naves•3m ago•0 comments

Making Deep Learning Go Brrrr from First Principles

https://horace.io/brrr_intro.html
1•tosh•3m ago•0 comments

Electronics engineer – neurotech – London (hybrid/remote)

https://netholabs.com/electronics_engineer_812
1•catubc•7m ago•1 comments

Why Stanford Says AI Agents Become Marxist

https://www.flyingpenguin.com/why-stanford-says-ai-agents-become-marxist/
2•feigewalnuss•12m ago•0 comments

Palestinians forced to demolish own homes to make way for Israeli theme park

https://www.theguardian.com/world/2026/may/16/palestinians-demolish-family-homes-jerusalem-kings-...
2•hebelehubele•14m ago•0 comments

A message from kurdistan – my love for China and DeepSeek

https://old.reddit.com/r/DeepSeek/comments/1tadbm6/a_message_from_kurdistan_my_love_for_china_and/
1•chewz•15m ago•0 comments

Your VPS Is a Sitting Duck

https://github.com/rockballslab/vps-secure
1•rockballslab•18m ago•0 comments

Is Bitwarden Getting Enshitified?

https://www.fastcompany.com/91542655/bitwarden-scrubs-always-free-and-inclusion-values-from-its-w...
1•bobek•24m ago•1 comments

Experience Layer for AI

https://cortexdb.ai/blog/v1
1•prmalik•27m ago•0 comments

Pretext – pure-arithmetic text measurement for proportional fonts

https://somnai-dreams.github.io/pretext-demos/
2•Teever•32m ago•0 comments

TunnelForge, a L2TP client for Android 12

https://github.com/evokelektrique/tunnel-forge
1•femdiya•33m ago•0 comments

The Whitepaper Thunderdome: HAGE vs. Storage Is Not Memory

https://medium.com/@vektormemory/the-whitepaper-thunderdome-hage-vs-storage-is-not-memory-8a76fd6...
1•vektormemory•40m ago•0 comments

Why birth rates are falling everywhere all at once

https://www.ft.com/content/fba35eca-df3a-4ad6-b42d-eb08eb7c9ad3
2•quick_brown_fox•43m ago•0 comments

Trump warns Taiwan against declaring independence

https://www.bbc.com/news/articles/ce8p61v7l68o
2•vrganj•44m ago•1 comments

$2B Conflict: Sam Altman "Side Hustles" Are Now Center of a Legal Warzone

https://www.gadgetreview.com/the-2-billion-conflict-sam-altmans-side-hustles-are-now-the-center-o...
1•g42gregory•45m ago•0 comments

Sense Humans with WiFi – Ruview

https://cognitum.one/RuView#capabilities
1•unixhero•46m ago•0 comments

Goodbye Travel Agents, Hello AI Agents

https://blog.denv.it/posts/goodbye-travel-agents-hello-ai-agents/
2•denysvitali•47m ago•0 comments

Do High-Quality EDC Knives Justify Their Price Gap?

https://www.paragon-knives.com/
1•bgzlsxaz•49m ago•0 comments

Jjw: A Workspace Manager for Jj

https://aran.dev/posts/introducing-jjw-jj-workspace-manager/
1•aranw•53m ago•0 comments

Show HN: New release of jd-GUI-duo 2.0.112 is out

https://github.com/nbauma109/jd-gui-duo/releases/tag/2.0.112
1•nbauma109•54m ago•0 comments

InclusionAI/Ring-2.6-1T is now open-sourced

https://huggingface.co/inclusionAI/Ring-2.6-1T
1•gainsurier•55m ago•0 comments

The Quiet Renovation at Bitwarden

https://blog.ppb1701.com/the-quiet-renovation-at-bitwarden
1•RyeCombinator•56m ago•0 comments

OXP – Write one WASM extension, run natively in VS Code, JetBrains, and Neovim

https://oxp.sh/
2•aldgar•58m ago•0 comments

The Download: deepfake porn's stolen bodies and AI sharing private numbers

https://www.technologyreview.com/2026/05/14/1137257/the-download-deepfake-porn-bodies-ai-exposing...
3•joozio•59m ago•0 comments

Frontier AI has broken the open CTF format

https://kabir.au/blog/the-ctf-scene-is-dead
47•frays•1h ago•23 comments

QuantumGuard – Free Quantum

https://quantumguard.site
1•pavan6599•1h ago•0 comments

Nested Callbacks (2013)

https://blog.michellebu.com/2013/03/21-nested-callbacks/
1•cod1r•1h ago•0 comments

Global News Reporting Briefs

https://www.worldbrief.info
1•reader9274•1h ago•0 comments

Asynchronicity in Continuous Batching

https://huggingface.co/blog/continuous_async
1•eigenBasis•1h ago•0 comments

MiniPlasma, a Powerful LPE

https://deadeclipse666.blogspot.com/2026/05/miniplasma-powerful-lpe.html
1•geekone•1h ago•0 comments